rubeus_diamond
Request a legitimate TGT and modify its PAC data to create a stealthier forged ticket. Re-signs with krbtgt key for improved evasion over golden tickets.
Instructions
Forge a Diamond Ticket (modified legitimate TGT).
Requests a legitimate TGT and then modifies it with new PAC data. More stealthy than golden tickets as it starts with a real ticket.
Requires krbtgt key for re-signing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| user | No | Username to authenticate as | |
| domain | Yes | Domain FQDN | |
| password | No | User password | |
| rc4 | No | User RC4/NTLM hash | |
| aes256 | No | User AES256 key | |
| krbkey | Yes | krbtgt key for re-signing | |
| ticketuser | No | Username to put in modified ticket | |
| ticketuserid | No | User ID for modified ticket | |
| groups | No | Group SIDs for modified PAC | |
| sids | No | Extra SIDs for SID history | |
| dc | No | Domain controller | |
| outfile | No | Output file for ticket | |
| ptt | No | Pass-the-ticket to current session | |
| nowrap | No | Don't wrap base64 output | |
| certificate | No | Certificate for PKINIT | |
| certificatepassword | No | Certificate password | |
| tgtdeleg | No | Use tgtdeleg trick for initial TGT | |
| createnetonly | No | Program to spawn |