Golden and Silver Ticket: forging Kerberos
The KDC signs tickets with secret keys. If you steal those keys, you forge tickets the domain accepts as authentic.
Golden ticket
The krbtgt account signs all TGTs. With its NT hash (obtained via DCSync on a compromised DC) you forge a TGT for any user, with any groups — including Domain Admins. Near-total persistence.
mimikatz kerberos::golden /user:x /domain:d /sid:S-.. /krbtgt:HASH /id:500Silver ticket
With a service account hash you forge a TGS for that service directly, bypassing the KDC. Stealthier (no DC traffic), but limited to that service.
Defence
Rotate krbtgt twice (invalidates existing golden tickets) after a compromise. Protect DCs (golden requires their compromise). Short ticket lifetimes and monitoring do not stop a forged ticket: the defence is preventing key theft.