CTD-000139

Constrained delegation with protocol transition to the krbtgt account

Critical
Active Directory
Defense Evasion Lateral Movement Privilege Escalation
v15

Signature Identity

CTD-000139
Threat ID
15
Version
IOE
Indicator Type

Threat Description

A threat actor can gain control of the trusted krbtgt account for the constrained delegation with protocol transition and exploit this access to escalate privileges within the network. The attacker compromises the krbtgt account that has been configured for constrained delegation, allowing it to impersonate users and access specified services.

MITRE ATT&CK: Attack Tactics

Defense Evasion Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

Credential Hardening

Remediation

  1. Review objects in findings. This configuration is usually associated with an application.
  2. Determine the application using this configuration and understand the requirements. If there is no need for an application, this could be an artifact from a previous compromise and should be removed immediately. If the application requires this configuration, you must ensure it is properly configured.
  3. Open Active Directory Users and Computers.
  4. Locate the krbtgt account.
  5. Right-click on the account.
  6. Select Properties.
  7. Navigate to the Delegation tab.
  8. Choose Do not trust this computer for delegation.
  9. Click Apply to save the changes.

Frequently Asked Questions

What does Constrained delegation with protocol transition to the krbtgt account mean?

When a service is configured for constrained delegation with protocol transition to the krbtgt account, it allows the krbtgt account to authenticate as another user. This configuration enables Kerberos authentication mechanisms to be used by an attacker if the krbtgt account is compromised.

Constrained delegation with protocol transition to the krbtgt account is rated critical because it enables a threat actor to obtain the Kerberos ticket-granting ticket (TGT) for the compromised krbtgt account, allowing them to authenticate as any user and access network resources. This is due to the reliance on the integrity of the krbtgt account in the Kerberos authentication mechanism.

An attacker can use the compromised krbtgt account to obtain a Kerberos ticket-granting ticket (TGT) for another user, allowing them to authenticate as that user and access network resources. This is achieved through the Kerberos authentication mechanism, which relies on the integrity of the krbtgt account.

Cayosoft Guardian continuously monitors Active Directory for services configured for constrained delegation with protocol transition to the krbtgt account, detecting any issues that may indicate a compromised account. When an issue is detected, Guardian flags it as a security concern so administrators can take action.

Cayosoft Guardian helps reduce the risk by providing visibility into services configured for constrained delegation with protocol transition to the krbtgt account, allowing administrators to review and correct the configuration. This limits an attacker's ability to obtain a Kerberos ticket-granting ticket (TGT) for the compromised account.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Kerberos
Attack Tactics
Defense Evasion Lateral Movement Privilege Escalation
Defend Tactics
Credential Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical