commit cc3cf0e9bbce671fc33068583515b514ac8280e4 parent 6332a6d352cdf9f19033e04c0409c2db0c8c02a8 Author: $: DAΞMON <zer0sec.xp@icloud.com> Date: Mon, 10 Aug 2026 03:17:49 +0100 🔧 Update [main] | 10 Aug 2026 03:17:49 BST 📊 Stats: +371 / -37 across 138 file(s) 📁 Breakdown: ➕1 ✏️136 🗑️1 🔀0 👤 Author: $: DAΞMON 📝 Changes: ✏️ Modified .gitignore ✏️ Modified package.json ✏️ Modified scripts/port-vault.py ➕ Added scripts/stamp-subcategory.py ✏️ Modified src/components/SearchModal.astro ✏️ Modified src/content.config.ts ✏️ Modified src/content/sheets/active-directory/active-directory-attacks.md ✏️ Modified src/content/sheets/active-directory/active-directory-cheat-sheet.md ✏️ Modified src/content/sheets/active-directory/ad-pentest-tools.md ✏️ Modified src/content/sheets/active-directory/adcs-attack-methodology.md ✏️ Modified src/content/sheets/active-directory/attack-1-password-spraying.md ✏️ Modified src/content/sheets/active-directory/attack-10-credential-hunting-in-shares-gpp-passwords.md ✏️ Modified src/content/sheets/active-directory/attack-11-golden-ticket-attack.md ✏️ Modified src/content/sheets/active-directory/attack-12-silver-ticket-attack.md ✏️ Modified src/content/sheets/active-directory/attack-13-diamond-ticket-attack.md ✏️ Modified src/content/sheets/active-directory/attack-14-sapphire-ticket-attack.md ✏️ Modified src/content/sheets/active-directory/attack-15-unconstrained-delegation-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-16-constrained-delegation-abuse-s4u2proxy.md ✏️ Modified src/content/sheets/active-directory/attack-17-resource-based-constrained-delegation-rbcd.md ✏️ Modified src/content/sheets/active-directory/attack-18-bronze-bit-attack-cve-2020-17049.md ✏️ Modified src/content/sheets/active-directory/attack-19-genericall-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-2-kerberoasting.md ✏️ Modified src/content/sheets/active-directory/attack-20-genericwrite-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-21-writedacl-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-22-writeowner-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-23-forcechangepassword-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-24-allextendedrights-dcsync-ace-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-25-shadow-credentials-attack-msds-keycredentiallink.md ✏️ Modified src/content/sheets/active-directory/attack-26-adminsdholder-persistence-via-acl.md ✏️ Modified src/content/sheets/active-directory/attack-27-esc1-san-specification-in-template.md ✏️ Modified src/content/sheets/active-directory/attack-28-esc2-any-purpose-eku-no-eku.md ✏️ Modified src/content/sheets/active-directory/attack-29-esc3-certificate-request-agent.md ✏️ Modified src/content/sheets/active-directory/attack-3-as-rep-roasting.md ✏️ Modified src/content/sheets/active-directory/attack-30-esc4-template-write-permissions.md ✏️ Modified src/content/sheets/active-directory/attack-31-esc6-editf-attributesubjectaltname2-flag.md ✏️ Modified src/content/sheets/active-directory/attack-32-esc7-vulnerable-ca-officer-permissions.md ✏️ Modified src/content/sheets/active-directory/attack-33-esc8-ntlm-relay-to-adcs-http-endpoint.md ✏️ Modified src/content/sheets/active-directory/attack-34-esc11-ntlm-relay-to-adcs-rpc.md ✏️ Modified src/content/sheets/active-directory/attack-35-golden-certificate-attack.md ✏️ Modified src/content/sheets/active-directory/attack-36-certifried-cve-2022-26923.md ✏️ Modified src/content/sheets/active-directory/attack-37-dcsync-attack.md ✏️ Modified src/content/sheets/active-directory/attack-38-dcshadow-attack.md ✏️ Modified src/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md ✏️ Modified src/content/sheets/active-directory/attack-4-pass-the-hash-pth.md ✏️ Modified src/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md ✏️ Modified src/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md ✏️ Modified src/content/sheets/active-directory/attack-42-printerbug-spoolsample.md ✏️ Modified src/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md ✏️ Modified src/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md ✏️ Modified src/content/sheets/active-directory/attack-45-token-impersonation-seimpersonateprivilege.md ✏️ Modified src/content/sheets/active-directory/attack-46-dnsadmins-dll-injection.md ✏️ Modified src/content/sheets/active-directory/attack-47-machineaccountquota-maq-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-48-gpp-password-decryption.md ✏️ Modified src/content/sheets/active-directory/attack-49-abusing-backup-operators-group.md ✏️ Modified src/content/sheets/active-directory/attack-5-pass-the-ticket-ptt.md ✏️ Modified src/content/sheets/active-directory/attack-50-abusing-account-operators-group.md ✏️ Modified src/content/sheets/active-directory/attack-51-abusing-server-operators-group.md ✏️ Modified src/content/sheets/active-directory/attack-52-abusing-print-operators-group.md ✏️ Modified src/content/sheets/active-directory/attack-53-exchange-windows-permissions-writedacl-to-dcsync.md ✏️ Modified src/content/sheets/active-directory/attack-54-psexec-remote-execution-via-smb.md ✏️ Modified src/content/sheets/active-directory/attack-55-winrm-evil-winrm-lateral-movement.md ✏️ Modified src/content/sheets/active-directory/attack-56-rdp-lateral-movement-and-hijacking.md ✏️ Modified src/content/sheets/active-directory/attack-57-dcom-lateral-movement.md ✏️ Modified src/content/sheets/active-directory/attack-58-wmi-lateral-movement.md ✏️ Modified src/content/sheets/active-directory/attack-59-scm-service-manager-lateral-movement.md ✏️ Modified src/content/sheets/active-directory/attack-6-overpass-the-hash-pass-the-key.md ✏️ Modified src/content/sheets/active-directory/attack-60-token-stealing-and-impersonation.md ✏️ Modified src/content/sheets/active-directory/attack-61-skeleton-key-attack.md ✏️ Modified src/content/sheets/active-directory/attack-62-dsrm-backdoor-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-63-sid-history-injection.md ✏️ Modified src/content/sheets/active-directory/attack-64-golden-ticket-persistence.md ✏️ Modified src/content/sheets/active-directory/attack-65-acl-backdooring-persistence-via-dcsync-ace.md ✏️ Modified src/content/sheets/active-directory/attack-66-malicious-gpo-creation.md ✏️ Modified src/content/sheets/active-directory/attack-67-adcs-certificate-based-persistence.md ✏️ Modified src/content/sheets/active-directory/attack-68-cross-domain-trust-abuse-sid-history.md ✏️ Modified src/content/sheets/active-directory/attack-69-forest-trust-abuse-cross-forest-ticket-forging.md ✏️ Modified src/content/sheets/active-directory/attack-7-ntlm-relay-attacks.md ✏️ Modified src/content/sheets/active-directory/attack-70-adcs-cross-domain-enrollment.md ✏️ Modified src/content/sheets/active-directory/attack-71-pam-trust-abuse-bastion-forest.md ✏️ Modified src/content/sheets/active-directory/attack-72-laps-password-extraction.md ✏️ Modified src/content/sheets/active-directory/attack-73-gmsa-password-extraction.md ✏️ Modified src/content/sheets/active-directory/attack-74-azure-ad-connect-credential-extraction.md ✏️ Modified src/content/sheets/active-directory/attack-75-sccm-mecm-exploitation.md ✏️ Modified src/content/sheets/active-directory/attack-76-mssql-server-and-linked-server-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-77-dfscoerce-ms-dfsnm-coercion.md ✏️ Modified src/content/sheets/active-directory/attack-78-ad-recycle-bin-object-abuse.md ✏️ Modified src/content/sheets/active-directory/attack-8-llmnr-nbt-ns-mdns-poisoning.md ✏️ Modified src/content/sheets/active-directory/attack-9-mitm6-ipv6-dns-spoofing-dhcpv6-takeover.md 🗑️ Deleted src/content/sheets/active-directory/attack.md ✏️ Modified src/content/sheets/active-directory/bloodhound-ce-python.md ✏️ Modified src/content/sheets/active-directory/bloodhound-python.md ✏️ Modified src/content/sheets/active-directory/bloodhound.md ✏️ Modified src/content/sheets/active-directory/bloodyad.md ✏️ Modified src/content/sheets/active-directory/certificate-persistence-certifried-cve-2022-26923.md ✏️ Modified src/content/sheets/active-directory/certipy-ad.md ✏️ Modified src/content/sheets/active-directory/certipy.md ✏️ Modified src/content/sheets/active-directory/dpersist2-rogue-ca-certificate-ntauth-injection.md ✏️ Modified src/content/sheets/active-directory/dpersist3-malicious-misconfiguration-acl-backdoor.md ✏️ Modified src/content/sheets/active-directory/esc1-san-specification-in-template.md ✏️ Modified src/content/sheets/active-directory/esc10-weak-certificate-mapping.md ✏️ Modified src/content/sheets/active-directory/esc11-ntlm-relay-to-adcs-rpc-icpr.md ✏️ Modified src/content/sheets/active-directory/esc12-shell-access-to-ca-with-yubihsm.md ✏️ Modified src/content/sheets/active-directory/esc13-issuance-policy-oid-group-link.md ✏️ Modified src/content/sheets/active-directory/esc14-weak-explicit-certificate-mapping.md ✏️ Modified src/content/sheets/active-directory/esc15-ekuwu-cve-2024-49019.md ✏️ Modified src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md ✏️ Modified src/content/sheets/active-directory/esc17-adcs-certificate-spoofing-to-attack-https-enabled-wsus-clients.md ✏️ Modified src/content/sheets/active-directory/esc2-any-purpose-eku-no-eku-the-swiss-certificate.md ✏️ Modified src/content/sheets/active-directory/esc3-misconfigured-enrollment-agent-templates.md ✏️ Modified src/content/sheets/active-directory/esc4-vulnerable-certificate-template-access-control.md ✏️ Modified src/content/sheets/active-directory/esc5-vulnerable-pki-object-access-control.md ✏️ Modified src/content/sheets/active-directory/esc6-editf-attributesubjectaltname2-flag.md ✏️ Modified src/content/sheets/active-directory/esc7-vulnerable-ca-access-control-manageca-managecertificates.md ✏️ Modified src/content/sheets/active-directory/esc8-ntlm-relay-to-adcs-http-web-enrollment.md ✏️ Modified src/content/sheets/active-directory/esc9-no-security-extension-template-level.md ✏️ Modified src/content/sheets/active-directory/faketime.md ✏️ Modified src/content/sheets/active-directory/golden-certificate-attack-dpersist1.md ✏️ Modified src/content/sheets/active-directory/impacket.md ✏️ Modified src/content/sheets/active-directory/kerberoasting-local-on-host.md ✏️ Modified src/content/sheets/active-directory/kerberoasting.md ✏️ Modified src/content/sheets/active-directory/kerbrute.md ✏️ Modified src/content/sheets/active-directory/ldap-enumeration.md ✏️ Modified src/content/sheets/active-directory/ldap-search.md ✏️ Modified src/content/sheets/active-directory/ldapdomaindump.md ✏️ Modified src/content/sheets/active-directory/mimikatz.md ✏️ Modified src/content/sheets/active-directory/netexec.md ✏️ Modified src/content/sheets/active-directory/persist1-active-user-credential-theft-via-certificates.md ✏️ Modified src/content/sheets/active-directory/persist2-machine-account-persistence-via-certificates.md ✏️ Modified src/content/sheets/active-directory/persist3-account-persistence-via-certificate-renewal.md ✏️ Modified src/content/sheets/active-directory/rubeus.md ✏️ Modified src/content/sheets/active-directory/shadow-credentials-msds-keycredentiallink-abuse.md ✏️ Modified src/content/sheets/active-directory/sharphound.md ✏️ Modified src/content/sheets/active-directory/theft1-exporting-certificates-and-keys.md ✏️ Modified src/content/sheets/active-directory/theft2-user-certificate-theft-via-dpapi.md ✏️ Modified src/content/sheets/active-directory/theft3-machine-certificate-theft-via-dpapi.md ✏️ Modified src/content/sheets/active-directory/theft4-finding-certificate-files.md ✏️ Modified src/content/sheets/active-directory/theft5-ntlm-theft-via-pkinit-unpac-the-hash.md ✏️ Modified src/pages/[category]/index.astro 📈 Line changes per file: • .gitignore +2 -0 • package.json +2 -1 • scripts/port-vault.py +5 -2 • scripts/stamp-subcategory.py +96 -0 • src/components/SearchModal.astro +19 -2 • src/content.config.ts +4 -0 • src/content/sheets/active-directory/active-directory-attacks.md +1 -0 • src/content/sheets/active-directory/active-directory-cheat-sheet.md +1 -0 • src/content/sheets/active-directory/ad-pentest-tools.md +1 -0 • src/content/sheets/active-directory/adcs-attack-methodology.md +1 -0 • src/content/sheets/active-directory/attack-1-password-spraying.md +1 -0 • src/content/sheets/active-directory/attack-10-credential-hunting-in-shares-gpp-passwords.md +1 -0 • src/content/sheets/active-directory/attack-11-golden-ticket-attack.md +1 -0 • src/content/sheets/active-directory/attack-12-silver-ticket-attack.md +1 -0 • src/content/sheets/active-directory/attack-13-diamond-ticket-attack.md +1 -0 • src/content/sheets/active-directory/attack-14-sapphire-ticket-attack.md +1 -0 • src/content/sheets/active-directory/attack-15-unconstrained-delegation-abuse.md +1 -0 • src/content/sheets/active-directory/attack-16-constrained-delegation-abuse-s4u2proxy.md +1 -0 • src/content/sheets/active-directory/attack-17-resource-based-constrained-delegation-rbcd.md +1 -0 • src/content/sheets/active-directory/attack-18-bronze-bit-attack-cve-2020-17049.md +1 -0 • src/content/sheets/active-directory/attack-19-genericall-abuse.md +1 -0 • src/content/sheets/active-directory/attack-2-kerberoasting.md +1 -0 • src/content/sheets/active-directory/attack-20-genericwrite-abuse.md +1 -0 • src/content/sheets/active-directory/attack-21-writedacl-abuse.md +1 -0 • src/content/sheets/active-directory/attack-22-writeowner-abuse.md +1 -0 • src/content/sheets/active-directory/attack-23-forcechangepassword-abuse.md +1 -0 • src/content/sheets/active-directory/attack-24-allextendedrights-dcsync-ace-abuse.md +1 -0 • src/content/sheets/active-directory/attack-25-shadow-credentials-attack-msds-keycredentiallink.md +1 -0 • src/content/sheets/active-directory/attack-26-adminsdholder-persistence-via-acl.md +1 -0 • src/content/sheets/active-directory/attack-27-esc1-san-specification-in-template.md +1 -0 • src/content/sheets/active-directory/attack-28-esc2-any-purpose-eku-no-eku.md +1 -0 • src/content/sheets/active-directory/attack-29-esc3-certificate-request-agent.md +1 -0 • src/content/sheets/active-directory/attack-3-as-rep-roasting.md +1 -0 • src/content/sheets/active-directory/attack-30-esc4-template-write-permissions.md +1 -0 • src/content/sheets/active-directory/attack-31-esc6-editf-attributesubjectaltname2-flag.md +1 -0 • src/content/sheets/active-directory/attack-32-esc7-vulnerable-ca-officer-permissions.md +1 -0 • src/content/sheets/active-directory/attack-33-esc8-ntlm-relay-to-adcs-http-endpoint.md +1 -0 • src/content/sheets/active-directory/attack-34-esc11-ntlm-relay-to-adcs-rpc.md +1 -0 • src/content/sheets/active-directory/attack-35-golden-certificate-attack.md +1 -0 • src/content/sheets/active-directory/attack-36-certifried-cve-2022-26923.md +1 -0 • src/content/sheets/active-directory/attack-37-dcsync-attack.md +1 -0 • src/content/sheets/active-directory/attack-38-dcshadow-attack.md +1 -0 • src/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md +1 -0 • src/content/sheets/active-directory/attack-4-pass-the-hash-pth.md +1 -0 • src/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md +1 -0 • src/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md +1 -0 • src/content/sheets/active-directory/attack-42-printerbug-spoolsample.md +1 -0 • src/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md +1 -0 • src/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md +1 -0 • src/content/sheets/active-directory/attack-45-token-impersonation-seimpersonateprivilege.md +1 -0 • src/content/sheets/active-directory/attack-46-dnsadmins-dll-injection.md +1 -0 • src/content/sheets/active-directory/attack-47-machineaccountquota-maq-abuse.md +1 -0 • src/content/sheets/active-directory/attack-48-gpp-password-decryption.md +1 -0 • src/content/sheets/active-directory/attack-49-abusing-backup-operators-group.md +1 -0 • src/content/sheets/active-directory/attack-5-pass-the-ticket-ptt.md +1 -0 • src/content/sheets/active-directory/attack-50-abusing-account-operators-group.md +1 -0 • src/content/sheets/active-directory/attack-51-abusing-server-operators-group.md +1 -0 • src/content/sheets/active-directory/attack-52-abusing-print-operators-group.md +1 -0 • src/content/sheets/active-directory/attack-53-exchange-windows-permissions-writedacl-to-dcsync.md +1 -0 • src/content/sheets/active-directory/attack-54-psexec-remote-execution-via-smb.md +1 -0 • src/content/sheets/active-directory/attack-55-winrm-evil-winrm-lateral-movement.md +1 -0 • src/content/sheets/active-directory/attack-56-rdp-lateral-movement-and-hijacking.md +1 -0 • src/content/sheets/active-directory/attack-57-dcom-lateral-movement.md +1 -0 • src/content/sheets/active-directory/attack-58-wmi-lateral-movement.md +1 -0 • src/content/sheets/active-directory/attack-59-scm-service-manager-lateral-movement.md +1 -0 • src/content/sheets/active-directory/attack-6-overpass-the-hash-pass-the-key.md +1 -0 • src/content/sheets/active-directory/attack-60-token-stealing-and-impersonation.md +1 -0 • src/content/sheets/active-directory/attack-61-skeleton-key-attack.md +1 -0 • src/content/sheets/active-directory/attack-62-dsrm-backdoor-abuse.md +1 -0 • src/content/sheets/active-directory/attack-63-sid-history-injection.md +1 -0 • src/content/sheets/active-directory/attack-64-golden-ticket-persistence.md +1 -0 • src/content/sheets/active-directory/attack-65-acl-backdooring-persistence-via-dcsync-ace.md +1 -0 • src/content/sheets/active-directory/attack-66-malicious-gpo-creation.md +1 -0 • src/content/sheets/active-directory/attack-67-adcs-certificate-based-persistence.md +1 -0 • src/content/sheets/active-directory/attack-68-cross-domain-trust-abuse-sid-history.md +1 -0 • src/content/sheets/active-directory/attack-69-forest-trust-abuse-cross-forest-ticket-forging.md +1 -0 • src/content/sheets/active-directory/attack-7-ntlm-relay-attacks.md +1 -0 • src/content/sheets/active-directory/attack-70-adcs-cross-domain-enrollment.md +1 -0 • src/content/sheets/active-directory/attack-71-pam-trust-abuse-bastion-forest.md +1 -0 • src/content/sheets/active-directory/attack-72-laps-password-extraction.md +1 -0 • src/content/sheets/active-directory/attack-73-gmsa-password-extraction.md +1 -0 • src/content/sheets/active-directory/attack-74-azure-ad-connect-credential-extraction.md +1 -0 • src/content/sheets/active-directory/attack-75-sccm-mecm-exploitation.md +1 -0 • src/content/sheets/active-directory/attack-76-mssql-server-and-linked-server-abuse.md +1 -0 • src/content/sheets/active-directory/attack-77-dfscoerce-ms-dfsnm-coercion.md +1 -0 • src/content/sheets/active-directory/attack-78-ad-recycle-bin-object-abuse.md +1 -0 • src/content/sheets/active-directory/attack-8-llmnr-nbt-ns-mdns-poisoning.md +1 -0 • src/content/sheets/active-directory/attack-9-mitm6-ipv6-dns-spoofing-dhcpv6-takeover.md +1 -0 • src/content/sheets/active-directory/attack.md +0 -11 • src/content/sheets/active-directory/bloodhound-ce-python.md +1 -0 • src/content/sheets/active-directory/bloodhound-python.md +1 -0 • src/content/sheets/active-directory/bloodhound.md +1 -0 • src/content/sheets/active-directory/bloodyad.md +1 -0 • src/content/sheets/active-directory/certificate-persistence-certifried-cve-2022-26923.md +1 -0 • src/content/sheets/active-directory/certipy-ad.md +1 -0 • src/content/sheets/active-directory/certipy.md +1 -0 • src/content/sheets/active-directory/dpersist2-rogue-ca-certificate-ntauth-injection.md +1 -0 • src/content/sheets/active-directory/dpersist3-malicious-misconfiguration-acl-backdoor.md +1 -0 • src/content/sheets/active-directory/esc1-san-specification-in-template.md +1 -0 • src/content/sheets/active-directory/esc10-weak-certificate-mapping.md +1 -0 • src/content/sheets/active-directory/esc11-ntlm-relay-to-adcs-rpc-icpr.md +1 -0 • src/content/sheets/active-directory/esc12-shell-access-to-ca-with-yubihsm.md +1 -0 • src/content/sheets/active-directory/esc13-issuance-policy-oid-group-link.md +1 -0 • src/content/sheets/active-directory/esc14-weak-explicit-certificate-mapping.md +1 -0 • src/content/sheets/active-directory/esc15-ekuwu-cve-2024-49019.md +1 -0 • src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md +1 -0 • src/content/sheets/active-directory/esc17-adcs-certificate-spoofing-to-attack-https-enabled-wsus-clients.md +1 -0 • src/content/sheets/active-directory/esc2-any-purpose-eku-no-eku-the-swiss-certificate.md +1 -0 • src/content/sheets/active-directory/esc3-misconfigured-enrollment-agent-templates.md +1 -0 • src/content/sheets/active-directory/esc4-vulnerable-certificate-template-access-control.md +1 -0 • src/content/sheets/active-directory/esc5-vulnerable-pki-object-access-control.md +1 -0 • src/content/sheets/active-directory/esc6-editf-attributesubjectaltname2-flag.md +1 -0 • src/content/sheets/active-directory/esc7-vulnerable-ca-access-control-manageca-managecertificates.md +1 -0 • src/content/sheets/active-directory/esc8-ntlm-relay-to-adcs-http-web-enrollment.md +1 -0 • src/content/sheets/active-directory/esc9-no-security-extension-template-level.md +1 -0 • src/content/sheets/active-directory/faketime.md +1 -0 • src/content/sheets/active-directory/golden-certificate-attack-dpersist1.md +1 -0 • src/content/sheets/active-directory/impacket.md +1 -0 • src/content/sheets/active-directory/kerberoasting-local-on-host.md +1 -0 • src/content/sheets/active-directory/kerberoasting.md +1 -0 • src/content/sheets/active-directory/kerbrute.md +1 -0 • src/content/sheets/active-directory/ldap-enumeration.md +1 -0 • src/content/sheets/active-directory/ldap-search.md +1 -0 • src/content/sheets/active-directory/ldapdomaindump.md +1 -0 • src/content/sheets/active-directory/mimikatz.md +1 -0 • src/content/sheets/active-directory/netexec.md +1 -0 • src/content/sheets/active-directory/persist1-active-user-credential-theft-via-certificates.md +1 -0 • src/content/sheets/active-directory/persist2-machine-account-persistence-via-certificates.md +1 -0 • src/content/sheets/active-directory/persist3-account-persistence-via-certificate-renewal.md +1 -0 • src/content/sheets/active-directory/rubeus.md +1 -0 • src/content/sheets/active-directory/shadow-credentials-msds-keycredentiallink-abuse.md +1 -0 • src/content/sheets/active-directory/sharphound.md +1 -0 • src/content/sheets/active-directory/theft1-exporting-certificates-and-keys.md +1 -0 • src/content/sheets/active-directory/theft2-user-certificate-theft-via-dpapi.md +1 -0 • src/content/sheets/active-directory/theft3-machine-certificate-theft-via-dpapi.md +1 -0 • src/content/sheets/active-directory/theft4-finding-certificate-files.md +1 -0 • src/content/sheets/active-directory/theft5-ntlm-theft-via-pkinit-unpac-the-hash.md +1 -0 • src/pages/[category]/index.astro +113 -21 Diffstat:
138 files changed, 371 insertions(+), 37 deletions(-)
diff --git a/.gitignore b/.gitignore @@ -7,3 +7,5 @@ dist/ /pagefind/ # curation intermediates (keep manifest, drop bulky index) candidates.json +# Pagefind index copied into public/ so the dev server can serve it +/public/pagefind/ diff --git a/package.json b/package.json @@ -6,8 +6,9 @@ "description": "DÆMON//SEC — a curated vault of IT & cybersecurity cheatsheets", "scripts": { "dev": "astro dev", - "build": "astro build && pagefind --site dist", + "build": "astro build && pagefind --site dist && npm run pagefind:public", "preview": "astro preview", + "pagefind:public": "rm -rf public/pagefind && cp -R dist/pagefind public/pagefind", "astro": "astro" }, "dependencies": { diff --git a/scripts/port-vault.py b/scripts/port-vault.py @@ -76,12 +76,15 @@ SKIP_RE = re.compile(r"(roadmap|dashboard|attack-flow|most-used-commands|esc att def is_non_sheet(rel): base = rel.split("/")[-1] - stem = base[:-3] if base.lower().endswith(".md") else base + # Strip a leading emoji/space so covers like "🔵 Attack.md" match — the + # emoji prefix is exactly what let one slip through the first run. + bare = strip_emoji(base).strip() + stem = bare[:-3] if bare.lower().endswith(".md") else bare if not stem.strip(): return True # Git/.md — empty stub if stem.startswith("_"): return True # _ADCS Dashboard / _index files - if base.lower() in ("attack.md", "readme.md"): + if bare.lower() in ("attack.md", "readme.md"): return True # category cover / scripts readme return bool(SKIP_RE.search(stem)) diff --git a/scripts/stamp-subcategory.py b/scripts/stamp-subcategory.py @@ -0,0 +1,96 @@ +#!