Kerberos Tickets
MITRE ATT&CK, Credential Access, Technique T1558
Stealing Kerberos Tickets on Linux
Kerberos Credential Cache (ccache) files contain Kerberos credentials for the domain user that has authenticated to the Linux machine, this is often a cached TGT. These are referred to as a Linux Cached Credential and are stored in /tmp
and can be exfiltrated by an attacker to request service tickets.
Last updated