KrbRelayUp

This is essentially a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Enumeration

Tools: cme (crackmapexec) arrow-up-right

Attack with Shadow Account

Purpose: Create a shadow account for existing machine account and abuse it to get a TGT for Administrator

Tools: KrbRelayUp.exearrow-up-right, Rubeus.exearrow-up-right, impacketarrow-up-right

With Resource Based Constrained Delegation

Purpose: Create a new machine account and abuse it to reset the Administrator's password

Tools: KrbRelay.exearrow-up-right, Sharpmad.exe arrow-up-right

Last updated