daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 64609dbf1ea4dda7623ac7ce75058f05e0c758d5
parent f09ff7596b9b8702c862d720ff1635b48f42a7da
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Sun, 20 Sep 2026 03:39:35 +0100

Expand Recycle Bin cheat sheet: native PS, PowerView, bloodyAD, ldapsearch

Add Windows PowerShell enumeration both WITHOUT PowerView (Get-ADObject
-IncludeDeletedObjects) and WITH PowerView (Get-DomainSearcher + .Tombstone),
alongside the existing bloodyAD and ldapsearch methods.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Diffstat:
Msrc/content/sheets/active-directory/ad-recycle-bin-tombwatcher.md | 36++++++++++++++++++++++++++++++++----
1 file changed, 32 insertions(+), 4 deletions(-)

diff --git a/src/content/sheets/active-directory/ad-recycle-bin-tombwatcher.md b/src/content/sheets/active-directory/ad-recycle-bin-tombwatcher.md @@ -39,13 +39,39 @@ rusthound-ce -c All -d tombwatcher.htb -u 'john@tombwatcher.htb' -p 'password' - ## 2 · Enumerate the AD Recycle Bin -**From Windows / WinRM (native module, on any DC):** pull `objectSid` and `lastKnownParent` so copies can be told apart. +Four ways to read deleted objects — pick whichever matches your foothold. Always pull `objectSid` and `lastKnownParent` so duplicate copies can be told apart (see §3). + +### A · Windows PowerShell — native, no PowerView + +The `ActiveDirectory` module ships on every DC (and any host with RSAT). `-IncludeDeletedObjects` is the switch: + +```powershell +Import-Module ActiveDirectory +Get-ADObject -Filter 'isDeleted -eq $true -and name -ne "Deleted Objects"' ` + -IncludeDeletedObjects -Properties objectSid,lastKnownParent,msDS-LastKnownRDN | + Format-Table msDS-LastKnownRDN,objectSid,lastKnownParent +# target one by its old name: +Get-ADObject -LDAPFilter '(msDS-LastKnownRDN=cert_admin)' -IncludeDeletedObjects -Properties * +``` + +### B · Windows PowerShell — with PowerView + +PowerView has no deleted-object cmdlet, but its searcher exposes the tombstone control. Grab a `Get-DomainSearcher`, flip `.Tombstone`, then `FindAll()`: ```powershell -Get-ADObject -Filter 'isDeleted -eq $true -and name -ne "Deleted Objects"' -IncludeDeletedObjects -Property objectSid,lastKnownParent +Import-Module .\PowerView.ps1 +$ds = Get-DomainSearcher -LDAPFilter '(&(isDeleted=TRUE)(!(name=Deleted Objects)))' +$ds.Tombstone = $true # adds the LDAP "Show Deleted Objects" control +$ds.PropertiesToLoad.AddRange(@('msDS-LastKnownRDN','objectSid','lastKnownParent')) +$ds.FindAll() | ForEach-Object { $_.Properties } ``` -**From Linux (no upload, no shell) with bloodyAD** — `1.2.840.113556.1.4.2064` is the LDAP *Show Deleted Objects* control: +> [!warning] With PowerView, `Get-DomainObject` will NOT show them +> `Get-DomainObject` / `Get-DomainUser` build a searcher **without** the tombstone control, so the bin looks empty and you conclude there's nothing there — exactly the trap that wastes time on a box like this. You must drop to the raw `Get-DomainSearcher` + `.Tombstone = $true` above. And PowerView cannot **restore** an object — for that you still fall back to native `Restore-ADObject` or bloodyAD (§4). Native `Get-ADObject -IncludeDeletedObjects` (A) is one line and does both halves, so prefer it when the module is present. + +### C · Linux — bloodyAD (no upload, no shell) + +`1.2.840.113556.1.4.2064` is the LDAP *Show Deleted Objects* control: ```bash bloodyAD -u john -d tombwatcher.htb -p ':8846f7eaee8fb117ad06bdd830b7586c' \ @@ -53,7 +79,9 @@ bloodyAD -u john -d tombwatcher.htb -p ':8846f7eaee8fb117ad06bdd830b7586c' \ --filter '(isDeleted=TRUE)' --attr name,objectSid,lastKnownParent ``` -**From Linux with ldapsearch** — same control by OID, add `!` to make it critical: +### D · Linux — ldapsearch + +Same control by OID; the leading `!` marks it critical: ```bash ldapsearch -x -H ldap://10.129.232.167 -D 'john@tombwatcher.htb' -w 'password' \