logo

Abusing Delegation with Impacket (Part 2): Constrained Delegation

ID: 2f266264-7c26-52de-b355-b2e2337a074a

STIX ID: report--2f266264-7c26-52de-b355-b2e2337a074a

Feed Name: Black Hills Infosec Blog

Date Published: 2025-11-12

Date Updated: 2026-04-27

Author: BHIS

...
...

This technical write-up demonstrates how attackers can abuse Active Directory constrained delegation (with and without protocol transition) to impersonate high-privileged accounts and perform actions like DCSync. It covers S4U2Self/S4U2Proxy workflows, adding/modifying SPNs, SPN hijacking via GenericWrite, and reflective RBCD using Machine Account Quota, providing concrete Impacket command examples and cleanup steps for each attack scenario.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.