TL;DR If you only have access to a valid machine hash, you can leverage the Kerberos S4U2Self proxy for local privilege escalation, which allows reopening and expanding potential local-to-domain pivoting paths, such as SEImpersonate!
The post Abusing S4U2Self for Active Directory Pivoting appeared first on Black Hills Information Security, Inc..