{
  "node_id": "mitre-attack-t1558-steal-or-forge-kerberos-tickets",
  "title": "MITRE ATT&CK T1558: Steal or Forge Kerberos Tickets (Enterprise Tactic TA0006 - Credential Access)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1558 (Steal or Forge Kerberos Tickets) is an Enterprise Credential Access technique. Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as \"realms\", there are three basic participants: client, service, and Key Distribution Center (KDC). ATT&CK documents 5 sub-techniques: T1558.001 Golden Ticket; T1558.002 Silver Ticket; T1558.003 Kerberoasting; T1558.004 AS-REP Roasting; T1558.005 Ccache Files. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1015 Active Directory Configuration, M1043 Credential Access Protection, M1041 Encrypt Sensitive Information, M1027 Password Policies, M1047 Audit, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, AC-19.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}