detecting-golden-ticket-attacks
Detect Kerberos golden ticket attacks by analyzing Windows Security event logs for anomalous TGT usage patterns. Parses Event IDs 4624, 4672, and 4768 from EVTX files to identify tickets with abnormal lifetimes, domain SID mismatches, and privilege escalation sequences where non-admin accounts receive admin-level privileges without corresponding group membership changes.
Source facts
- Repository
- autohandai/community-skills
- Last source activity
- March 16, 2026 at 00:59
- Detected SKILL.md language
- English
- Stars
- 10
- Forks
- 3
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.