影钥窃权
原名:abusing-shadow-credentials-for-privesc
使用pyWhisker/Whisker/Certipy向msDS-KeyCredentialLink写入攻击者公钥(Shadow Credentials),通过PKINIT获取目标NT哈希,无需重置密码。适用于BloodHound显示GenericWrite/GenericAll/AddKeyCredentialLink权限时,作为ForceChangePassword的隐蔽替代方案。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-04
- TRACE 评分
- 3.4 / 5
内容概览
Legal Notice: This skill is for authorized security testing and educational purposes only. Shadow Credentials grant full takeover of the targeted account. Use only against systems you own or are explicitly authorized in writing to test. Unauthorized access is a crime. The Shadow Credentials technique abuses the msDS-KeyCredentialLink attribute of Active Directory user and computer objects. This attribute stores raw public keys ("Key Credentials") used by Windows Hello for Business and Azure AD device registration for passwordless certificate-based logon via PKINIT (Public Key Cryptography for Initial Authentication in Kerberos). If an attacker has write permission over a target object's msDS-KeyCredentialLink — typically granted by GenericWrite, GenericAll, WriteProperty, or AddKeyCredentialLink ACEs surfaced in BloodHound — they can append their own attacker-generated public key. They t…