<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Delegations on The Manticore Project</title><link>https://themanticoreproject.com/tags/delegations/</link><description>Recent content in Delegations on The Manticore Project</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Mon, 02 Jun 2025 10:00:00 +0000</lastBuildDate><atom:link href="https://themanticoreproject.com/tags/delegations/index.xml" rel="self" type="application/rss+xml"/><item><title>Active Directory - Auditing and managing Kerberos delegations with Delegations</title><link>https://themanticoreproject.com/blog/kerberos-delegations/</link><pubDate>Mon, 02 Jun 2025 10:00:00 +0000</pubDate><guid>https://themanticoreproject.com/blog/kerberos-delegations/</guid><description>&lt;p>During security assessments of Active Directory environments, one of the first things I look at is Kerberos delegations. Misconfigured delegations are a well-known attack vector: an attacker who compromises a service account with unconstrained delegation can impersonate any user who authenticates to that service. Constrained delegations and resource-based constrained delegations (RBCD) are safer, but they still require careful configuration.&lt;/p>
&lt;p>The problem is that existing tools often only cover one side of the coin: they can find delegations, but not modify them. Or they can set up RBCD for exploitation, but not audit the full picture. I wanted a single tool that could audit, find, add, remove, clear, and monitor all three types of Kerberos delegations from a single binary, on any platform.&lt;/p></description></item></channel></rss>