Active Kerberos Delegation Abuse Response (Unconstrained / RBCD Chain / Privilege Escalation)
When DR-DELEG-1 (coercion active) or a completed RBCD chain, S4U activity, lateral movement, or DA privilege acquisition is confirmed; removes delegation abuse from the root, clears persistence, and bridges to the sibling playbook for the krbtgt procedure if domain-compromise is confirmed.
msDS-AllowedToActOnBehalfOfOtherIdentity attribute. After closing the delegation vector, invalidate all affected service tickets.Prepare
6 steps- Verify Kerberos and AD change auditing
Confirm that EID 4624, 4741, 4742, 4769, 5136 and Sysmon EID 1/3 auditing is enabled on DCs; and that the "DS Access > Audit Directory Service Changes" policy is active on all DCs
- Prepare delegation inventory
A current baseline inventory of unconstrained (`TrustedForDelegation`), constrained (`msDS-AllowedToDelegateTo`), and RBCD (`msDS-AllowedToActOnBehalfOfOtherIdentity`) objects must be available; without it, the Detect step is blind
- Document coercion vector status
Print Spooler service status on DCs and EFSRPC RPC filtering status must have been previously documented; this is a preparation input, not an incident-time action
- Pre-plan krbtgt reset procedure
If domain-compromise is confirmed, a krbtgt double reset is applied with a ≥10-hour waiting window; a change ticket and AD owner + CISO approval are mandatory; this procedure is executed in the sibling "Kerberos Credential Harvesting" PB-B playbook
- RACI and approval chain
Emergency isolation decisions require L2/IR approval; krbtgt reset is initiated only after domain-compromise is confirmed and with AD owner + CISO/change board sign-off