logo

DirectAccess and Kerberos Resource-based Constrained Delegation

ID: 578117af-438f-5eb3-b87b-c75361e82840

STIX ID: report--578117af-438f-5eb3-b87b-c75361e82840

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2020-08-19

Date Updated: 2026-04-30

...
...

This report describes a penetration test case study where a low-privileged domain user with GenericAll rights over a target computer exploited resource-based constrained delegation (RBCD) by creating a machine account, modifying msDS-AllowedToActOnBehalfOfOtherIdentity, and using Rubeus to obtain impersonation Kerberos tickets; the attack was impeded by IPv6/DirectAccess environment issues until IPv6 support was added to Rubeus, and though full exploitation was not achieved the write-up highlights the high-impact risk of AD ACL misconfigurations and provides mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.