Initial commit - 611 cybersecurity skills across all subdomains

This commit is contained in:
mukul975
2026-02-25 10:47:44 +01:00
commit 22a7ab1462
1765 changed files with 280648 additions and 0 deletions
@@ -0,0 +1,24 @@
# Standards and References - Constrained Delegation Abuse
## MITRE ATT&CK References
| Technique ID | Name | Tactic |
|-------------|------|--------|
| T1558.003 | Steal or Forge Kerberos Tickets: Kerberoasting | Credential Access |
| T1550.003 | Pass the Ticket | Lateral Movement |
| T1134.001 | Token Impersonation/Theft | Privilege Escalation |
| T1078.002 | Valid Accounts: Domain Accounts | Persistence |
## Key Research
- ired.team: Kerberos Constrained Delegation abuse
- HackTricks: Constrained Delegation methodology
- GuidePoint Security: Delegating Like a Boss
- ManageEngine: Constrained delegation attacks explained
- SpecterOps: Delegation abuse research
## Tools
- Rubeus: https://github.com/GhostPack/Rubeus
- Impacket getST.py: https://github.com/fortra/impacket
- PowerView: https://github.com/PowerShellMafia/PowerSploit
@@ -0,0 +1,22 @@
# Workflows - Constrained Delegation Abuse
## S4U Attack Chain
```
1. Enumerate → findDelegation.py or PowerView
2. Obtain account credentials → password, hash, or TGT
3. S4U2self → Request ticket as target user to compromised service
4. S4U2proxy → Forward ticket to delegated service (CIFS/LDAP/HTTP)
5. Access → Use ticket for privileged access to target service
6. Escalate → DCSync via LDAP or file access via CIFS
```
## Alternate Service Name Workflow
```
1. Delegation configured for: CIFS/DC01.domain.local
2. Request S4U ticket for CIFS as administrator
3. Modify SPN in ticket to LDAP/DC01.domain.local
4. Use modified ticket for DCSync (secretsdump.py -k)
5. Full domain compromise achieved
```