Skip to content

Silver Tickets

Active Directory environments rely on Kerberos for service authentication, and silver tickets exploit specific service delegation configurations to bypass traditional authentication mechanisms. Unlike golden tickets, which target the krbtgt service, silver tickets focus on service principal names (SPNs) with constrained delegation enabled. This section explores the mechanics, use cases, and limitations of silver ticket techniques.


Mechanics of Silver Tickets

A silver ticket is a Ticket Granting Service (TGS) ticket for a specific SPN, encrypted with the service account’s password hash. It allows an attacker to authenticate to a service (e.g., SQL Server, file share) without needing the user’s password. The process involves:
1. Capturing the service account’s password hash (via pass-the-hash, Kerberos ticket interception, or other methods).
2. Generating a forged TGS ticket for the target SPN using the hash.
3. Using the ticket to authenticate to the service, bypassing domain controller validation.

The ticket includes the service account’s credentials, which are validated against the service’s SPN configuration. This is only possible if the service account has constrained delegation configured to allow delegation to the target service.


Constrained Delegation and Silver Tickets

Constrained delegation is a critical enabler for silver tickets. It allows a service account (e.g., SQLSvc) to delegate user credentials to another service (e.g., HTTP/fileshare). For a silver ticket to work:
- The target service must have an SPN registered in Active Directory.
- The service account must have constrained delegation configured to allow delegation to the target service.

Example: If a service account PrintSvc is delegated to a print server (print/printserver), an attacker with PrintSvc credentials can generate a silver ticket for print/printserver and authenticate to the print server without domain controller interaction.


Techniques and Use Cases

Common scenarios for silver tickets:
- Service account compromise: If an attacker gains access to a service account with constrained delegation, they can exploit it to access other services.
- Pass-the-ticket attacks: Forged silver tickets can be used to access services without needing the service account’s password.

Example command (Mimikatz):

kerberos::ticket /service:HTTP/fileshare /user:svc_fileshare /domain:example.com /hash <NTLM_HASH>
This generates a silver ticket for the HTTP/fileshare SPN using the service account’s NTLM hash. The ticket can then be used to authenticate to the file share service.


Limitations of Silver Tickets

  1. Service-specific: Silver tickets are only valid for services with constrained delegation. If the target service lacks delegation, the ticket is useless.
  2. SPN enumeration: Attackers must identify valid SPNs in the domain, which may require reconnaissance (e.g., ldapsearch or tools like PowerView).
  3. Ticket lifetime: Kerberos tickets have a limited lifetime (default: 10 hours), requiring the attacker to use the ticket before expiration.
  4. Password dependency: The ticket relies on the service account’s password hash. If the password is changed, the ticket becomes invalid.

Key takeaways

  • Silver tickets exploit constrained delegation to authenticate to services without domain controller involvement.
  • They require access to a service account’s password hash and a valid SPN with delegation configured.
  • Limitations include service-specific validity, the need for SPN enumeration, and ticket expiration.
  • Silver tickets are less powerful than golden tickets but remain a critical vector in targeted attacks against misconfigured services.