Hunting in Active Directory: Unconstrained Delegation & Forests Trusts
ID: f61fff79-305b-51c5-8968-99438b1c0c46
STIX ID: report--f61fff79-305b-51c5-8968-99438b1c0c46
Feed Name: SpecterOps Blog
This post analyzes an attack where an adversary leverages unconstrained delegation and a two-way forest trust to coerce a foreign Domain Controller to authenticate to an attacker-controlled server via the MS-RPRN "printer bug" (SpoolSample), then captures the DC's TGT using Rubeus to impersonate the DC and perform actions like DCSync; the author details the attack flow, expected Windows security events (e.g. 4624, 4611, 4673, 4675, 5145), and offers detection recommendations focused on Rubeus command/LSA behavior, IPC$/spoolss bindings, SID filtering events and aggregation strategies for servers with unconstrained delegation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
