Steal or Forge Kerberos Tickets: Golden Ticket

Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.[1] Golden tickets enable adversaries to generate authentication material for any account in Active Directory.[2]

Using a golden ticket, adversaries are then able to request ticket granting service (TGS) tickets, which enable access to specific resources. Golden tickets require adversaries to interact with the Key Distribution Center (KDC) in order to obtain TGS.[3]

The KDC service runs all on domain controllers that are part of an Active Directory domain. KRBTGT is the Kerberos Key Distribution Center (KDC) service account and is responsible for encrypting and signing all Kerberos tickets.[4] The KRBTGT password hash may be obtained using OS Credential Dumping and privileged access to a domain controller.

ID: T1558.001
Sub-technique of:  T1558
Platforms: Windows
Contributors: Itamar Mizrahi, Cymptom
Version: 1.2
Created: 11 February 2020
Last Modified: 24 October 2025

Procedure Examples

ID Name Description
S0363 Empire

Empire can leverage its implementation of Mimikatz to obtain and use golden tickets.[5]

G0004 Ke3chang

Ke3chang has used Mimikatz to generate Kerberos golden tickets.[6]

S0002 Mimikatz

Mimikatz's kerberos module can create golden tickets.[7][8]

S1071 Rubeus

Rubeus can forge a ticket-granting ticket.[9]

S0633 Sliver

Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets.[10]

Mitigations

ID Mitigation Description
M1015 Active Directory Configuration

For containing the impact of a previously generated golden ticket, reset the built-in KRBTGT account password twice, which will invalidate any existing golden tickets that have been created with the KRBTGT hash and other Kerberos tickets derived from it. For each domain, change the KRBTGT account password once, force replication, and then change the password a second time. Consider rotating the KRBTGT account password every 180 days.[11]

M1026 Privileged Account Management

Limit domain admin account permissions to domain controllers and limited servers. Delegate other admin functions to separate accounts.

Detection Strategy

ID Name Analytic ID Analytic Description
DET0144 Detect Forged Kerberos Golden Tickets (T1558.001) AN0405

Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.

References