| name | detecting-golden-ticket-attacks-in-kerberos-logs |
| description | Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs. Use when detecting golden ticket attacks in active directory by analyzing kerberos. |
| domain | cybersecurity |
| tags | ["threat-hunting","golden-ticket","kerberos","active-directory","mitre-t1558-001","credential-abuse"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Detecting Golden Ticket Attacks In Kerberos Logs
Overview
Cybersecurity skill for detecting golden ticket attacks in kerberos logs. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting golden ticket attacks in kerberos logs"
-
"Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anoma"
-
When KRBTGT account hash may have been compromised via DCSync or NTDS.dit extraction
-
When hunting for forged Kerberos tickets used for persistent domain access
-
After incident response reveals credential theft at the domain level
-
When investigating impossible logon patterns (users logging in from multiple locations simultaneously)
-
During post-breach assessment to determine if Golden Tickets are in use
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Windows Security Event IDs 4768, 4769, 4771 on domain controllers
- Kerberos policy configuration knowledge (max ticket lifetime, encryption types)
- Domain controller audit policy enabling Kerberos Service Ticket Operations
- SIEM with ability to correlate Kerberos events across multiple DCs
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}