During a Golden Ticket attack, the attacker gains persistence by creating a forged TGT. What is required to successfully forge this ticket?
Trap 1: The NTLM hash of the target service account and a valid TGS.
The NTLM hash of a service account is used for Silver Tickets, not Golden Tickets. A Golden Ticket requires the hash of the domain's KRBTGT account, which acts as the 'master key' for issuing and verifying tickets across the entire Active Directory domain.
Trap 2: The domain administrator's plaintext password and a captured TGS.
The administrator password is not needed for a Golden Ticket. The attack relies on the KRBTGT hash. While an administrator password provides high privileges, the KRBTGT hash provides persistent, undetectable access that persists even if the administrator password is changed or the account is disabled.
Trap 3: A valid TGT obtained from an authenticated user on the network.
Golden Tickets do not require an existing, captured TGT from a real user. Instead, the attacker constructs the ticket from scratch using the KRBTGT hash. This allows the attacker to impersonate any user, including accounts that may not even exist on the domain.
- A
The NTLM hash of the target service account and a valid TGS.
Why it fails: The NTLM hash of a service account is used for Silver Tickets, not Golden Tickets. A Golden Ticket requires the hash of the domain's KRBTGT account, which acts as the 'master key' for issuing and verifying tickets across the entire Active Directory domain.
- B
The password and NTLM hash of the KRBTGT domain account.
To forge a Golden Ticket, the attacker must have the NTLM hash of the KRBTGT account. With this hash, they can sign their own TGTs. The domain controller will accept these forged tickets as valid, assuming they were generated by the legitimate KDC service.
- C
The domain administrator's plaintext password and a captured TGS.
Why it fails: The administrator password is not needed for a Golden Ticket. The attack relies on the KRBTGT hash. While an administrator password provides high privileges, the KRBTGT hash provides persistent, undetectable access that persists even if the administrator password is changed or the account is disabled.
- D
A valid TGT obtained from an authenticated user on the network.
Why it fails: Golden Tickets do not require an existing, captured TGT from a real user. Instead, the attacker constructs the ticket from scratch using the KRBTGT hash. This allows the attacker to impersonate any user, including accounts that may not even exist on the domain.