Constrained Delegation Considerations for Lateral Movement
ID: fb585f58-0c2a-508e-a048-18085830dce0
STIX ID: report--fb585f58-0c2a-508e-a048-18085830dce0
Feed Name: SensePost Blog
This post explains how attackers can abuse Active Directory constrained delegation to impersonate users and move laterally by altering Kerberos service tickets, even when the configured delegated service (e.g., eventlog) is not directly useful. It covers enumeration of delegation settings, the S4U process, and practical execution from Linux and Windows using Cerbero, Impacket, and Rubeus to obtain and inject CIFS/HTTP/HOST/RPCSS tickets for PsExec, WinRM, and WMI, along with operational considerations to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
