From cybersecurity-skills
Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 downgrades, abnormal ticket lifetimes, and krbtgt anomalies in Splunk and Elastic SIEM.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:detecting-golden-ticket-forgeryThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A Golden Ticket attack (MITRE ATT&CK T1558.001) involves forging a Kerberos Ticket Granting Ticket (TGT) using the krbtgt account NTLM hash, granting unrestricted access to any service in the Active Directory domain. This skill detects Golden Ticket usage by analyzing Event ID 4769 for RC4 encryption type (0x17) in environments enforcing AES, identifying tickets with abnormal lifetimes exceedin...
A Golden Ticket attack (MITRE ATT&CK T1558.001) involves forging a Kerberos Ticket Granting Ticket (TGT) using the krbtgt account NTLM hash, granting unrestricted access to any service in the Active Directory domain. This skill detects Golden Ticket usage by analyzing Event ID 4769 for RC4 encryption type (0x17) in environments enforcing AES, identifying tickets with abnormal lifetimes exceeding domain policy, correlating TGS requests with missing corresponding TGT requests (Event ID 4768), and detecting krbtgt password age anomalies.
JSON report with Golden Ticket indicators including RC4 downgrades, orphaned TGS requests, abnormal ticket lifetimes, and risk-scored alerts with MITRE ATT&CK technique mapping.
npx claudepluginhub mukul975/anthropic-cybersecurity-skills --plugin cybersecurity-skillsDetect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 downgrades, abnormal ticket lifetimes, and krbtgt anomalies in Splunk and Elastic SIEM.
Detects Kerberos Golden Ticket forgery via Windows Event ID 4769 analysis in Splunk/Elastic SIEM for RC4 encryption downgrades, abnormal lifetimes, and krbtgt anomalies. For threat hunting and SOC detection rules.
Detects Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades, abnormal ticket lifetimes, and krbtgt anomalies in Splunk and Elastic SIEM.