Silver Tickets
Silver Tickets
Step 1: To check if our current user has access to a resource of HTTP SPN or any SPN.
# Example:
iwr -UseDefaultCredentials http://web04
# To check the list of SPN for users present.
Import-Module .\PowerView.ps1
Get-NetUser -SPN | select samaccountname,serviceprincipalnameStep 2: Run mimikatz to extract the AD cached credential.
Step 3: Domain SID Collection (excluding the identifier)
Step 4: Targeting the SPN
Step 5: Creating a Silver Ticket
TIP:
Last updated