Golden Ticket
Last updated
Last updated
user: is the username to impersonate (any user)
domain: is the FQDN of the current domain
sid: is the SID of the current domain
krbtgt: is the NTLM hash of the krbtgt account
ticket: is the filename to save as
Use /startoffset
, /endin
and /renewmax
to control the start offset, duration and the maximum renewals (all in minutes).
TIP: Get-DomainPolicy | select -expand KerberosPolicy
.
In the golden ticket, you’re not restricted to a single service, you got the KRBTGT so you can create your own TGT, so you can create a TGS for any service you want.