Pass-the-Ticket attack involves stealing and reusing Kerberos authentication tickets instead of passwords or hashes. This attack exploits weaknesses in the Kerberos protocol, which is widely used in Windows Active Directory environments, allowing attackers to impersonate legitimate users.

MITRE ATT&CK ID: T1550.003


1- Kerberos Authentication Overview


2- Steps of a PtT Attack

a. Initial Access

b. Ticket Extraction

c. Ticket Reuse

d. Lateral Movement and Privilege Escalation


3- Key Tools for PtT Attacks