[{"data":1,"prerenderedAt":669},["ShallowReactive",2],{"blog-shadows-credential-in-active-directory":3},{"post":4,"upNext":640,"linkedPosts":668},{"id":5,"title":6,"author":7,"body":8,"date":621,"description":622,"draft":623,"extension":624,"faq":625,"image":18,"lang":626,"lastReviewed":625,"link":627,"meta":628,"navigation":629,"path":630,"seo":631,"stem":632,"tags":633,"type":638,"__hash__":639},"content\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory.md","Shadow Credentials in Active Directory: A Silent Threat","Wisarud Wongta",{"type":9,"value":10,"toc":612},"minimark",[11,20,25,28,31,44,47,50,55,66,69,73,76,92,95,101,112,118,126,135,153,157,171,173,177,181,195,199,236,240,259,265,272,275,319,324,331,336,388,391,396,399,444,449,454,457,489,494,499,502,504,508,512,535,539,556,558,563,567,570,574,608],[12,13,14],"p",{},[15,16],"img",{"alt":17,"src":18,"width":19},"","\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-a82354e1-6720-4092-bad1-424aaf26a198.jpg","100%",[21,22,24],"h2",{"id":23},"introduction","Introduction",[12,26,27],{},"Shadow Credentials เป็นเทคนิคในการโจมตีรูปแบบหนึ่งที่ทำให้ attacker สามารถแฝงตัวเข้ายึดเครื่อง computer หรือ user ที่อยู่บน environment ของ Active Directory (AD) โดยการไปแก้ไขค่าบางอย่างที่ใช้ในการยืนยันตัวตนด้วย Key Trust โดยเทคนิคนี้จะสามารถทำการโจมตีไปที่ Windows implementation of Public Key Cryptography for Initial Authentication (PKINIT) ทำให้สามารถทำการเข้าถึงเครื่อง computer หรือ user โดยที่ไม่จำเป็นต้องใช้วิธีการโจมตีที่เป็น password-based",[12,29,30],{},"ในบทความนี้เราจะกล่าวถึงเนื้อหาต่าง ๆ ดังนี้",[32,33,34,38,41],"ul",{},[35,36,37],"li",{},"Understanding Shadow Credentials",[35,39,40],{},"Shadow Credentials in Action",[35,42,43],{},"Mitigation and detection techniques ",[45,46],"hr",{},[21,48,37],{"id":49},"understanding-shadow-credentials",[51,52,54],"h4",{"id":53},"what-are-shadow-credentials","What Are Shadow Credentials?",[12,56,57,58,62,63,65],{},"Shadow Credentials เป็นการโจมตีที่ใช้ประโยชน์จากความสามารถของวิธีการยืนยันตัวตนทางเลือก (เช่น certificates) สำหรับ AD accounts โดยแทนที่จะขโมยรหัสผ่านหรือ hash ผู้โจมตีสามารถทำการ register key pair ไปยัง account เป้าหมาย ซึ่งทำให้สามารถ authenticate เป็นผู้ใช้คนนั้นได้โดยไม่จำเป็นต้องรู้รหัสผ่านที่แท้จริง เทคนิคนี้จะสามารถทำการโจมตีได้ก็ต่อเมื่อผู้โจมตีมีสิทธิ์ write access กับ attribute ",[59,60,61],"code",{},"msDS-KeyCredentialLink"," ของเครื่องเป้าหมาย ซึ่ง ",[59,64,61],{}," เป็น attribute ที่เก็บ cryptographic key ที่ใช้สำหรับการ authenticate",[12,67,68],{},"ในการ authenticate บน Active Directory Environment นั้น, NTLM และ Kerberos ทำหน้าที่เป็นโปรโตคอลในการ authenticate หลักภายในโดเมนของ Active Directory โดยทำให้มั่นใจว่ามีการตรวจสอบตัวตนของ security principal อย่างถูกต้อง ซึ่งโปรโตคอล Kerberos อาศัยการเข้ารหัสที่เรียกว่า symmetric cryptography ระหว่างไคลเอนต์และเซิร์ฟเวอร์ โดยมีการใช้ตั๋วหรือ tickets เพื่อ authenticate",[51,70,72],{"id":71},"เกริ่นคร่าว-ๆ-เกี่ยวกับ-kerberostickets","เกริ่นคร่าว ๆ เกี่ยวกับ Kerberos Tickets",[12,74,75],{},"Kerberos มีการใช้งาน ticket สองประเภทหลัก ๆ โดยแต่ละประเภทมีบทบาทในการ authenticate ที่แตกต่างกันดังนี้:",[77,78,79,86],"ol",{},[35,80,81,85],{},[82,83,84],"strong",{},"Ticket Granting Ticket"," (TGT): เมื่อทำการ authenticate สำเร็จ TGT จะถูกออกให้และใช้เป็นสัญลักษณ์แสดงถึงตัวตนที่ได้รับการยืนยันแล้ว",[35,87,88,91],{},[82,89,90],{},"Ticket Granting Service(TGS)",": ticket นี้จะถูกใช้โดย principal หรือตัวตนที่ได้รับการ authenticate แล้วเท่านั้น TGS ใช้สำหรับการยืนยันตัวตนกับ service ต่างๆ ภายในโดเมน ช่วยให้สามารถเข้าถึง service ต่าง ๆ ภายใน Domain ได้โดยไม่ต้องผ่านกระบวนการ authenticate ซ้ำ",[12,93,94],{},"ในขั้นตอนในการขอ TGT การส่ง request จาก client ไปยัง Key Distribution Centre (KDC) จะมีกระบวนการที่เรียกว่า pre-authentication ซึ่งจะมีการทำ encryption ของข้อมูลฝั่ง client โดยจะมีวิธีการอยู่สองวิธีคือ ",[12,96,97,100],{},[82,98,99],{},"Symmetric Validation:"," โดยทั่วไปแล้ว Kerberos authentication จะมีการทำงานโดยทำการเข้ารหัส timestamp ด้วย symmetric key ที่สร้างมาจากรหัสผ่านของ client ซึ่งมีการใช้งาน encryption algorithms ต่าง ๆ เช่น RC4, DES หรือ AES128–256 เพื่อให้มั่นใจว่าในกระบวรการ authentication จะมีความปลอดภัยเพียงพอ ",[12,102,103,106,107,111],{},[82,104,105],{},"Asymmetric Validation",": ในการเพิ่มระดับความปลอดภัยของ Active Directory จึงมีการใช้วิธีการใหม่นอกจากการใช้ Symmetric Validation นั่นคือ ",[108,109,110],"em",{},"PKINIT"," ซึ่งอนุญาตให้มีการ authenticate ผ่านวิธีการแบบ Asymmetric โดยใช้ key pair (public key, private key), Public Key Infrastructure (PKI) จะช่วยให้ KDC และ client สามารถแลกเปลี่ยน public key ของกันและกันได้โดยใช้ digital certificates ที่ถูก signed โดย entity ที่ทั้งสองฝ่ายได้สร้าง trusted agreement ไว้ ผ่าน Certification Authority (CA) ทั้งหมดนี้คือ Certificate Trust model ซึ่งจะมีความเกี่ยวข้องกับการโจมตี Shadow Credential นั่นเอง",[51,113,115,116],{"id":114},"ทำความรู้จักกับ-attribute-msds-keycredentiallink","ทำความรู้จักกับ attribute ",[59,117,61],{},[12,119,120,122,123,125],{},[59,121,61],{}," เป็น attribute พิเศษที่เกี่ยวข้องกับ LDAP Service ซึ่งถูกเพิ่มเข้ามาใน Windows Server 2016 โดยจะทำหน้าที่เป็น attribute ที่เก็บค่าของ public key ที่ linked กับ computer หรือ user object บนโดเมน เมื่อ certificate ถูกเชื่อมกับ machine account แล้ว ค่าของ public key ก็จะถูกเก็บไว้ภายใน attribute ",[59,124,61],{}," นั้นเอง",[12,127,128,129,131,132,134],{},"โดยในการแก้ไขค่าของ attribute ",[59,130,61],{},"จะมีเงื่อนไขบางอย่าง คือ user objects จะไม่สามารถแก้ไข attribute ของ ",[59,133,61],{}," ของตนเองได้ ในขณะที่ computer objects จะสามารถทำได้ แต่จะสามารถเพิ่มได้เฉพาะในกรณีที่ยังไม่มี KeyCredential อยู่แล้วเท่านั้น",[12,136,137,138,141,142,145,146,149,150,152],{},"และเมื่อผู้ใช้มีสิทธิ์ ",[59,139,140],{},"GenericAll",", ",[59,143,144],{},"GenericWrite"," หรือ ",[59,147,148],{},"WriteAccountRestrictions"," ใน Discretionary Access Control List หรือ DACL สำหรับ object นั้น ๆ ซึ่งอาจเป็นได้ทั้ง computer หรือ user account ผู้ใช้คนดังกล่าวจะสามารถแก้ไข attribute ของ object ได้ซึ่งรวมถึงการแก้ไข attribute ",[59,151,61],{},"ของ object เป้าหมายให้เป็นค่าของ public key ที่ต้องการได้ ซึ่งหากมีการตั้งค่าที่ผิดพลาดก็อาจจะทำให้มีความเสี่ยงในการถูกโจมตีด้วย Shadow Credential นั้นเอง",[51,154,156],{"id":155},"why-are-they-dangerous","Why Are They Dangerous?",[32,158,159,165],{},[35,160,161,164],{},[82,162,163],{},"Persistence:"," Attacker จะยังคงมีสิทธิ์ในการเข้าถึงแม้ว่าจะมีการเปลี่ยนรหัสผ่านของเครื่องที่ถูกโจมตีแล้ว",[35,166,167,170],{},[82,168,169],{},"Stealth:"," ไม่มีการแก้ไขรหัสผ่านได ๆ ทำให้ยากต่อการถูกตรวจจับ",[45,172],{},[21,174,176],{"id":175},"shadow-credentials-inaction","Shadow Credentials in Action",[51,178,180],{"id":179},"pre-requisites","Pre-requisites",[77,182,183,186,189],{},[35,184,185],{},"Domain Controller ต้องเป็น Windows Server 2016 ขึ้นไป",[35,187,188],{},"Domain Controller ต้องมีการใช้งาน certificate สำหรับ authentication (มีการใช้งาน AD CS)",[35,190,191,192,194],{},"สามารถเข้าถึงหรือมี account ที่มีสิทธิ์ในการแก้ไข attribute ",[59,193,61],{}," ของเครื่องเป้าหมาย",[51,196,198],{"id":197},"how-attackers-exploit-shadow-credentials","How Attackers Exploit Shadow Credentials",[77,200,201,210,216,225],{},[35,202,203,206,207,209],{},[82,204,205],{},"Obtain Write Access:"," attacker ต้องมีสิทธิ์ในการแก้ไขค่า attribute ",[59,208,61],{}," ของ เป้าหมาย (เป็นได้ทั้ง user และ computer)",[35,211,212,215],{},[82,213,214],{},"Generate a Key Pair",": attacker ทำการสร้าง asymmetric key pair (public and private keys)",[35,217,218,221,222,224],{},[82,219,220],{},"Register the Key",": เพิ่มค่า public key ที่ทำการสร้างในขั้นตอนก่อนหน้าและนำไปแทนที่ใน attributute ",[59,223,61],{}," ของเป้าหมาย",[35,226,227,230,231],{},[82,228,229],{},"Authenticate as the Target:"," attacker ก็จะสามารถทำการ authenticate ด้วย PKINIT เป็น user ได้เลยโดยไม่จำเป็นต้องรู้รหัสผ่าน\n",[15,232],{"alt":17,"src":233,"width":234,"height":235},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-c8613660-840d-4c7f-8c93-5c997f5a9f0d.jpg",861,932,[51,237,239],{"id":238},"hands-on-exploiting-shadow-credentials-withwhisker","Hands-On: Exploiting Shadow Credentials with whisker",[12,241,242,249,250,255,256,258],{},[243,244,248],"a",{"href":245,"rel":246},"https:\u002F\u002Fgithub.com\u002Feladshamir\u002FWhisker%3Ftab%3Dreadme-ov-file",[247],"nofollow","Whisker"," เป็นเครื่องมือที่ช่วยในการโจมตี Shadow Credential แบบอัตโนมัติ ถูกพัฒนาด้วยภาษา C# เป็น 1 ในเครื่องมือภายในโปรเจค ",[243,251,254],{"href":252,"rel":253},"https:\u002F\u002Fgithub.com\u002FMichaelGrafnetter\u002FDSInternals",[247],"DSInternal"," ที่ถูกพัฒนาโดยคุณ Michael Grafnetter, Whisker จะช่วยในการ add, replace attribute ",[59,257,61],{}," ให้กับ user