detecting-golden-ticket-attacks
通过分析 Windows 安全事件日志中的异常 TGT 使用模式,检测 Kerberos 黄金票据(Golden Ticket)攻击。从 EVTX 文件中解析事件 ID 4624、4672 和 4768,识别具有异常生命周期的票据、域 SID 不匹配,以及非管理员账户无对应组成员身份变更却获得管理员级别权限的特权提升序列。
Source facts
- Repository
- killvxk/cybersecurity-skills-zh
- Last source activity
- March 17, 2026 at 21:38
- Detected SKILL.md language
- Chinese
- Stars
- 42
- Forks
- 9
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.