Skip to content

Ticket Mitigation

Active Directory environments are particularly vulnerable to golden and silver ticket attacks due to the reliance on Kerberos authentication. Mitigating these threats requires a combination of policy hardening, account protection, and proactive monitoring. Below are best practices to reduce the risk of ticket-based exploitation.


Kerberos Policy Hardening

Kerberos policies control ticket lifetimes, encryption types, and password complexity. Misconfigurations can enable attackers to exploit tickets or forge credentials.

1. Limit Ticket Lifetimes

Reduce the TicketLifetime and RenewableLifetime values to minimize the window for ticket misuse.
- Example: Set TicketLifetime to 8 hours and RenewableLifetime to 1 day.

Set-KerberosPolicy -TicketLifetime 8:00:00 -RenewableLifetime 1:00:00
Note: Adjust values based on organizational requirements and operational needs.

2. Disable Weak Encryption Types

RC4 is deprecated and vulnerable to attacks. Enforce AES-256 or AES-128.
- Example: Block RC4 in Group Policy:

Computer Configuration > Policies > Windows Settings > Security Settings > Kerberos Policy > Encryptors allowed in Kerberos
Remove RC4 HMAC from the list.

3. Enforce Password Complexity

Ensure service accounts and user accounts use strong, complex passwords.
- Example: Configure password policies via Group Policy:

Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy
Set minimum length to 12 characters, enforce complexity, and disable password reuse.


Protecting Service Accounts and Machine Accounts

Attackers often target service accounts (e.g., MSSQLSvc) or machine accounts to escalate privileges.

1. Use Protected Users Group

Add critical service accounts to the Protected Users group to prevent them from being targeted via golden tickets.
- Example:

Add-ADGroupMember -Identity "Protected Users" -Members "MSSQLSvc/SQLServer.domain.com"
This restricts the ability to request tickets for these accounts.

2. Secure Machine Account Passwords

Machine accounts (e.g., DC01$) should have strong, unique passwords.
- Example: Use PowerShell to check machine account passwords:

Get-ADComputer -Identity "DC01$" | Select-Object -ExpandProperty PasswordLastSet
Ensure passwords are changed regularly and stored securely.


Auditing and Monitoring

Proactive monitoring helps detect anomalous Kerberos activity.

1. Enable Kerberos Auditing

Log failed authentication attempts and ticket requests.
- Example: Configure audit policies via Group Policy:

Computer Configuration > Policies > Windows Settings > Security Settings > Audit Policy > Audit Kerberos Authentication
Set to Success and Failure.

2. Monitor Event Logs

Check for suspicious events like:
- Event ID 4768: "A Kerberos authentication ticket was requested."
- Event ID 4769: "A Kerberos authentication ticket was issued."
- Example: Query logs via PowerShell:

Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4768,4769} | Format-List


Key takeaways

  • Hardened Kerberos policies (e.g., short ticket lifetimes, AES encryption) reduce exploitation opportunities.
  • Protect service and machine accounts by restricting access and enforcing strong passwords.
  • Audit and monitor Kerberos events to detect unauthorized ticket requests or issuance.
  • Regularly review password policies and ensure compliance with complexity and rotation requirements.