Techniques › T1558 › T1558.001
T1558.001 Golden Ticket
credential access — Windows · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
1
Sigma rules tagged attack.t1558.001
0
KEV CVEs mapped here
<p>Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket. Golden tickets enable adversaries to generate authentication material for any account in Active Directory.</p><p>Using a golden ticket, adversaries are then able to request ticket granting service (TGS) tickets, which enable access to specific resources. Golden tickets require adversaries to interact with the Key Distribution Center (KDC) in order to obtain TGS.</p><p>The KDC service runs all on domain controllers that are part of an Active Directory domain. KRBTGT is the Kerberos Key Distribution Center (KDC) service account and is responsible for encrypting and signing all Kerberos tickets. The KRBTGT password hash may be obtained using OS Credential Dumping and privileged access to a domain controller.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0144 Detect Forged Kerberos Golden Tickets (T1558.001) v1.0
AN0405 WindowsDetects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.Tunable:
TicketLifetimeThresholdAllowedEncryptionTypesPrivilegedAccountPatternsProcessAllowlist
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1558.001
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2026-07-29 · logsource: product=windows service=security · 9c5d2b84-1f7e-4a3c-d6b8-e04f9a17c523
Detects a Kerberos TGT request (Event 4768) for a known Domain Controller machine account
originating from an IP address that is not a known Domain Controller. DC machine accounts
should only request TGTs from their own IP. Any TGT request for a DC account from a
workstation or non-DC host is anomalous and indicates one of the following:
- PKINIT abuse (CVE-2026-54121 / Certighost): attacker authenticating as a DC via a
forged certificate from their workstation
- Overpass-the-Hash: attacker converting a stolen DC machine account NTLM hash into a
Kerberos TGT
- Pass-the-Hash (RC4): attacker using the DC machine account hash directly with Kerberos
Rules tagged at the parent level (attack.t1558) 6
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: frack113
· 2022-10-14 · logsource: product=windows service=security · 5a44727c-3b85-4713-8c44-4401d5499629
Detects possible Kerberos Replay Attack on the domain controllers when "KRB_AP_ERR_REPEAT" Kerberos response is sent to the client
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2018-09-09 (modified 2026-06-15) · logsource: category=antivirus · 78cc2dd2-7d20-4d32-93ff-057084c38b93
Detects a highly relevant Antivirus alert that reports password dumpers and stealers.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset.
Author: frack113
· 2022-10-14 (modified 2023-12-14) · logsource: product=windows service=security · 94309181-d345-4cbf-b5fe-061769bdf9cb
Detects logon with "Special groups" and "Special Privileges" can be thought of as Administrator groups or privileges.
Author: Florian Roth (Nextron Systems), David ANDRE
· 2021-11-08 (modified 2024-06-27) · logsource: product=windows category=file_event · 9e099d99-44c2-42b6-a6d8-54c3545cab29
Detects the creation of files created by mimikatz such as ".kirbi", "mimilsa.log", etc.
Author: frack113
· 2025-03-05 · logsource: product=windows category=ps_script · cdfa73b6-3c9d-4bb8-97f8-ddbd8921f5c5
Detects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.
Author: Ilyas Ochkov, oscd.community
· 2019-10-24 (modified 2024-03-15) · logsource: product=windows category=network_connection · e54979bd-c5f9-4d6c-967b-a04b19ac4c74
Detects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.