CTD-000051

AD Krbtgt account password was not reset recently

High
Active Directory
Credential Access Persistence
v25

Signature Identity

CTD-000051
Threat ID
25
Version
IOE
Indicator Type

Threat Description

The risk of not changing your krbtgt account password regularly in an Active Directory environment is significant as it is a critical component of the Kerberos authentication protocol, which is used to authenticate users and services in an AD environment. A threat actor who gains access to the krbtgt password could potentially use it to carry out a range of attacks on the AD infrastructure, including:
  1. Golden ticket attacks: By obtaining the KRBTGT password, a threat actor can generate a “golden ticket”, which is a forged Kerberos ticket that can be used to gain unrestricted access to any resource in the AD environment. This allows the attacker to impersonate any user or service in the domain and carry out any action they desire.
  2. Pass-the-hash attacks: The KRBTGT password is also used to derive the hash values of other AD account passwords. If a threat actor obtains the KRBTGT password, they can use it to perform “pass-the-hash” attacks, where they use the hash values of other user passwords to authenticate and gain access to resources in the domain.
  3. Persistence: If a threat actor gains access to the KRBTGT password, they can use it to create persistent backdoors into the AD environment, making it easier for them to maintain access and carry out further attacks in the future.
Therefore, it is crucial to change the KRBTGT password regularly to minimize the risk of compromise and ensure the security of the AD infrastructure.

MITRE ATT&CK: Attack Tactics

Credential Access Persistence

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To reset the krbtgt account password please follow instructions in the Microsoft Learn article: Active Directory Forest Recovery – Reset the krbtgt password.

Frequently Asked Questions

What does AD Krbtgt account password was not reset recently mean?

The krbtgt account password in the Active Directory environment has not been changed recently. This is a critical component of Kerberos authentication, used to authenticate users and services.

An unchanged krbtgt password allows attackers to obtain the Kerberos ticket-granting service's credentials, enabling them to impersonate users or services. This can lead to unauthorized access and data breaches.

Attackers can use an unchanged krbtgt password for golden ticket attacks, pass-the-hash attacks, or creating persistent backdoors into the Active Directory environment. This enables them to maintain a foothold in the AD infrastructure and escalate privileges.

Cayosoft Guardian continuously monitors the krbtgt account's password status across the Active Directory environment. When an unchanged or unreset password is found, Guardian flags it as a security issue and provides visibility to administrators.

Cayosoft Guardian alerts administrators to change the krbtgt password regularly, ensuring the Kerberos ticket-granting service account's password remains secure and minimizing exposure to golden ticket and pass-the-hash attacks. This helps support investigation and response efforts by providing a clear audit trail of changes.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Forest-wide Infrastructure
Attack Tactics
Credential Access Persistence
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical