Case 46299F · Identity & AD · L4 Advanced
Golden vs Silver Tickets
Practise as: Explain it · Interview · Deep dive
Interview questionCompare golden and silver tickets: what key does each need, and which is harder to detect?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Golden ticket: forged TGT signed with the krbtgt hash; grants any identity and group to any service in the domain
- Silver ticket: forged service ticket signed with a service or computer account hash; valid only for that service
- Silver tickets never touch the DC (no 4769), so detection relies on host logs and PAC validation anomalies
- Golden ticket detection: TGS requests with no prior TGT issue (4769 without 4768), odd lifetimes, nonexistent users
- Recovery from golden ticket: reset krbtgt twice, waiting for replication and max ticket lifetime between resets
If the interviewer pushes back
- What are diamond and sapphire tickets and why are they stealthier than classic golden tickets?
- Why must krbtgt be reset twice rather than once?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.