Kerberos Golden Tickets
- by Vince
-
in Blog
-
Hits: 1314
If an attacker were to get on your network, compromise the domain, and takeover the krbtgt account, creating a golden ticket is an almost guaranteed method for persistence as long as you don't reset the password for that account -- twice. "The password must be changed twice to effectively remove the password history." I don't know if there's a "best practice" but according to Ping Castle, or at least its implication, we probably want to change it every 60 days.