Pass the Ticket from Windows
Kerberos
Pass the Ticket (PtT) - Windows
Overview
π Kerberos Protocol Refresher
Authentication Flow
π Scenario
π Harvesting Kerberos Tickets (Windows)
π₯ Using Mimikatz
π₯ Using Rubeus
π Extracting Kerberos Keys
Mimikatz - sekurlsa::ekeys
sekurlsa::ekeysπ§ͺ OverPass the Hash (Pass the Key)
Mimikatz
Rubeus
π« Pass the Ticket (PtT) with Rubeus
Method 1: Request and Submit TGT
Method 2: Import .kirbi File
.kirbi FileMethod 3: Use Base64 Encoded Ticket
Convert .kirbi to Base64 with PowerShell
.kirbi to Base64 with PowerShellπ« Pass the Ticket (PtT) with Mimikatz
π» PowerShell Remoting + PtT
Prerequisites:
Mimikatz Flow:
Rubeus Flow:
Last updated