Hunting Kerberos And Ad Delegation Abuse

Hunt for Active Directory Kerberos delegation configurations that let one identity act as another: a service account with unconstrained delegation that can impersonate any user who authenticates to it and reuse their ticket anywhere, constrained delegation configured so a service can request tickets for higher-privileged targets, resource-based delegation an attacker can set on an object they control to relay into it, a service account with a weak password exposed to Kerberoasting through its service principal name, and an account not requiring pre-authentication that is roastable offline. Use when a service is allowed to reuse or request a user's Kerberos identity and the scope of that delegation is the boundary. The delegation right or roastable credential is the source, the impersonated higher-privileged identity is the sink, and the overbroad delegation or crackable service account is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-kerberos-and-ad-delegation-abuse commit bf0bab8190

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-kerberos-and-ad-delegation-abuse