githubEdit

Silver Ticket

Fake TGS we make it to access on specific service

We can use it when we have NTLM Hash for Service account (MSSQL, HTTP)

circle-check

to do forged Silver Ticket we need to

  • Password hash for the service Account

  • Domain SID

  • SPN

or we need to

  • Machine's NTLM hash

  • Domain SID

  • Hostname of Computer

  • user to impersonate

circle-check
.\Rubeus hash /password:P@ssw0rd
image.png

then domains SID

GET SPN

Launch the attack

Last updated