Ticket Mitigation
Active Directory environments are particularly vulnerable to golden and silver ticket attacks due to the reliance on Kerberos authentication. Mitigating these threats requires a combination of policy hardening, account protection, and proactive monitoring. Below are best practices to reduce the risk of ticket-based exploitation.
Kerberos Policy Hardening¶
Kerberos policies control ticket lifetimes, encryption types, and password complexity. Misconfigurations can enable attackers to exploit tickets or forge credentials.
1. Limit Ticket Lifetimes¶
Reduce the TicketLifetime and RenewableLifetime values to minimize the window for ticket misuse.
- Example: Set TicketLifetime to 8 hours and RenewableLifetime to 1 day.
2. Disable Weak Encryption Types¶
RC4 is deprecated and vulnerable to attacks. Enforce AES-256 or AES-128.
- Example: Block RC4 in Group Policy:
Computer Configuration > Policies > Windows Settings > Security Settings > Kerberos Policy > Encryptors allowed in Kerberos
RC4 HMAC from the list.
3. Enforce Password Complexity¶
Ensure service accounts and user accounts use strong, complex passwords.
- Example: Configure password policies via Group Policy:
Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy
Protecting Service Accounts and Machine Accounts¶
Attackers often target service accounts (e.g., MSSQLSvc) or machine accounts to escalate privileges.
1. Use Protected Users Group¶
Add critical service accounts to the Protected Users group to prevent them from being targeted via golden tickets.
- Example:
2. Secure Machine Account Passwords¶
Machine accounts (e.g., DC01$) should have strong, unique passwords.
- Example: Use PowerShell to check machine account passwords:
Auditing and Monitoring¶
Proactive monitoring helps detect anomalous Kerberos activity.
1. Enable Kerberos Auditing¶
Log failed authentication attempts and ticket requests.
- Example: Configure audit policies via Group Policy:
Computer Configuration > Policies > Windows Settings > Security Settings > Audit Policy > Audit Kerberos Authentication
2. Monitor Event Logs¶
Check for suspicious events like:
- Event ID 4768: "A Kerberos authentication ticket was requested."
- Event ID 4769: "A Kerberos authentication ticket was issued."
- Example: Query logs via PowerShell:
Key takeaways¶
- Hardened Kerberos policies (e.g., short ticket lifetimes, AES encryption) reduce exploitation opportunities.
- Protect service and machine accounts by restricting access and enforcing strong passwords.
- Audit and monitor Kerberos events to detect unauthorized ticket requests or issuance.
- Regularly review password policies and ensure compliance with complexity and rotation requirements.