A Golden Ticket attack abuses the Kerberos authentication protocol by forging Ticket-Granting Tickets (TGTs) using the KRBTGT account’s password hash. In Active Directory, the KRBTGT account is a special account used by the Key Distribution Center (KDC) to encrypt and sign Kerberos tickets. If an attacker compromises the KRBTGT hash, they can mint tickets that grant them virtually unlimited access across the domain essentially giving them "golden" credentials.

image.png

MITRE ATT&CK ID: T1558.001


1- Understanding the Attack


2- Steps of a Golden Ticket Attack

a. Compromise the KRBTGT Hash

b. Forge a Kerberos Ticket-Granting Ticket (TGT)

c. Use the Forged Ticket