A diamond ticket is a stealthier variant of a golden ticket, in that it is not created from nothing, but instead modified from an existing TGT. It’s harder to detect a diamond ticket since it is a legitimately issued ticket, just with modified content.
To generate a diamond ticket with Rubeus:
/tgtdeleg
: obtain ticket for current user through GSS-API and faked delegation; it doesn’t matter what the current user is: no elevation is needed to obtain this ticket, and the username will be overwritten anyway- Use 512 for
/groups
for Domain Admins group, 519 for Enterprise Admins group.