Kerberos Delegation Abuse: Unconstrained, Constrained, and RBCD

The three flavours of Kerberos delegation, what each one hands an attacker, and why resource-based delegation is both the safest and the most abusable.

2026-01-20 · 4 min · 743 words · lcz

Active Directory Certificate Services: ESC1 Through ESC8 in Practice

Why certificate services are the most reliable escalation path in enterprise AD, and the eight misconfigurations worth checking on every engagement.

2024-12-18 · 4 min · 659 words · lcz

NTLM Relay Attacks: Coercion, Poisoning, and Defenses

Why relaying NTLM authentication is still effective in 2022, and what actually stops it.

2022-08-14 · 3 min · 530 words · lcz

BloodHound and SharpHound: Mapping Active Directory Attack Paths

How to collect the right AD data once, then query it as a graph instead of guessing your way to Domain Admin.

2021-07-22 · 3 min · 517 words · lcz

Kerberoasting: From SPN Enumeration to Offline Cracking

Why requesting service tickets for accounts with SPNs is still one of the most reliable ways to escalate from a domain user to plaintext credentials.

2020-12-08 · 3 min · 449 words · lcz