Skip to content
← LibraryTechnique entry
AD-RBCDLateral Movement

Resource-Based Constrained Delegation (RBCD) Abuse

Write msDS-AllowedToActOnBehalfOfOtherIdentity on a target computer to S4U2self/S4U2proxy into it.

§ Where this technique fits

AD-RBCD is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 3.7 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Pass the Ticket
    T1550.003 · Lateral Movement
    seen 2×
  2. 02
    SMB/Windows Admin Shares
    T1021.002 · Lateral Movement
    seen 1×