Kerberos Delegation
Service Ticket Cheatsheet
Service
Description
Ticket(s)
Unconstrained Delegation
Find Unconstrained Delegation
ldapsearch (&(samAccountType=805306369)(userAccountControl:1.2.840.113556.1.4.803:=524288)) --attributes samaccountnameExploit
Constrained Delegation
Find Constrained Delegation
Check Protocol Transition
Exploit (Protocol Transition Enabled)
Exploit (Protocol Transition NOT Enabled)
Service Name Substitution
Find Delegation to Weak Service
Exploit (Substitute CIFS for TIME)
S4U2self Computer Takeover
Trigger Authentication (SpoolSample/PetitPotam)
Use Captured Computer TGT
Resource-Based Constrained Delegation (RBCD)
Requirements
Find Write Access (PowerView via SOCKS)
Identify SID Owner
Account with SPN Options
Option
Description
Configure RBCD
Exploit
Cleanup
Quick Reference
Delegation Type
Attribute
Attack Summary
Last updated