Steal or Forge Kerberos Tickets T1558

Tactic: Credential Access

Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.

Events covered

38 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
Security-AuditingEvent ID 4611A trusted logon process has been registered with the Local Security Authority.
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4627Group membership information.
Security-AuditingEvent ID 4649A replay attack was detected.
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4673A privileged service was called.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4690An attempt was made to duplicate a handle to an object.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4704A user right was assigned.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4738A user account was changed.
Security-AuditingEvent ID 4741A computer account was created.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5140A network share object was accessed.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Defender-IdentityLogonEventsLogonSuccessIdentity logon succeeded
ESFexecProcess Execution
ESFopenFile Open
Directory-Services-SAMEvent ID 16990The security account manager blocked a non-administrator from creating an Active Directory account in this domain with mismatched objectClass and u...
Directory-Services-SAMEvent ID 16991The security account manager blocked a non-administrator from creating or renaming a computer account using an invalid sAMAccountName.
Kerberos-Key-Distribution-CenterEvent ID 16While processing a TGS request for the target server %1, the account %2 did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of %3)
Kerberos-Key-Distribution-CenterEvent ID 27While processing a TGS request for the target server %1, the account %2 did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of %3)
Kerberos-Key-Distribution-CenterEvent ID 35The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC (%1) that did not contain a PAC attributes field
Kerberos-Key-Distribution-CenterEvent ID 36The Key Distribution Center (KDC) encountered a ticket that did not contain a PAC while processing a request for another ticket
Kerberos-Key-Distribution-CenterEvent ID 37The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket
Kerberos-Key-Distribution-CenterEvent ID 38The Key Distribution Center (KDC) encountered a ticket that contained inconsistent information about the account that requested the ticket
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PowerShellEvent ID 800Event ID 800

Authoring guide

These 98 rules share fields, values, and exclusions.

Fields filtered most (94 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID29eq 28, in 14769, 4104, 4738, 4688, 4768
CommandLine16contains 11, regex_match 4, eq 1, in 1, wildcard 1(?i)\.exe"?\s+(((harvest|ptt|s4u|asktgt|brute|createneton..., -clsid , -cn , -computername , -cp
ScriptBlockText14contains 9, eq 3, in 1, match 1get-domainuser, kerberosrequestorsecuritytoken, system.identitymodel.tokens.kerberosrequestorsecuritytoken, -ldapfilter*(useraccountcontrol:1.2.840.113556.1.4.803:=524288), -properties*msds-allowedtodelegateto
TargetUserName12eq 6, contains 2, cross_field_compare 1, ends_with 1, is_not_null 1, match 1$, $@, %account_allowed_proxy%, %allowed_s4u2proxy_accounts%, %allowed_unconstrained_accounts%
Status11eq 110, 0x0
TicketEncryptionType11eq 10, in 10x17, 0x18, 18, 23
Image10ends_with 8, starts_with 2, eq 1, is_not_null 1?:\windows\system32\, ?:\windows\syswow64\, \device\harddiskvolume, \krbrelay.exe, \krbrelayup.exe
ServiceName10ends_with 5, ne 2, cross_field_compare 1, eq 1, is_not_null 1$, *$, krbtgt, TargetUserName
host.os.type10eq 10
src_ip10eq 7, ne 2, cidr_match 1%domain_controllers_ips%, ::1, 127.0.0.1, 127.0.0.0/8
Channel9eq 9, in 9
OriginalFileName9eq 9setspn.exe, klist.exe, krbrelay.exe, krbrelayup.exe, nxc.exe
eventtype9eq 9
DestinationPort8eq 7, in 188, 389, 445
EventType8eq 7, in 1start, creation, exec, logged-in, open

Top indicator values (823 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
TicketEncryptionTypeeq
0x17
89
EventIDeq
4104
7269
EventIDeq
4769
711
EventIDeq
4738
48
EventIDeq
4688
3317
EventIDeq
4741
22
EventIDeq
4768
214
src_ipeq
%domain_controllers_ips%
7
DestinationPorteq
88
67
ServiceSidends_with
-502
64
Statuseq
0
67
Statuseq
0x0
55
Initiatedeq
egress
517
ServiceNameends_with
$
54
SourcePortge
49152
516
EventTypeeq
start
4391
Protocoleq
tcp
426
TicketOptionseq
0x40810000
44
event.categoryeq
process
4142
Codenameeq
Golden Ticket
33
CommandLineregex_match
(?i)\.exe"?\s+(((harvest|ptt|s4u|asktgt|brute|createnetonly|changepw|hash|tgs...
33
LogonTypeeq
Network
341
MessageTypeeq
2
321
event.typeeq
start
31078
process_idne
4
344
AuthenticationPackageNameeq
kerberos
25
CommandLinecontains
-clsid
22
Imageends_with
\tomcat\bin\tomcat8.exe
2
OriginalFileNameeq
setspn.exe
22
PreAuthTypeeq
0
22

Exclusions (197 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
src_ipeq
%domain_controllers_ips%
7
ServiceNameends_with
$
4
TargetUserNamecontains
$@
4
process.code_signature.trustedeq
true
4
Imagewildcard
?:\windows\system32\lsass.exe
3
Imagewildcard
\device\harddiskvolume*\windows\system32\lsass.exe
2
destination.addresswildcard
127.*
3
destination.addresswildcard
::1
3
Imageends_with
\tomcat\bin\tomcat8.exe
2
ScriptBlockTexteq
sentinelbreakpoints
2
ServiceNamecontains
$
2
ServiceNamecontains
krbtgt
2
ServiceSidends_with
-502
2
TargetUserNameeq
%account_allowed_proxy%
2
process_nameeq
powershell.exe
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 35 rules

Elastic 26 rules

Splunk 27 rules

Kusto 10 rules