Protected Users: you thought you were safe uh?
ID: 34c3cf4e-58ee-5725-a32f-ec5c3d00ad8d
STIX ID: report--34c3cf4e-58ee-5725-a32f-ec5c3d00ad8d
Feed Name: SensePost Blog
This report demonstrates that the Active Directory built-in RID 500 (Administrator) account remains exempt from key protections of the "Protected Users" group: RC4-based Kerberos authentication and delegation can still be leveraged, enabling OverPass-the-Hash and RBCD delegation abuse when an NT hash or active session is available. The authors provide proof-of-concept tests, exploitation scenarios, and mitigations (restrict protocol encryption via ms-DSSupportedProtocolEncryption, set the account as sensitive and non-delegable, or disable the account), and note Microsoft considers the behavior intended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
