Full text
University of Derby Department of Computer Science BSc (Hons) Computer networks & security Active Directory vulnerabilities, exploitations and detection. By Sakellariou G. Apostolos 2024
Abstract This thesis analyzes the security weaknesses in Active Directory, with a specific emphasis on advanced attack techniques that exploit the Kerberos authentication protocol. This research provides a comprehensive examination of several important cyber attacks, including Kerberoasting, Overpass-the-Hash, Silver Ticket, and Golden Ticket. The study focuses on explaining how each attack is done and the consequences of these attacks. Conducted in a controlled virtual lab, the experiments reveal how weak password policies, inadequate monitoring, and outdated encryption methods facilitate unauthorized access and privilege escalation. The results emphasize the necessity of implementing strong security mechanisms, thorough monitoring, and ongoing training to protect the active directory enviroment. Suggested measures to increase organizational security against new threats include the implementation of robust password policies, regular updates to user accounts, the utilization of advanced detection tools, and the implementation of active security approaches. Keywords: Active Directory, Kerberos authentication protocol, Kerberoasting, Golden Ticket attack, Overpass-the-Hash attack, Silver Ticket attack, Attack Detection 2
Acknowledgements I want to start by saying how grateful I am to Mr. Antonis Kapellas, my supervising professor, for all the help and advice he gave me during my study. His thoughts and suggestions were very helpful in making sure that my work was relevant to real life, and the important materials he gave me helped make completing this thesis much easier. I also want to thank Professor Michael Dagiakidis for his assistance in setting up my virtual lab, which was crucial for the successful execution of my research experiments. Finally, I want to thank my father from the bottom of my heart for always being there for me and supporting me. His trust in me has been a constant source of strength and inspiration for me on this journey. Thank you all for your support! 3
Table of Contents 1 Introduction 6 1.1 ProjectRationale........................... 6 1.2 Project Aim and Objectives . . . . . . . . . . . . . . . . . . . . . 6 2 Literature Review 8 2.1 Introduction.............................. 8 2.2 Active Directory Vulnerabilities . . . . . . . . . . . . . . . . . . . 8 2.3 Kerberos Authentication . . . . . . . . . . . . . . . . . . . . . . . 8 2.4 Vulnerabilities exploitation . . . . . . . . . . . . . . . . . . . . . 9 2.4.1 Kerberoasting Attack . . . . . . . . . . . . . . . . . . . . 9 2.4.2 Overpass the hash Attack . . . . . . . . . . . . . . . . . . 13 2.4.3 Silver ticket Attack . . . . . . . . . . . . . . . . . . . . . . 23 2.4.4 Golden ticket Attack . . . . . . . . . . . . . . . . . . . . . 27 2.5 AttackDetection........................... 32 2.5.1 Kerberoasting Detection . . . . . . . . . . . . . . . . . . . 32 2.5.2 Overpass the hash Detection . . . . . . . . . . . . . . . . 34 2.5.3 Silver ticket Detection . . . . . . . . . . . . . . . . . . . . 35 2.5.4 Golden ticket Detection . . . . . . . . . . . . . . . . . . . 37 2.6 Conclusions.............................. 38 2.6.1 KeyIssues........................... 38 2.6.2 Refined Research Questions . . . . . . . . . . . . . . . . . 40 3 Research Methodology 41 3.1 Introduction.............................. 41 3.2 ResearchStrategy .......................... 41 3.3 DataAnalysis............................. 42 3.4 Ethics ................................. 42 4 Findings and Analysis 43 4.1 Introduction.............................. 43 4.2 Analysis................................ 43 4.3 Conclusions.............................. 44 4
5 Conclusion and Recommendation 45 5.1 Conclusion .............................. 45 5.2 Recommendation........................... 45 6 Bibliography 47 7 Appendices 49 7.1 Description of Lab Environment . . . . . . . . . . . . . . . . . . 51 7.2 NetworkTopology .......................... 51 7.3 ToolsandScripts........................... 52 7.4 GlossaryofTerms .......................... 52 5
Chapter 1 Introduction 1.1 Project Rationale In the modern digital age, ensuring the security of computer networks is of the highest priority, particularly due to the rising frequency of cyber-attacks aimed at vital infrastructures of businesses. Active Directory (AD) is a crucial component of many businesses’ infrastructure (Chai & Gillis, 2021), offering vital authentication and authorization functions. Nevertheless, the extensive utilization of it also renders it more susceptible to malicious individuals. Gaining a comprehensive understanding of the weaknesses present in Active Directory and the techniques used to exploit these weaknesses is essential for creating strong security protocols. This thesis aims to identify and analyze prevalent vulnerabilities in Active Directory, investigate several methods of exploiting these vulnerabilities, and assess the efficacy of various detection mechanisms. By pursuing this objective, the purpose is to enhance the existing knowledge on network security and offer practical guidance to security experts in order to protect their systems from these advanced threats. 1.2 Project Aim and Objectives The main objective of this thesis is to carry out a comprehensive study of the vulnerabilities present in Active Directory, the methods employed by attackers to exploit these vulnerabilities, and the related methods for detecting such attacks. In order to accomplish this goal, the following objectives have been set: •Enumerate and classify the most common vulnerabilities in Active Directory. •Perform hands-on demonstrations of prevalent exploitation techniques, such as Kerberoasting, Overpass-the-Hash, Silver Ticket, and Golden Ticket attacks. 6
•Examine the detection techniques for each of these attacks, evaluating their efficacy and limitations. •Based on the findings of this research, I represent implementing measures to enhance the security and detection mechanisms of Active Directory, with a specific emphasis on following administrative best practices. 7
Chapter 2 Literature Review 2.1 Introduction The primary goal of this literature study is to offer a thorough and extensive summary of the current research and studies concerning Active Directory vulnerabilities, methods of exploitation, and approaches for detection. This paper will provide an overview of the fundamental principles of Active Directory, explore particular weaknesses that attackers frequently target, and analyze the methods employed to identify and counteract these exploits. Furthermore, it will discuss the significance of Kerberos in Active Directory and its dual position as both a target and a tool in certain security scenarios. 2.2 Active Directory Vulnerabilities Active Directory (AD) is an essential element in numerous corporate settings, tasked with the responsibility of verifying user identities, granting access permissions, and enforcing rules and regulations within Windows domains (Microsoft Corporation, 2022). Active Directory, despite its significance, is exposed to multiple vulnerabilities, especially in cases of misconfigurations at the administrative level. The vulnerabilities can be classified into several forms, such as poor authentication systems, inappropriate delegation settings, and inadequate monitoring practices. 2.3 Kerberos Authentication Kerberos is the default protocol utilized in an Active Directory (AD) domain. Users can access network services by utilizing tickets instead of passwords. These tickets are generated for each session and have a limited time period of use. Users can obtain remote services by requesting a service ticket from a domain controller (DC), which acts as the key distribution center (KDC) in the Active 8
Directory (AD) implementation of Kerberos (The Mitre Corporation, 2020). When clients request service tickets for given services from a DC, they use unique identifiers called service principal names (SPNs). To enable Kerberos authentication, it is required that SPNs are registered in AD with at least one service logon account. 2.4 Vulnerabilities exploitation 2.4.1 Kerberoasting Attack The Kerberoasting attack, initially introduced by Tim Medin , is a method of obtaining the credentials of a remote service without the need to send any traffic directly to the service (Medin, 2014). Kerberoasting is categorized as a sub-method of the Steal or Forge Kerberos Tickets technique, which is classified under the Credential Access techniques (Mitre Corporation, 2020). The attack distinguishes itself from the other two subtechniques (Golden and Silver Ticket) based on the specific level of permissions that are need. Kerberoasting can be executed without the need for a local administrator account or an account having higher permissions in the domain (Demers & Lee, 2022). A valid domain account or the ability to sniff traffic within a domain is enough for an attacker to carry on Kerberoasting. The exploitation of Kerberoasting was conducted in a controlled virtual lab environment consisting of a domain controller, a Windows 10 PC client, and an attacker machine running Kali Linux. While there are multiple methods to execute this attack, the Havoc C2 (Command and Control) framework was utilized on the Kali Linux machine for this experiment. The Windows PC was previously compromised using a payload deployed from the attacker machine, establishing an active session between the two computers. Figure 1: Havoc framework: Healthy connection with windows client computer. As shown in Figure 1, a connection has already been established with the client computer at IP address 192.168.50.30, and we are prepared to initiate the Kerberoasting attack. After obtaining the password for the ”pc user” account, which belongs to the 9
Figure 10: Purging the pc user’s tickets. $k l i s t purge 16
Figure 11: pc user’s without kerberos tickets. $klist We are now ready to create the Kerberos ticket for the ”ceo” user. In the image (Figure 12), the PowerShell command executed uses Rubeus, a tool designed for Kerberos ticket operations. The command below is employed to request a Ticket Granting Ticket (TGT) for the ”ceo” user in the lab.com domain. The ”/rc4” parameter specifies the NTLM hash of the ”ceo” user’s password, and the ”/ptt” flag indicates that the ticket should be injected directly into the current session upon creation. This process allows us to impersonate the ”ceo” user by obtaining a valid TGT, which can then be used to access resources and services that the ”ceo” user has permissions for within the domain. 17
Figure 12: Creating a TGT for ”ceo” user. $.\Rubeus . exe asktgt /domain : lab . com / user : ceo / rc4 :8846F7EAEE8FB117AD06BDD830B7586C / ptt The output (Figure 13) shows that the TGT request was successful. The TGT is built using the provided NTLM hash, and the request is sent to the Domain Controller. The Base64-encoded ticket is displayed, followed by confirmation that the ticket has been successfully imported to our current session (Figure 14). The final section of the output confirms the details of the imported ticket, including the service name (krbtgt/lab.com), the service realm (LAB.COM), and the user realm (LAB.COM), all associated with the ”ceo” user. This ticket allows us to impersonate the ”ceo” user and access resources within the lab.com domain. 18
Figure 13: TGT of ”ceo” user. 19
Figure 14: Current session with ceo’s TGT. $klist The output of Figure 15 reveals that the ”ceo” user is a member of ”Domain Admins” groups, indicating that this account has significant privileges within the domain. Having verified the elevated privileges of the ”ceo” user, we proceed to access the confidential folder on the domain controller (Figure 16). This successful access confirms the effectiveness of the attack, demonstrating the ability to exploit the Kerberos ticket to gain unauthorized access to critical resources within the domain. 20
Figure 15: The ”ceo” user is in Domain Admins group. $net user /domain ceo 21
Figure 16: We have access to confidential-folder on the domain controller. $l s \\Dc\confidential−folder These cached tickets confirm that the ”ceo” user has accessed multiple services, including the domain’s CIFS service, which is used for accessing shared folders and files on the network. The presence of these tickets verifies that the ”ceo” user has domain admin privileges and can access sensitive resources. (Figure 17) 22
