Kerberos Relay
mitm6 + Kerberos DNS Relay + AD CS ESC8
Tools
KrbRelay
KrbRelayUp
RELAY
Relay authentication to LDAP(S) with automatic machine creation and configure RBCD:
Perform RBCD with UPNs:
RBCD with UPNsSPAWN
Execute a command as NT AUTHORITY\SYSTEM via RBCD abuse:
As @ShitSecure mentioned, executing the binary as a .NET Reflective Assembly from PowerShell will fail because the PowerShell process will have already initialized the security parameters for COM itself after having been launched, so CoInitializeSecurity will not contain those new parameters attempted to set by KrbRelay(Up).
RemoteKrbRelay
KrbRelay-SMBServer
Stop/start services with Cmd:
Stop/start services with PowerShell and attack:
Last updated