Abusing S4U2Self for Active Directory Pivoting
ID: cfe83e8d-00c9-5cfc-a099-8898a6a4a021
STIX ID: report--cfe83e8d-00c9-5cfc-a099-8898a6a4a021
Feed Name: Black Hills Infosec Blog
Threat Score
This blog demonstrates how an attacker who has obtained a machine account NTLM hash can abuse Kerberos S4U2Self to impersonate domain users on that machine, create or re-enable local administrator accounts, and then leverage SEImpersonate to escalate to domain compromise; it provides step-by-step proof-of-concept commands, discusses limitations (rotating machine passwords, Remote UAC, requirement for active domain sessions), and offers mitigation context.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
