Malicious Kerberos TGS Ticket Request Related to a Potential Golden Ticket (via security)

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-08-30
Updated
2026-08-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects request a potential Golden ticket. Findings returned by this rule may not confirm at 100% that a Golden ticket was generated and further investigations would be required to confirm it. Another indicator (in case of a lazy Golden ticket) to check would be to check if the TargetUserName refers to an existing user in the domain.

Related detections3 linkedT1558.001 — drag to rearrange
Masquerading Administrator Login Impersonation with Forged Golden Ticket (via security)
Malicious Shared Folder Access with Forged Golden Ticket (via security)
Suspicious Kerberos Password Account Reset to Issue Potential Golden Ticket (via security)
Malicious Kerberos TGS Ticket Request Related to a Potential Golden Ticket (via security)
Pivot detection · T1558.001 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.