How to Achieve Eternal Persistence Part 2: Outliving the Krbtgt Password Reset
Common Information
Type Value
UUID 9fe3a005-9d31-42f6-b224-9d8862051f5a
Fingerprint a098e4110cf037f5
Analysis status DONE
Considered CTI value -2
Text language
Published May 30, 2024, 7:43 a.m.
Added to db Aug. 31, 2024, 10:48 a.m.
Last updated Nov. 18, 2024, 11:24 a.m.
Headline How to Achieve Eternal Persistence Part 2: Outliving the Krbtgt Password Reset
Title How to Achieve Eternal Persistence Part 2: Outliving the Krbtgt Password Reset
Detected Hints/Tags/Attributes 47/1/12
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 412 Hunt & Hackett Blog https://www.huntandhackett.com/blog/rss.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 4131
github.com
Details Github username 2
billchaison
Details Github username 3
huntandhackett
Details IPv4 1
192.168.88.129
Details IPv4 1
192.168.88.128
Details Url 1
https://github.com/billchaison/securechannel
Details Url 2
https://github.com/huntandhackett/passiveaggression
Details Url 1
https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/modify-default-intra-site-dc-replication-interval#more
Details Url 1
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/b06e6b30-fe57-4e0f-ba1a-5214c953a5df
Details Url 1
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-sams/04428101-3a8d-48fe-a324-7206cf8f8bc3
Details Url 1
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-sams/e6d9295f-dbb8-46a5-98f7-f4d3f970f36b
Details Url 2
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-reset-the-krbtgt-password