Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

Silver Ticket

← Back to Glossary
By NHI Mgmt Group Updated September 20, 2026 Domain: Threats, Abuse & Incident Response

A Silver Ticket is a forged Kerberos service ticket created or modified by an attacker to gain access to a specific service. Because the attack abuses trust in ticket contents, defenders must focus on key protection, permission boundaries, and monitoring for abnormal access patterns rather than relying only on endpoint controls.

How a Silver Ticket works

A Silver Ticket is dangerous because the attacker forges a service ticket that a target service may accept as valid. The attack does not need to break the service directly; it exploits trust in ticket contents, which is why service-specific trust boundaries matter as much as the workstation or browser where the activity appears to originate.

In practice, the forged ticket is aimed at one service instance rather than the whole Kerberos realm. That makes the technique attractive when an attacker already has enough material to mint or modify a ticket, then wants a quieter path to a specific file share, database, web application, or other Kerberos-protected service.

This is why Kerberos incidents often involve credential material, ticket lifetime, service account protection, and visibility into unusual service access. Defenders need to understand the trust path from ticket issuance to service acceptance, not just whether an endpoint looks healthy.

Why Silver Ticket attacks are hard to spot

Silver Ticket abuse can blend into normal authentication flow because the forged ticket is presented to the service, not always to the central ticket-granting path that defenders inspect first. That means the absence of obvious domain-controller activity does not prove the access was legitimate.

Detection becomes harder when monitoring is tuned only for interactive logons or obvious endpoint malware signals. A forged service ticket may produce access that looks “Kerberos-like” at the service boundary while still being unauthorized, especially if the attacker matches the target service and uses valid-seeming ticket fields.

Good monitoring therefore focuses on service-side anomalies, ticketing anomalies, and access that does not fit the normal user, host, or time pattern. For a broader identity and access lens, NHIMG’s Ultimate Guide to Non-Human Identities is useful for understanding why privileged, non-interactive access paths need stronger visibility and lifecycle controls.

Security implications for Kerberos environments

The main security problem is trust abuse: if a service accepts a forged ticket, the attacker may obtain application-level access even when other security layers remain intact. That can expose data, enable lateral movement, or let an intruder act as a legitimate user within the service’s own permission scope.

Because service tickets are tied to the service account and its keys, weak key protection or long-lived service credentials increase exposure. If an attacker can obtain the right signing material, they can often persist at the service layer even when the original entry point is removed.

Mitigations rely on protecting the relevant keys, constraining service permissions, reducing ticket or credential lifetime where possible, and correlating service access with expected behavior. NIST SP 800-53 Rev 5 Security and Privacy Controls is a strong baseline for tying those protections to access control, audit, and configuration management.

What defenders should focus on

The most effective response is to treat Silver Ticket risk as a service trust problem, not just an endpoint problem. That means knowing which services are most sensitive, which accounts or keys they trust, and where a forged ticket would create the most damaging access.

Operationally, defenders should pay close attention to service-account hygiene, ticket validation assumptions, and logging that captures unusual service authorization outcomes. When a service is high-value, the surrounding access model should be designed to make silent ticket abuse harder to sustain.

For practitioners who want a control-oriented perspective on identity abuse and privilege exposure, the OWASP Non-Human Identity Top 10 helps frame the same class of risk around overprivilege, secret handling, and lifecycle weakness. For cryptographic and key-protection angles, NIST SP 800-57 Key Management is relevant to protecting the material that makes forged tickets possible.

Risk and Threat Considerations

Silver Ticket attacks are high risk because they can convert stolen service material into stealthy service-level access. The compromise may remain local to one application, but the impact can still be severe if that service protects sensitive data or supports broader lateral movement.

Failure mechanism: An attacker obtains or derives the key material needed to forge a service ticket, then presents a ticket the target service accepts without relying on the normal end-to-end trust path.

Impact: Unauthorized access can occur even when central authentication controls appear normal, which can delay detection and allow deeper compromise of data or downstream systems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorizationsSilver Ticket abuse succeeds by bypassing expected service authorization boundaries.
DE.CM-8 — Vulnerability MonitoringAbnormal service access patterns are a key detection signal for forged ticket abuse.
PR.DS-1 — Data-at-Rest ProtectionService ticket abuse often targets protected data exposed through the accepted service session.
Recommendation — Enforce least-privilege access rules and review service authorization assumptions regularly. Monitor service activity for unexpected access patterns and investigate anomalies quickly. Protect sensitive service data so a forged ticket does not directly expose high-value information.
CIS Controls v85.1 — Establish and Maintain an Inventory of AccountsService accounts and their trust relationships are central to Silver Ticket exposure.
5.2 — Use Unique PasswordsStrong, unique service credentials reduce the chance of ticket-forging abuse.
Recommendation — Inventory service accounts and their dependencies so trust boundaries are visible and governed. Use unique, strong credentials for service accounts and rotate them on a defined schedule.
NIST SP 800-63SP 800-63B — Authentication and Lifecycle ManagementKerberos service access depends on strong authenticator handling and lifecycle discipline.
Recommendation — Apply strong lifecycle controls to authenticators and reduce exposure from long-lived trust material.

Practitioner Guidance

What to watch for: Focus on services that can be reached with locally accepted tickets but show odd access patterns, especially where the user, host, or timing does not match expected behavior. The practical question is whether the service’s trust boundary is strong enough to reject forged or stale access paths.

Governance implication: Ownership of service accounts, key rotation, and service-side logging must be explicit, because Silver Ticket risk usually emerges where those responsibilities are diffuse. A service that nobody actively governs is a service that attackers can often trust more than defenders do.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org