Active Directory Constrained Delegation

How to enumerate and exploit Kerberos Constrained Delegation in Active Directory for privilege escalation. Use this skill whenever the user mentions constrained delegation, S4U2self, S4U2proxy, msDS-AllowedToDelegateTo, TrustedToAuthForDelegation, Kerberos delegation attacks, or any scenario involving service account impersonation in AD environments. Also trigger for Rubeus s4u commands, Impacket getST with altservice, or when investigating delegation-based privilege escalation paths.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/windows-hardening/active-directory-methodology/constrained-delegation commit df3aacfc67

Frequently asked questions

npx skillmds@latest add abelrguezr/active-directory-constrained-delegation