daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adds-enumerate.md (17854B)


      1 ---
      2 title: "Active Directory - Enumeration"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adds-enumerate.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-enumerate.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Enumeration
     12 
     13 ## Using BloodHound
     14 
     15 Use the appropriate data collector to gather information for **BloodHound** or **BloodHound Community Edition (CE)** across various platforms.
     16 
     17 * [BloodHoundAD/AzureHound](https://github.com/BloodHoundAD/AzureHound) for Azure Active Directory
     18 * [BloodHoundAD/SharpHound](https://github.com/BloodHoundAD/SharpHound) for local Active Directory (C# collector)
     19 * [FalconForceTeam/SOAPHound](https://github.com/FalconForceTeam/SOAPHound) for local Active Directory (C# collector using ADWS)
     20 * [g0h4n/RustHound-CE](https://github.com/g0h4n/RustHound-CE) for local Active Directory (Rust collector)
     21 * [NH-RED-TEAM/RustHound](https://github.com/NH-RED-TEAM/RustHound) for local Active Directory (Rust collector)
     22 * [fox-it/BloodHound.py](https://github.com/fox-it/BloodHound.py) for local Active Directory (Python collector)
     23 * [coffeegist/bofhound](https://github.com/coffeegist/bofhound) for local Active Directory  (Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel)
     24 * [c3c/ADExplorerSnapshot.py](https://github.com/c3c/ADExplorerSnapshot.py) for local Active Directory (Generate BloodHound compatible JSON from AD Explorer snapshot)
     25 * [CrowdStrike/sccmhound](https://github.com/CrowdStrike/sccmhound) for local Active Directory (C# collector using Microsoft Configuration Manager)
     26 * [SpecterOps/MSSQLHound](https://github.com/SpecterOps/MSSQLHound) for MSSQL attack paths (BloodHound OpenGraph PowerShell collector)
     27 * [SpecterOps/SnowHound](https://github.com/SpecterOps/SnowHound) for Snowflake attack paths (BloodHound OpenGraph PowerShell collector)
     28 * [SpecterOps/GitHound](https://github.com/SpecterOps/GitHound) for GitHub attack paths (BloodHound OpenGraph PowerShell collector)
     29 * [SpecterOps/1PassHound](https://github.com/SpecterOps/1PassHound) for 1Password attack paths (BloodHound OpenGraph PowerShell collector)
     30 * [TheSleekBoyCompany/AnsibleHound](https://github.com/TheSleekBoyCompany/AnsibleHound) for Ansible WorX and Ansible Tower attack paths (BloodHound OpenGraph Go collector)
     31 * [p0dalirius/sharehound](https://github.com/p0dalirius/sharehound) - for Network Shares attack paths (BloodHound OpenGraph Python collector)
     32 * [C0KERNEL/SecretHound](https://github.com/C0KERNEL/SecretHound) - for secrets (BloodHound OpenGraph Python collector)
     33 * [F41zK4r1m/GCP-Hound](https://github.com/F41zK4r1m/GCP-Hound) - for GCP attack path (BloodHound OpenGraph Python collector)
     34 * [SpecterOps/ConfigManBearPig](https://github.com/SpecterOps/ConfigManBearPig) - for SCCM attack path (BloodHound OpenGraph PowerShell collector)
     35 
     36 **Examples**:
     37 
     38 * Use [BloodHoundAD/AzureHound](https://github.com/BloodHoundAD/AzureHound) (more info: [Cloud - Azure Pentest](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md#azure-recon-tools))
     39 
     40 * Use [BloodHoundAD/SharpHound.exe](https://github.com/BloodHoundAD/BloodHound) - run the collector on the machine using SharpHound.exe
     41 
     42   ```powershell
     43   .\SharpHound.exe -c all -d active.htb --searchforest
     44   .\SharpHound.exe -c all,GPOLocalGroup # all collection doesn't include GPOLocalGroup by default
     45   .\SharpHound.exe --CollectionMethod DCOnly # only collect from the DC, doesn't query the computers (more stealthy)
     46 
     47   .\SharpHound.exe -c all --LdapUsername <UserName> --LdapPassword <Password> --JSONFolder <PathToFile>