โดยอัตโนมัติ",[12,260,261,262,264],{},"สำหรับตัวอย่างจาก Bloodhound ด้านล่างจะเห็นว่า user \"Shadow\" มีสิทธิ์ \"AddKeyCredentialLink\" กับ user \"Sonic\" ดังนั้นเราจะทำการใช้งานเครื่องมือนี้บน workstation ของ user \"Shadow\" เพื่อทำการแก้ไขค่า ",[59,263,61],{}," ของ user \"Sonic\"",[12,266,267],{},[15,268],{"alt":17,"src":269,"width":270,"height":271},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-f0efb706-7d4f-4161-9c15-9bf1d7285a16.jpg",1400,207,[12,273,274],{},"เริ่มด้วยการ list keycredential ของ user \"Sonic\" ด้วยคำสั่งด้านล่าง",[276,277,281],"pre",{"className":278,"code":279,"language":280,"meta":17,"style":17},"language-bash shiki shiki-themes github-light",".\\Whisker.exe list \u002Ftarget:\u003Ctarget>\n","bash",[59,282,283],{"__ignoreMap":17},[284,285,288,292,296,300,303,306,310,313,316],"span",{"class":286,"line":287},"line",1,[284,289,291],{"class":290},"sYu0t",".",[284,293,295],{"class":294},"sgsFI","\\",[284,297,299],{"class":298},"sYBdl","Whisker.exe",[284,301,302],{"class":298}," list",[284,304,305],{"class":298}," \u002Ftarget:",[284,307,309],{"class":308},"sD7c4","\u003C",[284,311,312],{"class":298},"targe",[284,314,315],{"class":294},"t",[284,317,318],{"class":308},">\n",[12,320,321,322],{},"จากผลลัพธ์ของการใช้คำสั่งจะเห็นว่า user \"Sonic\" มีข้อมูล publickey อยู่ที่ attribute ",[59,323,61],{},[12,325,326],{},[15,327],{"alt":17,"src":328,"width":329,"height":330},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-62c79370-6122-40fc-aa03-f8a16529727f.jpg",1366,160,[12,332,333,334,264],{},"จากนั้นทำการสั่งใช้งานให้ whisker ทำการสร้าง certificate และทำการ add Public key ไปยัง attribute ",[59,335,61],{},[276,337,339],{"className":278,"code":338,"language":280,"meta":17,"style":17},".\\Whisker.exe add \u002Ftarget:\u003Ctarget> \u002Fdomain:\u003Cdomain> \u002Fdc:\u003Cdc_ip>\n",[59,340,341],{"__ignoreMap":17},[284,342,343,345,347,349,352,354,356,358,360,363,366,368,371,374,376,379,381,384,386],{"class":286,"line":287},[284,344,291],{"class":290},[284,346,295],{"class":294},[284,348,299],{"class":298},[284,350,351],{"class":298}," add",[284,353,305],{"class":298},[284,355,309],{"class":308},[284,357,312],{"class":298},[284,359,315],{"class":294},[284,361,362],{"class":308},">",[284,364,365],{"class":298}," \u002Fdomain:",[284,367,309],{"class":308},[284,369,370],{"class":298},"domai",[284,372,373],{"class":294},"n",[284,375,362],{"class":308},[284,377,378],{"class":298}," \u002Fdc:",[284,380,309],{"class":308},[284,382,383],{"class":298},"dc_i",[284,385,12],{"class":294},[284,387,318],{"class":308},[12,389,390],{},"จะเห็นว่าเมื่อ Whikser ทำงานเสร็จสิ้น จะมีการสร้างคำสั่ง Rubeus ที่ใช้ในการดึง password มาให้ด้วย โดยการใช้ certificate เพื่อทำการร้องขอ TGT และนำไปดึงข้อมูล password ของ user