hackweb
notes on hacking and technology
IT EN
main menu
user menu
you are not logged in

Golden and Silver Ticket: forging Kerberos

June 1, 2025 · 1 min read · #active-directory #kerberos #persistence

The KDC signs tickets with secret keys. If you steal those keys, you forge tickets the domain accepts as authentic.

Golden ticket

The krbtgt account signs all TGTs. With its NT hash (obtained via DCSync on a compromised DC) you forge a TGT for any user, with any groups — including Domain Admins. Near-total persistence.

mimikatz kerberos::golden /user:x /domain:d /sid:S-.. /krbtgt:HASH /id:500

Silver ticket

With a service account hash you forge a TGS for that service directly, bypassing the KDC. Stealthier (no DC traffic), but limited to that service.

Defence

Rotate krbtgt twice (invalidates existing golden tickets) after a compromise. Protect DCs (golden requires their compromise). Short ticket lifetimes and monitoring do not stop a forged ticket: the defence is preventing key theft.


« back to home

latest posts
 
your IP address:
216.73.216.108
visitor #0
MOTD:
Every abstraction leaks somewhere.
Here we look at where.
topics