/usr/bin/env python3 +""" +Stamp a `subcategory` onto Active Directory sheets so the category page can +group its 130+ entries instead of listing them flat. + +The grouping is not invented — it is the taxonomy the source vault already +uses. Every sheet carries a `source: "vault:…"` path, and the AD-Attack set +is filed under Category-One … Category-Ten, the ADCS work under +ACL-ESC-Techniques, the ticket work under Kerberos. This maps those source +folders to kill-chain-ordered names; anything loose in ActiveDirectory/ is +tooling and recon. + +Idempotent: re-running rewrites the same `subcategory:` line. Only sheets +under src/content/sheets/active-directory are touched. + +Usage: python3 scripts/stamp-subcategory.py +""" +import os, re + +REPO = os.path.normpath(os.path.join(os.path.dirname(os.path.abspath(__file__)), "..")) +AD = os.path.join(REPO, "src", "content", "sheets", "active-directory") + +# Source folder → subcategory. The AD-Attack categories collapse a couple of +# ways: Category-Four (ESC attacks) merges with the ACL-ESC-Techniques folder, +# and Category-Two (tickets/delegation) merges with the Kerberos folder, so a +# reader sees one "ADCS & Certificates" section rather than two half-sections. +def subcat_for(source): + s = source.replace("vault:", "") + m = re.search(r"AD-Attack/Category-(\w+)", s) + if m: + return { + "One": "Credential Access", + "Two": "Kerberos & Delegation", + "Three": "ACL Abuse", + "Four": "ADCS & Certificates", + "Five": "Domain Controller Attacks", + "Six": "Privilege & Group Abuse", + "Seven": "Lateral Movement", + "Eight": "Persistence", + "Nine": "Trust Abuse", + "Ten": "Advanced & Post-Exploitation", + }.get(m.group(1), "Advanced & Post-Exploitation") + if "ACL-ESC-Techniques" in s: + return "ADCS & Certificates" + if "/Kerberos/" in s: + return "Kerberos & Delegation" + return "Tooling & Recon" + +def read_source(fm): + m = re.search(r'^source:\s*"?(?:source:\s*)?"?([^"\n]+)"?\s*$', fm, flags=re.M) + # Some early files double-wrote the key ("source: source: \"vault:…\""); + # this tolerates both. Fall back to a looser grab of the vault path. + if m and "vault:" in m.group(0): + vm = re.search(r"vault:[^\"\n]+", m.group(0)) + if vm: + return vm.group(0) + vm = re.search(r"vault:[^\"\n]+", fm) + return vm.group(0) if vm else "" + +def main(): + changed = 0 + counts = {} + for f in sorted(os.listdir(AD)): + if not f.endswith(".md"): + continue + path = os.path.join(AD, f) + txt = open(path, encoding="utf-8").read() + if not txt.startswith("---"): + continue + end = txt.find("\n---", 3) + if end == -1: + continue + fm, body = txt[:end], txt[end:] + + source = read_source(fm) + sub = subcat_for(source) if source else "Tooling & Recon" + counts[sub] = counts.get(sub, 0) + 1 + + line = f'subcategory: "{sub}"' + if re.search(r"^subcategory:.*$", fm, flags=re.M): + fm = re.sub(r"^subcategory:.*$", line, fm, count=1, flags=re.M) + else: + # Insert right after the category line so frontmatter stays tidy. + fm = re.sub(r"^(category:.*)$", r"\1\n" + line, fm, count=1, flags=re.M) + + new = fm + body + if new != txt: + open(path, "w", encoding="utf-8").write(new) + changed += 1 + + print(f"stamped {changed} AD sheets") + for k in sorted(counts): + print(f" {k:32} {counts[k]}") + +if __name__ == "__main__": + main() diff --git a/src/components/SearchModal.astro b/src/components/SearchModal.astro @@ -80,6 +80,23 @@ import Icon from './Icon.astro'; let pagefind: any = null; let loading: Promise<any> | null = null; + /* Native dynamic import, hidden from Vite. + + Pagefind ships as a prebuilt ES module with its own WASM and code-split + chunks. A literal `import(path)` is rewritten by Vite's dev server: it + appends `?import` and tries to push pagefind's bundle through its own + transform pipeline, which 500s — so search worked under `astro preview` + (no Vite) but never under `astro dev`. `@vite-ignore` doesn't help; Vite + still rewrites the specifier. + + Building the import through `new Function` means the token `import(` is + never in source Vite can scan, so it emits a genuine browser-native + import that fetches pagefind untouched. Pagefind's own internal chunk + imports then resolve against its real URL and are served straight from + `public/pagefind/` (or `dist/pagefind/` in prod). */ + const nativeImport: (u: string) => Promise<any> = + new Function('u', 'return import(u)') as any; + function loadPagefind() { if (loading) return loading; /* Join on a normalised base rather than concatenating onto it. @@ -90,8 +107,8 @@ import Icon from './Icon.astro'; trailing slashes first makes the join correct whether or not the base carries one. */ const path = `${BASE.replace(/\/+$/, '')}/pagefind/pagefind.js`; - loading = import(/* @vite-ignore */ path) - .then(async (mod) => { await mod.init?.(); pagefind = mod; return mod; }) + loading = nativeImport(path) + .then(async (mod: any) => { await mod.init?.(); pagefind = mod; return mod; }) .catch(() => { pagefind = false; return null; }); return loading; } diff --git a/src/content.config.ts b/src/content.config.ts @@ -9,6 +9,10 @@ const sheets = defineCollection({ title: z.string(), description: z.string().default(''), category: z.string(), + // Optional second-level grouping shown as sub-sections on a busy + // category page (Active Directory has 130+ sheets). Derived from the + // source vault path by scripts/stamp-subcategory.py. + subcategory: z.string().optional(), tags: z.array(z.string()).default([]), tools: z.array(z.string()).default([]), difficulty: z.enum(['beginner', 'intermediate', 'advanced']).default('intermediate'), diff --git a/src/content/sheets/active-directory/active-directory-attacks.md b/src/content/sheets/active-directory/active-directory-attacks.md @@ -2,6 +2,7 @@ title: "Active Directory Attack Methodology" description: "End-to-end AD exploitation: enum, roasting, delegation, lateral movement, DCSync, persistence." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, methodology, kerberos, lateral-movement] tools: [Impacket, Rubeus, Mimikatz, CrackMapExec] difficulty: advanced diff --git a/src/content/sheets/active-directory/active-directory-cheat-sheet.md b/src/content/sheets/active-directory/active-directory-cheat-sheet.md @@ -2,6 +2,7 @@ title: "Active-Directory_cheat_sheet" description: "This cheat sheet contains common enumeration and attack methods for Windows Active Directory." category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/ad-pentest-tools.md b/src/content/sheets/active-directory/ad-pentest-tools.md @@ -2,6 +2,7 @@ title: "AD Pentest Tools Workflow" description: "Tooling-oriented AD engagement workflow with copy-paste commands from enumeration to domain takeover." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, tooling, workflow, enumeration] tools: [NetExec, BloodHound, Impacket, ldapsearch] difficulty: advanced diff --git a/src/content/sheets/active-directory/adcs-attack-methodology.md b/src/content/sheets/active-directory/adcs-attack-methodology.md @@ -2,6 +2,7 @@ title: "ADCS Attack Methodology" description: "ADCS/ESC attack index following Certified Pre-Owned taxonomy: ESC, THEFT, PERSIST, DPERSIST phases." category: active-directory +subcategory: "ADCS & Certificates" tags: [active-directory, adcs, esc, certificates] tools: [Certipy, Certify] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-1-password-spraying.md b/src/content/sheets/active-directory/attack-1-password-spraying.md @@ -2,6 +2,7 @@ title: "Attack #1 — Password Spraying" description: "Password spraying is a low-and-slow credential attack that inverts the logic of traditional brute force. Instead of hammering one account with many…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "kerberos", "adcs", "privilege-escalation", "lateral-movement"] tools: ["NetExec", "Impacket", "BloodHound", "Kerbrute", "Evil-WinRM"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-10-credential-hunting-in-shares-gpp-passwords.md b/src/content/sheets/active-directory/attack-10-credential-hunting-in-shares-gpp-passwords.md @@ -2,6 +2,7 @@ title: "Attack #10 — Credential Hunting in Shares GPP Passwords" description: "This attack is split into two closely related techniques: GPP Password Decryption (a specific catastrophic vulnerability) and broad credential hunting…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory"] tools: ["NetExec", "Impacket", "Mimikatz", "BloodHound", "Metasploit"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-11-golden-ticket-attack.md b/src/content/sheets/active-directory/attack-11-golden-ticket-attack.md @@ -2,6 +2,7 @@ title: "Attack #11 — Golden Ticket Attack" description: "The Golden Ticket attack is the most powerful persistence technique in Active Directory. It exploits the fundamental trust model of the Kerberos protocol…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation", "persistence"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Evil-WinRM"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-12-silver-ticket-attack.md b/src/content/sheets/active-directory/attack-12-silver-ticket-attack.md @@ -2,6 +2,7 @@ title: "Attack #12 — Silver Ticket Attack" description: "The Silver Ticket attack is the surgical counterpart to the Golden Ticket. Instead of forging a Ticket Granting Ticket (TGT) with the KRBTGT hash (which…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "adcs", "credential-access", "ntlm"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Hashcat"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-13-diamond-ticket-attack.md b/src/content/sheets/active-directory/attack-13-diamond-ticket-attack.md @@ -2,6 +2,7 @@ title: "Attack #13 — Diamond Ticket Attack" description: "The Diamond Ticket is an evolution of the Golden Ticket that was developed to bypass modern detection mechanisms. While a Golden Ticket forges a TGT…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "adcs", "credential-access", "kerberos", "privilege-escalation"] tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-14-sapphire-ticket-attack.md b/src/content/sheets/active-directory/attack-14-sapphire-ticket-attack.md @@ -2,6 +2,7 @@ title: "Attack #14 — Sapphire Ticket Attack" description: "The Sapphire Ticket is the most OPSEC-friendly ticket forging technique in the Kerberos attack family. It addresses the final detection gap that Diamond…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation"] tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-15-unconstrained-delegation-abuse.md b/src/content/sheets/active-directory/attack-15-unconstrained-delegation-abuse.md @@ -2,6 +2,7 @@ title: "Attack #15 — Unconstrained Delegation Abuse" description: "Unconstrained Delegation is a legacy Kerberos feature that allows a service to impersonate any user to any other service in the domain. When a computer…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "adcs", "credential-access", "delegation"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-16-constrained-delegation-abuse-s4u2proxy.md b/src/content/sheets/active-directory/attack-16-constrained-delegation-abuse-s4u2proxy.md @@ -2,6 +2,7 @@ title: "Attack #16 — Constrained Delegation Abuse (S4U2Proxy)" description: "Constrained Delegation was designed as a safer alternative to Unconstrained Delegation. Instead of caching every user's TGT, a service configured for…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "delegation", "hashing"] tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-17-resource-based-constrained-delegation-rbcd.md b/src/content/sheets/active-directory/attack-17-resource-based-constrained-delegation-rbcd.md @@ -2,6 +2,7 @@ title: "Attack #17 — Resource-Based Constrained Delegation (RBCD)" description: "Resource-Based Constrained Delegation (RBCD) flips traditional Constrained Delegation on its head. Instead of the delegating account specifying which…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "delegation"] tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "ldapsearch"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-18-bronze-bit-attack-cve-2020-17049.md b/src/content/sheets/active-directory/attack-18-bronze-bit-attack-cve-2020-17049.md @@ -2,6 +2,7 @@ title: "Attack #18 — Bronze Bit Attack (CVE-2020-17049)" description: "The Bronze Bit attack exploits CVE-2020-17049, a vulnerability in the Kerberos Constrained Delegation mechanism. It allows an attacker to bypass the…" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "delegation"] tools: ["Impacket", "Mimikatz", "Rubeus"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-19-genericall-abuse.md b/src/content/sheets/active-directory/attack-19-genericall-abuse.md @@ -2,6 +2,7 @@ title: "Attack #19 — GenericAll Abuse" description: "GenericAll is the most dangerous misconfigured ACL permission in Active Directory. It grants a principal (user, group, or computer) full control over a…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "kerberos", "adcs", "delegation", "privilege-escalation"] tools: ["NetExec", "Impacket", "Rubeus", "Certipy", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-2-kerberoasting.md b/src/content/sheets/active-directory/attack-2-kerberoasting.md @@ -2,6 +2,7 @@ title: "Attack #2 — Kerberoasting" description: "Kerberoasting is a post-compromise, offline credential attack that abuses a fundamental design feature of the Kerberos protocol. When any authenticated…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "kerberos", "privilege-escalation", "sql-injection", "hashing"] tools: ["NetExec", "Impacket", "Rubeus", "BloodHound", "Kerbrute"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-20-genericwrite-abuse.md b/src/content/sheets/active-directory/attack-20-genericwrite-abuse.md @@ -2,6 +2,7 @@ title: "Attack #20 — GenericWrite Abuse" description: "GenericWrite allows an attacker to write to any non-protected attribute on a target AD object. While it doesn't grant full control like GenericAll, it…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "kerberos", "hashing"] tools: ["Rubeus", "Certipy", "Hashcat", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-21-writedacl-abuse.md b/src/content/sheets/active-directory/attack-21-writedacl-abuse.md @@ -2,6 +2,7 @@ title: "Attack #21 — WriteDACL Abuse" description: "WriteDACL allows an attacker to modify the Discretionary Access Control List of a target AD object — meaning they can grant themselves (or any principal)…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "credential-access", "privilege-escalation", "hashing"] tools: ["Impacket", "Mimikatz", "BloodHound", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-22-writeowner-abuse.md b/src/content/sheets/active-directory/attack-22-writeowner-abuse.md @@ -2,6 +2,7 @@ title: "Attack #22 — WriteOwner Abuse" description: "WriteOwner allows an attacker to change the owner of an AD object to themselves. Since the owner of an object has the implicit right to modify the…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "adcs", "credential-access", "delegation"] tools: ["Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-23-forcechangepassword-abuse.md b/src/content/sheets/active-directory/attack-23-forcechangepassword-abuse.md @@ -2,6 +2,7 @@ title: "Attack #23 — ForceChangePassword Abuse" description: "ForceChangePassword (also known as User-Force-Change-Password extended right) allows a principal to reset another user's password without knowing their…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "delegation", "privilege-escalation"] tools: ["Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-24-allextendedrights-dcsync-ace-abuse.md b/src/content/sheets/active-directory/attack-24-allextendedrights-dcsync-ace-abuse.md @@ -2,6 +2,7 @@ title: "Attack #24 — AllExtendedRights DCSync ACE Abuse" description: "AllExtendedRights is a blanket permission that grants every extended right on an AD object. When applied to the domain root object, this includes the two…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "credential-access", "delegation"] tools: ["Impacket", "Mimikatz", "BloodHound", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-25-shadow-credentials-attack-msds-keycredentiallink.md b/src/content/sheets/active-directory/attack-25-shadow-credentials-attack-msds-keycredentiallink.md @@ -2,6 +2,7 @@ title: "Attack #25 — Shadow Credentials Attack (msDS-KeyCredentialLink)" description: "Shadow Credentials is one of the stealthiest account takeover techniques in Active Directory. It abuses the msDS-KeyCredentialLink attribute — originally…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "kerberos", "adcs", "persistence", "hashing"] tools: ["Impacket", "Rubeus", "Certipy", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-26-adminsdholder-persistence-via-acl.md b/src/content/sheets/active-directory/attack-26-adminsdholder-persistence-via-acl.md @@ -2,6 +2,7 @@ title: "Attack #26 — AdminSDHolder Persistence via ACL" description: "AdminSDHolder is a built-in Active Directory persistence mechanism that attackers can abuse for permanent, self-healing backdoor access. The…" category: active-directory +subcategory: "ACL Abuse" tags: ["active-directory", "adcs", "credential-access", "persistence"] tools: ["Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-27-esc1-san-specification-in-template.md b/src/content/sheets/active-directory/attack-27-esc1-san-specification-in-template.md @@ -2,6 +2,7 @@ title: "Attack #27 — ESC1 SAN Specification in Template" description: "ESC1 is the most impactful and commonly exploited ADCS vulnerability — a misconfigured certificate template that allows any low-privileged domain user to…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "kerberos", "adcs", "privilege-escalation"] tools: ["NetExec", "Impacket", "Rubeus", "Certipy", "Evil-WinRM"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-28-esc2-any-purpose-eku-no-eku.md b/src/content/sheets/active-directory/attack-28-esc2-any-purpose-eku-no-eku.md @@ -2,6 +2,7 @@ title: "Attack #28 — ESC2 Any Purpose EKU No EKU" description: "ESC2 exploits certificate templates configured with the \"Any Purpose\" Extended Key Usage (EKU) (OID 2.5.29.37.0) or no EKU at all. Such certificates are…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Certipy", "Certify", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-29-esc3-certificate-request-agent.md b/src/content/sheets/active-directory/attack-29-esc3-certificate-request-agent.md @@ -2,6 +2,7 @@ title: "Attack #29 — ESC3 Certificate Request Agent" description: "ESC3 exploits the Certificate Request Agent (Enrollment Agent) EKU. A template with this EKU allows the enrolled user to request certificates on behalf of…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Certipy", "Certify", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-3-as-rep-roasting.md b/src/content/sheets/active-directory/attack-3-as-rep-roasting.md @@ -2,6 +2,7 @@ title: "Attack #3 — AS-REP Roasting" description: "AS-REP Roasting targets Active Directory accounts that have the \"Do not require Kerberos preauthentication\" flag set (DONT_REQ_PREAUTH). Under normal…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "kerberos", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-30-esc4-template-write-permissions.md b/src/content/sheets/active-directory/attack-30-esc4-template-write-permissions.md @@ -2,6 +2,7 @@ title: "Attack #30 — ESC4 Template Write Permissions" description: "ESC4 exploits overly permissive ACLs on certificate templates. If a low-privileged user has WriteProperty, WriteDACL, WriteOwner, or FullControl on a…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-31-esc6-editf-attributesubjectaltname2-flag.md b/src/content/sheets/active-directory/attack-31-esc6-editf-attributesubjectaltname2-flag.md @@ -2,6 +2,7 @@ title: "Attack #31 — ESC6 EDITF_ATTRIBUTESUBJECTALTNAME2 Flag" description: "ESC6 is a CA-wide misconfiguration where the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is enabled on the Certificate Authority. When this flag is set, it allows…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Certipy", "Certify", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-32-esc7-vulnerable-ca-officer-permissions.md b/src/content/sheets/active-directory/attack-32-esc7-vulnerable-ca-officer-permissions.md @@ -2,6 +2,7 @@ title: "Attack #32 — ESC7 Vulnerable CA Officer Permissions" description: "ESC7 exploits overly permissive CA permissions. If a low-privileged user has ManageCA rights on the Certificate Authority, they can grant themselves…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-33-esc8-ntlm-relay-to-adcs-http-endpoint.md b/src/content/sheets/active-directory/attack-33-esc8-ntlm-relay-to-adcs-http-endpoint.md @@ -2,6 +2,7 @@ title: "Attack #33 — ESC8 NTLM Relay to ADCS HTTP Endpoint" description: "ESC8 is one of the most impactful ADCS attacks — it enables a full domain compromise from unauthenticated or low-privileged access by combining NTLM…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] tools: ["Impacket", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-34-esc11-ntlm-relay-to-adcs-rpc.md b/src/content/sheets/active-directory/attack-34-esc11-ntlm-relay-to-adcs-rpc.md @@ -2,6 +2,7 @@ title: "Attack #34 — ESC11 NTLM Relay to ADCS RPC" description: "ESC11 is similar to ESC8 but targets the CA's RPC enrollment interface (MS-ICPR) instead of the HTTP web enrollment. If the CA does not enforce packet…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] tools: ["Impacket", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-35-golden-certificate-attack.md b/src/content/sheets/active-directory/attack-35-golden-certificate-attack.md @@ -2,6 +2,7 @@ title: "Attack #35 — Golden Certificate Attack" description: "The Golden Certificate attack is the ADCS equivalent of a Golden Ticket. By stealing the Certificate Authority's private key and CA certificate, an…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "kerberos"] tools: ["Mimikatz", "Rubeus", "Certipy", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-36-certifried-cve-2022-26923.md b/src/content/sheets/active-directory/attack-36-certifried-cve-2022-26923.md @@ -2,6 +2,7 @@ title: "Attack #36 — Certifried (CVE-2022-26923)" description: "Certifried (CVE-2022-26923) exploits a flaw in how Active Directory maps computer account certificates to machine accounts. An attacker can create a new…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "credential-access", "persistence"] tools: ["Impacket", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-37-dcsync-attack.md b/src/content/sheets/active-directory/attack-37-dcsync-attack.md @@ -2,6 +2,7 @@ title: "Attack #37 — DCSync Attack" description: "DCSync is the most efficient method for extracting every credential in an Active Directory domain without ever touching the NTDS.dit file on disk or…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "kerberos", "credential-access", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Certipy", "Hashcat"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-38-dcshadow-attack.md b/src/content/sheets/active-directory/attack-38-dcshadow-attack.md @@ -2,6 +2,7 @@ title: "Attack #38 — DCShadow Attack" description: "DCShadow allows an attacker to register a rogue Domain Controller in Active Directory and push malicious changes via the legitimate replication protocol…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "credential-access"] tools: ["Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md b/src/content/sheets/active-directory/attack-39-ntds-dit-extraction-and-dumping.md @@ -2,6 +2,7 @@ title: "Attack #39 — NTDS.dit Extraction and Dumping" description: "The NTDS.dit file is the Active Directory database stored on every Domain Controller at C:\\Windows\\NTDS\\ntds.dit. It contains all domain credentials (NT…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "kerberos", "credential-access", "hashing"] tools: ["NetExec", "Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-4-pass-the-hash-pth.md b/src/content/sheets/active-directory/attack-4-pass-the-hash-pth.md @@ -2,6 +2,7 @@ title: "Attack #4 — Pass-the-Hash (PtH)" description: "Pass-the-Hash is a credential replay attack that exploits a fundamental design characteristic of the NTLM authentication protocol. When Windows…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "ntlm", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Hashcat"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md b/src/content/sheets/active-directory/attack-40-zerologon-cve-2020-1472.md @@ -2,6 +2,7 @@ title: "Attack #40 — Zerologon (CVE-2020-1472)" description: "Zerologon is a critical vulnerability in the Netlogon Remote Protocol (MS-NRPC) that allows an unauthenticated attacker with network access to a DC to set…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory"] tools: ["NetExec", "Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md b/src/content/sheets/active-directory/attack-41-petitpotam-cve-2021-36942.md @@ -2,6 +2,7 @@ title: "Attack #41 — PetitPotam (CVE-2021-36942)" description: "PetitPotam exploits the Encrypting File System Remote Protocol (MS-EFSR) to coerce a target (typically a DC) to authenticate to an attacker-controlled…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] tools: ["Impacket", "Certipy", "Responder", "OpenSSL", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-42-printerbug-spoolsample.md b/src/content/sheets/active-directory/attack-42-printerbug-spoolsample.md @@ -2,6 +2,7 @@ title: "Attack #42 — PrinterBug SpoolSample" description: "The PrinterBug (aka SpoolSample) abuses the MS-RPRN (Print System Remote Protocol) RpcRemoteFindFirstPrinterChangeNotificationEx function to coerce a…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "kerberos", "adcs", "delegation", "ntlm"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md b/src/content/sheets/active-directory/attack-43-printnightmare-cve-2021-34527.md @@ -2,6 +2,7 @@ title: "Attack #43 — PrintNightmare (CVE-2021-34527)" description: "PrintNightmare is a critical RCE