Group Managed Service Accounts (GMSA)
GMSA Account & Constrained Delegation
Build
Then, in the AD Users & Computers GUI, set msDS-AllowedToDelegateTo attribute of sql_svc to "DNS/dc.vulnlab.local" (or whatever SPN you want to allow constrained delegation to).
In order to read the GMSA password later you have to enable LDAPS (Add Role "Active Directory Certificate Services" and restart).
Exploit
Read GMSA password & use it to exploit the constrained delegation.
Sometimes you will have to sync your local time to either a targets webserver, or just google.
Resources
Last updated