Compliance Node Overview
MITRE CAPEC-645 (Use of Captured Tickets (Pass The Ticket)) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary uses stolen Kerberos tickets to access systems/resources that leverage the Kerberos authentication protocol. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. An adversary can obtain any one of these tickets (e.g. Likelihood of attack: Low. Typical severity: High. Maps to weaknesses CWE-522, CWE-294, CWE-308. Relates to MITRE ATT&CK T1550.003.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/645.html
SHA-256 integrity: bfe264f12e07a6624df87364fce8d58bab04042f7c97b1041417d577393173eb
Primary Citations — 11 traced to source
- MITRE CAPEC-645: Use of Captured Tickets (Pass The Ticket) (https://capec.mitre.org/data/definitions/645.html)
- CWE-522: underlying weakness (http://cwe.mitre.org/data/definitions/522.html)
+ 9 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.