- How do SOC analysts detect Steal or Forge Kerberos Tickets?
- Detection centers on SIEM, XDR telemetry for the credential access phase of the attack. Detect Golden Ticket attacks by monitoring for Kerberos TGTs with unusually long validity periods, inconsistent user SID values, or attributes that do not match expected domain configurations. Alert on Kerberoasting activity by monitoring for large volumes of Kerberos service ticket requests using RC4 encryption from single sources, particularly from workstations that would not normally request many service tickets.
- What does a Steal or Forge Kerberos Tickets alert look like?
- A representative SIEM detection is "Kerberos Golden Ticket Attack Indicators" (critical severity): Authentication event detected for account "Administrator" with a Kerberos TGT valid for 10 years (87600 hours), compared to the domain default of 10 hours. The ticket also contains a non-standard SID value not present in Active Directory. These attributes are definitive indicators of a forged Golden Ticket created using the compromised KRBTGT account hash.
- Which tools detect Steal or Forge Kerberos Tickets, and how can I practice?
- Steal or Forge Kerberos Tickets (T1558) is best surfaced with SIEM, XDR telemetry, which exposes the credential access signals described above. Practice detecting it on those exact consoles in SOCSimulator Operations, free.