Attack Tutorial: How a Golden Ticket Attack Works

Sdílet
Vložit
  • čas přidán 8. 09. 2024
  • This video explains what information an attacker needs to carry out a Golden Ticket attack, details the techniques involved and demonstrates the attack in action.
    In short, adversaries use a tool like mimikatz to extract password hashes for the KRBTGT account to forge Kerberos ticket-granting tickets (TGTs) which the adversary can control the access granted to, these are called Golden Tickets because they can provide unlimited and virtually undetectable access to any system connected to Active Directory.
    To learn more about this attack and how to mitigate, detect and respond to it, go to: www.netwrix.co...
    Learn about other attacks in our attack catalog: www.netwrix.co...

Komentáře • 10

  • @kmnews
    @kmnews Před 2 lety +4

    These are extremely helpful, thank you for making these videos!

  • @UnknownUnknown-ss9je
    @UnknownUnknown-ss9je Před rokem +1

    Hi,
    I have watch your videos and it is really helpfull to understand how it works.
    Could you please provide some of the mitigation and prevention to eradicate the attack.
    Thank you!

  • @NH-ic3ri
    @NH-ic3ri Před rokem

    Great video

  • @gisselleguzman381
    @gisselleguzman381 Před rokem

    Very nice!

  • @bryanmccaffrey4385
    @bryanmccaffrey4385 Před měsícem

    Steve Holt!!

  • @fdis_me809
    @fdis_me809 Před 6 měsíci

    Great vid thank you. How did you get mimikatz to run on the Windows box without Defender kicking in?

  • @dpkseth22
    @dpkseth22 Před rokem

    what exact artifacts (Command-line / Registry / File Folder behavior) will confirm that symptoms belong to Golden ticket?

  • @zomgoose
    @zomgoose Před měsícem

    SCARY!!!

  • @shubhamsavita2163
    @shubhamsavita2163 Před rokem

    I am still seeing "Access Denied" after storing the key in the last part, I have basically two VMs one for DC and another for User(gets IP from DC). I am running these commands from User to access DC escalated privileges.