Figure 17: Cashed tickets of ”ceo” user TGT and TGS tickets. $klist 2.4.3 Silver ticket Attack The Silver Ticket attack is a method of forging Kerberos service tickets to gain access to specific services within an Active Directory (AD) environment. Unlike the Golden Ticket attack, which targets the Ticket Granting Ticket (TGT) for unrestricted access across the domain, the Silver Ticket attack focuses on compromising the Ticket Granting Service (TGS) for a particular service, allowing the attacker to access that service without the need for constant interaction with the Key Distribution Center (KDC) (P´erez, 2019). This attack takes advantage of service accounts, which often have less stringent security measures compared to other accounts. In a Silver Ticket attack, the attacker first needs the NTLM hash of the service account password in our case ”A9FDFA038C4B75EBC76DC855DD74F0DA” 23
(NTLM hash of password123 Figure 6) of the sql user account that we found with Kerberoasting. Once the NTLM hash is obtained, the attacker can forge a TGS for the targeted service, effectively impersonating the service account and gaining access to the associated service resources. In this case scenario we have the clear password so we have to convert it to the NTML hash (Figure 18). Figure 18: Generating the NTLM hash $.\Rubeus . exe hash /password : password123 The attacker generates a TGS for the targeted service using the generated NTLM hash. This involves crafting the ticket with the necessary information, including the SPN (Figure 19),NTML hash (Figure 18), SID (Figure 26), user and domain. 24
Figure 19: Searching for SPNs. $.\GetUserSPNs . ps1 The final step involves the creation of the Silver Ticket using Rubeus (Figure 20), showing the detailed parameters used to forge the ticket. The Rubeus command ”Rubeus.exe silver” is used to create a Silver Ticket. In the provided figure, we specify various parameters including the service account name ”/service:sql user/lab.com”, the RC4 hash , the SID, the username , and the domain name. Figure 20: Rubeus creating the silver ticket. $.\Rubeus . exe s i l v e r / s e r v i c e : s q l u s e r / lab . com / rc4 :A9FDFA038C4B75EBC76DC855DD74F0DA / s id : S−1−5−212134806138−80834246−46628613 / user : Administrator /domain : lab . com / ptt The successful creation of the ticket is confirmed by Rubeus, indicating that the attacker now has the ticket that can be used to impersonate the administrator for the specified service. The last step is to pass the ticket on our current session with the command ”/ptt” as shown in the figure. This completes the process, allowing the attacker to use the forged ticket to access the targeted service. 25
2.5 Attack Detection 2.5.1 Kerberoasting Detection Kerberoasting is an advanced attack method that focuses on obtaining service account credentials in Active Directory. This attack exploits inherent vulnerabilities in the Kerberos authentication system, enabling attackers to obtain service account credentials without needing elevated privileges.. Attackers can exploit these vulnerabilities to obtain unauthorized access to sensitive data and potentially escalate their privileges within the domain. Comprehending the complexities of Kerberoasting and using strong detection techniques is essential for protecting Active Directory environments. Kerberoasting is the process of obtaining Kerberos service tickets (TGS) for service accounts within an Active Directory domain. An individual with domain user account has the ability to request these tickets, which are encrypted using the password hash of the service account. The attacker retrieves these tickets from the computer’s memory and tries to decrypt them offline, employing software like hashcat or John the ripper. Cracking the password successfully exposes the service account’s password, giving the attacker entry to systems and perhaps enabling them to gain higher privileges, if the account has higher permissions. Tim Medin first described this technique at DerbyCon 2014, emphasizing its efficacy in hacking Active Directory domains. The attack is especially powerful because of the widespread habit of choosing easily guessable passwords for service accounts and the rare occurrence of password updates for these accounts, rendering them vulnerable. An efficient way to identify Kerberoasting is to implement thorough logging and monitoring of Kerberos service ticket requests. Configure Domain Controllers to log Kerberos service ticket requests (Event ID 4769) and renewals (Event ID 4770). Through constant tracking of these records, companies can detect anomalous patterns in service ticket requests, perhaps signaling the presence of Kerberoasting operations (Metcalf, 2017). More precisely, a large number of TGS requests that are encrypted with RC4 can indicate a potential issue, since current Windows systems usually employ AES encryption for Kerberos tickets. By filtering logs to specifically target RC4 encryption (Ticket Encryption Type 0x17), one can effectively narrow down and identify probable Kerberoasting attempts. This strategy is effective since the usage of RC4 encryption should be limited in environments that have AES capability, resulting in RC4-encrypted TGS requests an unusual occurrence that deserves inquiry. Another crucial part of detection involves monitoring for actions related to scanning for Service Principal Names (SPNs). Attackers frequently use SPN scans to detect service accounts that are vulnerable to Kerberoasting attacks. Organizations should establish monitoring tools to identify unexpected SPN query patterns and analyze them with TGS queries to detect reconnaissance operations that may indicate an upcoming Kerberoasting attack. PowerShell scripts, like those offered by Impacket, can be utilized to list and analyze SPNs. This makes it crucial for administrators to periodically review SPN assignments to 32
