During an internal network penetration test, you compromise a Linux workstation and discover plaintext credentials for a domain service account cached in memory. You want to move laterally to a critical database server using Pass-the-Hash without triggering Kerberos logging anomalies. Which technique is most appropriate for establishing this lateral movement?
Trap 1: Injecting the cleartext password into the LSASS process memory of…
Injecting plaintext credentials into LSASS requires interactive administrative access or specific vulnerable service states which are rarely present remotely without prior session establishment. Furthermore, handling raw cleartext increases memory artifact exposure and triggers aggressive endpoint detection rules.
Trap 2: Generating a golden ticket using the krbtgt hash obtained from a…
Golden ticket generation requires the long-term secret key of the krbtgt account, which is exclusive to domain controllers. The scenario explicitly describes a compromised workstation service account rather than enterprise administrator access to the domain root.
Trap 3: Requesting a Kerberos service ticket for the target database using…
Kerberos protocol architecture relies on cryptographic keys derived from user passwords, such as AES or RC4 keys, rather than NTLM hashes. Attempting to request a Kerberos ticket directly with an NTLM hash fails because the Key Distribution Center expects pre-authentication data encrypted with proper Kerberos keys.
- A
Injecting the cleartext password into the LSASS process memory of the remote database server.
Why it fails: Injecting plaintext credentials into LSASS requires interactive administrative access or specific vulnerable service states which are rarely present remotely without prior session establishment. Furthermore, handling raw cleartext increases memory artifact exposure and triggers aggressive endpoint detection rules.
- B
Generating a golden ticket using the krbtgt hash obtained from a compromised domain controller.
Why it fails: Golden ticket generation requires the long-term secret key of the krbtgt account, which is exclusive to domain controllers. The scenario explicitly describes a compromised workstation service account rather than enterprise administrator access to the domain root.
- C
Authenticating to the Server Message Block (SMB) service using the retrieved NTLM password hash directly.
Pass-the-Hash allows an attacker to authenticate against SMB and RPC services using the NTLM hash directly without needing the plaintext password. This leverages existing protocol specifications where the client proves knowledge of the secret via challenge-response math rather than sending plaintext credentials.
- D
Requesting a Kerberos service ticket for the target database using the cached NTLM hash.
Why it fails: Kerberos protocol architecture relies on cryptographic keys derived from user passwords, such as AES or RC4 keys, rather than NTLM hashes. Attempting to request a Kerberos ticket directly with an NTLM hash fails because the Key Distribution Center expects pre-authentication data encrypted with proper Kerberos keys.