Join our Newsletter — 33% off our NHI Course
Home Glossary Threats, Abuse & Incident Response Bronze Bit Attack
Threats, Abuse & Incident Response

Bronze Bit Attack

← Back to Glossary
By NHI Mgmt Group Updated September 9, 2026 Domain: Threats, Abuse & Incident Response

Bronze Bit is an exploit technique for CVE-2020-17049 that targets Kerberos delegation behavior in Active Directory. It allows an attacker to abuse delegation controls so a compromised identity can impersonate users that should not be delegable, which broadens access and increases lateral movement risk in enterprise environments.

Expanded Definition

Bronze Bit Attack is a technique associated with CVE-2020-17049 that abuses Kerberos delegation behavior in Active Directory. The practical issue is not Kerberos itself, but a delegation control failure that lets a compromised identity act with more privilege than the original account should allow.

In security terms, the attack sits at the boundary between authentication, delegation, and authorization. It is often discussed alongside constrained delegation because the exploit depends on how service-to-service trust is represented and enforced. That makes the term narrower than generic Kerberos abuse and broader than a single malformed request: it is about turning a delegation path into unintended impersonation capability.

Definitions in the field are fairly stable, but usage can vary between writeups that focus on the vulnerability, the exploitation method, or the broader delegation weakness. For practitioners, the important boundary is that Bronze Bit is not a password theft issue by itself; it is a trust-abuse issue that becomes dangerous once an attacker has some foothold in an Active Directory environment.

Examples and Use Cases

  • A compromised service account is used to interact with Kerberos delegation in a way that yields impersonation rights beyond the account’s intended scope.
  • An internal red team validates whether delegated services can be coerced into requesting tickets for users that should not be delegable.
  • A defender reviews Active Directory delegation settings after a privilege escalation alert to determine whether constrained delegation paths are too permissive.
  • An incident responder correlates unusual ticket activity with lateral movement attempts that rely on service trust rather than direct credential capture.

The practical tradeoff is that delegation exists to support real application workflows, so the control goal is rarely to remove it entirely. Instead, teams have to balance functionality against the risk that a trusted service becomes a bridge for impersonation. That balance is especially sensitive in environments where older application patterns still rely on broad delegation exposure.

For readers who want a wider NHI context, NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks helps connect delegation abuse to broader machine-identity governance failures.

Security Implications

Bronze Bit matters because delegation abuse can turn a single compromised identity into a much larger access problem. Once impersonation is possible, the blast radius is no longer limited to the initial account, since the attacker may gain access to user resources, services, or administrative workflows that were never directly exposed.

The recognizable failure mechanism is weak trust enforcement around ticket generation and service delegation. When delegation rules are broader than intended, or when monitoring does not distinguish normal service impersonation from malicious use, the compromise can blend into ordinary enterprise traffic. That makes detection difficult, especially in large Active Directory estates where delegation is already common.

In NHIMG research, 97% of NHIs carry excessive privileges, increasing unauthorized access and broadening the attack surface. That figure is especially relevant here because Bronze Bit-style abuse thrives where trust and privilege are already overextended.

A common practitioner symptom is not an obvious crash or outage, but a quiet expansion of what the compromised identity can do. Teams often notice the issue only after lateral movement, unexpected access patterns, or service accounts reaching downstream resources that should have remained out of scope.

Domain and Governance Relevance

Bronze Bit is a useful reminder that identity governance in Active Directory is not only about user accounts. Delegation settings, service account scope, and ticket behavior all shape whether an identity can safely act on behalf of another identity, which means governance has to cover trust paths as well as direct logon rights.

In NHI and machine-identity environments, the same pattern shows up whenever one non-human principal can impersonate another principal or broker access on its behalf. That makes delegation control part of machine-identity assurance, not a niche Kerberos detail. If service identities are overprivileged or poorly inventoried, delegated access can become an untracked privilege multiplier.

This is why Bronze Bit belongs in NHI governance discussions even though it is rooted in Active Directory. The lesson is broader than a single exploit: organizations need clear ownership of delegated trust, regular review of impersonation paths, and visibility into which identities are allowed to act for others.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1134 — Access Token ManipulationBronze Bit abuses delegation to impersonate another identity and expand access.
T1550 — Use Alternate Authentication MaterialThe attack relies on abusing authentication material and trust to gain access.
Recommendation — Map ticket and impersonation abuse to T1134 and hunt for delegated access misuse. Investigate alternate-ticket abuse paths and tighten controls around trusted authentication material.
CIS Controls v85.3 — Disable Dormant AccountsCompromised delegated identities are high-value accounts that should be reduced and governed.
6.3 — Data ProtectionDelegation abuse often exposes protected systems and data through expanded access.
Recommendation — Reduce the attack surface by removing unused identities that can still be abused in delegation chains. Limit access paths so delegated compromise cannot reach sensitive data beyond intended scope.
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorizationsBronze Bit is fundamentally a failure of authorization scope in delegated access.
Recommendation — Enforce least privilege on delegation relationships and review authorization scope regularly.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org