logo

Attack Tactics 9: Shadow Creds for PrivEsc w/ Kent & Jordan

ID: 777f87b2-5d3b-5da5-90eb-d61f5467cc3c

STIX ID: report--777f87b2-5d3b-5da5-90eb-d61f5467cc3c

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2025-01-20

Date Updated: 2026-04-27

Author: BHIS

...
...

This webcast transcript details an Active Directory abuse technique called "shadow credentials" where attackers coerce Windows services, capture machine authentication, and relay it to update the msDS-KeyCredentialLink attribute—allowing certificate-based authentication as a computer object to obtain Kerberos tickets and escalate to administrative privileges. The talk covers a step‑by‑step lab (SSH tunnels, PetitPotem, NTLMRelayX, PKINIT, Whisker), practical detection challenges (msDS-KeyCredentialLink is not audited by default), and primary mitigations (enforce LDAP signing/channel binding and SMB signing, restrict who can write the attribute, and enable targeted auditing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.