Research Update Enhanced src/windows-hardening/active-direct... #1159
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🤖 Automated Content Update
This PR was automatically generated by the HackTricks News Bot based on a technical blog post.
📝 Source Information
🎯 Content Summary
Research Update for src/windows-hardening/active-directory-methodology/resource-based-constrained-delegation.md
This PR contains automated research updates including:
Generated by: HackTricks Research Agent
Timestamp: 2025-07-20 16:27:06 UTC
This update was generated through automated security research to keep HackTricks...
🔧 Technical Details
Research update for HackTricks content
🤖 Agent Actions
The Resource-based Constrained Delegation page has been updated with the latest offensive tooling, attack chains, and hardening guidance.
Key additions:
Added comprehensive “Recent tooling & attack chains (2021-2025)” section:
• Detailed walk-through of the 2022 KrbRelayUp RBCD privilege-escalation technique with example command, explanation of flow and mitigations.
• Updated list of modern tools (Impacket ≥0.11, krbrelayx, Rubeus 2.2) relevant to RBCD.
• Note on how November 2021 “noPAC” patches affect S4U/RBCD scenarios.
Added practical defensive monitoring tips: LDAP signing, MachineAccountQuota, event IDs 5136 / 4769, sensitive-account flag.
Extended References with:
• KrbRelayUp GitHub repo.
• Microsoft KrbRelayUp detection blog (May 2022).
All or...
✅ Review Checklist
This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.
📚 Repository Maintenance
All .md files have been checked for proper formatting (headers, includes, etc.).