Golden Ticket
Dump hashes - Get the krbtgt hash
Make golden ticket
Use /ticket instead of /ptt to save the ticket to file instead of loading in current powershell process To get the SID use Get-DomainSID
from powerview
Use the DCSync feature for getting krbtgt hash. Execute with DA privileges
Check WMI Permission
BetterSafetyKatz Golden Ticket
Last updated