Diamond Ticket
When we forge a
diamont ticket
, there is no pre-auth request corresponding to the forged ticket. This is an anomaly and can be detected by MDIs.To bypass this, we can request a TGT, decrypt it, modify if, then re-encrypt it, using the AES keys of the
krbtgt
account.Diamond ticket is the opsec safe version of the golden ticket.
Rubeus
Last updated