✨ Feature Description
Hello,
when abusing certificate-based authentication for a user who is a member of Domain Admins, it is possible to obtain their NTLM hash.
However, if this high-privileged account is also a member of the Protected Users group, the NTLM hash becomes effectively useless for authentication purposes (aside from offline password cracking), since NTLM-based authentication mechanisms are disabled for such accounts.
Given this restriction, the question arises:
Is it possible to retrieve the Kerberos AES keys (AES128/AES256) of a user account by presenting the certificate in order to authenticate as the user?
🚀 Why is this feature important?
- Post Exploitation is not possible when Users inside the Domain Admins group are also in the Protected Users group, since NTLM authentication is prohibited
🔄 Alternatives or Workarounds
No response
📎 Additional Context or Mockups
No response
✨ Feature Description
Hello,
when abusing certificate-based authentication for a user who is a member of Domain Admins, it is possible to obtain their NTLM hash.
However, if this high-privileged account is also a member of the Protected Users group, the NTLM hash becomes effectively useless for authentication purposes (aside from offline password cracking), since NTLM-based authentication mechanisms are disabled for such accounts.
Given this restriction, the question arises:
Is it possible to retrieve the Kerberos AES keys (AES128/AES256) of a user account by presenting the certificate in order to authenticate as the user?
🚀 Why is this feature important?
🔄 Alternatives or Workarounds
No response
📎 Additional Context or Mockups
No response