ADCS + PetitPotam NTLM Relay: Obtaining krbtgt Hash with Domain Controller Machine Certificate
Conditions
Overview

Domain Takeover
Lab Setup
Installing Tools

Configuring Virtual Environment



Finding Certificate Authority

Setting up NTLM Relay

Forcing DC01 to Authenticate to NTLM Relay

Requesting DC01$ TGT



Remember
RBCD: Remote Computer Takeover
Lab Setup
Setting up NTLM Relay
Kerberos Resource-based Constrained Delegation: Computer Object TakeoverForcing WS01 to Authenticate to NTLM Relay




Calculating Hash

Impersonating Domain Admin on WS01


WebClient Service


RBCD: Local Computer TakeOver / Local Privilege Escalation

Lab Setup
Calculating Hash

Impersonating Domain Admin on WS01

Decoding TGS to .kirbi

Converting .kirbi Ticket to .ccache

Exporting KRB5CCNAME

Executing Code as Domain Admin on WS01


PetitPotam blocked?
References
PreviousActive Directory Lab with Hyper-V and PowerShellNextFrom Misconfigured Certificate Template to Domain Admin
Last updated