Attack Tutorial: How a Golden Ticket Attack Works

Поділитися
Вставка
  • Опубліковано 28 вер 2024
  • This video explains what information an attacker needs to carry out a Golden Ticket attack, details the techniques involved and demonstrates the attack in action.
    In short, adversaries use a tool like mimikatz to extract password hashes for the KRBTGT account to forge Kerberos ticket-granting tickets (TGTs) which the adversary can control the access granted to, these are called Golden Tickets because they can provide unlimited and virtually undetectable access to any system connected to Active Directory.
    To learn more about this attack and how to mitigate, detect and respond to it, go to: www.netwrix.co...
    Learn about other attacks in our attack catalog: www.netwrix.co...

КОМЕНТАРІ • 10

  • @kmnews
    @kmnews 2 роки тому +4

    These are extremely helpful, thank you for making these videos!

  • @NH-ic3ri
    @NH-ic3ri Рік тому

    Great video

  • @shubhamsavita2163
    @shubhamsavita2163 Рік тому

    I am still seeing "Access Denied" after storing the key in the last part, I have basically two VMs one for DC and another for User(gets IP from DC). I am running these commands from User to access DC escalated privileges.

  • @UnknownUnknown-ss9je
    @UnknownUnknown-ss9je 2 роки тому +1

    Hi,
    I have watch your videos and it is really helpfull to understand how it works.
    Could you please provide some of the mitigation and prevention to eradicate the attack.
    Thank you!

  • @bryanmccaffrey4385
    @bryanmccaffrey4385 2 місяці тому

    Steve Holt!!

  • @zomgoose
    @zomgoose 2 місяці тому

    SCARY!!!

  • @dpkseth22
    @dpkseth22 Рік тому

    what exact artifacts (Command-line / Registry / File Folder behavior) will confirm that symptoms belong to Golden ticket?

  • @fdis_me809
    @fdis_me809 7 місяців тому

    Great vid thank you. How did you get mimikatz to run on the Windows box without Defender kicking in?

  • @gisselleguzman381
    @gisselleguzman381 Рік тому

    Very nice!