<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>RBCD on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/rbcd/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/rbcd/index.xml" rel="self" type="application/rss+xml"/><item><title>bloodyAD</title><link>https://wearethebug.dev/posts/bloodyad/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/bloodyad/</guid><description>Active Directory privilege escalation swiss-army knife. Quick reference for common bloodyAD operations.</description></item><item><title>NetExec Advanced</title><link>https://wearethebug.dev/posts/netexec-advanced/</link><pubDate>Fri, 28 Aug 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/netexec-advanced/</guid><description>Follow-up to the NetExec cheatsheet: deeper Active Directory abuse techniques, delegation attacks, and operational tooling for experienced operators.</description></item><item><title>HTB: Heron</title><link>https://wearethebug.dev/posts/htb-heron/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/htb-heron/</guid><description>Heron is a small Active Directory scenario that involves typical vulnerabilities found in real word company environments. It's designed for penetration testers and red teamers in search of a quick and challenging lab.</description></item><item><title>ERTLabs: Calipendula</title><link>https://wearethebug.dev/posts/ertlabs-calipendula/</link><pubDate>Sat, 08 Nov 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-calipendula/</guid><description>Calipendula is a hybrid GCP and Active Directory breach scenario, pushing you through cloud IAM enumeration, service account chaining, RBCD relay attacks, multi-hop tunnelling in a segmented network.</description></item><item><title>VULNLAB: Phantom</title><link>https://wearethebug.dev/posts/vl-phantom/</link><pubDate>Wed, 26 Feb 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-phantom/</guid><description>Phantom is a medium-difficulty Windows AD exploitation machine. The foothold involves discovering a publicly accessible SMB share, cracking a VeraCrypt container, and abusing Resource-Based Constrained Delegation (RBCD) to escalate privileges.</description></item><item><title>VULNLAB: Ifrit</title><link>https://wearethebug.dev/posts/vl-ifrit/</link><pubDate>Sun, 15 Sep 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-ifrit/</guid><description>Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with foundational AD and pentesting knowledge to hone covert red teaming skills. Players aim for Domain Admin while evading real-time detections, practicing AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, and relay attacks across multiple forests.</description></item><item><title>VULNLAB: Heron</title><link>https://wearethebug.dev/posts/vl-heron/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-heron/</guid><description>Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting with an enumeration of the internal website for domain users and performing AS-REP roasting, decrypting GPP password from the sysvol share, leading to smb share having write access to web.config, gaining a shell by using AspNetCoreModule for executing powershell commands which lead to finding linux admin’s credentials, reusing the same password that will lead to another user which has WriteAccountRestrictions on dc that leads to resource based delegation</description></item><item><title>VULNLAB: Push</title><link>https://wearethebug.dev/posts/vl-push/</link><pubDate>Fri, 22 Sep 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-push/</guid><description>Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item><item><title>VULNLAB: Bruno</title><link>https://wearethebug.dev/posts/vl-bruno/</link><pubDate>Sat, 02 Jul 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bruno/</guid><description>Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.</description></item></channel></rss>