Kerberos Delegation Abuse: Unconstrained, Constrained, and RBCD
The three flavours of Kerberos delegation, what each one hands an attacker, and why resource-based delegation is both the safest and the most abusable.
The three flavours of Kerberos delegation, what each one hands an attacker, and why resource-based delegation is both the safest and the most abusable.
Why certificate services are the most reliable escalation path in enterprise AD, and the eight misconfigurations worth checking on every engagement.
Mapping a Microsoft cloud tenant from a single set of valid credentials, and reading the result as an attack graph.
Why relaying NTLM authentication is still effective in 2022, and what actually stops it.
How to collect the right AD data once, then query it as a graph instead of guessing your way to Domain Admin.