Golden Ticket
Theory
The long-term key of the krbtgt
account can be used to forge a special TGT (Ticket Granting Ticket) that can later be used with Pass-the-ticket to access any resource within the AD domain. The krbtgt
's key is used to encrypt the PAC. In a Golden Ticket scenario, an attacker that has knowledge of the krbtgt
long-term key, will usually forge a PAC indicating that the user belongs to privileged groups. This PAC will be embedded in a forged TGT. The TGT will be used to request Service Tickets than will then feature the PAC presented in the TGT, hence granting lots of access to the attacker.
The Golden Ticket requires krbtgt
's RC4 key (i.e. NT hash) or AES key (128 or 256 bits). In most cases, this can only be achieved with domain admin privileges through a DCSync attack. Because of this, golden tickets only allow lateral movement and not privilege escalation.
Practice
Linux
Windows
Last updated