Skip to content

Conversation

@4ndr3w6
Copy link
Contributor

@4ndr3w6 4ndr3w6 commented Jun 24, 2025

Re-cutting the Diamond Ticket.

This PR adds the ability to now

  1. Supply /opsec to diamond
  2. Supply /ldap via [/ldapuser] and [/ldappassword] to diamond
  3. Supply a service ticket to forge a diamond service ticket

Blog post with more information: https://www.huntress.com/blog/recutting-the-kerberos-diamond-ticket

@4ndr3w6
Copy link
Contributor Author

4ndr3w6 commented Jun 24, 2025

Fixed app.config and Rubeus.csproj back to 4.0

@oripka
Copy link

oripka commented Jul 17, 2025

It seems to me ldapuser and ldappassword do not work. Somehow the code uses creduser and credpassword instead, which worked in my testing

@HarmJ0y
Copy link
Member

HarmJ0y commented Jul 23, 2025

It doesn't seem like there are conflicts, and I'm OK to merge - do you have any thoughts on the above issue @4ndr3w6 (ldap creds)?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants