Glossary
Silver ticket
A Silver Ticket is a forged Kerberos service ticket built with a service account's hash, granting access to that single service.
A Silver Ticket is a forged Kerberos service ticket (TGS) created using the password hash of the target service's own account, such as a computer account or service account, rather than the domain-wide krbtgt account. Because the service verifies tickets locally using its own key, the ticket does not need to be validated by a domain controller, allowing an attacker who holds that one hash to impersonate any user against that specific service.
This matters because the attack is scoped but stealthy: since the target service does not consult the DC, no Kerberos ticket-granting activity appears in domain controller logs, making detection reliant on host and service-level auditing instead. Mitigation includes strong, unique, and regularly rotated service account and computer account passwords, minimizing standing service-account privileges, and reviewing local logon and access logs on high-value servers.
See Kerberos hardening.