logo

Attacking FreeIPA — Part I Authentication

ID: ba7aa438-41e5-5385-ae9b-e7c46752a638

STIX ID: report--ba7aa438-41e5-5385-ae9b-e7c46752a638

Feed Name: SpecterOps Blog

Date Published: 2019-11-25

Date Updated: 2026-04-30

Author: Julian Catrambone

...
...

This post outlines attacker-focused tradecraft for operating in FreeIPA-managed Unix environments, covering key indicators of enrollment (e.g., /etc/krb5.conf, /etc/ipa/default.conf, /etc/krb5.keytab), relevant environment variables (KRB5CCNAME, KRB5_KTNAME, etc.), and common Kerberos/IPA utilities (ipa, kinit, klist). It explains how Kerberos credentials are stored and can be leveraged—parsing and reusing CCACHE tickets from disk and the Linux keyring (with klist and Tickey), as well as extracting and using keytabs to obtain TGTs (via klist, KeytabParser, and kinit). The piece serves as a practical guide for situational awareness and credential re-use within FreeIPA domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.