Persistence
Get a foothold first !
Disable Defender
AMSI Bypass
Golden Ticket
Execute mimikatz on DC as DA to get krbtgt hash
Create a ticket on any machine - pass the ticket attack
List Kerberos services available
To use the DCSync feature for getting krbtg hash execute the below command with DA privileges
Silver Ticket
Execute mimikatz on DC as DA to get krbtgt hash
Using hash of the Domain Controller computer account, below command provides access to shares on the DC
Skeleton Key
Use the below command to inject a skeleton-Key
access any machine with valid username and password as mimikatz
In case LSASS is running as a protected process, we can still use Skeleton Key but it needs the mimikatz driver (mimidriv.sys) on disk of the target DC
Last updated