นั่นเอง",[12,392,393],{},[15,394],{"alt":17,"src":395,"width":19},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-548e8d31-e235-4fcc-abcb-85ef3d4ff84f.jpg",[12,397,398],{},"ก็เป็นอันเสร็จสิ้นขั้นตอนการโจมตีด้วยวิธีการ Shadow Credential Attacks \nโดยหลังจากนี้จะเป็นการแสดงตัวอย่างการขยายผลด้วยวิธีการโจมตีข้างต้น ด้วยการใช้งานเครื่องมือ Rubeus ในการ show credential ของ user \"Sonic\" ",[276,400,402],{"className":278,"code":401,"language":280,"meta":17,"style":17},"Rubeus.exe asktgt \u002Fuser:sonic \u002Fcertificate:\u003Ccertfromwhisker> \u002Fpassword:\"Le5kc2QjNAEajuRH\" \u002Fdomain:VAULT.TEC \u002Fdc:SANTA-MONICA.VAULT.TEC \u002Fgetcredentials \u002Fshow\n",[59,403,404],{"__ignoreMap":17},[284,405,406,410,413,416,419,421,424,427,429,432,435,438,441],{"class":286,"line":287},[284,407,409],{"class":408},"s7eDp","Rubeus.exe",[284,411,412],{"class":298}," asktgt",[284,414,415],{"class":298}," \u002Fuser:sonic",[284,417,418],{"class":298}," \u002Fcertificate:",[284,420,309],{"class":308},[284,422,423],{"class":298},"certfromwhiske",[284,425,426],{"class":294},"r",[284,428,362],{"class":308},[284,430,431],{"class":298}," \u002Fpassword:\"Le5kc2QjNAEajuRH\"",[284,433,434],{"class":298}," \u002Fdomain:VAULT.TEC",[284,436,437],{"class":298}," \u002Fdc:SANTA-MONICA.VAULT.TEC",[284,439,440],{"class":298}," \u002Fgetcredentials",[284,442,443],{"class":298}," \u002Fshow\n",[12,445,446],{},[15,447],{"alt":17,"src":448,"width":19},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-b8c0d48a-3e47-4591-8a23-529979e3f84d.jpg",[12,450,451],{},[15,452],{"alt":17,"src":453,"width":19},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-ed088135-ae48-4d5c-88fa-b36d36d624f3.jpg",[12,455,456],{},"หรือสามารถนำ certificate มา pass the ticket เพื่อ impersonate ไปเป็น user \"Sonic\" ก็ได้เช่นเดียวกัน",[276,458,460],{"className":278,"code":459,"language":280,"meta":17,"style":17},"Rubeus.exe asktgt \u002Fuser:sonic \u002Fcertificate:\u003Ccertfromwhisker> \u002Fpassword:\"Le5kc2QjNAEajuRH\" \u002Fdomain:VAULT.TEC \u002Fdc:SANTA-MONICA.VAULT.TEC \u002Fptt\n",[59,461,462],{"__ignoreMap":17},[284,463,464,466,468,470,472,474,476,478,480,482,484,486],{"class":286,"line":287},[284,465,409],{"class":408},[284,467,412],{"class":298},[284,469,415],{"class":298},[284,471,418],{"class":298},[284,473,309],{"class":308},[284,475,423],{"class":298},[284,477,426],{"class":294},[284,479,362],{"class":308},[284,481,431],{"class":298},[284,483,434],{"class":298},[284,485,437],{"class":298},[284,487,488],{"class":298}," \u002Fptt\n",[12,490,491],{},[15,492],{"alt":17,"src":493,"width":19},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-3a91d92a-e914-422f-b291-95894b940a8c.jpg",[12,495,496],{},[15,497],{"alt":17,"src":498,"width":19},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-aa20cf9a-496b-41a5-9625-a8a89730f535.jpg",[12,500,501],{},"ด้วยวิธีการดังกล่าวจะทำให้ผู้โจมตีทำการ compromise account ได้ถึงแม้ว่าจะไม่ทราบ credential ใด ๆ เลย และถึงแม้ว่า