KrbRelayUp

This is essentially a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Enumeration

Tools: cme (crackmapexec)

Attack with Shadow Account

Purpose: Create a shadow account for existing machine account and abuse it to get a TGT for Administrator

Tools: KrbRelayUp.exe, Rubeus.exe, impacket

With Resource Based Constrained Delegation

Purpose: Create a new machine account and abuse it to reset the Administrator's password

Tools: KrbRelay.exe, Sharpmad.exe

Last updated