Steal or Forge Kerberos Tickets

T1558

Technique with 5 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.

On Windows, the built-in klist utility can be used to list and analyze cached Kerberos tickets.

Detection rules40

Rules on DetectionCode tagged with T1558 or one of its sub-techniques.

Sigma21

RuleLevelLog sourceTechnique
Antivirus - Password Dumper SignaturecriticalNULL / antivirusT1558
HackTool - Mimikatz Kirbi File Creationcriticalwindows / file_eventT1558
HackTool - Rubeus Executioncriticalwindows / process_creationT1558.003
HackTool - KrbRelay Executionhighwindows / process_creationT1558.003
HackTool - KrbRelayUp Executionhighwindows / process_creationT1558.003
HackTool - RemoteKrbRelay Executionhighwindows / process_creationT1558.003
HackTool - Rubeus Execution - ScriptBlockhighwindows / ps_scriptT1558.003
Register new Logon Process by Rubeushighwindows / NULLT1558.003
Replay Attack Detectedhighwindows / NULLT1558
Suspicious Kerberos Ticket Request via CLIhighwindows / process_creationT1558.003
Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlockhighwindows / ps_scriptT1558.003
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'highwindows / NULLT1558.003
Kerberoasting Activity - Initial Querymediumwindows / NULLT1558.003
Kerberos Network Traffic RC4 Ticket Encryptionmediumzeek / NULLT1558.003
Potential CVE-2021-42287 Exploitation Attemptmediumwindows / NULLT1558.003

Splunk19

RuleTypeRiskData sourceTechnique
Disabled Kerberos Pre-Authentication Discovery With Get-ADUserTTPNULLPowershell Script Block Logging 4104T1558.004
Disabled Kerberos Pre-Authentication Discovery With PowerViewTTPNULLPowershell Script Block Logging 4104T1558.004
Kerberoasting spn request with RC4 encryptionTTPNULLWindows Event Log Security 4769T1558.003
Kerberos Pre-Authentication Flag Disabled in UserAccountControlTTPNULLWindows Event Log Security 4738T1558.004
Kerberos Pre-Authentication Flag Disabled with PowerShellTTPNULLPowershell Script Block Logging 4104T1558.004
Kerberos Service Ticket Request Using RC4 EncryptionTTPNULLWindows Event Log Security 4769T1558.001
Rubeus Command Line ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1558.003 T1558.004
ServicePrincipalNames Discovery with PowerShellTTPNULLPowershell Script Block Logging 4104T1558.003
ServicePrincipalNames Discovery with SetSPNTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1558.003
Unusual Number of Kerberos Service Tickets RequestedAnomalyNULLWindows Event Log Security 4769T1558.003
Windows Computer Account Created by Computer AccountTTPNULLWindows Event Log Security 4741T1558
Windows Computer Account Requesting Kerberos TicketTTPNULLWindows Event Log Security 4768T1558
Windows Computer Account With SPNTTPNULLWindows Event Log Security 4741T1558
Windows Domain Admin Impersonation IndicatorTTPNULLWindows Event Log Security 4627T1558
Windows Kerberos Local Successful LogonTTPNULLWindows Event Log Security 4624T1558

Sub-techniques5

IDNameExamples
T1558.001Golden Ticket5
T1558.002Silver Ticket4
T1558.003Kerberoasting12
T1558.004AS-REP Roasting1
T1558.005Ccache Files1

Groups1

Software0

None recorded.

Campaigns1

Procedure examples2

Groups1

Used byProcedure example
GroupAkira

Akira have used scripts to dump Kerberos authentication credentials.

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket.

References2

  1. ADSecurity Kerberos Ring Decoder Open source
    Sean Metcalf. (2014, September 12). Kerberos, Active Directory’s Secret Decoder Ring. Retrieved February 27, 2020.
  2. Microsoft Klist Open source
    Microsoft. (2021, March 3). klist. Retrieved October 14, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.