Skip to content

[Feature] Receiving AES Keys for a User #347

Description

@chr1s-uni

✨ Feature Description

Hello,
when abusing certificate-based authentication for a user who is a member of Domain Admins, it is possible to obtain their NTLM hash.

However, if this high-privileged account is also a member of the Protected Users group, the NTLM hash becomes effectively useless for authentication purposes (aside from offline password cracking), since NTLM-based authentication mechanisms are disabled for such accounts.

Given this restriction, the question arises:

Is it possible to retrieve the Kerberos AES keys (AES128/AES256) of a user account by presenting the certificate in order to authenticate as the user?

🚀 Why is this feature important?

  • Post Exploitation is not possible when Users inside the Domain Admins group are also in the Protected Users group, since NTLM authentication is prohibited

🔄 Alternatives or Workarounds

No response

📎 Additional Context or Mockups

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions