logo

Abusing Delegation with Impacket (Part 1): Unconstrained Delegation

ID: 11f177e6-7bc8-5b10-abfc-6f5328dfba3c

STIX ID: report--11f177e6-7bc8-5b10-abfc-6f5328dfba3c

Feed Name: Black Hills Infosec Blog

Date Published: 2025-11-05

Date Updated: 2026-04-27

Author: BHIS

...
...

### Executive Summary This blog post details how attackers can abuse Kerberos unconstrained delegation in Active Directory environments to escalate privileges and obtain domain credentials. It explains Kerberos concepts and the double‑hop problem, then provides hands‑on procedures—adding SPNs or modifying DNS records, running a Kerberos relay listener (krbrelayx), coercing a Domain Controller to authenticate to the attacker, exporting the obtained TGT, and performing DCSync—along with cleanup steps and caveats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.