In , the decision moves to the resource: the target computer defines in the msDS-AllowedToActOnBehalfOfOtherIdentity attribute who is allowed to impersonate it. The administrative advantage: Admin permissions are not needed to configure delegation — control over the target object is enough.
שלב 1: ניצול MachineAccountQuota כדי ליצור חשבון מחשב EVIL-PC$ בשליטת התוקף. שלב 2: עם הרשאת GenericWrite על TARGET-PC כותבים את msDS-AllowedToActOnBehalfOfOtherIdentity כך ש־EVIL-PC$ רשאי להתחזות. שלב 3: בקשת S4U מפיקה כרטיס בתור Administrator וגישה מלאה ל־TARGET-PC. הגנה: MachineAccountQuota=0, ניטור אירוע 5136, ו־Protected Users. BloodHound מסייע לאתר הרשאות כתיבה על אובייקטי מחשב.
Why attackers love RBCD
- By default, every domain user can join up to 10 computers () and create a computer account under their control.
- If the attacker has write permission on the target computer object — they set on it in favor of the account they created.
- They then request an S4U ticket and impersonate the local Administrator on that computer.
Defense
- Lower to 0 and delegate computer joining to a dedicated team.
- Check write permissions (GenericWrite / WriteDACL) on computer objects — helps map this.
- Monitor changes to the msDS-AllowedToActOnBehalfOfOtherIdentity attribute (Event ID 5136).
- Place sensitive accounts in Protected Users and mark them as unable to be delegated.