     48   .\SharpHound.exe -c all --LdapUsername <UserName> --LdapPassword <Password> --domaincontroller 10.10.10.100 -d active.htb
     49 
     50   .\SharpHound.exe -c All,GPOLocalGroup --outputdirectory C:\Windows\Temp --prettyprint --randomfilenames --collectallproperties --throttle 10000 --jitter 23  --outputprefix internalallthething
     51   ```
     52 
     53 * Use [BloodHoundAD/SharpHound.ps1](https://github.com/BloodHoundAD/BloodHound/blob/master/Collectors/SharpHound.ps1) - run the collector on the machine using Powershell
     54 
     55   ```powershell
     56   Invoke-BloodHound -SearchForest -CSVFolder C:\Users\Public
     57   Invoke-BloodHound -CollectionMethod All  -LDAPUser <UserName> -LDAPPass <Password> -OutputDirectory <PathToFile>
     58   ```
     59 
     60 * Use [ly4k/Certipy](https://github.com/ly4k/Certipy) to collect certificates data
     61 
     62   ```ps1
     63   certipy find 'corp.local/john:Passw0rd@dc.corp.local' -bloodhound
     64   certipy find 'corp.local/john:Passw0rd@dc.corp.local' -old-bloodhound
     65   certipy find 'corp.local/john:Passw0rd@dc.corp.local' -vulnerable -hide-admins -username user@domain -password Password123
     66   ```
     67 
     68 * Use [NH-RED-TEAM/RustHound](https://github.com/OPENCYBER-FR/RustHound)
     69 
     70   ```ps1
     71   # Windows with GSSAPI session
     72   rusthound.exe -d domain.local --ldapfqdn domain
     73   # Windows/Linux simple bind connection username:password
     74   rusthound.exe -d domain.local -u user@domain.local -p Password123 -o output -z
     75   # Linux with username:password and ADCS module for @ly4k BloodHound version
     76   rusthound -d domain.local -u 'user@domain.local' -p 'Password123' -o /tmp/adcs --adcs -z
     77   ```
     78 
     79 * Use [FalconForceTeam/SOAPHound](https://github.com/FalconForceTeam/SOAPHound)
     80 
     81   ```ps1
     82   --buildcache: Only build cache and not perform further actions
     83   --bhdump: Dump BloodHound data
     84   --certdump: Dump AD Certificate Services (ADCS) data
     85   --dnsdump: Dump AD Integrated DNS data
     86 
     87   SOAPHound.exe --buildcache -c c:\temp\cache.txt
     88   SOAPHound.exe -c c:\temp\cache.txt --bhdump -o c:\temp\bloodhound-output
     89   SOAPHound.exe -c c:\temp\cache.txt --bhdump -o c:\temp\bloodhound-output --autosplit --threshold 1000
     90   SOAPHound.exe -c c:\temp\cache.txt --certdump -o c:\temp\bloodhound-output
     91   SOAPHound.exe --dnsdump -o c:\temp\dns-output
     92   ```
     93 
     94 * Use [fox-it/BloodHound.py](https://github.com/fox-it/BloodHound.py)
     95 
     96   ```ps1
     97   pip install bloodhound
     98   bloodhound-python -d domain.local -u username -p password -gc LAB2008DC01.domain.local -c all
     99   ```
    100 
    101 * Use [c3c/ADExplorerSnapshot.py](https://github.com/c3c/ADExplorerSnapshot.py) to query data from SysInternals/ADExplorer snapshot  (ADExplorer remains a legitimate binary signed by Microsoft, avoiding detection with security solutions).
    102 
    103   ```py
    104   ADExplorerSnapshot.py <snapshot path> -o <*.json output folder path>
    105   ```
    106 
    107 Then import the zip/json files into the Neo4J database and query them.
    108 
    109 ```powershell
    110 root@payload$ apt install bloodhound 
    111 
    112 # start BloodHound and the database
    113 root@payload$ neo4j console
    114 # or use docker
    115 root@payload$ docker run -itd -p 7687:7687 -p 7474:7474 --env NEO4J_AUTH=neo4j/bloodhound -v $(pwd)/neo4j:/data neo4j:4.4-community
    116 
    117 root@payload$ ./bloodhound --no-sandbox
    118 Go to http://127.0.0.1:7474, use db:bolt://localhost:7687, user:neo4J, pass:neo4j
    119 ```
    120 
    121 NOTE: Currently BloodHound Community Edition is still a work in progress, it is highly recommended to stay on the original [BloodHoundAD/BloodHound](https://github.com/BloodHoundAD/BloodHound/) version.
    122 
    123 ```ps1
    124 git clone https://github.com/SpecterOps/BloodHound
    125 cd examples/docker-compose/
    126 cat docker-compose.yml | docker compose -f - up
    127 # UI: http://localhost:8080/ui/login
    128 # Username: admin
    129 # Password: see your Docker logs
    130 ```
    131 
    132 You can add some custom queries like :
    133 
    134 * [BloodHound Queries For All - SpecterOps](https://queries.specterops.io/)
    135 * [Bloodhound-Custom-Queries from @hausec](https://github.com/hausec/Bloodhound-Custom-Queries/blob/master/customqueries.json)
    136 * [BloodHoundQueries from CompassSecurity](https://github.com/CompassSecurity/BloodHoundQueries/blob/master/customqueries.json)
    137 * [BloodHound Custom Queries from Exegol - @ShutdownRepo](https://raw.githubusercontent.com/ThePorgs/Exegol-images/main/sources/assets/bloodhound/customqueries.json)
    138 * [Certipy BloodHound Custom Queries from ly4k](https://github.com/ly4k/Certipy/blob/main/customqueries.json)
    139 
    140 Replace the customqueries.json file located at `/home/username/.config/bloodhound/customqueries.json` or `C:\Users\USERNAME\AppData\Roaming\BloodHound\customqueries.json`.
    141 
    142 ## Using PowerView
    143   
    144 * **Get Current Domain:** `Get-NetDomain`
    145 * **Enum Other Domains:** `Get-NetDomain -Domain <DomainName>`
    146 * **Get Domain SID:** `Get-DomainSID`
    147 * **Get Domain Policy:**
    148 
    149   ```powershell
    150   Get-DomainPolicy
    151 
    152   #Will show us the policy configurations of the Domain about system access or kerberos
    153   (Get-DomainPolicy)."system access"
    154   (Get-DomainPolicy)."kerberos policy"
    155   ```
    156 
    157 * **Get Domain Controlers:**
    158 
    159   ```powershell
    160   Get-NetDomainController
    161   Get-NetDomainController -Domain <DomainName>
    162   ```
    163 
    164 * **Enumerate Domain Users:**
    165 
    166   ```powershell
    167   Get-NetUser
    168   Get-NetUser -SamAccountName <user> 
    169   Get-NetUser | select cn
    170   Get-UserProperty
    171 
    172   #Check last password change
    173   Get-UserProperty -Properties pwdlastset
    174 
    175   #Get a specific "string" on a user's attribute
    176   Find-UserField -SearchField Description -SearchTerm "wtver"
    177   
    178   #Enumerate user logged on a machine
    179   Get-NetLoggedon -ComputerName <ComputerName>
    180   
    181   #Enumerate Session Information for a machine
    182   Get-NetSession -ComputerName <ComputerName>
    183   
    184   #Enumerate domain machines of the current/specified domain where specific users are logged into
    185   Find-DomainUserLocation -Domain <DomainName> | Select-Object UserName, SessionFromName
    186   ```
    187 
    188 * **Enum Domain Computers:**
    189 
    190   ```powershell
    191   Get-NetComputer -FullData
    192   Get-DomainGroup
    193 
    194   #Enumerate Live machines 
    195   Get-NetComputer -Ping
    196   ```
    197 
    198 * **Enum Groups and Group Members:**
    199 
    200   ```powershell
    201   Get-NetGroupMember -GroupName "<GroupName>" -Domain <DomainName>
    202   
    203   #Enumerate the members of a specified group of the domain
    204   Get-DomainGroup -Identity <GroupName> | Select-Object -ExpandProperty Member
    205   
    206   #Returns all GPOs in a domain that modify local group memberships through Restricted Groups or Group Policy Preferences
    207   Get-DomainGPOLocalGroup | Select-Object GPODisplayName, GroupName
    208   ```
    209 
    210 * **Enumerate Shares**
    211 
    212   ```powershell
    213   #Enumerate Domain Shares
    214   Find-DomainShare
    215   
    216   #Enumerate Domain Shares the current user has access
    217   Find-DomainShare -CheckShareAccess
    218   ```
    219 
    220 * **Enum Group Policies:**
    221 
    222   ```powershell
    223   Get-NetGPO
    224 
    225   # Shows active Policy on specified machine
    226   Get-NetGPO -ComputerName <Name of the PC>
    227   Get-NetGPOGroup
    228 
    229   #Get users that are part of a Machine's local Admin group
    230   Find-GPOComputerAdmin -ComputerName <ComputerName>
    231   ```
    232 
    233 * **Enum OUs:**
    234 
    235   ```powershell
    236   Get-NetOU -FullData 
    237   Get-NetGPO -GPOname <The GUID of the GPO>
    238   ```
    239 
    240 * **Enum ACLs:**
