logo

Hunting in Active Directory: Unconstrained Delegation & Forests Trusts

ID: f61fff79-305b-51c5-8968-99438b1c0c46

STIX ID: report--f61fff79-305b-51c5-8968-99438b1c0c46

Feed Name: SpecterOps Blog

Threat Score
75/100

Date Published: 2018-11-28

Date Updated: 2026-04-30

...
...

This post analyzes an attack where an adversary leverages unconstrained delegation and a two-way forest trust to coerce a foreign Domain Controller to authenticate to an attacker-controlled server via the MS-RPRN "printer bug" (SpoolSample), then captures the DC's TGT using Rubeus to impersonate the DC and perform actions like DCSync; the author details the attack flow, expected Windows security events (e.g. 4624, 4611, 4673, 4675, 5145), and offers detection recommendations focused on Rubeus command/LSA behavior, IPC$/spoolss bindings, SID filtering events and aggregation strategies for servers with unconstrained delegation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.