vulnerability in the Windows Print Spooler service that allows an authenticated user to execute arbitrary code as SYSTEM…" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "credential-access", "privilege-escalation"] tools: ["Impacket", "Mimikatz", "Metasploit", "Meterpreter", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md b/src/content/sheets/active-directory/attack-44-nopac-sam-the-admin-cve-2021-42278-42287.md @@ -2,6 +2,7 @@ title: "Attack #44 — noPAC Sam-the-Admin (CVE-2021-42278 42287)" description: "noPAC (Sam-the-Admin) chains two CVEs to escalate from any domain user to Domain Admin:" category: active-directory +subcategory: "Domain Controller Attacks" tags: ["active-directory", "adcs", "kerberos", "privilege-escalation"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-45-token-impersonation-seimpersonateprivilege.md b/src/content/sheets/active-directory/attack-45-token-impersonation-seimpersonateprivilege.md @@ -2,6 +2,7 @@ title: "Attack #45 — Token Impersonation (SeImpersonatePrivilege)" description: "Token Impersonation is a local privilege escalation technique that exploits the Windows SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) to…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory", "adcs", "privilege-escalation", "sql-injection"] tools: ["Impacket", "Mimikatz", "Metasploit", "Meterpreter", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-46-dnsadmins-dll-injection.md b/src/content/sheets/active-directory/attack-46-dnsadmins-dll-injection.md @@ -2,6 +2,7 @@ title: "Attack #46 — DNSAdmins DLL Injection" description: "Members of the DnsAdmins group can configure the DNS service to load an arbitrary DLL via the ServerLevelPluginDll registry key. Since the DNS service…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory"] tools: ["PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-47-machineaccountquota-maq-abuse.md b/src/content/sheets/active-directory/attack-47-machineaccountquota-maq-abuse.md @@ -2,6 +2,7 @@ title: "Attack #47 — MachineAccountQuota (MAQ) Abuse" description: "By default, any authenticated domain user can create up to 10 computer accounts (controlled by ms-DS-MachineAccountQuota). These attacker-created machine…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory"] tools: ["NetExec", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-48-gpp-password-decryption.md b/src/content/sheets/active-directory/attack-48-gpp-password-decryption.md @@ -2,6 +2,7 @@ title: "Attack #48 — GPP Password Decryption" description: "Group Policy Preferences (GPP) allowed admins to set local admin passwords, create scheduled tasks, and configure services via Group Policy — with the…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory"] tools: ["NetExec", "Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-49-abusing-backup-operators-group.md b/src/content/sheets/active-directory/attack-49-abusing-backup-operators-group.md @@ -2,6 +2,7 @@ title: "Attack #49 — Abusing Backup Operators Group" description: "Members of Backup Operators have the SeBackupPrivilege and SeRestorePrivilege, which grants them the ability to read and write any file on the system —…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory", "privilege-escalation", "hashing"] tools: ["Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-5-pass-the-ticket-ptt.md b/src/content/sheets/active-directory/attack-5-pass-the-ticket-ptt.md @@ -2,6 +2,7 @@ title: "Attack #5 — Pass-the-Ticket (PtT)" description: "Pass-the-Ticket is a Kerberos credential theft and replay attack where an attacker extracts a valid Kerberos ticket — either a Ticket Granting Ticket…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "kerberos", "ntlm", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-50-abusing-account-operators-group.md b/src/content/sheets/active-directory/attack-50-abusing-account-operators-group.md @@ -2,6 +2,7 @@ title: "Attack #50 — Abusing Account Operators Group" description: "net user backdoor P@ssword123! /add /domain" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory", "kerberos", "sql-injection", "pivoting"] tools: ["Rubeus", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-51-abusing-server-operators-group.md b/src/content/sheets/active-directory/attack-51-abusing-server-operators-group.md @@ -2,6 +2,7 @@ title: "Attack #51 — Abusing Server Operators Group" description: "sc.exe \\\\DC01 create evilsvc binPath= \"cmd.exe /c net user hacker P@ss123! /add && net localgroup Administrators hacker /add\" start= auto sc.exe \\\\DC01…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory", "adcs"] tools: ["PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-52-abusing-print-operators-group.md b/src/content/sheets/active-directory/attack-52-abusing-print-operators-group.md @@ -2,6 +2,7 @@ title: "Attack #52 — Abusing Print Operators Group" description: "whoami /priv" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory", "privilege-escalation"] tools: ["PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-53-exchange-windows-permissions-writedacl-to-dcsync.md b/src/content/sheets/active-directory/attack-53-exchange-windows-permissions-writedacl-to-dcsync.md @@ -2,6 +2,7 @@ title: "Attack #53 — Exchange Windows Permissions (WriteDACL to DCSync)" description: "In many environments, the Exchange Windows Permissions security group has WriteDACL on the domain root object. This is a well-known legacy…" category: active-directory +subcategory: "Privilege & Group Abuse" tags: ["active-directory", "credential-access"] tools: ["Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-54-psexec-remote-execution-via-smb.md b/src/content/sheets/active-directory/attack-54-psexec-remote-execution-via-smb.md @@ -2,6 +2,7 @@ title: "Attack #54 — PsExec Remote Execution via SMB" description: "PsExec is the most iconic lateral movement technique in Active Directory environments. It enables an attacker with valid administrator credentials to…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "kerberos", "privilege-escalation", "lateral-movement", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Evil-WinRM", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-55-winrm-evil-winrm-lateral-movement.md b/src/content/sheets/active-directory/attack-55-winrm-evil-winrm-lateral-movement.md @@ -2,6 +2,7 @@ title: "Attack #55 — WinRM Evil-WinRM Lateral Movement" description: "Windows Remote Management (WinRM) is a SOAP-based protocol for remote management over HTTP/HTTPS (ports 5985/5986). Evil-WinRM provides an interactive…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "lateral-movement"] tools: ["Mimikatz", "Evil-WinRM", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-56-rdp-lateral-movement-and-hijacking.md b/src/content/sheets/active-directory/attack-56-rdp-lateral-movement-and-hijacking.md @@ -2,6 +2,7 @@ title: "Attack #56 — RDP Lateral Movement and Hijacking" description: "RDP (Remote Desktop Protocol, port 3389) provides full GUI access to remote systems. Beyond standard RDP with credentials, attackers can hijack existing…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "lateral-movement", "hashing"] tools: ["NetExec", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-57-dcom-lateral-movement.md b/src/content/sheets/active-directory/attack-57-dcom-lateral-movement.md @@ -2,6 +2,7 @@ title: "Attack #57 — DCOM Lateral Movement" description: "DCOM (Distributed Component Object Model) allows code execution on remote systems by instantiating COM objects. The MMC20.Application, ShellWindows, and…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "lateral-movement"] tools: ["Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-58-wmi-lateral-movement.md b/src/content/sheets/active-directory/attack-58-wmi-lateral-movement.md @@ -2,6 +2,7 @@ title: "Attack #58 — WMI Lateral Movement" description: "WMI (Windows Management Instrumentation) enables remote process execution via the Win32_Process.Create() method. WMI-based execution is the stealthiest…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "kerberos", "lateral-movement", "hashing"] tools: ["Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-59-scm-service-manager-lateral-movement.md b/src/content/sheets/active-directory/attack-59-scm-service-manager-lateral-movement.md @@ -2,6 +2,7 @@ title: "Attack #59 — SCM Service Manager Lateral Movement" description: "The Service Control Manager (SCM) allows remote service creation and management via named pipes (\\pipe\\svcctl). An attacker with admin credentials can…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "lateral-movement"] tools: ["Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-6-overpass-the-hash-pass-the-key.md b/src/content/sheets/active-directory/attack-6-overpass-the-hash-pass-the-key.md @@ -2,6 +2,7 @@ title: "Attack #6 — Overpass-the-Hash (Pass-the-Key)" description: "Overpass-the-Hash (OPtH) is a hybrid attack that converts a stolen NTLM hash into a fully valid Kerberos TGT. This is the critical conceptual bridge in…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "kerberos", "ntlm", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-60-token-stealing-and-impersonation.md b/src/content/sheets/active-directory/attack-60-token-stealing-and-impersonation.md @@ -2,6 +2,7 @@ title: "Attack #60 — Token Stealing and Impersonation" description: "When a privileged user (e.g., Domain Admin) is logged into a compromised machine, their access token persists in memory. An attacker with local…" category: active-directory +subcategory: "Lateral Movement" tags: ["active-directory", "credential-access", "delegation", "privilege-escalation", "lateral-movement"] tools: ["Mimikatz", "Meterpreter", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-61-skeleton-key-attack.md b/src/content/sheets/active-directory/attack-61-skeleton-key-attack.md @@ -2,6 +2,7 @@ title: "Attack #61 — Skeleton Key Attack" description: "The Skeleton Key attack patches the LSASS process on a Domain Controller to add a master password (\"skeleton key\") that works alongside every user's real…" category: active-directory +subcategory: "Persistence" tags: ["active-directory", "privilege-escalation"] tools: ["Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-62-dsrm-backdoor-abuse.md b/src/content/sheets/active-directory/attack-62-dsrm-backdoor-abuse.md @@ -2,6 +2,7 @@ title: "Attack #62 — DSRM Backdoor Abuse" description: "Every DC has a Directory Services Restore Mode (DSRM) administrator account with a separate password set during DC promotion. By default, this account…" category: active-directory +subcategory: "Persistence" tags: ["active-directory", "ntlm", "privilege-escalation", "hashing"] tools: ["Mimikatz", "Evil-WinRM", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-63-sid-history-injection.md b/src/content/sheets/active-directory/attack-63-sid-history-injection.md @@ -2,6 +2,7 @@ title: "Attack #63 — SID History Injection" description: "sIDHistory is an AD attribute designed for domain migrations — it preserves a user's old SID so they retain access to resources from a previous domain. An…" category: active-directory +subcategory: "Persistence" tags: ["active-directory", "privilege-escalation"] tools: ["Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-64-golden-ticket-persistence.md b/src/content/sheets/active-directory/attack-64-golden-ticket-persistence.md @@ -2,6 +2,7 @@ title: "Attack #64 — Golden Ticket Persistence" description: "A Golden Ticket provides persistent domain access by forging TGTs using the KRBTGT hash. As a persistence technique (not just one-time escalation), the…" category: active-directory +subcategory: "Persistence" tags: ["active-directory", "kerberos", "adcs", "credential-access", "persistence"] tools: ["Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-65-acl-backdooring-persistence-via-dcsync-ace.md b/src/content/sheets/active-directory/attack-65-acl-backdooring-persistence-via-dcsync-ace.md @@ -2,6 +2,7 @@ title: "Attack #65 — ACL Backdooring (Persistence via DCSync ACE)" description: "An attacker with DA can add hidden ACEs to domain objects to maintain persistent access. The most common pattern: grant a seemingly innocuous user DCSync…" category: active-directory +subcategory: "Persistence" tags: ["active-directory", "adcs", "credential-access", "persistence"] tools: ["PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-66-malicious-gpo-creation.md b/src/content/sheets/active-directory/attack-66-malicious-gpo-creation.md @@ -2,6 +2,7 @@ title: "Attack #66 — Malicious GPO Creation" description: "An