Attacking Kerberos Delegation

Identify and abuse Active Directory Kerberos delegation — unconstrained delegation with printer-bug coercion, constrained delegation with protocol transition (S4U2Self/S4U2Proxy), and resource-based constrained delegation via machine-account creation and msDS-AllowedToActOnBehalfOfOtherIdentity. Use when BloodHound or enumeration flags delegation, when you control an account with an SPN or GenericWrite over a computer, or when escalating within a domain.

trilwu 8f797b5 8.3 KB Updated

File contents

trilwu/secskills/tree/main/secskills-offense/skills/attacking-kerberos-delegation commit 8f797b50ff

Frequently asked questions

npx skillmds add trilwu/attacking-kerberos-delegation