Skip to content

Glossary

Golden ticket

A Golden Ticket is a forged Kerberos ticket-granting ticket built with a stolen krbtgt hash, granting unlimited domain access.

A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT) created once an attacker has obtained the password hash of the krbtgt account, which underpins the entire domain's Kerberos trust. Because the krbtgt hash can sign a TGT for any user, any privilege level, and any expiration date, possession of it lets an attacker mint valid-looking authentication tokens that domain controllers will accept without needing further contact with a legitimate account.

This matters because a Golden Ticket survives ordinary remediation such as password resets for individual accounts and can grant persistent, near-undetectable domain admin access for years if the krbtgt hash is not rotated. The primary defense is protecting the krbtgt account and its hash from exposure (which is why DCSync protection matters), rotating the krbtgt password twice after any suspected compromise, and monitoring for anomalous ticket lifetimes or encryption types.

See Kerberos hardening.