verify their necessity and correct management. Moreover, behavioral analytics can be used to identify patterns, such as a single user making several requests for TGS tickets across different services within a brief period of time. Establishing honeypot service accounts with Service Principal Names (SPNs) that are not meant to be requested can serve as a highly effective mechanism (Medin, 2020), promptly detecting any endeavors to obtain tickets for these accounts as malicious activity. In order to reduce the danger of Kerberoasting, businesses should implement strong password restrictions for service accounts. Service account passwords should have a considerable length, ideally exceeding 25 characters. They should also be complex and should be changed on a regular basis. Managed Service Accounts (MSAs) and Group Managed Service Accounts (gMSAs) are advised due to their ability to automatically generate and routinely modify complicated passwords without the need for manual intervention. Effective administration and examination of service accounts hold the same importance. This means making sure that Service Principal Names (SPNs) are allocated to accounts only when required and promptly revoke SPNs when the corresponding service is terminated. Service accounts should be assigned to dedicated Organizational Units (OUs) and closely monitored for any deviations from expected behavior. An advanced method for detection involves including Kerberos event logs into a Security Information and Event Management (SIEM) system . This allows for the centralized monitoring of events, enhancing the detection of patterns that indicate a Kerberoasting attack. SIEM solutions can employ analytics and machine learning algorithms to identify these patterns, improving the accuracy of detection. To enhance detection efficiency, it is beneficial to filter and decrease the number of 4769 events by filtering service accounts and prioritizing malformations (Splunk Threat Research Team, 2022).Enabling thorough PowerShell logging and sending these logs to a centralized repository can help detect the use of PowerShell scripts for SPN enumeration and ticket requests (Metcalf, 2017). Events, such as the use of ”KerberosRequestorSecurityToken”, should trigger alerts for further investigation. To summarize, Kerberoasting is a powerful attack technique that can compromise the credentials of service accounts in Active Directory environments. Organizations can safeguard themselves against this threat by comprehending its mechanics and implementing strong detection and mitigation strategies as mentioned above. An effective defense against Kerberoasting is built upon comprehensive logging, monitoring, and auditing, as well as the implementation of strong password policies and the utilization of managed service accounts (Medin, 2020). Utilizing advanced detection techniques, such as integrating Security Information and Event Management (SIEM) and implementing PowerShell logging, significantly improves an organization’s capability to identify and react to Kerberoasting attempts. Consistent monitoring and proactive actions are crucial for protecting Active Directory environments from this and other advanced attack techniques. 33
2.5.2 Overpass the hash Detection Overpass-the-Hash, also referred to as Pass-the-Key attack, is an advanced attack method that exploits a user’s password NTLM hash to gain unauthorized access to network resources, bypassing the need for the actual password. This technique leverages the Kerberos protocol to gain higher levels of access and move horizontally across a network. Having the ability to identify and prevent these attacks is essential for maintaining the security of an Active Directory environment. The attack follows a series of steps: first, the attacker gains access to a system, then they retrieve password hashes. These hashes are then used to obtain Kerberos tickets, which enable the attacker to authenticate and gain access to different network resources without needing the actual passwords.To identify Overpass-the-Hash attacks, it is necessary to employ a combination of monitoring and analyzing network traffic, authentication logs, and system behaviors (Warren, 2023). Crucial signs of such attacks consist of atypical login patterns, uncommon service establishment, memory scraping activities, and an enormous flood of authentication requests within a brief a certain timeframe. Conducting surveillance for the use of tools such as Rubeus or mimikatz and the establishment of unauthorized services can aid in the detection of potential Overpass-the-Hash attacks. Logging and monitoring are important for effectively detecting Overpass-theHash attacks (Petri, 2024), it is essential to have a full log of authentication events in order to identify these attacks. It is recommended to set up Active Directory environments to record complete authentication events. Through monitoring of these occurrences, administrators have the ability to detect suspicious trends (Warren, 2023), such as an enormous rise of authentication requests within a brief timeframe, which may indicate the presence of an attack. In addition, tracking of unexpected login times and locations can aid in the identification of unauthorized access attempts. An example of this is when a user account, which usually logs in from a specific location, suddenly begins logging in from multiple locations. This could indicate the presence of an Overpassthe-Hash attack. Security Information and Event Management (SIEM) systems can be employed to collect and examine these logs (Petri, 2024), offering instant alerts for potentially malicious actions. Perpetrators frequently create unusual services to ensure their continued presence within the network and any unusual service creation should be thoroughly examined. Overpass-the-Hash attacks often involve a high volume of authentication requests in a short period. By analyzing network traffic, administrators can identify spikes in authentication traffic and investigate the source of these requests. Tools like Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) can be used to monitor network traffic and detect anomalies. Additionally, monitoring for the use of known attack tools like Mimikatz or Rubeus can help identify potential attacks. These tools often generate specific network traffic patterns that can be detected and flagged for further investigation. Endpoint Detection and Response (EDR) solutions offer comprehensive insight into the actions performed on endpoints (Saydag & Moore, 2019), enabling administrators to promptly 34
