BigHugger
sk Skill · mukul975

abusing-shadow-credentials-for-privesc

Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythonprivilege-escalationkey-credential-linkpkinitcertipyshadow-credentialspywhiskeractive-directoryred-team
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python