SecurityCipher
Home Blog About Us

Learn Paths, courses, and reference docs

  • 🚀 Start Here Beginner path through the site
  • 🗺️ Penetration Testing Roadmap Structured path to become a pentester
  • 🎓 Free Security Courses Current free Udemy coupon listings
  • 📄 Secure Code Explain Vulnerable vs secure code side by side
  • 🎯 Penetration Testing Tricks Field notes for real engagements
  • 📖 Vulnerability Explain How common vulns actually work

Checklists Interactive reviews and LLM risks

  • ✅ Security Checklists Hub All interactive security checklists
  • 📋 Writeup Checklists Steps derived from real writeups
  • 🧠 LLM AI Security Checklist Controls for LLM apps
  • 🤖 OWASP LLM Top 10 LLM Top 10 risks mapped out
  • 🧰 Burp Suite Guide Step-by-step Burp tutorials
  • 📘 Payload Field Manual Safe-first probes and signals

Practice Browser labs, games, and explorers

  • 🔬 Interactive Labs SQL injection, AI, architecture review
  • 🎮 Security Games Phishing, JWT, WAF, and more
  • 🚗 On-Call Drive Neon-city arcade security missions
  • • Shift Zero SOC desk: phish, OTP, malware, tickets
  • ❓ Application Security Quiz Web, secure coding, and cloud quizzes
  • 🗺️ OWASP Top 10 Explorer Clickable risk map with signals
  • 🔀 Interactive Attack Paths Recon-to-impact chains

Tools & Career Databases, jobs, and community

  • 🛠️ Security Tools Curated recon, SAST, and bounty tools
  • 🔎 CVE Lookup Multi-source CVE intelligence
  • 💰 Bug Bounty Programs Live public scopes to search
  • 💼 Cybersecurity Jobs Roles from company career pages
  • 🧑‍💻 Security Researchers Community profiles and submissions
  • 🎤 Security Conferences Upcoming and past events
Browse all Security resources hub Freelance Security →
My Resume
Freelance SecurityFreelance
New Security Researchers Join the directory - submit your profile for review Submit profile →
← Security Tools View on GitHub

Whisker

C# tool to take over AD accounts by abusing msDS-KeyCredentialLink (shadow credentials).

Whisker

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.

This tool is based on code from DSInternals by Michael Grafnetter (@MGrafnetter).

For this attack to succeed, the environment must have a Domain Controller running at least Windows Server 2016, and the Domain Controller must have a server authentication certificate to allow for PKINIT Kerberos authentication.

More details are available at the post Shadow Credentials: Abusing Key Trust Account Mapping for Takeover.

Usage

Add a new value to the msDS-KeyCredentialLink attribute of a target object:

  • /target:<samAccountName>: Required. Set the target name. Computer objects should end with a '$' sign.

  • /domain:<FQDN>: Optional. Set the target Fully Qualified Domain Name (FQDN). If not provided, will try to resolve the FQDN of the current user.

  • /dc:<IP/HOSTNAME>: Optional. Set the target Domain Controller (DC). If not provided, will try to target the Primary Domain Controller (PDC).

  • /path:<PATH>: Optional. Set the path to store the generated self-signed certificate for authentication. If not provided, the certificate will be printed as a Base64 blob.

  • /password:<PASWORD>: Optional. Set the password for the stored self-signed certificate. If not provided, a random password will be generated.

Example: Whisker.exe add /target:computername$ /domain:constoso.local /dc:dc1.contoso.local /path:C:\path\to\file.pfx /password:P@ssword1

Remove a value from the msDS-KeyCredentialLink attribute of a target object:

  • /target:<samAccountName>: Required. Set the target name. Computer objects should end with a '$' sign.

  • /deviceID:<GUID>: Required. Set the DeviceID of the value to remove from the attribute msDS-KeyCredentialLink of the target object. Must be a valid GUID.

  • /domain:<FQDN>: Optional. Set the target Fully Qualified Domain Name (FQDN). If not provided, will try to resolve the FQDN of the current user.

  • /dc:<IP/HOSTNAME>: Optional. Set the target Domain Controller (DC). If not provided, will try to target the Primary Domain Controller (PDC).

Example: Whisker.exe remove /target:computername$ /domain:constoso.local /dc:dc1.contoso.local /deviceid:2de4643a-2e0b-438f-a99d-5cb058b3254b

Clear all the values of the the msDS-KeyCredentialLink attribute of a target object:

  • /target:<samAccountName>: Required. Set the target name. Computer objects should end with a '$' sign.

  • /domain:<FQDN>: Optional. Set the target Fully Qualified Domain Name (FQDN). If not provided, will try to resolve the FQDN of the current user.

  • /dc:<IP/HOSTNAME>: Optional. Set the target Domain Controller (DC). If not provided, will try to target the Primary Domain Controller (PDC).

Example: Whisker.exe clear /target:computername$ /domain:constoso.local /dc:dc1.contoso.local

⚠️ Warning: Clearing the msDS-KeyCredentialLink attribute of accounts configured for passwordless authentication will cause disruptions.

List all the values of the the msDS-KeyCredentialLink attribute of a target object:

  • /target:<samAccountName>: Required. Set the target name. Computer objects should end with a '$' sign.

  • /domain:<FQDN>: Optional. Set the target Fully Qualified Domain Name (FQDN). If not provided, will try to resolve the FQDN of the current user.

  • /dc:<IP/HOSTNAME>: Optional. Set the target Domain Controller (DC). If not provided, will try to target the Primary Domain Controller (PDC).

Example: Whisker.exe list /target:computername$ /domain:constoso.local /dc:dc1.contoso.local

References

  • https://github.com/MichaelGrafnetter/DSInternals
  • https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab
Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • AI-Generated Code Security Bugs: A Vibe Coding Case Study
    AI-Generated Code Security Bugs: A Vibe Coding Case Study
    October 7, 2026/
    0 Comments
  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
© 2026 Security Cipher. All rights reserved. Privacy Policy · Terms & Conditions