identify and prevent attacks as they occur. These solutions have the capability to monitor endpoints for indications of Overpass-the-Hash attacks, such as the aforementioned tools designed for extracting credentials (Warren, 2023). EDR solutions are capable of identifying memory scraping activities, a common technique used to extract the NTLM password hashes from computer RAM. Privileged Access Management (PAM) solutions assist in the management and regulation of privileged access to crucial systems. Through the implementation of PAM, organizations can uphold the principle of least privilege, guaranteeing that users are granted only the necessary access to carry out their tasks. PAM solutions have the capability to monitor and record all activities related to privileged access, thereby offering comprehensive audit trails for forensic analysis. PAM solutions have the capability to enforce just-in-time access, which means that users are granted temporary access to privileged accounts only when it is necessary. This measure aids in mitigating the potential for credential theft and unauthorized access. Other method to Mitigate this attacking with Network segmentation that is the process of dividing a network into smaller segments (Petri, 2024), each having its own set of security controls. Organizations can restrict the horizontal progression of attackers by dividing the network into segments. For example, it is possible to segregate critical systems and sensitive data into isolated segments that have more stringent access controls, the implementation of firewalls and access controls between segments can also help in the detection and prevention of unauthorized access. Detecting and mitigating Overpass-the-Hash attacks requires a multi-layered approach involving comprehensive logging and monitoring security measures(Saydag & Moore, 2019). By implementing strong password policies, network segmentation, PAM solutions, and regular audits, organizations can significantly reduce the risk of such attacks. Maintaining the security of Active Directory environments requires constant monitoring and the use of complex detection tools and techniques . Organizations can protect themselves against Overpass-the-Hash attacks and other advanced threats by staying updated on the latest attack methods and implementing strong security practices. 2.5.3 Silver ticket Detection Unlike Golden Ticket attacks that target the Ticket Granting Ticket (TGT), Silver Ticket attacks focus on forging Kerberos Service Tickets (TGS) for specific services, allowing attackers to gain unauthorized access to service resources within the domain. This attack exploits the fact that service tickets can be created without needing to interact with the Key Distribution Center (KDC), making it harder to detect. Silver Ticket attacks use the capability to impersonate any service and gain access to its resources within the domain. The attacker initially penetrates the network and retrieves the NTLM hash of a service account, using this hash, the attacker can generate fraudulent TGS tickets that grant continuous and unrestricted entry to the targeted service, avoiding standard authentication measures. The access is valid as long as the service account password remains unchanged, resulting in a highly persistent attack. 35
Detecting Silver Ticket attacks involves monitoring for specific indicators that suggest unauthorized Kerberos activity. Key indicators include abnormal service ticket usage patterns, discrepancies in ticket lifetimes (Metcalf, 2015), and authentication attempts from unexpected locations and devices. For instance, legitimate Kerberos tickets have standard lifetimes unlike forged tickets that may exhibit unusually long or customized lifetimes. Monitoring for tickets with irregular lifetimes can help identify potential Silver Ticket activity (Ganesh, 2021). Analyzing service ticket usage patterns for anomalies, such as service tickets requested by unexpected accounts or from unexpected machines, is also critical. Effective monitoring of Kerberos-related events is crucial (Metcalf, 2015). Examining network traffic for Kerberos protocol activity could reveal suspicious actions, and utilizing technologies such as Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) systems can aid in detecting these unusual behaviors. Implementing Endpoint Detection and Response (EDR) solutions provides detailed visibility into endpoint activities (Ganesh, 2021), allowing administrators to detect and respond to attacks in real-time. EDR solutions can monitor endpoints for signs of credential dumping tools, and can detect suspicious processes and memory accesses indicative of an attack. To successfully prevent Silver Ticket attacks, it is necessary to implement both proactive and regular measures. Enforcing strong password policies for service accounts is critical, passwords should be long, complex, and changed regularly. Additionally, using Managed Service Accounts (MSAs) and Group Managed Service Accounts (gMSAs) that automatically generate and manage complex passwords can mitigate the risk of credential theft (Metcalf, 2015). Regular auditing of service accounts, ensuring they adhere to strict password policies and monitoring their use, helps reduce the attack surface. Implementing network segmentation to limit the lateral movement of attackers and enforcing strict access controls between network segments can contain the impact of a Silver Ticket attack. Conducting regular audits and penetration testing assists in the identification and resolution of security vulnerabilities within the network. Audits should involve an examination of password rules, access controls, and network segmentation, whereas penetration testing emulates attacks to identify vulnerabilities and evaluate the efficacy of security safeguards. In summary, Silver Ticket attacks provide a substantial risk to the security of Active Directory environments since they enable attackers to get unauthorized access to certain services. Efficient detection depends on the incorporation of extensive logging, anomaly detection, and proactive security measures (Ganesh, 2021). To boost their defenses against Silver Ticket attacks, organizations can greatly improve their security by implementing strict password regulations, conducting frequent audits of service accounts, monitoring for abnormal login patterns, and deploying advanced detection technologies. Continuously alertness and strong security policies are necessary to protect your systems settings from this advanced attack. 36
2.5.4 Golden ticket Detection Detecting Golden Ticket attacks is crucial for maintaining the integrity of Active Directory (AD) environments. These attacks exploit the Kerberos authentication protocol, allowing attackers to create counterfeit Kerberos Ticket Granting Tickets (TGTs) that grant unlimited access to AD resources. The attack hinges on compromising the Kerberos Key Distribution Center (KDC), specifically the krbtgt account, to forge TGTs. Understanding how to detect and mitigate these attacks is vital for ensuring robust security. Golden Ticket attacks use the capability to impersonate any user and gain access to any service within the domain. The attacker initially penetrates the network and retrieves the hash of the krbtgt account using tools such as Mimikatz. Using this hash, anybody can generate fraudulent TGTs that grant continuous and unrestricted entry, avoiding standard authentication measures. The access is valid forever as long as the krbtgt account password remains unchanged, resulting in a highly persistent attack. Detecting Golden Ticket attacks involves monitoring for specific indicators that suggest unauthorized Kerberos activity. Key indicators include abnormal ticket lifetimes, unusual logon patterns, and event logs that signal suspicious activity. For instance, legitimate Kerberos tickets have standard lifetimes, and forged tickets may exhibit unusually long or customized lifetimes (Petri, 2024). Monitoring for tickets with irregular lifetimes can help identify potential Golden Ticket activity. As seen on Figure 28, the default lifetime of the ticket is 10 years (As you can see on Figure 20) on Mimikatz. However, it is important to note that an attacker can modify this parameter. Analyzing logon patterns for anomalies, such as logons from unusual locations or at odd times, is also critical. A sudden surge in logons from an administrative account across various systems can indicate a compromised account being used with a Golden Ticket(Petri, 2024). Effective monitoring of Kerberos-related events is crucial. It is important to carefully examine Event IDs 4768 and 4769, as they record requests for Kerberos authentication tickets and service tickets, accordingly. An extensive number of these occurrences, particularly those involving privileged accounts, necessitate further examination. In addition, conducting surveillance for irregularities in service ticket activity, such as service tickets initiated by unexpected user accounts or from unexpected devices, might offer timely indications of potential issues. Examining network traffic for Kerberos protocol activity could reveal suspicious actions, and utilizing technologies such as Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) systems can aid in detecting these unusual behaviors (Manage Engine, 2022). Implementing Endpoint Detection and Response (EDR) solutions provides detailed visibility into endpoint activities, allowing administrators to detect and respond to attacks in real-time. EDR solutions can monitor endpoints for signs of credential dumping tools, and can detect suspicious processes and memory accesses indicative of an ongoing Golden Ticket attack. To successfully avoid Golden Ticket attacks, you need to take both proactive steps and regular checks. Regular password changes for the krbtgt account disrupt the 37
validity of forged TGTs. To make sure that any current Golden Tickets are no longer valid, the krbtgt account password should be changed at least every six months. There must also be strict control of privileged accounts. Putting strict controls on privileged accounts and making sure they undergo periodic inspections can help lower risks. Using Privileged Access Management (PAM) tools to make sure that just-in-time access rules are followed makes security even better (Manage Engine, 2022). It is crucial to provide security training and knowledge to administrators and security staff regarding the risks and indicators associated with Golden Ticket attacks. Consistent training on current attack methodologies and defensive techniques might assist in maintaining an ongoing security position. Regularly conducting audits and penetration testing assists in the identification and resolution of security vulnerabilities within the network (Petri, 2024). Audits should involve an examination of password rules, access controls, and network segmentation, whereas penetration testing emulates attacks to identify vulnerabilities and evaluate the efficacy of security safeguards. Summing up Golden Ticket attacks provide an important threat to the security of Active Directory setups as they enable attackers to get prolonged and uncontrolled entry to domain resources. Efficient detection relies on the integration of comprehensive logging, anomaly detection, and proactive security measures. To strengthen their defenses against Golden Ticket assaults, enterprises can greatly improve their security by frequently updating the krbtgt password,penetration testing, administrator threat training, closely monitoring for unusual authentication patterns, and utilizing advanced detection technologies. To protect active directory (AD) settings from this advanced threat, it is crucial to maintain constant awareness and implement strong security measures. 2.6 Conclusions 2.6.1 Key Issues The research conducted in this thesis has highlighted several critical issues within the realm of Active Directory (AD) security. One of the most significant issues is the inherent vulnerabilities present in the Kerberos authentication protocol, which is foundational to AD operations. These vulnerabilities provide attackers with multiple vectors for compromising AD environments, as demonstrated through the Kerberoasting, Overpass-the-Hash, Silver Ticket, and Golden Ticket attacks. Kerberoasting leverages the encryption of service tickets to extract and crack service account credentials bypassing the need for higher privileges. This attack exploits the use of weak password policies and the common habit of infrequently changing passwords for service accounts. The penetration tests demonstrated that upon acquiring an authorized domain user account, an attacker can request service tickets, intercept them, and using tools such as Hashcat to offline decrypt the passwords. The vulnerability exploited in this case is the utilization 38
