Silver Ticket

T1558.002

Sub-technique of T1558 Steal or Forge Kerberos Tickets.View on attack.mitre.org

About this technique

Adversaries who have the password hash of a target service account (e.g. SharePoint, MSSQL) may forge Kerberos ticket granting service (TGS) tickets, also known as silver tickets. Kerberos TGS tickets are also known as service tickets.

Silver tickets are more limited in scope in than golden tickets in that they only enable adversaries to access a particular resource (e.g. MSSQL) and the system that hosts the resource; however, unlike golden tickets, adversaries with the ability to forge silver tickets are able to create TGS tickets without interacting with the Key Distribution Center (KDC), potentially making detection more difficult.

Password hashes for target services may be obtained using OS Credential Dumping or Kerberoasting.

Detection rules0

Rules on DetectionCode tagged with T1558.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples4

Software4

Used byProcedure example
ToolAADInternals

AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account.

ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use silver tickets.

ToolMimikatz

Mimikatz's kerberos module can create silver tickets.

ToolRubeus

Rubeus can create silver tickets.

References2

  1. ADSecurity Detecting Forged Tickets Open source
    Metcalf, S. (2015, May 03). Detecting Forged Kerberos Ticket (Golden Ticket & Silver Ticket) Use in Active Directory. Retrieved December 23, 2015.
  2. ADSecurity Silver Tickets Open source
    Sean Metcalf. (2015, November 17). How Attackers Use Kerberos Silver Tickets to Exploit Systems. Retrieved February 27, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.