Palo Alto Networks Unit 42 detailed two advanced Kerberos forged-ticket techniques—Diamond Ticket and Sapphire Ticket—that build on the classic Golden Ticket attack to compromise Active Directory domains. Instead of creating a fake ticket from scratch, both methods alter a legitimately issued ticket-granting ticket (TGT), making them harder to detect because the ticket originates from a domain controller. The attacks require theft of the KRBTGT account password hash and can give an intruder broad or effectively unconstrained access by modifying the Privileged Attribute Certificate (PAC) or changing identity data inside the TGT.
The report said Sapphire Ticket abuses U2U and S4U2Self to obtain a legitimate high-privilege PAC and transplant it into another user’s TGT, while Diamond Ticket directly edits a valid TGT’s PAC to add privileges or impersonate another user. Unit 42 linked forged-ticket tradecraft to activity associated with Playful Taurus / APT15 / NICKEL, which has previously used Mimikatz and credential-dumping techniques for Golden Ticket persistence. Recommended detection opportunities include monitoring for KRBTGT hash theft and DCSync behavior, suspicious combined use of U2U and S4U2Self, mismatches between TGT and TGS activity, and Windows events such as 4627, 4728, and 4732.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On its December 2022 publication, Unit 42 described Diamond Ticket and Sapphire Ticket as newer Kerberos forged-ticket techniques that modify legitimate TGTs and outlined detection opportunities for Active Directory defenders.
Microsoft Threat Intelligence Center reported that around December 2021 the same threat actor used Mimikatz, WDigest, NTDSDump, and other password-dumping tools to gather credentials.
An NCC Group incident response investigation from May 2017 reported that Playful Taurus used Mimikatz to dump credentials and generate Kerberos Golden Tickets for persistence.
Unit 42 said Playful Taurus, also known as APT15, Ke3chang, and NICKEL, has targeted oil, government, diplomatic, military, and non-governmental organizations since 2010.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.