Kerberos Relay

mitm6 + Kerberos DNS Relay + AD CS ESC8

Tools

KrbRelay

KrbRelayUp

RELAY

Relay authentication to LDAP(S) with automatic machine creation and configure RBCD:

Perform RBCD with UPNs:

RBCD with UPNs

SPAWN

Execute a command as NT AUTHORITY\SYSTEM via RBCD abuse:

RemoteKrbRelay

KrbRelay-SMBServer

Stop/start services with Cmd:

Stop/start services with PowerShell and attack:

Last updated