Kerberos never needs the plaintext password: the AS exchange is keyed on the account's secret key, which is derived from the password (RC4 key = the NT hash; AES keys = PBKDF2 over the password). So if you hold the NT hash or an AES key, you can request a legitimate TGT and become that account in Kerberos. When the input is the NT hash this is called overpass-the-hash; when it is the AES key it is pass-the-key. They are the bridge from a recovered secret (dumping, DCSync) into full Kerberos movement.
Requesting the TGT#
# Overpass-the-hash: NT (RC4) hash -> TGT
getTGT.py -hashes :<nthash> example.local/user
# Pass-the-key: AES256 key -> TGT (stealthier where RC4 is monitored/disabled)
getTGT.py -aesKey <aes256key> example.local/user
export KRB5CCNAME=user.ccache
wmiexec.py -k -no-pass example.local/user@<host> # use the ticket
# Rubeus, on-host
Rubeus.exe asktgt /user:user /rc4:<nthash> /ptt
Rubeus.exe asktgt /user:user /aes256:<aes256key> /ptt
The resulting TGT is indistinguishable from a normal logon's: this is a legitimate ticket, just obtained from the key instead of the password.
Why choose this over pass-the-hash#
Pass-the-hash reuses the NT hash over NTLM. Overpass-the-hash converts the same hash into Kerberos, which matters when:
- The target accepts only Kerberos (NTLM disabled or blocked).
- You want to move with tickets (pass-the-ticket, delegation abuse) rather than NTLM auth.
- You want to be quieter: a Kerberos logon blends with normal traffic better than NTLM exec in some environments.
RC4 vs AES#
- Supplying the RC4 key (the NT hash) forces an RC4-encrypted exchange, which can stand out where the domain is AES-only or where RC4 downgrade is monitored.
- Supplying the AES256 key produces an AES exchange that matches normal clients. Recover AES keys from LSASS (
sekurlsa::ekeys) or from an-just-dcNTDS dump and prefer them.
Exploitation notes#
- Overpass-the-hash plus the AES key is the stealthy default for reusing a recovered machine or service secret as Kerberos.
- A TGT obtained this way drives everything downstream: pass-the-ticket, S4U delegation abuse, and service-ticket requests.
- Clock skew matters: Kerberos rejects tickets outside a ~5-minute window, so sync to the DC's time before requesting.
Tools#
- Impacket (
getTGT.py,-k): request and use TGTs from hash or AES key. - Rubeus (
asktgt): on-host TGT request with/rc4,/aes256,/ptt. - Mimikatz (
sekurlsa::ekeys): recover AES keys from LSASS for pass-the-key.
References#
- The Hacker Recipes: pass the key / overpass the hash
- Microsoft: Kerberos key types and etypes