Open cardosec

Case 46299F · Identity & AD · L4 Advanced

Golden vs Silver Tickets

Practise as: Explain it · Interview · Deep dive

Interview questionCompare golden and silver tickets: what key does each need, and which is harder to detect?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Golden ticket: forged TGT signed with the krbtgt hash; grants any identity and group to any service in the domain
  2. Silver ticket: forged service ticket signed with a service or computer account hash; valid only for that service
  3. Silver tickets never touch the DC (no 4769), so detection relies on host logs and PAC validation anomalies
  4. Golden ticket detection: TGS requests with no prior TGT issue (4769 without 4768), odd lifetimes, nonexistent users
  5. Recovery from golden ticket: reset krbtgt twice, waiting for replication and max ticket lifetime between resets

If the interviewer pushes back

  • What are diamond and sapphire tickets and why are they stealthier than classic golden tickets?
  • Why must krbtgt be reset twice rather than once?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.