account ที่ถูก compromise จะมีการเปลี่ยนรหัสผ่าน ผู้โจมตีก็ยังสามารถที่จะใช้งาน certificate ที่สร้างขึ้นเพื่อ impersonate เป็น user นั้นได้อยู่ดี",[45,503],{},[21,505,507],{"id":506},"detection-prevention","Detection & Prevention",[51,509,511],{"id":510},"how-to-detect-shadow-credentials","How to Detect Shadow Credentials",[32,513,514,526],{},[35,515,516,519,520,519,522,525],{},[82,517,518],{},"Monitor"," ",[59,521,61],{},[82,523,524],{},"Changes",": ทำการตรวจสอบ event logs หากมีการแก้ไขค่า attribute",[35,527,528,531,532,534],{},[82,529,530],{},"Audit Write Permissions",": ตรวจสอบ users\u002Fgroups ที่มีสิทธิ์ในการเขียนหรือแก้ไขค่า ",[59,533,61],{}," อย่างสม่ำเสมอ",[51,536,538],{"id":537},"how-to-prevent-shadow-credential-attacks","How to Prevent Shadow Credential Attacks",[32,540,541,550],{},[35,542,543,546,547,549],{},[82,544,545],{},"Restrict Write Access:"," ทำการจำกัดไม่ให้มีการแก้ไข attribute ",[59,548,61],{}," โดย user ที่ไม่สมควรแก้ไข",[35,551,552,555],{},[82,553,554],{},"Implement Certificate-Based Authentication Monitoring",": ติดตามกระบวนการ authentication ที่ไม่ได้มาตรฐาน",[45,557],{},[12,559,560],{},[15,561],{"alt":17,"src":562,"width":19},"\u002Fimages\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory\u002Fimages-4859bf6a-c75c-4b47-bceb-f59fd3346193.jpg",[21,564,566],{"id":565},"conclusion","Conclusion",[12,568,569],{},"Shadow Credential เป็นวิธีการโจมตีบน Activie Directory Enviroment ที่มีความรุนแรงและยังสามารถถูกตรวจจับได้ยาก ซึ่งการทำความเข้าใจการทำงานของการโจมตีดังกล่าว, วิธีที่ attacker จะนำไปใช้, การตรวจจับและการป้องกันการโจมตีนี้ก็ถือเป็นส่วนสำคัญที่จะทำให้สามารถทำการป้องกันการโจมตีนี้ได้",[21,571,573],{"id":572},"related-articles","Related Articles",[32,575,576,582,588,595,602],{},[35,577,578],{},[243,579,581],{"href":580},"\u002Fblogs\u002Fintroduction-to-adcs","Introduction to Active Directory Certificate Services (AD CS)",[35,583,584],{},[243,585,586],{"href":586,"rel":587},"https:\u002F\u002Fwww.thehacker.recipes\u002Fad\u002Fmovement\u002Fkerberos\u002Fshadow-credentials",[247],[35,589,590],{},[243,591,594],{"href":592,"rel":593},"https:\u002F\u002Fi-tracing.com\u002Fblog\u002Fdacl-shadow-credentials\u002F",[247],"Golden Ticket Attacks: How Attackers Forge Authentication",[35,596,597],{},[243,598,601],{"href":599,"rel":600},"https:\u002F\u002Fwww.ired.team\u002Foffensive-security-experiments\u002Factive-directory-kerberos-abuse\u002Fshadow-credentials",[247],"Detecting Persistence in Active Directory",[35,603,604],{},[243,605,607],{"href":245,"rel":606},[247],"https:\u002F\u002Fgithub.com\u002Feladshamir\u002FWhisker?tab=readme-ov-file",[609,610,611],"style",{},"html pre.shiki code .sYu0t, html code.shiki .sYu0t{--shiki-default:#005CC5}html pre.shiki code .sgsFI, html code.shiki .sgsFI{--shiki-default:#24292E}html pre.shiki code .sYBdl, html code.shiki .sYBdl{--shiki-default:#032F62}html