You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Request for a TGT using the hash of the user with CD using kekeo (Which me must have collected before)
Keep a note of the TGT return ticket
Now request a TGS with the 2nd step and 4th step values as parameters in /service and /tgt
Keep a note of the TGS return Ticket
Now we can inject the TGS return Ticket with Inkove-Mimikatz
We can now list the file systems of that account. Example : ls \\dc-mysql\C$ but can not use any WMI-Commands. We can use ScriptBlock to execute commands on the system.
But if the user DC we can do the same process and then do a DCSync attack