logo

Chaining multiple techniques and tools for domain takeover using RBCD

ID: d9548281-06b8-52d2-aa1b-943b4a1e5a81

STIX ID: report--d9548281-06b8-52d2-aa1b-943b4a1e5a81

Feed Name: SensePost Blog

Date Published: 2020-03-09

Date Updated: 2026-04-29

...
...

This post demonstrates a simulated Active Directory privilege escalation by combining targeted Kerberoasting with Resource-Based Constrained Delegation: compromise a user to control an SPN, take ownership of the DC to gain GenericAll, set msDS-AllowedToActOnBehalfOfOtherIdentity, and leverage Rubeus S4U to impersonate a Domain Admin and execute DCSync, using tools like BloodHound, PowerView, Rubeus, Impacket, and Mimikatz, with guidance on ticket handling and post-attack cleanup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.