Pass-the-Ticket Attack Report Template
Document Control
| Field |
Value |
| Domain |
[DOMAIN.LOCAL] |
| Engagement ID |
[ID] |
| Date |
[DATE] |
| Source Host |
Method |
Tickets Found |
High-Value |
|
Mimikatz/Rubeus |
|
|
2. Ticket Details
| User |
Type |
Service |
Expiry |
Encryption |
|
TGT/TGS |
krbtgt/cifs |
|
RC4/AES |
3. Lateral Movement Results
| Target |
Access |
Method |
Evidence |
|
Admin/User |
PsExec/SMB |
Screenshot |
4. Recommendations
- Enable Credential Guard
- Implement Protected Users group
- Enable LSASS RunAsPPL protection
- Monitor Event ID 4769 anomalies
- Reduce TGT lifetime for admin accounts
MITRE ATT&CK
- T1550.003 - Pass the Ticket
- T1003.001 - LSASS Memory