← back to portfolio
Active Directory
Golden Ticket Investigation
Executive Summary
An alert flagged suspicious lateral movement toward the Domain Controller. Investigation of Kerberos-related
Security event logs revealed AS-REP roasting activity against a targeted account, followed by anomalous
KRBTGT-related ticket activity, and ultimately Administrator authentication consistent with Golden Ticket
usage. The compromised service account and source IP were identified, and the attack chain was reconstructed
from initial credential access through domain-wide impersonation.
Scenario
An alert was triggered within the network, indicating a possible attack on the Domain Controller.
The security team detected suspicious activity suggesting lateral movement attempts from a compromised
workstation to the DC. The objective was to trace the attacker's steps, determine their access point,
and prevent further escalation to the Domain Controller.
Evidence Collected
| Artifact | Source | Why It Mattered |
| Event ID 4624 | Security Logs | Logon to compromised SQLService account by attacker |
| Event ID 4624 | Security Logs | Suspicious ANONYMOUS LOGON observed |
| Event ID 4769 | Security Logs | Suspected AS-REP roasting activity, encryption type 0x17, requesting KRBTGT |
| Event ID 4768 | Security Logs | Kerberos activity involving KRBTGT and Administrator account authentication |
Timeline
| Time (UTC) | User | Event | Source |
| 2024-10-05 14:42:44 | Corrado | Kerberos service ticket request involving KRBTGT, encryption type 0x17 | EID 4769 |
| 2024-10-05 16:50:10 | Administrator | Kerberos activity involving KRBTGT | EID 4768 |
| 2024-10-05 16:50:29 | SQLService | Kerberos service ticket activity associated with SQLService | EID 4769 |
| 2024-10-05 17:37:56 | Corrado | Kerberos authentication request involving KRBTGT | EID 4768 |
| 2024-10-05 17:57:03 | Administrator | Multiple Kerberos service ticket requests followed by successful authentication | EID 4769, 4624 |
Key Findings
- SQLService was identified as the compromised service account.
- Activity involving the account "corrado" was consistent with AS-REP roasting.
- Source IP 192.168.110.129 was associated with multiple stages of the observed activity.
- Administrator authentication observed at 17:57:03 UTC was consistent with Golden Ticket usage.
- The attack chain involved KRBTGT-related Kerberos activity prior to Administrator impersonation.
Attack Chain
Initial Access
Initial access vector was not determined from available evidence.
Credential Access
AS-REP roasting performed against the account "corrado".
Lateral Movement
Activity from 192.168.110.129 observed interacting with the Domain Controller.
Impact
Golden Ticket usage resulted in Administrator impersonation.
Analyst Notes
Initial review focused on identifying the compromised account and source IP associated with suspicious Kerberos activity.
Timeline construction revealed that activity consistent with AS-REP roasting occurred prior to observed SQLService authentication activity.
Correlation of Event IDs 4768 and 4769 helped establish the sequence of Kerberos-related events leading to Administrator authentication.
The initial access vector could not be determined from the available evidence.
Lessons Learned
- Building a timeline early made it easier to identify inconsistencies in the assumed attack narrative.
- Separating observations from conclusions improved the quality of findings.
- Correlating Kerberos Event IDs 4768 and 4769 provided valuable context for understanding account activity.
Questions to Revisit
- Was SQLService compromised before the observed AS-REP roasting activity, or is earlier activity missing from the available logs?