Catalog WADComs

WAD · Tool

Impacket-describeTicket

1 technique Linux · ActiveDirectory · WindowsWADComs GPL-3.0

Impacket-DescribeTicket

NEW
Discovery LinuxActiveDirectoryWindows

Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline. Command Reference: Ticket file: out.ccache

# Describe a ticket offline (envelope, flags, and the PAC where it can be read)
describeTicket.py out.ccache
Native
Discovery
Requires
TGT
Services
Kerberos