logo

User-to-User Authentication: Down the Rabbit Hole – Part 1

ID: 4a0dff9b-2310-544f-8b6f-1b73855ad1f1

STIX ID: report--4a0dff9b-2310-544f-8b6f-1b73855ad1f1

Feed Name: SpecterOps Blog

Threat Score
65/100

Date Published: 2026-06-09

Date Updated: 2026-07-16

...
...

This blog post details Windows Kerberos U2U (user-to-user) authentication internals, how clients obtain and use TGT session keys for peer-to-peer Kerberos exchanges (with a focused example in RDP/NLA), and how those mechanisms enable the UnPAC-the-Hash technique—where an attacker using PKINIT and a compromised certificate can obtain a TGT/AS-reply key, decrypt PAC_CREDENTIAL_INFO, and recover NT hashes that can be used for Pass-the-Hash or further Kerberos abuses; the post is an explanatory TTP analysis rather than an incident report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.