CRTP Report Phase1 Phase2 English
CRTP Report Phase1 Phase2 English
Command: Invoke-Kerberoast
📷 Screenshot: Extracted TGS hash for offline cracking.
➤ Set msds-AllowedToActOnBehalfOfOtherIdentity
klist
Conclusion
Through detailed enumeration and exploitation of misconfigured delegation rights, the
exam objective was achieved:
- Initial enumeration using PowerView helped identify SPNs, trust relationships, and
delegation settings.
- Exploitation of Resource-Based Constrained Delegation allowed impersonation of a
Domain Admin.
- Full control over the target server 'mgmtsrv.tech.finance.corp' was obtained.