{"id":"T1558.001","name":"Golden Ticket","url":"https://attack.mitre.org/techniques/T1558/001","tactics":["credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0144","stix_id":"x-mitre-detection-strategy--cbf5f016-0801-4861-93d8-d372645778d5","name":"Detect Forged Kerberos Golden Tickets (T1558.001)","url":"https://attack.mitre.org/detectionstrategies/DET0144","analytics":[{"id":"AN0405","stix_id":"x-mitre-analytic--fd614a66-7e99-4a69-9070-3c11036f0335","name":"Analytic 0405","description":"Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.","url":"https://attack.mitre.org/detectionstrategies/DET0144#AN0405","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4672, 4634","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4769","data_component":"DC0084","data_component_name":"Active Directory Credential Request","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TicketLifetimeThreshold","description":"Kerberos TGT ticket lifetime exceeding default domain duration; tunable to environment-specific policies."},{"field":"AllowedEncryptionTypes","description":"Valid encryption algorithms for Kerberos tickets; anomalies (e.g., RC4) may indicate forgery."},{"field":"PrivilegedAccountPatterns","description":"Baseline of privileged accounts expected to perform Kerberos operations; deviations indicate suspicious activity."},{"field":"ProcessAllowlist","description":"Expected processes interacting with lsass.exe; deviations may indicate credential dumping."}],"live":true,"detection_strategies":["DET0144"],"techniques":["T1558.001"]}],"live":true,"version":"1.0","techniques":["T1558.001"]}],"sigma_rules":[{"id":"9c5d2b84-1f7e-4a3c-d6b8-e04f9a17c523","title":"DC Machine Account TGT Request from Non-DC Source IP","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-07-29","modified":null,"description":"Detects a Kerberos TGT request (Event 4768) for a known Domain Controller machine account\noriginating from an IP address that is not a known Domain Controller. DC machine accounts\nshould only request TGTs from their own IP. Any TGT request for a DC account from a\nworkstation or non-DC host is anomalous and indicates one of the following:\n\n  - PKINIT abuse (CVE-2026-54121 / Certighost): attacker authenticating as a DC via a\n    forged certificate from their workstation\n  - Overpass-the-Hash: attacker converting a stolen DC machine account NTLM hash into a\n    Kerberos TGT\n  - Pass-the-Hash (RC4): attacker using the DC machine account hash directly with Kerberos\n","references":["https://github.com/aniqfakhrul/CVE-2026-54121","https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.lateral-movement","attack.t1649","attack.t1550.003","attack.t1558.001","cve.2026-54121"],"path":"rules-placeholder/windows/builtin/security/win_security_dc_machine_accoutn_tgt_non_dc_ip.yml","techniques":["T1649","T1550.003","T1558.001"],"cves":["CVE-2026-54121"]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}