Skip to content

Adding shadow credentials attack#7

Open
j4s0nmo0n wants to merge 2 commits intologangoins:mainfrom
j4s0nmo0n:main
Open

Adding shadow credentials attack#7
j4s0nmo0n wants to merge 2 commits intologangoins:mainfrom
j4s0nmo0n:main

Conversation

@j4s0nmo0n
Copy link
Contributor

Hello,

I propose adding the Shadow Credentials attack as it is implemented in pywhisker.

Here, we can create and add a public key to the msDS-KeyCredentialLink attribute:

image

We can also display device information:

image

After that, we can request a TGT using our certificate:

image

Kerberos PKINIT authentication:

image

I hope this helps.

j4s0nmo0n and others added 2 commits February 1, 2026 10:41
Updated usage instructions and added Shadow Credentials options.
@logangoins
Copy link
Owner

Love this! Give me a bit of time to do QA and I'll get it merged!

This is another feature that I've wanted to add but haven't been able to. After this gets merged, I might also do an organization/overhaul/cleanup of the project, change the way argparsing works, and a few other changes as part of a major release now that a lot of features have been added and the project has been extended.

Thanks for all of your hard work as always!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants