Pass-the-Ticket for Lateral Movement
Requirements
- Credentials (password, RC4/NT hash, AES key, kirbi file) of the target domain user.
Having the credentials of a domain user, we can ask the DC for a new TGT for that user and inject it into the current logon session. This TGT is then used for authentication (e.g. using winrs
or accessing SMB shares) with privileges of the target user.
Watch out for domain name! It's very important in TGT request to use FQDN (e.g. adlab.local
instead of adlab
). Even if shortcut normally works, use FQDN in this case.
Windows:
IMPORTANT: Only one TGT can be applied at a time to the current logon session, so the previous TGT is wiped when the new ticket is applied when using the
/ptt
option. You can omit the/ptt
parameter to save the TGT to a file (not inject it into memory) and use it later.
Linux (request TGT and save it to .ccache
file):