of RC4 encryption, which, despite being outdated, is still present in numerous systems because of the need to maintain compatibility with older versions. Overpass-the-Hash attacks use the technique of NTLM hashes to get Kerberos tickets, eliminating the requirement for passwords in plain text. This approach emphasizes the vulnerability linked to NTLM hash theft and the significance of protecting hash storage and transmission. The study showcased the method by which an attacker can utilize the NTLM hash to get a Ticket Granting Ticket (TGT) and then gain entry to other network services as the compromised user. The ease with which these hashes can be obtained from memory using tools like Mimikatz or other NTLM stealing technics emphasizes the importance to store the hashes by limiting their availability. The Silver Ticket attacks, which include the creation of forged service tickets for targeted services within the domain, demonstrate an additional significant vulnerability. Attackers can gain unauthorized access to targeted services without interacting with the Key Distribution Center (KDC) by acquiring the NTLM hash of a service account and using it to create service tickets and in many cases the attacker could get more privileges if the services account have. This case highlights the importance of closely monitoring the use of service tickets and enforcing strict password requirements for service accounts. The trials demonstrated that service accounts are frequently overlooked in security audits, rendering them vulnerable to such assaults. Golden Ticket attacks represents a significant danger because they can create forged TGTs that grant uncontrolled access to the domain. The breach of the krbtgt account, which serves as the signatory for all Ticket Granting Tickets (TGTs), enables attackers to create tickets that can impersonate any user and get access to any service. The research demonstrated the enduring consequences of such an assault, as the counterfeit tickets retain their validity until the password of the krbtgt account is changed. This problem highlights the significance of routinely changing the krbtgt account password and keeping a close watch for any irregularities in ticket issuing and consumption. The enduring nature of such an attack renders it exceptionally hazardous as it might endure unnoticed for prolonged durations, granting assailants continuous entry to domain resources. The experiments demonstrated that while some detection mechanisms were effective, many required enhancement to identify more subtle attack patterns. The study emphasized the significance of thorough surveillance, strong password regulations, and proactive security measures in reducing these risks. It also emphasized the need for continuous education and training for IT personnel to stay abreast of the latest attack techniques and defensive measures. To effectively address the intricacy of these attacks and the advanced nature of the instruments employed, it is essential to adopt a comprehensive security strategy that combines technical and administrative measures. 39
2.6.2 Refined Research Questions Based on the key issues identified, the research questions can be refined to address the specific aspects of Active Directory security that are most vulnerable to these advanced attack techniques. The following refined research questions aim to guide future investigations and practical implementations of security measures: •What are the comprehensive security measures that can be adopted to protect Active Directory environments from a combination of advanced attack techniques? This overarching question aims to develop a holistic approach to AD security, integrating multiple layers of defense. It involves combining proactive measures such as strong password policies, regular audits, security training, and the deployment of advanced detection tools to create a robust security framework. By addressing these areas, organizations can significantly enhance their ability to protect against a wide range of advanced attack techniques. •How frequently should the krbtgt account password be changed to effectively counteract the persistence of Golden Ticket attacks, and what are the best practices for monitoring ticket issuance? This question addresses the specific frequency and procedures for updating the ”krbtgt” account password. It also explores the best practices for monitoring Kerberos ticket issuance and detecting anomalies that could indicate a Golden Ticket attack. Regular updates to the ”krbtgt” account password are essential for invalidating forged tickets and maintaining the security of the Kerberos authentication protocol. •What measures can enterprises take to enhance the security of Kerberos authentication protocol and reduce the vulnerabilities caused by Kerberoasting attacks? This question aims to explore the specific configurations and security practices that can enhance the resilience of the Kerberos protocol against Kerberoasting. It includes investigating the effectiveness of strong password policies, regular password changes, and the use of Managed Service Accounts (MSAs) and Group Managed Service Accounts (gMSAs). These measures are designed to make it more difficult for attackers to exploit weak passwords and gain access to service accounts. 40
Chapter 3 Research Methodology 3.1 Introduction The research methodology chapter of this thesis outlines the strategies, tools, and techniques utilized to investigate Active Directory vulnerabilities, their exploitation methods, and the corresponding detection mechanisms. This chapter is critical as it provides a structured approach to gathering, analyzing, and interpreting data, ensuring the validity and reliability of the findings. 3.2 Research Strategy The study approach for this thesis entails employing both qualitative and quantitative methods to comprehensively investigate Active Directory vulnerabilities and techniques for exploiting them. The qualitative part involves conducting a thorough examination of current literature and industry reports to gain a deep understanding of the theoretical foundations and operational consequences of Active Directory security. Quantitative approaches are utilized by conducting practical tests in a controlled laboratory setting to replicate real-world assault situations. The primary data collection method involves setting up a virtual lab environment comprising a domain controller, client machine, and attacker systems running Kali Linux and various tools like Mimikatz, and Rubeus. This setup allows for the practical demonstration of attacks such as Kerberoasting, Overpassthe-Hash, Silver Ticket, and Golden Ticket. Each attack is executed under controlled conditions to observe the vulnerabilities exploited and the impact on the Active Directory environment. 41
10. Medin, T. (2020) Detecting kerberoasting, RED SIEGE.Available at: https://redsiege.com/tools-techniques/2020/10/detecting-kerberoasting/. 11. Splunk Threat Research Team, S. (2022) Detecting active directory kerberos attacks, Splunk . Available at: https://www.splunk.com/en us/blog/security/detecting-active-directory-kerberosattacks-threat-research-release-march-2022.html. 12. Petri, D. (2024) Overpass the hash defense, Semperis. Available at: https://www.semperis.com/blog/how-to-defend-against-overpass-the-hash-attack/. 13. Saydag, B. and Moore, S. (2019) Defeating pass-the-hash, blackhat.com. Available at: https://www.blackhat.com/docs/us-15/materials/us-15-Moore-Defeating%20Passthe-Hash-Separation-Of-Powers-wp.pdf. 14. Warren, J. (2023) Overpass-the-hash attack: Principles and detection, Netwrix Blog. Available at: https://blog.netwrix.com/2022/10/04/overpass-the-hashattacks/. 15. Petri, D. (2024) How to defend against Golden Ticket attacks, Semperis. Available at: https://www.semperis.com/blog/how-to-defend-against-golden-ticketattacks/. 16. Manage Engine, L. (2022) Golden Ticket attack, ManageEngine Log360. Available at: https://www.manageengine.com/log-management/cyber-security/goldenticket-attack.html. 17. Metcalf, S. (2015) Detecting forged kerberos ticket (Golden Ticket & Silver Ticket) use in Active Directory, Active Directory Security. Available at: https://adsecurity.org/?p=1515. 18. Ganesh, B. (2021) Detecting and preventing a silver ticket attack , Security Investigation. Available at: https://www.socinvestigation.com/detecting-andpreventing-a-silver-ticket-attack/. 48
Chapter 7 Appendices 49
List of Figures 1 Havoc framework: Healthy connection with windows client computer. ................................. 9 2 Attacker machine network configuration. . . . . . . . . . . . . . . 10 3 Discovery of the sql user service principal name (SPN) and its associated Kerberos ticket in the lab.com domain. . . . . . . . . 11 4 Captured Kerberos ticket for the sql user service principal name (SPN) on the lab.com domain. . . . . . . . . . . . . . . . . . . . 12 5 Brute-forcing the TGS with hashcat . . . . . . . . . . . . . . . . 12 6 Hashcat output showing the successful brute-force cracking of the TGS................................... 13 7 pc user in domain users group. . . . . . . . . . . . . . . . . . . . 14 8 pc user access denied to confidential-folder on domain controller. 14 9 pc user’s active kerberos tickets. . . . . . . . . . . . . . . . . . . 15 10 Purging the pc user’s tickets. . . . . . . . . . . . . . . . . . . . . 16 11 pc user’s without kerberos tickets. . . . . . . . . . . . . . . . . . 17 12 Creating a TGT for ”ceo” user. . . . . . . . . . . . . . . . . . . . 18 13 TGTof”ceo”user........................... 19 14 Current session with ceo’s TGT. . . . . . . . . . . . . . . . . . . 20 15 The ”ceo” user is in Domain Admins group. . . . . . . . . . . . . 21 16 We have access to confidential-folder on the domain controller. . 22 17 Cashed tickets of ”ceo” user TGT and TGS tickets. . . . . . . . . 23 18 Generating the NTLM hash . . . . . . . . . . . . . . . . . . . . . 24 19 SearchingforSPNs. ......................... 25 20 Rubeus creating the silver ticket. . . . . . . . . . . . . . . . . . . 25 21 Rubeusoutput............................. 26 22 Rubeus silver ticket. . . . . . . . . . . . . . . . . . . . . . . . . . 26 23 Silver ticket cashed on our current session. . . . . . . . . . . . . . 27 24 Pc user attempts to access a shared resource. . . . . . . . . . . . 28 25 SID of the LAB.COM domain. . . . . . . . . . . . . . . . . . . . 29 26 Creating golden ticket with domain admin HTLM hash using Mimikatz................................ 30 27 Passing the golden ticket on our current session. . . . . . . . . . 30 28 Golden ticket on our current session. . . . . . . . . . . . . . . . . 31 29 We can access the ”C:” drive on the domain controller. . . . . . . 31 50
1 Network topology of the virtual lab environment. . . . . . . . . . 51 7.1 Description of Lab Environment The virtual lab was set up using Hyper-V Workstation on Azure labs. The lab consists of a Domain Controller running Windows Server 2019 (IP: 192.168.50.20/24), a client machine running Windows 10 pro (IP: 192.168.50.30/24), and an attacker machine running Kali Linux (IP: 192.168.50.10/24). The following hardware specifications were used: •Domain Controller: 4GB RAM, 2 CPUs •Windows 10 pro Client: 4GB RAM, 2 CPUs •Kali Linux Attacker: 4GB RAM, 2 CPUs 7.2 Network Topology Figure 1: Network topology of the virtual lab environment. 51
7.3 Tools and Scripts 1. Havoc: https://github.com/HavocFramework/Havoc 2. Mimikatz: https://github.com/ParrotSec/mimikatz 3. Rubeus: https://github.com/GhostPack/Rubeus 4. Impacket: https://github.com/fortra/impacket 5. GetUserSPNs.py Script: https://github.com/fortra/impacket/blob/master/examples/GetUserSPNs.py 6. GetUserSPNs.ps1 Script: https://github.com/nidem/kerberoast/blob/master/GetUserSPNs.ps1 7. Hashcat: https://github.com/hashcat/hashcat 8. Hashcat Documentation: https://hashcat.net/wiki/doku.php?id=hashcat Rockyou Wordlist: https://github.com/praetorian-inc/Hob0Rules/blob/master/wordlists/rockyou.txt.gz 7.4 Glossary of Terms •DC: Domain Controller. •AD: Active Directory. •TGT: Ticket Granting Ticket, a ticket used in Kerberos authentication. •TGS: Ticket Granding Service, a ticket used in Kerberos authentication. •SPN: Service Principal Name, a unique identifier for a service instance. •KDC: Key Distribution Center, a network service that issues Kerberos tickets. •AES: Advanced Encryption Standard, A symmetric encryption algorithm. •Brute Force Attack: A hacking method that uses trial and error to crack passwords, login credentials, and encryption keys. •Hash: Assign a numeric or alphanumeric string to (a piece of data) by applying a function whose output values are all the same number of bits in length. •Password Policy: A set of rules designed to enhance security by encouraging users to employ strong passwords. 52
•Attack Surface: The set of points on the boundary of a system, a system element, or an environment where an attacker can try to enter, cause an effect on, or extract data from, that system, system element, or environment. •Network Segmentation: An architecture that divides a network into smaller sections or subnets. •Honeypot: A honeypot is a network-attached system set up as a decoy to lure cyber attackers and detect, deflect and study hacking attempts to gain unauthorized access to information systems. 53