Attacking FreeIPA — Part I Authentication
ID: ba7aa438-41e5-5385-ae9b-e7c46752a638
STIX ID: report--ba7aa438-41e5-5385-ae9b-e7c46752a638
Feed Name: SpecterOps Blog
This post outlines attacker-focused tradecraft for operating in FreeIPA-managed Unix environments, covering key indicators of enrollment (e.g., /etc/krb5.conf, /etc/ipa/default.conf, /etc/krb5.keytab), relevant environment variables (KRB5CCNAME, KRB5_KTNAME, etc.), and common Kerberos/IPA utilities (ipa, kinit, klist). It explains how Kerberos credentials are stored and can be leveraged—parsing and reusing CCACHE tickets from disk and the Linux keyring (with klist and Tickey), as well as extracting and using keytabs to obtain TGTs (via klist, KeytabParser, and kinit). The piece serves as a practical guide for situational awareness and credential re-use within FreeIPA domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
