Active Directory (AD) uses the KRBTGT in the AD domain for Kerberos tickets. If an attacker wiggles into a network, they can use the golden ticket attack sequence. Changing the KerberOS password is a must-do task if you monitor and maintain an AD infrastructure. If you have had or suspect an intrusion, change that password immediately after the network has been stabilized, plan on changing it at least twice a year. Performing this action on a regular basis will stop golden ticket attacks.”]

