Files
Ares-mythic/documentation-payload/ares/commands/ticket_cache_purge.md
Aryma 03d283cf49 refactor(payload): rename apollo to ares and update documentation
This commit renames the Apollo payload type to Ares, moving all associated files and updating documentation accordingly. The change includes:
- Renaming directories from `apollo` to `ares`
- Updating documentation image references
- Maintaining the same code functionality while changing the payload name
- Adding new Ares-specific documentation files
- Removing old Apollo documentation files

The rename is done to reflect the new payload name while preserving all existing functionality.
2026-04-14 14:02:44 +07:00

44 lines
1.1 KiB
Markdown

+++
title = "ticket_cache_purge"
chapter = false
weight = 103
hidden = false
+++
{{% notice info %}}
Artifacts Generated: WindowsAPIInvoke
{{% /notice %}}
## Summary
Remove the specified ticket(s) from the current logon session, this uses LSA APIs to delete tickets from the active logon session on the host.
### Arguments
#### serviceName
the name of the service to remove, needs to include the domain name, not required if -all flag is present
#### All (Optional)
Argument flag to remove all tickets from the current logon session
#### luid (Optional)
Optional argument to remove a ticket from the cache of a different logon session, must be elevated.
## Usage
```
ticket_cache_purge -luid [luidValue] -serviceName [serviceName] -All
```
Example
```
ticket_cache_purge -serviceName ldap/machineName.DomainName.local/domainName.local@DomainName.local
ticket_cache_purge -serviceName cifs/machineName@DomainName.local
ticket_cache_purge -all
ticket_cache_purge -luid 0xabcd123 -serviceName cifs/machineName@DomainName.local
ticket_cache_purge -luid 0xabcd123 -All
```
## MITRE ATT&CK Mapping
- T1550