Pass the Ticket
Overview
Use mimikatz to dump TGT from LSASS memory
Will give us .kirbi ticket which can be used to gain domain admin if ticket is from domain admin
Reuse old ticket to impersonate that ticket
Can also use base64-encoded tickets gathered with Rubeus
Look for Administrator tickets
Exploitation
Mitigation:
Don't let domain admins log onto anything except the domain controller
Last updated