⤷ Title: Abusing S4U2Self for Active Directory Pivoting
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 11 Jun 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Informational #Red Team #Red Team Tools #Active Directory #Constrained Delegation #Hunter Wade #Kerberos #S4U2Self
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 11 Jun 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Informational #Red Team #Red Team Tools #Active Directory #Constrained Delegation #Hunter Wade #Kerberos #S4U2Self
Black Hills Information Security, Inc.
Abusing S4U2Self for Active Directory Pivoting - Black Hills Information Security, Inc.
TL;DR If you only have access to a valid machine hash, you can leverage the Kerberos S4U2Self proxy for local privilege escalation, which allows reopening and expanding potential local-to-domain pivoting paths, such as SEImpersonate!