Golden Ticket

Overview#

Golden Ticket is a Kerberos Forged Ticket Attack and often is a Advanced Persistent Threat (APT)

Golden Ticket has a High Attack Effort

Golden Ticket Outcome#

After an Attacker hacks a system and then hacks to obtain Local Administrative Accounts privileges, the tool can dump Microsoft Windows credentials, like LM hash and Kerberos tickets, from memory and perform pass-the-hash and pass-the-ticket attacks.

If the attacker is to gain full Local Administrative Accounts privileges on a Windows Domain Controller this feature allows creating a special Kerberos TGT ticket (Golden Ticket) which has the following properties: 3

Golden Ticket How To [2]#

The easiest way to obtain the information you'll need is to run Mimikatz 2.0 on a Domain Controller for the AD DOMAIN you wish to compromise.

Mimikatz includes a new feature called Golden Ticket.

Golden Ticket Attack requires the Attacker to have the following pieces of information available:

The easiest way to obtain the information you'll need is to run Mimikatz 2.0 on a Domain Controller for the AD DOMAIN you wish to compromise.

As of this writing, there are three encryption keys may be used for the Golden Ticket functionality:

More Information#

There might be more information for this subject on one of the following: