Compliance Node Overview
MITRE ATT&CK T1558.001 (Golden Ticket) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket. Golden tickets enable adversaries to generate authentication material for any account in Active Directory. Using a golden ticket, adversaries are then able to request ticket granting service (TGS) tickets, which enable access to specific resources. Golden tickets require adversaries to interact with the Key Distribution Center (KDC) in order to obtain TGS. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1015 Active Directory Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, AC-19.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1558/001/
SHA-256 integrity: 52bbfff9ca09df00358a43327b1d9a36335031d902e8dbd0e875f0e68cfe8026
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1558.001: Golden Ticket (https://attack.mitre.org/techniques/T1558/001/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access