# API Reference: Detecting Golden Ticket Attacks ## python-evtx Library ```python from Evtx.Evtx import FileHeader with open("Security.evtx", "rb") as f: fh = FileHeader(f) for record in fh.records(): xml_string = record.xml() ``` ## Key Event IDs ### Event 4768 - Kerberos TGT Request (AS-REQ) ```xml admin_user CORP.LOCAL 0x12 15 ::ffff:10.0.0.50 ``` ### Event 4624 - Logon Event ```xml user 3 Kerberos 10.0.0.50 WKS01 ``` ### Event 4672 - Special Privileges Assigned ```xml user CORP SeDebugPrivilege SeTcbPrivilege ``` ## Golden Ticket Detection Indicators | Indicator | Evidence | |-----------|----------| | Orphan logon | 4624 Kerberos logon with no 4768 TGT request | | Privilege anomaly | 4672 admin privs for non-admin account | | Abnormal TGT lifetime | TGT valid >10 hours (default max) | | RC4 TGT majority | >50% of TGTs using 0x17 encryption | | Domain SID mismatch | TGT domain SID differs from DC | ## MITRE ATT&CK - T1558.001 - Golden Ticket - T1550 - Use Alternate Authentication Material