Credential Guard and Kerberos delegation, (Mon, Dec 2nd)
ID: 3d421ada-b488-5ff2-959c-f1b975c4d0f9
STIX ID: report--3d421ada-b488-5ff2-959c-f1b975c4d0f9
Feed Name: SANS ISC Diary
This report outlines a red-team technique to obtain a user's Kerberos TGT without administrator rights by requesting a service ticket for an unconstrained delegation-enabled SPN (e.g., domain controller services), extracting the TGT from the AP-REQ authenticator using tools like Rubeus or a Cobalt Strike BOF, and then using it for operations such as SOCKS tunneling. It highlights that Windows Credential Guard prevents this by blocking unconstrained delegation (and NTLMv1), and advises organizations to test and enable Credential Guard—now default in Windows 11 22H2 and Windows Server 2025—to disrupt this attack path.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
