logo

Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation

ID: f72c3059-ac9f-5fae-9bea-d22a46eb3e33

STIX ID: report--f72c3059-ac9f-5fae-9bea-d22a46eb3e33

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2025-11-26

Date Updated: 2026-04-27

Author: BHIS

...
...

This post describes three practical methods to abuse resource-based constrained delegation (RBCD) in Active Directory—(1) leveraging CVE-2019-1040 (Drop the MIC) to relay/authenticate and configure RBCD, (2) using GenericWrite DACL permissions to add machine accounts via Machine Account Quota and configure RBCD, and (3) trusting a user SPN via GenericWrite—providing commands and tool examples (impacket, ntlmrelayx, PetitPotam) that culminate in obtaining service tickets and performing DCSync for domain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.