Sub-technique of T1558 Steal or Forge Kerberos Tickets.View on attack.mitre.org
Adversaries who have the password hash of a target service account (e.g. SharePoint, MSSQL) may forge Kerberos ticket granting service (TGS) tickets, also known as silver tickets. Kerberos TGS tickets are also known as service tickets.
Silver tickets are more limited in scope in than golden tickets in that they only enable adversaries to access a particular resource (e.g. MSSQL) and the system that hosts the resource; however, unlike golden tickets, adversaries with the ability to forge silver tickets are able to create TGS tickets without interacting with the Key Distribution Center (KDC), potentially making detection more difficult.
Password hashes for target services may be obtained using OS Credential Dumping or Kerberoasting.
Rules on DetectionCode tagged with T1558.002.
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account. |
| ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use silver tickets. |
| ToolMimikatz | Mimikatz's kerberos module can create silver tickets. |
| ToolRubeus | Rubeus can create silver tickets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.