What is a Golden Ticket attack in Active Directory environments?

Cybersecurity Fundamentals Hard

Cybersecurity Fundamentals — Hard

What is a Golden Ticket attack in Active Directory environments?

Key points

  • The Golden Ticket attack grants long-term access to the domain.
  • By using the KRBTGT account's password hash, the attacker can create their own tickets for authentication.
  • This attack is difficult to detect because it doesn't involve changing passwords or creating new accounts.

Ready to go further?

Related questions