← All Lessons
Premium
TechniqueActive Directory
Printer Bug Coercion
The printer bug abuses a documented print-spooler feature to force a target, often a domain controller, to authenticate to a host the attacker chooses, as its own machine account. This lesson explains why the coercion works, how it chains into unconstrained delegation to capture a domain controller's ticket, what the attacker gains, and how to explain the risk in interviews, reports, and stakeholder conversations.
Sign in or upgrade to unlock the full premium library.
What you'll learn
- MS-RPRN (Print System Remote Protocol)
- RpcRemoteFindFirstPrinterChangeNotification
- Authentication coercion
- Machine account authentication
- Forwardable TGT capture
What premium includes
- All 78 lessons: AD techniques, professional skills, each with interview answers and study kits
- Complete study kit for every lesson: quizzes, flashcards, and briefs
- Every learning track with full structured progression
- All 12 attack paths: full compromise walkthroughs for interviews and reports
- New lessons and attack paths added regularly