What MITRE ATT&CK T1558: Steal or Forge Kerberos Tickets (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1558 (Steal or Forge Kerberos Tickets) is an Enterprise Credential Access technique. Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as "realms", there are three basic participants: client, service, and Key Distribution Center (KDC). ATT&CK documents 5 sub-techniques: T1558.001 Golden Ticket; T1558.002 Silver Ticket; T1558.003 Kerberoasting; T1558.004 AS-REP Roasting; T1558.005 Ccache Files. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1015 Active Directory Configuration, M1043 Credential Access Protection, M1041 Encrypt Sensitive Information, M1027 Password Policies, M1047 Audit, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, AC-19.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1558/
SHA-256 integrity: 6a8417aa0d2dbf593c4cf1bbc5b948bcadcb872e601b9e2f99c1cf5d9b463c85
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1558: Steal or Forge Kerberos Tickets (https://attack.mitre.org/techniques/T1558/) with 5 sub-techniques
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access