logo

Detection of Kerberos Golden Ticket Attacks via Velociraptor

ID: 32889669-03c9-5249-b25c-0d77093cab5c

STIX ID: report--32889669-03c9-5249-b25c-0d77093cab5c

Feed Name: Detect FYI

Threat Score
78/100

Date Published: 2026-01-11

Date Updated: 2026-04-19

Author: dfirloading

...
...

This report explains the Golden Ticket attack against Active Directory Kerberos authentication: how attackers obtain the krbtgt NTLM hash (e.g., via DCSync), craft forged TGTs using mimikatz with long lifetimes and arbitrary group memberships, and use those tickets to impersonate accounts and access resources across a domain; it also provides detection opportunities such as checking unusually long ticket lifetimes and empty "Kdc Called" fields and correlating TGS events with successful logons.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.