Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0144 — Detect Forged Kerberos Golden Tickets (T1558.001)
DET0144

Detect Forged Kerberos Golden Tickets (T1558.001)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0405 Analytic 0405
Windows

Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.

WinEventLog:Security EventCode=4672, 4634 WinEventLog:Security EventCode=4769 WinEventLog:Sysmon EventCode=10
[TicketLifetimeThreshold] Kerberos TGT ticket lifetime exceeding default domain duration; tunable to environment-specific policies.
[AllowedEncryptionTypes] Valid encryption algorithms for Kerberos tickets; anomalies (e.g., RC4) may indicate forgery.
[PrivilegedAccountPatterns] Baseline of privileged accounts expected to perform Kerberos operations; deviations indicate suspicious activity.
[ProcessAllowlist] Expected processes interacting with lsass.exe; deviations may indicate credential dumping.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0144
STIX ID
x-mitre-detection-strategy--cbf5f016-0801-4861-93d8-d372645778d5
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.