Skip to content

Add /brokenmarriage flag to prevent CANONICALIZE when using opsec#212

Open
bcampbell-wsecure wants to merge 1 commit intoGhostPack:masterfrom
bcampbell-wsecure:brokenmarriage
Open

Add /brokenmarriage flag to prevent CANONICALIZE when using opsec#212
bcampbell-wsecure wants to merge 1 commit intoGhostPack:masterfrom
bcampbell-wsecure:brokenmarriage

Conversation

@bcampbell-wsecure
Copy link

Flag could also be renamed to /nocanonicalize or something generic.

This allows a Kerberos ticket to be created with most of the OPSEC features, but still perform the BM attack.

@CCob
Copy link
Contributor

CCob commented Sep 8, 2025

Not sure if it's really worth adding another parameter to the gazillion that are already there. By requesting no canonicalization, you've already wandered off what a genuine LSASS login request looks like anyway. Windows always requests canonicalization.

@bcampbell-wsecure
Copy link
Author

Doesn't matter what Windows does, matters what the EDR tooling actually checks :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants