LogoLogo
⌘Ctrlk
NetExec GithubNetexec Lab
LogoLogo
  • Welcome
  • News
  • Logo & Banner
  • NetExec Lab
    • Installation
    • Selecting & Using a Protocol
    • Target Formats
    • Using Credentials
    • Using Kerberos
    • Using Certificates
    • Using Modules
    • DNS options
    • Database General Usage
    • BloodHound Integration
    • Audit Mode
    • Ignore OpSec Warnings
    • Logging
    • Generate hosts file
    • Generate krb5.conf file
    • Generate TGT
    • Scan for Vulnerabilities
    • Enumeration
    • Password Spraying
    • Authentication
    • Command Execution
    • Spidering Shares
    • Get and Put Files
    • Obtaining Credentials
    • Defeating LAPS
    • Checking for Spooler & WebDav
    • Steal Microsoft Teams Cookies
    • Impersonate logged-on Users
    • Change User Password
    • 🆕Modify Group
    • Dump User Local Security Questions
    • Authentication
    • Enumerate Domain Users
    • Enumerate Domain Groups
    • 🆕Query LDAP
    • ASREPRoast
    • Find Domain SID
    • Kerberoasting
    • 🆕Find Misconfigured Delegation
    • Unconstrained Delegation
    • Admin Count
    • Machine Account Quota
    • Get User Descriptions
    • Dump gMSA
    • Pre2k Computer Account Abuse
    • Exploit ESC8 (ADCS)
    • Extract Subnet
    • Check LDAP Signing
    • Read DACL Rights
    • Extract gMSA Secrets
    • Bloodhound Ingestor
    • 🆕List DC IP / Enum Trust
    • 🆕Abuse Domain Trust: Raisechild
    • Enumerate Domain Trusts
    • 🆕Enumerate SCCM
    • 🆕Enumerate Entra ID
    • 🆕Dump PSO
    • 🆕Enumerate scriptPath
    • 🆕Enumerate Unsecure DNS Zones
    • Password Spraying
    • Authentication
    • Command Execution
    • Defeating LAPS
    • Obtaining Credentials
    • Enumeration
    • Password Spraying
    • Authentication
    • MSSQL PrivEsc
    • MSSQL Command Execution
    • MSSQL Upload & Download
    • Execute via xp_cmdshell
    • 🆕Enumerate Users by Bruteforcing RID
    • MSSQL Linked Servers
    • Password Spraying
    • Authentication
    • Command Execution
    • Get and Put Files
    • Authentication
    • Password Spraying
    • File Listing
    • File Upload & Download
    • Password Spraying
    • Screenshot (connected)
    • Screenshot Without NLA (not connected)
    • 🆕Command Execution
    • Password Spraying
    • Authentication
    • Command Execution
    • Enumeration
    • Download and Upload Files
    • 🆕Chmod
    • 🆕Escape to root file system
    • Authentication
    • Screenshot
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. LDAP protocol

Unconstrained Delegation

NetExec allows you to retrieve the list of all computers and users with the flag TRUSTED_FOR_DELEGATION

nxc ldap 192.168.0.104 -u harry -p pass --trusted-for-delegation

Alternatives Tools

LogoGitHub - ropnop/windapsearch: Python script to enumerate users, groups and computers from a Windows domain through LDAP queriesGitHub
LogoPowerSploit/Recon/PowerView.ps1 at dev · PowerShellMafia/PowerSploitGitHub

Resources:

https://troopers.de/downloads/troopers19/TROOPERS19_AD_Fun_With_LDAP.pdftroopers.de
LogoUnconstrained Delegation - Risqueshackndo
“Relaying” Kerberos - Having fun with unconstrained delegationdirkjanm.io
LogoHunting in Active Directory: Unconstrained Delegation & Forests TrustsSpecterOps
PreviousFind Misconfigured Delegation
NextAdmin Count

Last updated 1 year ago

Was this helpful?

  • Alternatives Tools
  • Resources:

Was this helpful?