CAPEC Definitions

    CAPEC Definitions / CAPEC-645

    CAPEC-645: Use of Captured Tickets (Pass The Ticket)

    An adversary uses stolen Kerberos tickets to access systems/resources that leverage the Kerberos authentication protocol. The Kerberos authentication protocol centers around a ticketing system which is used to request/grant access to services and to then access the requested services. An adversary can obtain any one of these tickets (e.g. Service Ticket, Ticket Granting Ticket, Silver Ticket, or Golden Ticket) to authenticate to a system/resource without needing the account's credentials. Depending on the ticket obtained, the adversary may be able to access a particular resource or generate TGTs for any account within an Active Directory Domain.

    Severity:High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Reset the built-in KRBTGT account password twice to invalidate the existence of any current Golden Tickets and any tickets derived from them.

    Monitor system and domain logs for abnormal access.

    Relationships with other CAPECs

    CAPEC-652: Use of Known Kerberos Credentials

    CAPEC-151: Identity Spoofing

    Prerequisites

    The adversary needs physical access to the victim system.

    The use of a third-party credential harvesting tool.

    Related Weaknesses

    CWE-522: Insufficiently Protected Credentials

    CWE-294: Authentication Bypass by Capture-replay

    CWE-308: Use of Single-factor Authentication