Common warning signs include Kerberos tickets with unusually long lifetimes, unexpected privileges on service tickets, suspicious token manipulation, and evidence of LSASS memory reads. Teams should also watch for sudden privilege escalation, credential dumping behaviour, and unusual access patterns in Active Directory and system logs. These indicators often appear before the attacker fully entrenchs.
How to tell a Golden Ticket attack is in progress
A golden ticket attack is rarely obvious from a single event. The strongest signal is a cluster of Kerberos abuse indicators that do not match normal domain behaviour: ticket lifetimes that are far longer than policy, service tickets carrying unusual privilege characteristics, and log patterns that suggest credential manipulation rather than ordinary authentication.
What the activity looks like in Kerberos, Active Directory, and endpoint telemetry
Look for forged or abnormally durable Kerberos activity, especially when it appears alongside sudden access to high-value systems, new administrative reach, or repeated use of a single ticket across multiple hosts. In practice, defenders often see the identity side first in directory and log data, while the endpoint side shows the memory access or dumping behaviour that enabled the forgery. For broader attack-pattern context, MITRE ATT&CK Enterprise Matrix remains the most useful reference for mapping credential access, privilege escalation, and lateral movement.
Suspicious token manipulation is another strong clue, especially when it coincides with privilege escalation that was not preceded by an expected approval, group change, or administrative workflow. If LSASS reads are present, treat them as especially important because they often indicate the attacker is preparing to harvest material needed for ticket forging or post-compromise movement. Endpoint telemetry that shows unusual process access to authentication material is therefore highly relevant, not just the Kerberos ticket artifacts themselves. For incident patterning, CISA cyber threat advisories are useful for comparing observed behaviour with known intrusion tradecraft.
Why these indicators matter and where teams usually miss them
The main weakness in golden ticket detection is that the forged ticket can look legitimate once it is accepted by Active Directory. That means defenders need to rely on correlation, not just one log line. A ticket that is valid for an unusually long time, used to access systems outside the user’s normal role, or paired with credential dumping behaviour should be treated as a potential compromise of the trust boundary itself. In more advanced cases, attackers also blend the activity into normal administrative access patterns, which makes baseline drift and privilege anomalies especially important.
Because the attack path usually starts earlier than the visible ticket use, the most valuable evidence often sits in the sequence: suspicious credential access, directory privilege changes, then abnormal Kerberos use. If that sequence is present, the issue is usually already beyond routine hygiene and into active compromise management. Teams that only search for failed logons or password resets will miss the forged-ticket stage entirely.
Risk and Threat Considerations
Golden Ticket activity is high-risk because it undermines the trust model behind Kerberos and can let an attacker impersonate privileged identities for extended periods. The danger is not only initial access, but durable, hard-to-detect persistence across the domain.
Failure mechanism: The attacker obtains or forges the material needed to mint a Kerberos ticket and then uses that ticket to request access that appears structurally valid to the domain.
Impact: The attacker can escalate privilege, move laterally, and maintain access even after the original compromise point is discovered, which makes remediation slower and more disruptive.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1003 — OS Credential Dumping | LSASS reads and credential dumping are core precursors to Golden Ticket abuse. |
| T1558.001 — Golden Ticket | This is the exact technique being discussed, including forged Kerberos ticket abuse. | |
| T1068 — Exploitation for Privilege Escalation | Sudden privilege escalation is a common consequence and indicator in this attack path. | |
| Recommendation — Hunt for LSASS access and credential dumping before domain ticket forgery. Map Kerberos anomalies directly to Golden Ticket activity and investigate domain compromise. Correlate privilege escalation with ticket anomalies to confirm post-compromise abuse. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Golden Ticket detection depends on correlating authentication, directory, and endpoint audit data. |
| IA-5 — Authenticator Management | Ticket abuse is enabled by compromised authentication material and weak credential lifecycle control. | |
| SI-4 — System Monitoring | Endpoint and directory monitoring are essential to spot LSASS access and abnormal Kerberos use. | |
| Recommendation — Correlate audit records across domain controllers and endpoints for forged-ticket indicators. Tighten authenticator lifecycle controls to reduce ticket-forging opportunities. Monitor for LSASS access, unusual ticket lifetimes, and abnormal privilege use. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | The attack is detected through log correlation across Kerberos, AD, and endpoint sources. |
| CIS-10 — Malware Defenses | Credential dumping and post-compromise tooling often accompany Golden Ticket activity. | |
| Recommendation — Centralise and review logs needed to spot ticket forgery and privilege abuse. Use malware defenses to reduce and detect credential dumping activity. | ||
Practitioner Guidance
What to verify: Confirm whether the suspicious ticket use lines up with known account behaviour, ticket policy, and recent directory changes. A single anomalous event is weak evidence; a ticket anomaly plus privilege drift plus LSASS access is far stronger.
Decision rule: If the activity includes ticket anomalies and evidence of credential access, treat it as an active domain compromise until proven otherwise. Prioritise containment of affected hosts and review of privileged account exposure before broad user remediation.
Practitioner takeaway: Golden Ticket detection is a correlation problem, not a signature problem, so the best response is to combine Kerberos, directory, and endpoint evidence into one compromise timeline.
Related resources from NHI Mgmt Group
- What are the signs that a Golden Ticket attack may be underway in Active Directory?
- What are the signs that a Golden GMSA attack may be underway?
- How should teams respond when a secret is found in a support ticket?
- What is the difference between a normal Kerberos ticket issue and a Golden Ticket attack?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org