Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Global Accelerated Learning • Est. 1999
Glossary Term Pass-the-Ticket PtT

Training Camp • Cybersecurity Glossary

What is Pass-the-Ticket PtT?

Pass-the-Ticket PtT steals and reuses a valid Kerberos ticket to authenticate as a victim without their password, enabling lateral movement in a domain.

Glossary > Threats, Malware & Attacks > Pass-the-Ticket PtT

Understanding Pass-the-Ticket PtT

Pass-the-Ticket PtT is a credential theft and lateral movement technique in which an attacker steals a valid Kerberos ticket from memory and reuses it to authenticate as the victim without knowing their password. By extracting Ticket Granting Tickets or service tickets from a compromised host, often with tools like Mimikatz, the adversary impersonates the user across the domain. Forged variants such as Golden and Silver Tickets extend the attack to long-term, privileged domain access.

Learn More About Pass-the-Ticket PtT:

Ready to Get Certified?

Turn knowledge into credentials with our instructor-led cybersecurity boot camps.

View All Courses →