Red vs. Blue: Kerberos Ticket Times, Checksums, and You!
ID: 34fd6728-4137-5742-85b5-48c96f3622db
STIX ID: report--34fd6728-4137-5742-85b5-48c96f3622db
Feed Name: TrustedSec blog
This detailed technical blog post explains how Kerberos ticket times (Start, End, Renew) and PAC/checksum signatures can be used to detect or evade forged tickets (Golden/Silver). It covers effects of domain Kerberos policy, Protected Users group, logonHours, and GPO priority on ticket lifetimes; describes the Server, KDC, Ticket, and FullPAC checksums; and gives defensive detection guidance (klist, Windows event IDs, checksum verification using KRBTGT) as well as Red team OPSEC tips (using Rubeus and PowerView to craft or validate forgery arguments).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
