Sub-technique of T1558 Steal or Forge Kerberos Tickets.View on attack.mitre.org
Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket. Golden tickets enable adversaries to generate authentication material for any account in Active Directory.
Using a golden ticket, adversaries are then able to request ticket granting service (TGS) tickets, which enable access to specific resources. Golden tickets require adversaries to interact with the Key Distribution Center (KDC) in order to obtain TGS.
The KDC service runs all on domain controllers that are part of an Active Directory domain. KRBTGT is the Kerberos Key Distribution Center (KDC) service account and is responsible for encrypting and signing all Kerberos tickets. The KRBTGT password hash may be obtained using OS Credential Dumping and privileged access to a domain controller.
Rules on DetectionCode tagged with T1558.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Kerberos Service Ticket Request Using RC4 Encryption | TTP | NULL | Windows Event Log Security 4769 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupKe3chang | Ke3chang has used Mimikatz to generate Kerberos golden tickets. |
| Used by | Procedure example |
|---|---|
| ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use golden tickets. |
| ToolMimikatz | Mimikatz's kerberos module can create golden tickets. |
| ToolRubeus | Rubeus can forge a ticket-granting ticket. |
| ToolSliver | Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.