pre.shiki code .sD7c4, html code.shiki .sD7c4{--shiki-default:#D73A49}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .s7eDp, html code.shiki .s7eDp{--shiki-default:#6F42C1}",{"title":17,"searchDepth":613,"depth":613,"links":614},2,[615,616,617,618,619,620],{"id":23,"depth":613,"text":24},{"id":49,"depth":613,"text":37},{"id":175,"depth":613,"text":176},{"id":506,"depth":613,"text":507},{"id":565,"depth":613,"text":566},{"id":572,"depth":613,"text":573},"2025-06-25","Shadow Credentials ทำให้ผู้โจมตียึดสิทธิ์ของเครื่องหรือ user บน Active Directory ได้โดยไม่ต้องรู้รหัสผ่าน บทความอธิบายว่ากลไกนี้อาศัยอะไรและทำงานอย่างไร",false,"md",null,"th","shadows-credential-in-active-directory",{},true,"\u002Fblogs\u002F2025-06-25-shadows-credential-in-active-directory",{"title":6,"description":622},"blogs\u002F2025-06-25-shadows-credential-in-active-directory",[634,635,636,637],"active-directory","windows-security","kerberos","pentest","ARTICLES","IuzSApRT1728s5wV1HEO2PaUKjGy-PzuRX38wnaX3ik",[641,650,659],{"id":642,"link":643,"title":644,"description":645,"image":646,"date":647,"type":638,"author":7,"tags":648},"content\u002Fblogs\u002F2026-08-10-ker-delg-pt1.md","ker-delg-pt1","Kerberos Delegation Attacks Part 1: Unconstrained Delegation","Kerberos Delegation ถูกสร้างมาเพื่อรองรับ multi-tier application แต่ trust relationship ที่ทรงพลังของมันก็เปิดช่องให้ attacker ปลอมเป็นผู้ใช้และทำ lateral movement ได้ถ้าตั้งค่าผิด","\u002Fimages\u002Fblogs\u002F2026-08-10-ker-delg-pt1\u002Fimage-20260803-161404.426Z-1207.png","2026-08-10",[637,649,634,636,635],"red-teaming",{"id":651,"link":652,"title":653,"description":654,"image":655,"date":656,"type":638,"author":657,"tags":658},"content\u002Fblogs\u002F2025-07-23-microsoft-officially-deprecates-ntlm-authentication-protocol-in-windows.md","microsoft-officially-deprecates-ntlm-authentication-protocol-in-windows","NTLM Authentication กำลังจะกลายเป็นอดีตจริงหรือ ?","Microsoft ออกมาประกาศว่า NTLM จะถูก deprecated อย่างเป็นทางการใน Windows 11 24H2 และ Windows Server 2025","\u002Fimages\u002Fblogs\u002F2025-07-23-microsoft-officially-deprecates-ntlm-authentication-protocol-in-windows\u002Fimages-416a6d4f-ce6a-4320-b51a-d5cc4e3b18d9.jpg","2025-07-23","Athittaya Saeloh",[635,634,636,637,649],{"id":660,"link":661,"title":662,"description":663,"image":664,"date":665,"type":638,"author":666,"tags":667},"content\u002Fblogs\u002F2021-08-27-attacking-kerberos-in-windows-domain-environment.md","attacking-kerberos-in-windows-domain-environment","Attacking Kerberos in Windows Domain Environment","รวมเทคนิคโจมตี Kerberos ใน Windows Domain สำหรับนักทดสอบเจาะระบบ เน้นที่มาที่ไปและวิธีการโจมตี มากกว่าฝั่ง detection และ prevention","\u002Fimages\u002Fblogs\u002F2021-08-27-attacking-kerberos-in-windows-domain-environment\u002Ffull.png","2021-08-27","Incognito Lab",[636,634,635,637],[],1791516131355]