attacker with GPO creation rights (or who compromises a GPO-managing account) can create or modify Group Policy Objects to execute malicious scripts…" category: active-directory +subcategory: "Persistence" tags: ["active-directory"] tools: ["NetExec", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-67-adcs-certificate-based-persistence.md b/src/content/sheets/active-directory/attack-67-adcs-certificate-based-persistence.md @@ -2,6 +2,7 @@ title: "Attack #67 — ADCS Certificate-Based Persistence" description: "An attacker who has compromised a DA account can request a long-lived client authentication certificate for that account. Even after the DA password is…" category: active-directory +subcategory: "Persistence" tags: ["active-directory", "adcs", "persistence", "hashing"] tools: ["Rubeus", "Certipy", "Certify", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-68-cross-domain-trust-abuse-sid-history.md b/src/content/sheets/active-directory/attack-68-cross-domain-trust-abuse-sid-history.md @@ -2,6 +2,7 @@ title: "Attack #68 — Cross-Domain Trust Abuse (SID History)" description: "In AD forests with multiple domains connected by trust relationships, compromising one child domain gives a path to the forest root domain. By forging a…" category: active-directory +subcategory: "Trust Abuse" tags: ["active-directory", "kerberos", "credential-access", "privilege-escalation", "hashing"] tools: ["Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-69-forest-trust-abuse-cross-forest-ticket-forging.md b/src/content/sheets/active-directory/attack-69-forest-trust-abuse-cross-forest-ticket-forging.md @@ -2,6 +2,7 @@ title: "Attack #69 — Forest Trust Abuse Cross-Forest Ticket Forging" description: "When two forests have a forest trust, users from one forest can access resources in the other (if explicitly permitted). An attacker who compromises the…" category: active-directory +subcategory: "Trust Abuse" tags: ["active-directory", "kerberos", "credential-access", "hashing"] tools: ["Impacket", "Mimikatz", "Rubeus", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-7-ntlm-relay-attacks.md b/src/content/sheets/active-directory/attack-7-ntlm-relay-attacks.md @@ -2,6 +2,7 @@ title: "Attack #7 — NTLM Relay Attacks" description: "NTLM relay is a man-in-the-middle attack that intercepts an NTLM authentication challenge-response in transit and forwards it to a different target before…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "kerberos", "ntlm", "relay", "hashing"] tools: ["Nmap", "NetExec", "Impacket", "Rubeus", "Hashcat"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-70-adcs-cross-domain-enrollment.md b/src/content/sheets/active-directory/attack-70-adcs-cross-domain-enrollment.md @@ -2,6 +2,7 @@ title: "Attack #70 — ADCS Cross-Domain Enrollment" description: "When ADCS is deployed in a multi-domain forest, certificate enrollment often uses Enterprise CAs that serve the entire forest. A user from a child domain…" category: active-directory +subcategory: "Trust Abuse" tags: ["active-directory", "adcs", "hashing"] tools: ["Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-71-pam-trust-abuse-bastion-forest.md b/src/content/sheets/active-directory/attack-71-pam-trust-abuse-bastion-forest.md @@ -2,6 +2,7 @@ title: "Attack #71 — PAM Trust Abuse (Bastion Forest)" description: "Get-ADTrust -Filter {TrustType -eq \"ForestTransitive\"} | Where ForestTransitive -eq $true netdom trust corp.local /domain:bastion.local /verify" category: active-directory +subcategory: "Trust Abuse" tags: ["active-directory", "privilege-escalation"] tools: ["PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-72-laps-password-extraction.md b/src/content/sheets/active-directory/attack-72-laps-password-extraction.md @@ -2,6 +2,7 @@ title: "Attack #72 — LAPS Password Extraction" description: "LAPS (Local Administrator Password Solution) stores unique, randomized local admin passwords in Active Directory attributes (ms-Mcs-AdmPwd for LAPS v1…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory"] tools: ["NetExec", "ldapsearch", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-73-gmsa-password-extraction.md b/src/content/sheets/active-directory/attack-73-gmsa-password-extraction.md @@ -2,6 +2,7 @@ title: "Attack #73 — gMSA Password Extraction" description: "Group Managed Service Accounts (gMSAs) have their passwords automatically managed by AD and stored in the msDS-ManagedPassword attribute. Principals…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory", "credential-access", "ntlm", "privilege-escalation", "hashing"] tools: ["NetExec", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-74-azure-ad-connect-credential-extraction.md b/src/content/sheets/active-directory/attack-74-azure-ad-connect-credential-extraction.md @@ -2,6 +2,7 @@ title: "Attack #74 — Azure AD Connect Credential Extraction" description: "Azure AD Connect synchronizes on-premises AD with Azure AD / Entra ID. The sync service stores a privileged AD account's credentials (the MSOL_ account or…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory", "credential-access", "privilege-escalation", "sql-injection"] tools: ["Impacket", "Mimikatz", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-75-sccm-mecm-exploitation.md b/src/content/sheets/active-directory/attack-75-sccm-mecm-exploitation.md @@ -2,6 +2,7 @@ title: "Attack #75 — SCCM MECM Exploitation" description: "Microsoft Endpoint Configuration Manager (MECM/SCCM) manages software deployment, patching, and configuration across enterprise environments. SCCM servers…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory", "lateral-movement"] tools: ["PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-76-mssql-server-and-linked-server-abuse.md b/src/content/sheets/active-directory/attack-76-mssql-server-and-linked-server-abuse.md @@ -2,6 +2,7 @@ title: "Attack #76 — MSSQL Server and Linked Server Abuse" description: "MSSQL servers in AD environments can be exploited for privilege escalation and lateral movement. Key techniques include: xp_cmdshell for RCE, linked…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement", "sql-injection"] tools: ["NetExec", "Impacket", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-77-dfscoerce-ms-dfsnm-coercion.md b/src/content/sheets/active-directory/attack-77-dfscoerce-ms-dfsnm-coercion.md @@ -2,6 +2,7 @@ title: "Attack #77 — DFSCoerce MS-DFSNM Coercion" description: "DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) protocol to coerce a target machine (typically a DC) into authenticating to…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory", "adcs", "ntlm", "relay"] tools: [] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-78-ad-recycle-bin-object-abuse.md b/src/content/sheets/active-directory/attack-78-ad-recycle-bin-object-abuse.md @@ -2,6 +2,7 @@ title: "Attack #78 — AD Recycle Bin Object Abuse" description: "When the AD Recycle Bin feature is enabled (Server 2008 R2+), deleted AD objects are moved to the CN=Deleted Objects container and retained for a…" category: active-directory +subcategory: "Advanced & Post-Exploitation" tags: ["active-directory", "privilege-escalation"] tools: ["NetExec", "ldapsearch", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-8-llmnr-nbt-ns-mdns-poisoning.md b/src/content/sheets/active-directory/attack-8-llmnr-nbt-ns-mdns-poisoning.md @@ -2,6 +2,7 @@ title: "Attack #8 — LLMNR NBT-NS mDNS Poisoning" description: "LLMNR (Link-Local Multicast Name Resolution), NBT-NS (NetBIOS Name Service), and mDNS (Multicast DNS) are fallback name resolution protocols built into…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "ntlm", "relay", "hashing"] tools: ["Nmap", "NetExec", "Impacket", "Hashcat", "John"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack-9-mitm6-ipv6-dns-spoofing-dhcpv6-takeover.md b/src/content/sheets/active-directory/attack-9-mitm6-ipv6-dns-spoofing-dhcpv6-takeover.md @@ -2,6 +2,7 @@ title: "Attack #9 — mitm6 (IPv6 DNS Spoofing DHCPv6 Takeover)" description: "mitm6 exploits a fundamental default behaviour of Windows: even in networks that have never deployed IPv6, every Windows machine continuously sends DHCPv6…" category: active-directory +subcategory: "Credential Access" tags: ["active-directory", "credential-access", "ntlm", "relay"] tools: ["Nmap", "NetExec", "Impacket", "Rubeus", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/attack.md b/src/content/sheets/active-directory/attack.md @@ -1,11 +0,0 @@ ---- -title: "Attack" -description: "Attack — operator reference." -category: active-directory -tags: ["active-directory"] -tools: [] -difficulty: advanced -updated: "2026-08-10" -source: "vault:ActiveDirectory/AD-Attack/Category-Five/🔵 Attack.md" ---- - diff --git a/src/content/sheets/active-directory/bloodhound-ce-python.md b/src/content/sheets/active-directory/bloodhound-ce-python.md @@ -2,6 +2,7 @@ title: "bloodhound-ce-python" description: "pipx install bloodhound-ce # provides bloodhound-ce-python" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory", "kerberos"] tools: ["Nmap", "Impacket", "BloodHound", "faketime"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/bloodhound-python.md b/src/content/sheets/active-directory/bloodhound-python.md @@ -2,6 +2,7 @@ title: "BloodHound-Python_" description: "bloodhound-python --help" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory", "kerberos"] tools: ["Nmap", "NetExec", "Impacket", "BloodHound", "SharpHound"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/bloodhound.md b/src/content/sheets/active-directory/bloodhound.md @@ -2,6 +2,7 @@ title: "BloodHound" description: "BloodHound data collection and analysis with the Python ingestor plus cypher query patterns." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, graph, enumeration] tools: [BloodHound, bloodhound-python] difficulty: intermediate diff --git a/src/content/sheets/active-directory/bloodyad.md b/src/content/sheets/active-directory/bloodyad.md @@ -2,6 +2,7 @@ title: "BloodyAD" description: "BloodyAD LDAP privilege-abuse toolkit: RBCD, shadow creds, DACL edits, password/attribute writes." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, ldap, acl-abuse] tools: [BloodyAD] difficulty: intermediate diff --git a/src/content/sheets/active-directory/certificate-persistence-certifried-cve-2022-26923.md b/src/content/sheets/active-directory/certificate-persistence-certifried-cve-2022-26923.md @@ -2,6 +2,7 @@ title: "Certificate Persistence — Certifried (CVE-2022-26923)" description: "Certifried is a privilege escalation vulnerability discovered by Oliver Lyak (the same researcher who wrote Certipy) and disclosed in May 2022. It carries…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "credential-access", "privilege-escalation", "persistence"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/certipy-ad.md b/src/content/sheets/active-directory/certipy-ad.md @@ -2,6 +2,7 @@ title: "Certipy-ad" description: "pip install certipy-ad --break-system-packages" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory", "kerberos", "adcs", "hashing"] tools: ["Certipy", "BloodHound", "Evil-WinRM", "OpenSSL"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/certipy.md b/src/content/sheets/active-directory/certipy.md @@ -2,6 +2,7 @@ title: "Certipy" description: "Certipy ADCS enumeration and ESC exploitation: template abuse, PKINIT, golden certificate, shadow creds." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, adcs, certificates] tools: [Certipy] difficulty: advanced diff --git a/src/content/sheets/active-directory/dpersist2-rogue-ca-certificate-ntauth-injection.md b/src/content/sheets/active-directory/dpersist2-rogue-ca-certificate-ntauth-injection.md @@ -2,6 +2,7 @@ title: "DPERSIST2 — Rogue CA Certificate (NTAuth Injection)" description: "The forest trusts any certificate chaining to a CA published in the NTAuthCertificates object for domain authentication. Normally that list holds only the…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "persistence"] tools: ["Certipy", "OpenSSL", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/dpersist3-malicious-misconfiguration-acl-backdoor.md b/src/content/sheets/active-directory/dpersist3-malicious-misconfiguration-acl-backdoor.md @@ -2,6 +2,7 @@ title: "DPERSIST3 — Malicious Misconfiguration (ACL Backdoor)" description: "Instead of forging certs now, DPERSIST3 backdoors the PKI ACLs so you can re-escalate whenever you like. You grant an attacker-controlled principal…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "delegation", "privilege-escalation", "persistence"] tools: ["Certipy", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc1-san-specification-in-template.md b/src/content/sheets/active-directory/esc1-san-specification-in-template.md @@ -2,6 +2,7 @@ title: "ESC1 — SAN Specification in Template" description: "ESC1 is the most commonly encountered and most directly exploitable ADCS misconfiguration. The vulnerability exists at the certificate template level —…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation", "hashing"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc10-weak-certificate-mapping.md b/src/content/sheets/active-directory/esc10-weak-certificate-mapping.md @@ -2,6 +2,7 @@ title: "ESC10 — Weak Certificate Mapping" description: "ESC10 exploits weak certificate-to-account mapping enforcement on the Domain Controller. When the DC receives a certificate for authentication, it must…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "kerberos", "adcs"] tools: ["NetExec", "Certipy", "BloodHound", "Evil-WinRM"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc11-ntlm-relay-to-adcs-rpc-icpr.md b/src/content/sheets/active-directory/esc11-ntlm-relay-to-adcs-rpc-icpr.md @@ -2,6 +2,7 @@ title: "ESC11 — NTLM Relay to ADCS RPC (ICPR)" description: "ESC11 is the RPC-based sibling of ESC8. Where ESC8 relays NTLM credentials to the CA's HTTP Web Enrollment endpoint, ESC11 relays them to the CA's RPC…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "ntlm", "relay"] tools: ["Impacket", "Certipy", "Metasploit", "Evil-WinRM", "Certify"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc12-shell-access-to-ca-with-yubihsm.md b/src/content/sheets/active-directory/esc12-shell-access-to-ca-with-yubihsm.md @@ -2,6 +2,7 @@ title: "ESC12 — Shell Access to CA with YubiHSM" description: "ESC12 was disclosed by Hans-Joachim Knobloch and targets Certificate Authorities that use a Yubico YubiHSM2 hardware device for protecting their CA…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Impacket", "Certipy", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc13-issuance-policy-oid-group-link.md b/src/content/sheets/active-directory/esc13-issuance-policy-oid-group-link.md @@ -2,6 +2,7 @@ title: "ESC13 — Issuance Policy OID Group Link" description: "ESC13 is fundamentally different from every other ESC attack. Where ESC1–ESC12 focus on impersonating a specific user, ESC13 achieves privilege escalation…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Impacket", "Certipy", "BloodHound", "ldapsearch", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc14-weak-explicit-certificate-mapping.md b/src/content/sheets/active-directory/esc14-weak-explicit-certificate-mapping.md @@ -2,6 +2,7 @@ title: "ESC14 — Weak Explicit Certificate Mapping" description: "ESC14 targets the altSecurityIdentities attribute on AD user and computer objects. This multi-valued attribute is used for explicit certificate-to-account…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation", "hashing"] tools: ["Impacket", "Certipy", "BloodHound", "ldapsearch", "OpenSSL"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc15-ekuwu-cve-2024-49019.md b/src/content/sheets/active-directory/esc15-ekuwu-cve-2024-49019.md @@ -2,6 +2,7 @@ title: "ESC15 — EKUwu (CVE-2024-49019)" description: "ESC15, nicknamed EKUwu, was discovered by Justin Bollinger at TrustedSec in late September 2024 and assigned CVE-2024-49019 by Microsoft on November 12…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["NetExec", "Rubeus", "Certipy", "Evil-WinRM", "OpenSSL"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md b/src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md @@ -2,6 +2,7 @@ title: "ESC16 — Security Extension Disabled on CA (Globally)" description: "ESC16 was introduced with Certipy v5 by Oliver Lyak and is one of the newest ADCS attack techniques. The vulnerability exists when the CA has been…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Certipy", "BloodHound", "Evil-WinRM", "faketime", "Certify"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc17-adcs-certificate-spoofing-to-attack-https-enabled-wsus-clients.md b/src/content/sheets/active-directory/esc17-adcs-certificate-spoofing-to-attack-https-enabled-wsus-clients.md @@ -2,6 +2,7 @@ title: "ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients" description: "ESC17 was coined by researchers Alexander Neff and Phil Knüfer at DigiTrace in January 2026. Unlike ESC1–ESC16 which target domain privilege escalation…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement"] tools: ["NetExec", "Impacket", "Certipy", "Responder", "OpenSSL"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc2-any-purpose-eku-no-eku-the-swiss-certificate.md b/src/content/sheets/active-directory/esc2-any-purpose-eku-no-eku-the-swiss-certificate.md @@ -2,6 +2,7 @@ title: "ESC2 — Any Purpose EKU No EKU (The Swiss Certificate)" description: "ESC2 gets its nickname \"The Swiss Certificate\" because a certificate issued from a vulnerable template can be used for any purpose — client auth, server…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Rubeus", "Certipy", "Evil-WinRM", "OpenSSL", "Certify"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc3-misconfigured-enrollment-agent-templates.md b/src/content/sheets/active-directory/esc3-misconfigured-enrollment-agent-templates.md @@ -2,6 +2,7 @@ title: "ESC3 — Misconfigured Enrollment Agent Templates" description: "ESC3 exploits the Certificate Request Agent EKU (OID 1.3.6.1.4.1.311.20.2.1). In legitimate AD environments, this EKU exists for scenarios like IT…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Mimikatz", "Rubeus", "Certipy", "Evil-WinRM", "OpenSSL"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc4-vulnerable-certificate-template-access-control.md b/src/content/sheets/active-directory/esc4-vulnerable-certificate-template-access-control.md @@ -2,6 +2,7 @@ title: "ESC4 — Vulnerable Certificate Template Access Control" description: "ESC4 is a permission-level attack, not a template configuration attack. Every ESC attack up to this point (ESC1–3) abused what a template was configured…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Rubeus", "Certipy", "BloodHound", "Evil-WinRM", "OpenSSL"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc5-vulnerable-pki-object-access-control.md b/src/content/sheets/active-directory/esc5-vulnerable-pki-object-access-control.md @@ -2,6 +2,7 @@ title: "ESC5 — Vulnerable PKI Object Access Control" description: "ESC5 is a broad category of permission-level attacks against the various Active Directory objects that comprise the PKI infrastructure. Unlike ESC4 which…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "pivoting"] tools: ["Impacket", "Certipy", "BloodHound", "OpenSSL", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc6-editf-attributesubjectaltname2-flag.md b/src/content/sheets/active-directory/esc6-editf-attributesubjectaltname2-flag.md @@ -2,6 +2,7 @@ title: "ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag" description: "certutil -config \"CA-SERVER\\DOMAIN-CA\" -getreg policy\\EditFlags" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Impacket", "Mimikatz", "Rubeus", "Certipy", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc7-vulnerable-ca-access-control-manageca-managecertificates.md b/src/content/sheets/active-directory/esc7-vulnerable-ca-access-control-manageca-managecertificates.md @@ -2,6 +2,7 @@ title: "ESC7 — Vulnerable CA Access Control (ManageCA ManageCertificates)" description: "ESC7 is a CA-level access control attack. Where ESC4 abused write permissions on a template object, ESC7 abuses dangerous permissions on the Certificate…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Rubeus", "Certipy", "BloodHound", "Metasploit", "Evil-WinRM"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc8-ntlm-relay-to-adcs-http-web-enrollment.md b/src/content/sheets/active-directory/esc8-ntlm-relay-to-adcs-http-web-enrollment.md @@ -2,6 +2,7 @@ title: "ESC8 — NTLM Relay to ADCS HTTP Web Enrollment" description: "ESC8 is a network-level NTLM relay attack against the ADCS Web Enrollment HTTP interface. Every ESC attack up to this point required you to already have…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "credential-access", "ntlm", "relay"] tools: ["Impacket", "Mimikatz", "Rubeus", "Certipy", "Evil-WinRM"] difficulty: advanced diff --git a/src/content/sheets/active-directory/esc9-no-security-extension-template-level.md b/src/content/sheets/active-directory/esc9-no-security-extension-template-level.md @@ -2,6 +2,7 @@ title: "ESC9 — No Security Extension (Template-Level)" description: "ESC9 is the template-level version of ESC16. Where ESC16 disabled the szOID_NTDS_CA_SECURITY_EXT SID extension globally across every certificate on the…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["NetExec", "Impacket", "Rubeus", "Certipy", "BloodHound"] difficulty: advanced diff --git a/src/content/sheets/active-directory/faketime.md b/src/content/sheets/active-directory/faketime.md @@ -2,6 +2,7 @@ title: "faketime" description: "sudo apt install faketime # ships as libfaketime" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory", "kerberos"] tools: ["Nmap", "NetExec", "Impacket", "Certipy", "BloodHound"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/golden-certificate-attack-dpersist1.md b/src/content/sheets/active-directory/golden-certificate-attack-dpersist1.md @@ -2,6 +2,7 @@ title: "Golden Certificate Attack — DPERSIST1" description: "The Golden Certificate Attack is a domain persistence technique — not a privilege escalation. By the time you execute this attack, you have already fully…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "kerberos", "adcs", "privilege-escalation", "persistence"] tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "Certipy"] difficulty: advanced diff --git a/src/content/sheets/active-directory/impacket.md b/src/content/sheets/active-directory/impacket.md @@ -2,6 +2,7 @@ title: "Impacket" description: "Impacket suite: secretsdump, psexec/wmiexec, GetUserSPNs, ntlmrelayx, ticketer, smbserver and more." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, smb, credentials, lateral-movement] tools: [Impacket] difficulty: intermediate diff --git a/src/content/sheets/active-directory/kerberoasting-local-on-host.md b/src/content/sheets/active-directory/kerberoasting-local-on-host.md @@ -2,6 +2,7 @@ title: "Kerberoasting — Local On-Host" description: "[1] Enumerate SPNs → [2] Request TGS Ticket → [3] Extract Hash → [4] Crack Offline" category: active-directory +subcategory: "Kerberos & Delegation" tags: ["active-directory", "kerberos", "sql-injection", "hashing"] tools: ["Impacket", "Mimikatz", "Rubeus", "Hashcat", "John"] difficulty: advanced diff --git a/src/content/sheets/active-directory/kerberoasting.md b/src/content/sheets/active-directory/kerberoasting.md @@ -2,6 +2,7 @@ title: "Kerberoasting" description: "Request and crack SPN service tickets: GetUserSPNs, Rubeus, hashcat modes and mitigation notes." category: active-directory +subcategory: "Kerberos & Delegation" tags: [active-directory, kerberos, cracking] tools: [Impacket, Rubeus, Hashcat] difficulty: intermediate diff --git a/src/content/sheets/active-directory/kerbrute.md b/src/content/sheets/active-directory/kerbrute.md @@ -2,6 +2,7 @@ title: "Kerbrute" description: "Kerbrute Kerberos pre-auth user enumeration and password spraying against a domain controller." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, kerberos, enumeration, spraying] tools: [Kerbrute] difficulty: beginner diff --git a/src/content/sheets/active-directory/ldap-enumeration.md b/src/content/sheets/active-directory/ldap-enumeration.md @@ -2,6 +2,7 @@ title: "LDAP Enumeration" description: "Manual ldapsearch queries to enumerate AD: users, groups, computers, ACLs, SPNs and attributes." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, ldap, enumeration] tools: [ldapsearch] difficulty: intermediate diff --git a/src/content/sheets/active-directory/ldap-search.md b/src/content/sheets/active-directory/ldap-search.md @@ -2,6 +2,7 @@ title: "LDAP Search" description: "Here's the updated cheat sheet using the specific credentials from the Support box:" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory"] tools: ["NetExec", "BloodHound", "ldapsearch"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/ldapdomaindump.md b/src/content/sheets/active-directory/ldapdomaindump.md @@ -2,6 +2,7 @@ title: "ldapdomaindump" description: "pip3 install ldapdomaindump" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory"] tools: ["Nmap", "NetExec", "BloodHound", "ldapsearch", "Evil-WinRM"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/mimikatz.md b/src/content/sheets/active-directory/mimikatz.md @@ -2,6 +2,7 @@ title: "Mimikatz" description: "Mimikatz credential extraction: sekurlsa, LSA dumps, DCSync, pass-the-hash/ticket, golden/silver tickets." