Skip to main content

Detecting Golden Ticket

Status: Scaffold — content in progress

Paired Attack: Golden Ticket
DRL Level: DRL-3 (rule drafted, lab validation pending)
Detection Confidence: [High / Medium / Low]

Required Telemetry

SourceEvent / FieldNotes
[Fill in][Fill in][Fill in]

Sigma Rule

title: Detecting Golden Ticket
status: experimental
# Fill in rule

KQL — Microsoft Sentinel

// Fill in KQL query

SPL — Splunk

// Fill in SPL query

False Positive Handling

[Document known benign causes]

Response Actions

[Initial response steps]

TopicLink
Attackgolden-ticket
Detection Frameworkdetection-framework