Umbra Wiki technique technique/T1558.002
Back to wiki

T1558.002 — Silver Ticket

provenance: imported · ATT&CK: T1558.002

T1558.002: Silver Ticket

MITRE ATT&CK® Enterprise technique

Tactics Credential Access
Platforms Windows
Permissions required
Version 1.1
Parent technique T1558

Description

Adversaries who have the password hash of a target service account (e.g. SharePoint, MSSQL) may forge Kerberos ticket granting service (TGS) tickets, also known as silver tickets. Kerberos TGS tickets are also known as service tickets.(Citation: ADSecurity Silver Tickets)

Silver tickets are more limited in scope in than golden tickets in that they only enable adversaries to access a particular resource (e.g. MSSQL) and the system that hosts the resource; however, unlike golden tickets, adversaries with the ability to forge silver tickets are able to create TGS tickets without interacting with the Key Distribution Center (KDC), potentially making detection more difficult.(Citation: ADSecurity Detecting Forged Tickets)

Password hashes for target services may be obtained using OS Credential Dumping or Kerberoasting.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1558/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/