Open s0i37 opened 4 years ago
Tickets in memory are not stored as kirbi (KRB-CRED). (not ASN1) I'm not aware of a yara rule around them, but it must not be complicated to make one.
Ok.
Can !mimikatz
windbg-extension extract kerberos tickets from memory dump?
Good day. I'm trying to extract kerberos tickets from memory with yara signatures. But:
klist
shows manyMay you please tell me, how can extract kerberos tickets from memory (minidump)