    241 
    242   ```powershell
    243   # Returns the ACLs associated with the specified account
    244   Get-ObjectAcl -SamAccountName <AccountName> -ResolveGUIDs
    245   Get-ObjectAcl -ADSprefix 'CN=Administrator, CN=Users' -Verbose
    246 
    247   #Search for interesting ACEs
    248   Invoke-ACLScanner -ResolveGUIDs
    249 
    250   #Check the ACLs associated with a specified path (e.g smb share)
    251   Get-PathAcl -Path "\\Path\Of\A\Share"
    252   ```
    253 
    254 * **Enum Domain Trust:**
    255 
    256   ```powershell
    257   Get-NetDomainTrust
    258   Get-NetDomainTrust -Domain <DomainName>
    259   ```
    260 
    261 * **Enum Forest Trust:**
    262 
    263   ```powershell
    264   Get-NetForestDomain
    265   Get-NetForestDomain Forest <ForestName>
    266 
    267   #Domains of Forest Enumeration
    268   Get-NetForestDomain
    269   Get-NetForestDomain Forest <ForestName>
    270 
    271   #Map the Trust of the Forest
    272   Get-NetForestTrust
    273   Get-NetDomainTrust -Forest <ForestName>
    274   ```
    275 
    276 * **User Hunting:**
    277 
    278   ```powershell
    279   #Finds all machines on the current domain where the current user has local admin access
    280   Find-LocalAdminAccess -Verbose
    281 
    282   #Find local admins on all machines of the domain:
    283   Invoke-EnumerateLocalAdmin -Verbose
    284 
    285   #Find computers were a Domain Admin OR a specified user has a session
    286   Invoke-UserHunter
    287   Invoke-UserHunter -GroupName "RDPUsers"
    288   Invoke-UserHunter -Stealth
    289 
    290   #Confirming admin access:
    291   Invoke-UserHunter -CheckAccess
    292   ```
    293 
    294 ## Using AD Module
    295 
    296 * **Get Current Domain:** `Get-ADDomain`
    297 * **Enum Other Domains:** `Get-ADDomain -Identity <Domain>`
    298 * **Get Domain SID:** `Get-DomainSID`
    299 * **Get Domain Controlers:**
    300 
    301   ```powershell
    302   Get-ADDomainController
    303   Get-ADDomainController -Identity <DomainName>
    304   ```
    305   
    306 * **Enumerate Domain Users:**
    307 
    308   ```powershell
    309   Get-ADUser -Filter * -Identity <user> -Properties *
    310 
    311   #Get a specific "string" on a user's attribute
    312   Get-ADUser -Filter 'Description -like "*wtver*"' -Properties Description | select Name, Description
    313   ```
    314 
    315 * **Enum Domain Computers:**
    316 
    317   ```powershell
    318   Get-ADComputer -Filter * -Properties *
    319   Get-ADGroup -Filter * 
    320   ```
    321 
    322 * **Enum Domain Trust:**
    323 
    324   ```powershell
    325   Get-ADTrust -Filter *
    326   Get-ADTrust -Identity <DomainName>
    327   ```
    328 
    329 * **Enum Forest Trust:**
    330 
    331   ```powershell
    332   Get-ADForest
    333   Get-ADForest -Identity <ForestName>
    334 
    335   #Domains of Forest Enumeration
    336   (Get-ADForest).Domains
    337   ```
    338 
    339 * **Enum Local AppLocker Effective Policy:**
    340 
    341  ```powershell
    342  Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
    343  ```
    344 
    345 ## User Hunting
    346 
    347 Sometimes you need to find a machine where a specific user is logged in.
    348 You can remotely query every machines on the network to get a list of the users's sessions.
    349 
    350 * netexec
    351 
    352   ```ps1
    353   nxc smb 10.10.10.0/24 -u Administrator -p 'P@ssw0rd' --sessions
    354   SMB         10.10.10.10    445    WIN-8OJFTLMU1IG  [+] Enumerated sessions
    355   SMB         10.10.10.10    445    WIN-8OJFTLMU1IG  \\10.10.10.10            User:Administrator
    356   ```
    357 
    358 * Impacket Smbclient
    359 
    360   ```ps1
    361   $ impacket-smbclient Administrator@10.10.10.10
    362   # who
    363   host:  \\10.10.10.10, user: Administrator, active:     1, idle:     0
    364   ```
    365 
    366 * PowerView Invoke-UserHunter
    367 
    368   ```ps1
    369   # Find computers were a Domain Admin OR a specified user has a session
    370   Invoke-UserHunter
    371   Invoke-UserHunter -GroupName "RDPUsers"
    372   Invoke-UserHunter -Stealth
    373   ```
    374 
    375 ## RID cycling
    376 
    377 In Windows, every security principal (user, group, etc.) has a Security Identifier (SID). The SID is a unique identifier used for access control.
