← back to portfolio
Active Directory

Golden Ticket Investigation

Category
Active Directory
Status
Complete
Domain Controller
SOPRANOS-DC
Method
Windows Security event log analysis
MITRE ATT&CK
T1558.004 AS-REP Roasting T1558.001 Golden Ticket T1078 Valid Accounts T1021 Remote Services
Executive Summary An alert flagged suspicious lateral movement toward the Domain Controller. Investigation of Kerberos-related Security event logs revealed AS-REP roasting activity against a targeted account, followed by anomalous KRBTGT-related ticket activity, and ultimately Administrator authentication consistent with Golden Ticket usage. The compromised service account and source IP were identified, and the attack chain was reconstructed from initial credential access through domain-wide impersonation.
Table of Contents
  1. Scenario
  2. Evidence Collected
  3. Timeline
  4. Key Findings
  5. Attack Chain
  6. Analyst Notes
  7. Lessons Learned
  8. Questions to Revisit

Scenario

An alert was triggered within the network, indicating a possible attack on the Domain Controller. The security team detected suspicious activity suggesting lateral movement attempts from a compromised workstation to the DC. The objective was to trace the attacker's steps, determine their access point, and prevent further escalation to the Domain Controller.

Evidence Collected

ArtifactSourceWhy It Mattered
Event ID 4624Security LogsLogon to compromised SQLService account by attacker
Event ID 4624Security LogsSuspicious ANONYMOUS LOGON observed
Event ID 4769Security LogsSuspected AS-REP roasting activity, encryption type 0x17, requesting KRBTGT
Event ID 4768Security LogsKerberos activity involving KRBTGT and Administrator account authentication

Timeline

Time (UTC)UserEventSource
2024-10-05 14:42:44CorradoKerberos service ticket request involving KRBTGT, encryption type 0x17EID 4769
2024-10-05 16:50:10AdministratorKerberos activity involving KRBTGTEID 4768
2024-10-05 16:50:29SQLServiceKerberos service ticket activity associated with SQLServiceEID 4769
2024-10-05 17:37:56CorradoKerberos authentication request involving KRBTGTEID 4768
2024-10-05 17:57:03AdministratorMultiple Kerberos service ticket requests followed by successful authenticationEID 4769, 4624

Key Findings

Attack Chain

Initial Access
Initial access vector was not determined from available evidence.
Credential Access
AS-REP roasting performed against the account "corrado".
Lateral Movement
Activity from 192.168.110.129 observed interacting with the Domain Controller.
Impact
Golden Ticket usage resulted in Administrator impersonation.

Analyst Notes

Initial review focused on identifying the compromised account and source IP associated with suspicious Kerberos activity.
Timeline construction revealed that activity consistent with AS-REP roasting occurred prior to observed SQLService authentication activity.
Correlation of Event IDs 4768 and 4769 helped establish the sequence of Kerberos-related events leading to Administrator authentication.
The initial access vector could not be determined from the available evidence.

Lessons Learned

Questions to Revisit