Golden Ticket Attacks

Golden Ticket Attacks

What is it?

  • When we compromise the krbtgt account, we own the domain

  • We can request access to any resource or system on the domain

  • Golden tickets == complete access to every machine

Requirements to do the Golden Ticket Attack

We need information about krbtgt account.

  1. NTLM Hash

  2. Domain SID

We need the SID of the domain

We need the NTLM hash of the account

We have both info here

2nd method to do it

• Extract krbtgt account hash

Domain SID

Generate a golden ticket

Pass the Golden Ticket

Once we have the ticket we can pass this ticket and can have command line access to every machine.

Now we have a session with golden ticket

We can also run command prompt with psexec.

We can also add a new user.

Bypass restrictions

Last updated