Unconstrained Delegation
Identify
Linux - remote
Windows - localADSearch.exe --search "(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))" --attributes samaccountname,dnshostname
Domain Controllers are always permitted for unconstrained delegation.
Exploit
Force DC to auth to our box and steal TGT
Monitor for tickets with Rubeus
OR: Run https://github.com/cube0x0/SharpSystemTriggers to coerce authentication
Where: - DC01 is the "target". - WEB is the "listener".Rebeus should capture a ticket