If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1550/003 - Use Alternate Authentication M.

site address: attack.mitre.org/techniques/T1550/003 redirected to: attack.mitre.org/techniques/T1550/003

site title: Use Alternate Authentication Material: Pass the Ticket, Sub-technique T1550.003 - Enterprise MITRE ATT&CK®

Our opinion (on Saturday 29 August 2026 19:56:29 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

use, alternate, authentication, material, pass, the, ticket, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,

Text of the page (most frequently used words):
the (44), #ticket (29), kerberos (19), and (18), retrieved (15), for (14), account (14), tickets (14), pass (13), att (10), all (10), password (10), access (10), krbtgt (9), service (9), hash (9), use (8), using (8), authentication (8), t1550 (8), 2015 (7), enterprise (7), domain (6), mimikatz (6), user (6), can (6), are (5), ics (5), mobile (5), none (5), techniques (5), november (5), january (5), security (5), golden (5), granting (5), that (5), mitre (4), detection (4), sub (4), metcalf (4), 2014 (4), active (4), directory (4), 2018 (4), cyber (4), centre (4), september (4), december (4), 2017 (4), with (4), tgt (4), also (4), lateral (4), movement (4), 003 (4), other (4), used (4), version (4), may (4), valid (4), resource (4), system (4), alternate (4), material (4), 2026 (3), reset (3), reference (3), cti (3), data (3), mitigations (3), defenses (3), 2020 (3), seaduke (3), national (3), october (3), bronze (3), butler (3), 2016 (3), 2024 (3), attacks (3), tgs (3), description (3), name (3), accounts (3), have (3), any (3), created (3), create (3), ptt (3), obtained (3), corporation (2), cookie (2), domains (2), resources (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), every (2), 180 (2), days (2), july (2), new (2), zealand (2), ncsc (2), tools (2), 2019 (2), dcsync (2), more (2), february (2), injection (2), absent (2), generation (2), hosts (2), strategy (2), windows (2), analytic (2), local (2), administrator (2), management (2), admin (2), which (2), from (2), change (2), pupy (2), has (2), remote (2), apt32 (2), apt29 (2), technique (2), adversaries (2), stolen (2), ntlm (2), particular (2), ckcon (2), person (2), faq (2), registered, trademarks, preferences, website, changelog, privacy, policy, terms, contact, filters, ucf, must, least, sean, symantec, response, forkmeiamfamous, latest, weapon, duke, armory, nicolas, verdier, australian, acsc, canadian, cccs, cert, cybersecurity, communications, integration, center, nccic, joint, report, publicly, available, hacking, march, schroeder, extrasids, august, now, unofficial, guide, command, counter, threat, unit, research, team, targets, japanese, enterprises, dahan, operation, cobalt, kitty, dunwoody, carr, easy, breach, derbycon, warren, how, detect, overpass, 2021, campbell, secret, life, deply, june, references, detects, unauthorized, correlating, 4769, requests, corresponding, logons, 4624, prior, 4768, activity, highlights, anomalous, chains, involving, unexpected, users, times, suspicious, via, like, tooling, into, lsass, memory, behavior, includes, network, expected, interactive, logon, patterns, an1000, det0352, not, allow, multiple, systems, m1018, limit, permissions, controllers, limited, servers, delegate, functions, separate, privileged, m1026, ensure, complex, unique, passwords, policies, m1027, contain, impact, previously, generated, built, twice, will, invalidate, existing, been, derived, each, once, force, replication, then, second, time, consider, rotating, configuration, m1015, mitigation, some, samples, module, s0053, perform, s0192, modules, implement, three, steps, required, extract, lsadump, s0002, forged, maintain, administrative, g0060, successfully, gained, g0050, g0016, procedure, examples, live, permalink, last, modified, ryan, becwar, vincent, toux, contributors, platforms, tactic, information, such, hashes, aes, keys, example, overpassing, involves, authenticate, while, key, distribution, enables, tgts, services, mechanism, generate, sharepoint, silver, when, preforming, captured, depending, level, allows, whereas, request, privileges, credential, dumping, move, laterally, within, environment, bypassing, normal, controls, method, authenticating, without, having, first, step, web, session, 004, 002, application, token, 001, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, about, get, started, detections,


