SpecterOps / BloodHound

Six Degrees of Domain Admin
https://bloodhoundenterprise.io/
Apache License 2.0
1.14k stars 113 forks source link

CoerceToTGT edge redo #957

Open elikmiller opened 3 days ago

elikmiller commented 3 days ago

Description

A new traversable edge named CoerceToTGT from computers and users configured with unconstrained delegation to the domain.

Motivation and Context

When a victim user or computer authenticate to a Kerberos service of a principal with unconstrained delegation, a TGT (reusable credentials) of the target is sent to the principal. An attacker with such a principal can use one of the many coercion techniques to get a privileged computer (e.g. DC) to authenticate to a compromised host and thereby compromise the environment.

This PR addresses: BP-982

How Has This Been Tested?

Added an ingest test.

Uploaded this data set which results in the edges of the screenshot: CoerceToTGT_BloodHound.zip

Use this Cypher query to get the edges showing: MATCH p=()-[r:CoerceToTGT]->() RETURN p

Screenshots (optional):

image

Types of changes

Checklist: