CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
A penetration tester has compromised an Active Directory domain controller. Using `Mimikatz`, they extract the `krbtgt` account's NTLM hash. The tester then plans to use this hash to create a forged Kerberos Ticket Granting Ticket (TGT) for any user, allowing them to authenticate to any service in the domain as that user for an extended period, even if the user's password changes. Which type of attack is the tester preparing to execute?
- APass-the-Hash (PtH)
- BGolden Ticket
- CKerberoasting
- DSilver Ticket
Show answer & explanationAnswer & explanation
Correct answer: B. Golden Ticket
The scenario explicitly describes the creation of a Golden Ticket. A Golden Ticket is a forged Kerberos TGT that is signed with the `krbtgt` account's NTLM hash. This grants an attacker arbitrary access to the Active Directory domain as any user, with any privileges, for an extended period, making it a highly potent post-exploitation technique.
Why the other options are wrong
- A. Pass-the-Hash uses a user's NTLM hash to authenticate to services, but it doesn't involve forging TGTs with the `krbtgt` hash.
- C. Kerberoasting extracts service account hashes from SPNs, which is unrelated to forging TGTs.
- D. A Silver Ticket is a forged Kerberos Service Ticket (TGS) for a specific service, not a TGT for the entire domain.
Golden Ticket Attack
A highly privileged Active Directory attack where an attacker, having obtained the `krbtgt` account's NTLM hash, forges a Kerberos Ticket Granting Ticket (TGT). This allows them to impersonate any user in the domain and gain persistent access to any resource.
- Requires `krbtgt` account's NTLM hash.
- Forges a Kerberos Ticket Granting Ticket (TGT).
- Grants arbitrary user impersonation and domain-wide access.
- Provides persistence, even after password changes.
Memory trick: Kerberos keys: Golden for the domain, Silver for a service, Roasting for hashes.