๐Ÿ“š Learning Objectives

By the end of this module, you will be able to:

๐Ÿ“‹ Module Prerequisites

Required Knowledge

  • Complete understanding of Kerberos protocol (Module 2)
  • Knowledge of Active Directory architecture (Module 1)
  • Experience with advanced Kerberos attacks (Module 3)
  • Familiarity with Mimikatz and Rubeus tools

๐ŸŽฏ Module Lessons

1

Kerberos Ticket Structure

Deep dive into Kerberos ticket components and cryptographic elements

90 min Theory + Practice

Key Topics:

  • Ticket Granting Ticket (TGT) Structure
  • Service Ticket (ST) Components
  • PAC (Privilege Attribute Certificate)
  • Ticket Encryption and Signing
  • KRBTGT Account and Key Material
2

Golden Ticket Attack

Master the most powerful Kerberos attack for domain persistence

120 min Theory + Practice

Key Topics:

  • KRBTGT Hash Extraction
  • Golden Ticket Creation Process
  • Ticket Injection and Usage
  • Domain-wide Persistence
  • Golden Ticket Limitations
3

Silver Ticket Attack

Service-specific ticket forgery for targeted service access

90 min Theory + Practice

Key Topics:

  • Service Account Hash Extraction
  • Silver Ticket Creation Process
  • Service Principal Name (SPN) Targeting
  • Service-specific Access
  • Silver Ticket vs Golden Ticket
4

Skeleton Key Attack

LSASS manipulation for persistent authentication bypass

90 min Theory + Practice

Key Topics:

  • LSASS Process Manipulation
  • Skeleton Key Installation
  • Universal Password Bypass
  • Persistence Mechanisms
  • Detection and Mitigation

๐Ÿงช Hands-On Labs

Lab 1: Golden Ticket Implementation

Objective: Extract KRBTGT hash and create Golden Ticket for domain persistence

Duration: 120 minutes Expert
  • Extract KRBTGT account hash using DCSync
  • Create Golden Ticket with Mimikatz
  • Inject Golden Ticket into memory
  • Test domain-wide access
  • Validate persistence across reboots
Start Lab

Lab 2: Silver Ticket Service Access

Objective: Create Silver Tickets for specific service access

Duration: 90 minutes Advanced
  • Identify target services and SPNs
  • Extract service account hashes
  • Create Silver Tickets for multiple services
  • Test service-specific access
  • Compare with Golden Ticket approach
Start Lab

๐Ÿ“Š Module Assessment

Final Module Assessment

Test your understanding of Golden and Silver Ticket attacks with our comprehensive assessment.

30 Questions 60 minutes 80% to pass

Topics Covered:

  • Kerberos Ticket Structure
  • Golden Ticket Attack Techniques
  • Silver Ticket Implementation
  • Skeleton Key Attacks

๐Ÿ”— Related Resources

Attack Tools

  • Mimikatz - Credential extraction and ticket manipulation
  • Rubeus - Advanced Kerberos attack toolkit
  • Impacket - Python AD protocols and tools

๐Ÿš€ Next Steps

Complete Module 4

Finish all lessons, labs, and assessments

Take Final Assessment

Move to Module 5

Advanced Domain Takeover techniques

Start Module 5

Explore Defense Strategies

Learn to defend against these attacks

Defense & Hardening

๐Ÿ“ง Stay Updated with Advanced AD Content

Get notified when we add new expert-level lessons and techniques!