<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Posts on 4m3rr0r&#39;s Blog</title>
		<link>https://4m3rr0r.me/posts/</link>
		<description>Recent content in Posts on 4m3rr0r&#39;s Blog</description>
		<generator>Hugo</generator>
		<language>en</language>
		
		
		
		
			<lastBuildDate>Sun, 07 Jun 2026 12:00:38 +0600</lastBuildDate>
		
			<atom:link href="https://4m3rr0r.me/posts/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Abusing Constrained Delegation Without Local Admin</title>
				<link>https://4m3rr0r.me/posts/abusing-constrained-delegation-without-local-admin/</link>
				<pubDate>Sun, 07 Jun 2026 12:00:38 +0600</pubDate>
				<guid>https://4m3rr0r.me/posts/abusing-constrained-delegation-without-local-admin/</guid>
				<description>&lt;p&gt;There is a persistent misconception in Active Directory penetration testing to pull off a Constrained Delegation attack, you need to compromise a host, escalate to local administrator, and dump credentials from memory.&lt;/p&gt;&#xA;&lt;p&gt;While dumping LSASS is a standard path it is not a strict requirement. If the target is a user account configured with a weak password, a standard domain user can execute a complete delegation attack and achieve Domain Administrator impersonation entirely over the network, without ever touching a target endpoint&amp;rsquo;s disk or needing elevated privileges.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