Text of the page (random words):
use alternate authentication material pass the ticket sub technique t1550 003 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise use alternate authentication material pass the ticket use alternate authentication material pass the ticket other sub techniques of use alternate authentication material 4 id name t1550 001 application access token t1550 002 pass the hash t1550 003 pass the ticket t1550 004 web session cookie adversaries may pass the ticket using stolen kerberos tickets to move laterally within an environment bypassing normal system access controls pass the ticket ptt is a method of authenticating to a system using kerberos tickets without having access to an account s password kerberos authentication can be used as the first step to lateral movement to a remote system when preforming ptt valid kerberos tickets for valid accounts are captured by os credential dumping a user s service tickets or ticket granting ticket tgt may be obtained depending on the level of access a service ticket allows for access to a particular resource whereas a tgt can be used to request service tickets from the ticket granting service tgs to access any resource the user has privileges to access 1 2 a silver ticket can be obtained for services that use kerberos as an authentication mechanism and are used to generate tickets to access that particular resource and the system that hosts the resource e g sharepoint 1 a golden ticket can be obtained for the domain using the key distribution service account krbtgt account ntlm hash which enables generation of tgts for any account in active directory 3 adversaries may also create a valid kerberos ticket using other user information such as stolen password hashes or aes keys for example overpassing the hash involves using a ntlm password hash to authenticate as a user i e pass the hash while also using the password hash to create a valid kerberos ticket 4 id t1550 003 sub technique of t1550 ⓘ tactic lateral movement ⓘ platforms windows contributors ryan becwar vincent le toux version 2 0 created 30 january 2020 last modified 12 may 2026 version permalink live version procedure examples id name description g0016 apt29 apt29 used kerberos ticket attacks for lateral movement 5 g0050 apt32 apt32 successfully gained remote access by using pass the ticket 6 g0060 bronze butler bronze butler has created forged kerberos ticket granting ticket tgt and ticket granting service tgs tickets to maintain administrative access 7 s0002 mimikatz mimikatz s lsadump dcsync and kerberos ptt modules implement the three steps required to extract the krbtgt account hash and create use kerberos tickets 8 9 10 11 s0192 pupy pupy can also perform pass the ticket 12 s0053 seaduke some seaduke samples have a module to use pass the ticket with kerberos for authentication 13 mitigations id mitigation description m1015 active directory configuration to contain the impact of a previously generated golden ticket reset the built in krbtgt account password twice which will invalidate any existing golden tickets that have been created with the krbtgt hash and other kerberos tickets derived from it 14 for each domain change the krbtgt account password once force replication and then change the password a second time consider rotating the krbtgt account password every 180 days 15 m1027 password policies ensure that local administrator accounts have complex unique passwords m1026 privileged account management limit domain admin account permissions to domain controllers and limited servers delegate other admin functions to separate accounts 1 m1018 user account management do not allow a user to be a local administrator for multiple systems detection strategy id name analytic id analytic description det0352 detection strategy for t1550 003 pass the ticket windows an1000 detects unauthorized kerberos ticket injection by correlating service ticket tgs 4769 requests with absent corresponding account logons 4624 and prior ticket granting ticket tgt 4768 activity highlights anomalous service ticket generation chains involving unexpected users hosts or times and suspicious injection of tickets via mimikatz like tooling into lsass memory behavior also includes network lateral movement using kerberos authentication absent expected interactive logon patterns references metcalf s 2014 november 22 mimikatz and active directory kerberos attacks retrieved june 2 2016 deply b 2014 january 13 pass the ticket retrieved september 12 2024 campbell c 2014 the secret life of krbtgt retrieved november 17 2024 warren j 2019 february 26 how to detect overpass the hash attacks retrieved february 4 2021 dunwoody m and carr n 2016 september 27 no easy breach derbycon 2016 retrieved september 12 2024 dahan a 2017 operation cobalt kitty retrieved december 27 2018 counter threat unit research team 2017 october 12 bronze butler targets japanese enterprises retrieved january 4 2018 metcalf s 2015 november 13 unofficial guide to mimikatz command reference retrieved december 23 2015 metcalf s 2015 august 7 kerberos golden tickets are now more golden retrieved december 1 2017 schroeder w 2015 september 22 mimikatz and dcsync and extrasids oh my retrieved december 4 2017 the australian cyber security centre acsc the canadian centre for cyber security cccs the new zealand national cyber security centre nz ncsc cert new zealand the uk national cyber security centre uk ncsc and the us national cybersecurity and communications integration center nccic 2018 october 11 joint report on publicly available hacking tools retrieved march 11 2019 nicolas verdier n d retrieved january 29 2018 symantec security response 2015 july 13 forkmeiamfamous seaduke latest weapon in the duke armory retrieved july 22 2015 sean metcalf 2014 november 10 kerberos krbtgt active directory s domain kerberos service account retrieved january 30 2020 ucf n d the password for the krbtgt account on a domain must be reset at least every 180 days retrieved november 5 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 63 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-63


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1550/003
X-GitHub-Request-Id 48B6:7B970:1FD6BFB:20280F9:6A93396C
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sat, 29 Aug 2026 19:56:28 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290029-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1788033389.799669,VS0,VE97
Vary Accept-Encoding
X-Fastly-Request-ID a1ecbc4add1932dc870cc406a77498f24ba0846e
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1550/003/
access-control-allow-origin *
expires Sat, 29 Aug 2026 20:06:28 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 1296:6F3AB:1F7D803:1FCECD4:6A93396C
x-github-edge-region fra
accept-ranges bytes
date Sat, 29 Aug 2026 19:56:29 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290038-RTM
x-cache MISS
x-cache-hits 0
x-timer S1788033389.924868,VS0,VE108
vary Accept-Encoding
x-fastly-request-id 933d1d2f270e580b7e3ba0a1fb5f0069ed74a7f8
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-eaa1
expires Sat, 29 Aug 2026 20:06:29 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 86BA:3660BB:1FFEBFD:20501E9:6A93396C
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 29 Aug 2026 19:56:29 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290038-RTM
x-cache MISS
x-cache-hits 0
x-timer S1788033389.040954,VS0,VE105
vary Accept-Encoding
x-fastly-request-id 58500e4c23f0c280d294ab7a97a77ade5908d2f7
content-length 10050

Meta Tags

title="Use Alternate Authentication Material: Pass the Ticket, Sub-technique T1550.003 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size10050
load time (s)0.580929
redirect count2
speed download17327
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"