User-to-User Authentication: Down the Rabbit Hole – Part 1
ID: 4a0dff9b-2310-544f-8b6f-1b73855ad1f1
STIX ID: report--4a0dff9b-2310-544f-8b6f-1b73855ad1f1
Feed Name: SpecterOps Blog
This blog post details Windows Kerberos U2U (user-to-user) authentication internals, how clients obtain and use TGT session keys for peer-to-peer Kerberos exchanges (with a focused example in RDP/NLA), and how those mechanisms enable the UnPAC-the-Hash technique—where an attacker using PKINIT and a compromised certificate can obtain a TGT/AS-reply key, decrypt PAC_CREDENTIAL_INFO, and recover NT hashes that can be used for Pass-the-Hash or further Kerberos abuses; the post is an explanatory TTP analysis rather than an incident report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
