MISC::Skeleton – 在 DC 中注入万能钥匙(Skeleton Key) 到 LSASS 进程中。这使得所有用户所使用的万能钥匙修补 DC 使用 “主密码” (又名万能钥匙)以及他们自己通常使用的密码进行身份验证。
具体原理有待分析。
可以看看这个ffcK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3q4V1M7$3g2U0N6i4u0A6N6s2W2Q4x3X3g2G2M7X3N6Q4x3V1k6Q4x3@1k6H3i4K6y4p5x3e0t1%4y4g2)9J5y4X3&6T1M7%4m8Q4x3@1t1`. Attackers Can Now Use Mimikatz to Implant Skeleton Key on Domain Controllers & BackDoor Your Active Directory Forest
注入时:Event 4611: A trusted logon process has been registered with the Local Security Authority.
登入时:Event 4688: A new process has been created. c:\wndows\temp\mimikatz.exe