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, credentials, kerberos] tools: [Mimikatz] difficulty: intermediate diff --git a/src/content/sheets/active-directory/netexec.md b/src/content/sheets/active-directory/netexec.md @@ -2,6 +2,7 @@ title: "NetExec (nxc)" description: "NetExec/CrackMapExec successor: SMB/WinRM/LDAP/MSSQL sweeps, cred spraying, dumping and modules." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, smb, credentials, enumeration] tools: [NetExec, nxc] difficulty: intermediate diff --git a/src/content/sheets/active-directory/persist1-active-user-credential-theft-via-certificates.md b/src/content/sheets/active-directory/persist1-active-user-credential-theft-via-certificates.md @@ -2,6 +2,7 @@ title: "PERSIST1 — Active User Credential Theft via Certificates" description: "The core persistence property of certificates: a certificate is valid until it expires or is revoked, independent of the account's password. If you enrol…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "persistence", "hashing"] tools: ["Certipy", "Certify", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/persist2-machine-account-persistence-via-certificates.md b/src/content/sheets/active-directory/persist2-machine-account-persistence-via-certificates.md @@ -2,6 +2,7 @@ title: "PERSIST2 — Machine Account Persistence via Certificates" description: "Machine accounts rotate their password automatically every ~30 days, which normally limits how long a stolen machine hash stays useful. A certificate…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "kerberos", "adcs", "credential-access", "persistence"] tools: ["Certipy", "Certify", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/persist3-account-persistence-via-certificate-renewal.md b/src/content/sheets/active-directory/persist3-account-persistence-via-certificate-renewal.md @@ -2,6 +2,7 @@ title: "PERSIST3 — Account Persistence via Certificate Renewal" description: "Templates that allow renewal let a holder present their current certificate and receive a fresh one with a new validity window, authenticated by the…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "persistence"] tools: ["Certipy", "OpenSSL", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/rubeus.md b/src/content/sheets/active-directory/rubeus.md @@ -2,6 +2,7 @@ title: "Rubeus" description: "Rubeus Kerberos abuse: kerberoast, asreproast, ticket forging, S4U, pass-the-ticket, overpass-the-hash." category: active-directory +subcategory: "Tooling & Recon" tags: [active-directory, kerberos, tickets] tools: [Rubeus] difficulty: advanced diff --git a/src/content/sheets/active-directory/shadow-credentials-msds-keycredentiallink-abuse.md b/src/content/sheets/active-directory/shadow-credentials-msds-keycredentiallink-abuse.md @@ -2,6 +2,7 @@ title: "Shadow Credentials — msDS-KeyCredentialLink Abuse" description: "Windows Hello for Business / Key Trust lets an account authenticate with a public/private key pair stored in the AD attribute msDS-KeyCredentialLink. If…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "ntlm", "relay", "lateral-movement"] tools: ["Rubeus", "Certipy", "BloodHound", "faketime"] difficulty: advanced diff --git a/src/content/sheets/active-directory/sharphound.md b/src/content/sheets/active-directory/sharphound.md @@ -2,6 +2,7 @@ title: "SharpHound_" description: "⚠️ Note: Make sure your SharpHound version matches your BloodHound version! You can check the compatible version in BloodHound CE's web UI under Settings…" category: active-directory +subcategory: "Tooling & Recon" tags: ["active-directory", "adcs", "privilege-escalation"] tools: ["Impacket", "BloodHound", "SharpHound", "Evil-WinRM", "Certify"] difficulty: intermediate diff --git a/src/content/sheets/active-directory/theft1-exporting-certificates-and-keys.md b/src/content/sheets/active-directory/theft1-exporting-certificates-and-keys.md @@ -2,6 +2,7 @@ title: "THEFT1 — Exporting Certificates and Keys" description: "THEFT1 is the simplest credential-theft primitive in the ADCS taxonomy: harvest certificates that are already enrolled on a machine you control, rather…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["Mimikatz", "Certipy", "faketime", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/theft2-user-certificate-theft-via-dpapi.md b/src/content/sheets/active-directory/theft2-user-certificate-theft-via-dpapi.md @@ -2,6 +2,7 @@ title: "THEFT2 — User Certificate Theft via DPAPI" description: "Windows protects user certificate private keys with DPAPI (Data Protection API). The encrypted key blobs live on disk; decrypting them normally requires…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs", "hashing"] tools: ["Mimikatz", "Certipy", "OpenSSL", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/theft3-machine-certificate-theft-via-dpapi.md b/src/content/sheets/active-directory/theft3-machine-certificate-theft-via-dpapi.md @@ -2,6 +2,7 @@ title: "THEFT3 — Machine Certificate Theft via DPAPI" description: "Identical concept to THEFT2 — User Certificate Theft via DPAPI but for machine certificates. These are protected by the machine DPAPI masterkey, which is…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "kerberos", "adcs", "credential-access", "privilege-escalation"] tools: ["Mimikatz", "Certipy", "PowerShell"] difficulty: advanced diff --git a/src/content/sheets/active-directory/theft4-finding-certificate-files.md b/src/content/sheets/active-directory/theft4-finding-certificate-files.md @@ -2,6 +2,7 @@ title: "THEFT4 — Finding Certificate Files" description: "No cryptography needed here. Admins and automation constantly leave certificate material lying around: exported .pfx backups, id_rsa-style key files…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "adcs"] tools: ["NetExec", "Certipy", "John", "Snaffler", "OpenSSL"] difficulty: advanced diff --git a/src/content/sheets/active-directory/theft5-ntlm-theft-via-pkinit-unpac-the-hash.md b/src/content/sheets/active-directory/theft5-ntlm-theft-via-pkinit-unpac-the-hash.md @@ -2,6 +2,7 @@ title: "THEFT5 — NTLM Theft via PKINIT (UnPAC-the-Hash)" description: "When you authenticate with a certificate via PKINIT, the KDC returns a TGT whose PAC contains the account's NTLM hash (so the account can later do NTLM…" category: active-directory +subcategory: "ADCS & Certificates" tags: ["active-directory", "kerberos", "adcs", "ntlm", "hashing"] tools: ["Rubeus", "Certipy", "Evil-WinRM", "faketime", "PowerShell"] difficulty: advanced diff --git a/src/pages/[category]/index.astro b/src/pages/[category]/index.astro @@ -22,24 +22,75 @@ export async function getStaticPaths() { interface Props { cat: CategoryDef; items: Sheet[]; n: string } const { cat, items, n } = Astro.props; -/* The ledger counts what the page can actually count. Difficulty spread is - the one figure a reader uses to decide where to start in a domain. */ +/* Kill-chain order for the sub-sections. A sheet whose subcategory isn't + listed falls to the end under its own name; a category with no + subcategories at all (every domain except Active Directory today) renders + one flat index, exactly as before. */ +const SUBCAT_ORDER = [ + 'Credential Access', + 'Kerberos & Delegation', + 'ACL Abuse', + 'ADCS & Certificates', + 'Domain Controller Attacks', + 'Privilege & Group Abuse', + 'Lateral Movement', + 'Persistence', + 'Trust Abuse', + 'Advanced & Post-Exploitation', + 'Tooling & Recon', +]; + +/* Within a section: numbered techniques first (attack-2 before attack-40, + esc1 before esc10 — numeric, not lexical), then everything else A→Z. The + prefix rank keeps all attack-* together, then all esc-*, and so on. */ +const PFX_RANK: Record<string, number> = { attack: 0, esc: 1, persist: 2, theft: 3, dpersist: 4 }; +function sortKey(entry: Sheet): [number, number, number, string] { + const slug = entry.id.split('/').pop() ?? ''; + const m = slug.match(/^([a-z]+)-?(\d+)/); + if (m && m[1] in PFX_RANK) return [0, PFX_RANK[m[1]], parseInt(m[2], 10), slug]; + return [1, 0, 0, (entry.data.title || slug).toLowerCase()]; +} +function cmp(a: Sheet, b: Sheet) { + const ka = sortKey(a), kb = sortKey(b); + for (let i = 0; i < ka.length; i++) { + if (ka[i] < kb[i]) return -1; + if (ka[i] > kb[i]) return 1; + } + return 0; +} + +const hasSubcats = items.some((s) => s.data.subcategory); +type Group = { name: string; items: Sheet[] }; +let groups: Group[] = []; +if (hasSubcats) { + const buckets = new Map<string, Sheet[]>(); + for (const s of items) { + const key = s.data.subcategory ?? 'Other'; + (buckets.get(key) ?? buckets.set(key, []).get(key)!).push(s); + } + const ordered = [ + ...SUBCAT_ORDER.filter((k) => buckets.has(k)), + ...[...buckets.keys()].filter((k) => !SUBCAT_ORDER.includes(k)).sort(), + ]; + groups = ordered.map((name) => ({ name, items: [...buckets.get(name)!].sort(cmp) })); +} + const byDifficulty = (level: string) => items.filter((s) => s.data.difficulty === level).length; const tools = new Set(items.flatMap((s) => s.data.tools)); +const bannerStats = [ + { label: 'Sheets', value: String(items.length).padStart(2, '0'), accent: true }, + ...(hasSubcats + ? [{ label: 'Sections', value: String(groups.length).padStart(2, '0') }] + : [{ label: 'Tools covered', value: String(tools.size).padStart(2, '0') }]), + { label: 'Beginner / adv', value: `${byDifficulty('beginner')} / ${byDifficulty('advanced')}` }, +]; + +/* Section accents cycle the palette so the sub-headers read as a colour + run down the page, the same key the masthead and marquee use. */ +const SECTION_ACCENTS = ['iris', 'foam', 'love', 'gold', 'rose', 'pine']; --- <Base title={`${cat.title} — DÆMON//SEC`} description={cat.blurb}> - <SectionBanner - n={n} - label={cat.tag} - title={cat.title} - blurb={cat.blurb} - accent={cat.accent} - stats={[ - { label: 'Sheets', value: String(items.length).padStart(2, '0'), accent: true }, - { label: 'Tools covered', value: String(tools.size).padStart(2, '0') }, - { label: 'Beginner / adv', value: `${byDifficulty('beginner')} / ${byDifficulty('advanced')}` }, - ]} - /> + <SectionBanner n={n} label={cat.tag} title={cat.title} blurb={cat.blurb} accent={cat.accent} stats={bannerStats} /> <div class="wrap"> <nav class="breadcrumb" style="margin-top:1.6rem;"> @@ -49,7 +100,16 @@ const tools = new Set(items.flatMap((s) => s.data.tools)); <div style="margin:1.4rem 0 2rem;"><CategoryNav active={cat.slug} /></div> - {items.length > 0 ? ( + {items.length === 0 && ( + <div class="slab" style="margin:1.5rem 0 3rem; padding:1.2rem 1.3rem;"> + <p class="muted mono" style="font-size:0.85rem;"> + No sheets in this domain yet. More landing soon — + <a class="accent-text" href={url('')}>back to the vault</a>. + </p> + </div> + )} + + {items.length > 0 && !hasSubcats && ( <div class="index" style="margin-bottom:3rem;"> {items.map((entry, i) => ( <RecordRow @@ -62,13 +122,45 @@ const tools = new Set(items.flatMap((s) => s.data.tools)); /> ))} </div> - ) : ( - <div class="slab" style="margin:1.5rem 0 3rem; padding:1.2rem 1.3rem;"> - <p class="muted mono" style="font-size:0.85rem;"> - No sheets in this domain yet. More landing soon — - <a class="accent-text" href={url('')}>back to the vault</a>. - </p> + )} + + {items.length > 0 && hasSubcats && ( + <div style="margin-bottom:3rem;"> + {groups.map((g, gi) => { + const acc = SECTION_ACCENTS[gi % SECTION_ACCENTS.length]; + return ( + <section class="subcat" id={`s-${gi}`}> + <div class="section-head" style="margin-bottom:0.9rem;"> + <div> + <p class="eyebrow" style={`--acc: var(--${acc});`}> + <span class="eyebrow__n">{String(gi + 1).padStart(2, '0')}</span> + <span class="eyebrow__mark">^:</span> + <span>{g.items.length} {g.items.length === 1 ? 'sheet' : 'sheets'}</span> + <span class="eyebrow__rule" aria-hidden="true"></span> + </p> + <h2>{g.name}</h2> + </div> + </div> + <div class="index"> + {g.items.map((entry, i) => ( + <RecordRow + href={url(sheetHref(entry))} + n={String(i + 1).padStart(2, '0')} + title={entry.data.title} + kind={entry.data.difficulty} + accent={acc} + meta={entry.data.updated ?? entry.id.split('/').pop()} + /> + ))} + </div> + </section> + ); + })} </div> )} </div> </Base> + +<style> + .subcat + .subcat { margin-top: clamp(2.2rem, 4.5vw, 3.4rem); } +</style>