    378 
    379 ```ps1
    380 S-1-5-21-<domain>-<RID>
    381 ```
    382 
    383 * `S-1-5-21-<domain>` = Base domain SID
    384 * `<RID>` = Unique ID assigned to a user/group
    385 
    386 RID cycling involves brute-forcing a range of RIDs (like 500–1500) by appending them to the known domain SID, and attempting to resolve each SID into a username.
    387 
    388 * Using [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)
    389 
    390   ```ps1
    391   netexec smb 10.10.11.231 -u guest -p '' --rid-brute 10000 --log rid-brute.txt
    392   SMB         10.10.11.231    445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:rebound.htb) (signing:True) (SMBv1:False)
    393   SMB         10.10.11.231    445    DC01             [+] rebound.htb\guest: 
    394   SMB         10.10.11.231    445    DC01             498: rebound\Enterprise Read-only Domain Controllers (SidTypeGroup)
    395   SMB         10.10.11.231    445    DC01             500: rebound\Administrator (SidTypeUser)
    396   SMB         10.10.11.231    445    DC01             501: rebound\Guest (SidTypeUser)
    397   SMB         10.10.11.231    445    DC01             502: rebound\krbtgt (SidTypeUser)
    398   ```
    399 
    400 * Using Impacket script [impacket/lookupsid.py](https://github.com/fortra/impacket/blob/master/examples/lookupsid.py)
    401 
    402   ```ps1
    403   lookupsid.py -no-pass 'guest@rebound.htb' 20000
    404   ```
    405 
    406 ## Other Interesting Commands
    407 
    408 * **Find Domain Controllers**
    409 
    410   ```ps1
    411   nslookup domain.com
    412   nslookup -type=srv _ldap._tcp.dc._msdcs.<domain>.com
    413   nltest /dclist:domain.com
    414   Get-ADDomainController -filter * | Select-Object name
    415   gpresult /r
    416   $Env:LOGONSERVER 
    417   echo %LOGONSERVER%
    418   ```
    419 
    420 ## References
    421 
    422 * [Explain like I’m 5: Kerberos - Apr 2, 2013 - @roguelynn](https://www.roguelynn.com/words/explain-like-im-5-kerberos/)
    423 * [Pen Testing Active Directory Environments - Part I: Introduction to netexec (and PowerView)](https://blog.varonis.com/pen-testing-active-directory-environments-part-introduction-netexec-powerview/)
    424 * [Pen Testing Active Directory Environments - Part II: Getting Stuff Done With PowerView](https://blog.varonis.com/pen-testing-active-directory-environments-part-ii-getting-stuff-done-with-powerview/)
    425 * [Pen Testing Active Directory Environments - Part III:  Chasing Power Users](https://blog.varonis.com/pen-testing-active-directory-environments-part-iii-chasing-power-users/)
    426 * [Pen Testing Active Directory Environments - Part IV: Graph Fun](https://blog.varonis.com/pen-testing-active-directory-environments-part-iv-graph-fun/)
    427 * [Pen Testing Active Directory Environments - Part V: Admins and Graphs](https://blog.varonis.com/pen-testing-active-directory-v-admins-graphs/)
    428 * [Pen Testing Active Directory Environments - Part VI: The Final Case](https://blog.varonis.com/pen-testing-active-directory-part-vi-final-case/)
    429 * [Attacking Active Directory: 0 to 0.9 - Eloy Pérez González - 2021/05/29](https://zer1t0.gitlab.io/posts/attacking_ad/)
    430 * [Fun with LDAP, Kerberos (and MSRPC) in AD Environments](https://speakerdeck.com/ropnop/fun-with-ldap-kerberos-and-msrpc-in-ad-environments)
    431 * [Penetration Testing Active Directory, Part I - March 5, 2019 - Hausec](https://hausec.com/2019/03/05/penetration-testing-active-directory-part-i/)
    432 * [Penetration Testing Active Directory, Part II - March 12, 2019 - Hausec](https://hausec.com/2019/03/12/penetration-testing-active-directory-part-ii/)
    433 * [Using bloodhound to map the user network - Hausec](https://hausec.com/2017/10/26/using-bloodhound-to-map-the-user-network/)
    434 * [PowerView 3.0 Tricks - HarmJ0y](https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993)
    435 * [SOAPHound - tool to collect Active Directory data via ADWS - Nikos Karouzos - 01/26/204](https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c)
    436 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)