logo

Abusing S4U2Self for Active Directory Pivoting

ID: cfe83e8d-00c9-5cfc-a099-8898a6a4a021

STIX ID: report--cfe83e8d-00c9-5cfc-a099-8898a6a4a021

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2025-06-11

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog demonstrates how an attacker who has obtained a machine account NTLM hash can abuse Kerberos S4U2Self to impersonate domain users on that machine, create or re-enable local administrator accounts, and then leverage SEImpersonate to escalate to domain compromise; it provides step-by-step proof-of-concept commands, discusses limitations (rotating machine passwords, Remote UAC, requirement for active domain sessions), and offers mitigation context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.