Kerberos tickets are credentials
Tickets are what actually grant access in a Windows environment, and stealing one skips the password entirely.
They sit in memory on machines people have logged into, which is why an attacker on one server harvests them rather than trying to crack anything. Changing a password does not necessarily invalidate what has already been issued. Thinking of tickets as credentials, with lifetimes and theft risk, explains most of the attacks in this area.
More on Windows and Active Directory
- Domain Admin is a forest-scale keyOne root under the whole forest
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
- Service accounts can become invisible administratorsThe pass with no face
