CTD-000087

AD domain with non-default permissions on krbtgt account

Critical
Active Directory
Credential Access Defense Evasion Persistence Privilege Escalation
v23

Signature Identity

CTD-000087
Threat ID
23
Version
IOC-IOE
Indicator Type

Threat Description

A threat actor with permission to modify the KRBTGT account can compromise it. Using the KRBTGT account, they can create a Kerberos ticket granting ticket (TGT) that provides authorization to any resource and sets the ticket expiration to any arbitrary time. This fake TGT is called a ‘Golden Ticket’ and allows attackers to achieve network persistence

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To change permissions using Active Directory Users and Computers:

  1. Press View > Advanced features.
  2. Locate the krbtgt account in the Users container.
  3. Right-click on it, and select Properties.
  4. Select the Security tab.
  5. Remove unwanted users or groups.
  6. Click OK to save the permission settings.

Frequently Asked Questions

What does AD domain with non-default permissions on krbtgt account mean?

AD domain with non-default permissions on krbtgt account means that one or more users or groups have been granted permission to modify the KRBTGT account's group membership in the Active Directory environment domain. This allows a threat actor with these permissions to compromise the KRBTGT account and create a Golden Ticket, which grants unauthorized Kerberos authentication.

This condition allows an attacker to modify the KRBTGT account's group membership, enabling them to create a Golden Ticket that authenticates as any user and sets the ticket expiration to any arbitrary time. This provides attackers with persistent access to the network.

When an attacker has permission to modify the KRBTGT account's group membership, they can create a Golden Ticket that grants them unauthorized Kerberos authentication. This allows them to bypass authentication and authorization controls, making it easier for them to move laterally within the network.

Cayosoft Guardian detects AD domain with non-default permissions on krbtgt account by continuously monitoring the group membership of the KRBTGT account across the Active Directory environment domain. When it finds non-default permissions, Guardian flags it as a security issue so administrators are aware of the potential risk.

Cayosoft Guardian helps reduce the risk by providing visibility into unauthorized group membership changes and alerting administrators to remove unwanted users or groups from the KRBTGT account's group membership. This limits the attacker's ability to create a Golden Ticket and reduces the risk of unauthorized Kerberos authentication.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Domain-wide Kerberos
Attack Tactics
Credential Access Defense Evasion Persistence Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical