Ad Delegation Abuse

Abuse Kerberos delegation to impersonate users and take over hosts — unconstrained, constrained (S4U2Self/S4U2Proxy), and resource-based (RBCD), including the coercion → NTLM-relay-to-LDAP → RBCD chain. Load in an AD environment when BloodHound/enum shows delegation rights, a machine account you control, GenericWrite/GenericAll over a computer, or coercion is possible. Signals: msDS-AllowedToActOnBehalfOfOtherIdentity, TRUSTED_FOR_DELEGATION, msDS-AllowedToDelegateTo, PetitPotam.

NoorQureshi Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/ad/ad-delegation-abuse commit e67cb09f3b

Frequently asked questions

npx skillmds@latest add noorqureshi/ad-delegation-abuse