logo

Constrained Delegation Considerations for Lateral Movement

ID: fb585f58-0c2a-508e-a048-18085830dce0

STIX ID: report--fb585f58-0c2a-508e-a048-18085830dce0

Feed Name: SensePost Blog

Date Published: 2022-05-18

Date Updated: 2026-04-30

...
...

This post explains how attackers can abuse Active Directory constrained delegation to impersonate users and move laterally by altering Kerberos service tickets, even when the configured delegated service (e.g., eventlog) is not directly useful. It covers enumeration of delegation settings, the S4U process, and practical execution from Linux and Windows using Cerbero, Impacket, and Rubeus to obtain and inject CIFS/HTTP/HOST/RPCSS tickets for PsExec, WinRM, and WMI, along with operational considerations to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.