ad-adds-enumerate.md (17854B)
1 --- 2 title: "Active Directory - Enumeration" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adds-enumerate.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-enumerate.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Enumeration 12 13 ## Using BloodHound 14 15 Use the appropriate data collector to gather information for **BloodHound** or **BloodHound Community Edition (CE)** across various platforms. 16 17 * [BloodHoundAD/AzureHound](https://github.com/BloodHoundAD/AzureHound) for Azure Active Directory 18 * [BloodHoundAD/SharpHound](https://github.com/BloodHoundAD/SharpHound) for local Active Directory (C# collector) 19 * [FalconForceTeam/SOAPHound](https://github.com/FalconForceTeam/SOAPHound) for local Active Directory (C# collector using ADWS) 20 * [g0h4n/RustHound-CE](https://github.com/g0h4n/RustHound-CE) for local Active Directory (Rust collector) 21 * [NH-RED-TEAM/RustHound](https://github.com/NH-RED-TEAM/RustHound) for local Active Directory (Rust collector) 22 * [fox-it/BloodHound.py](https://github.com/fox-it/BloodHound.py) for local Active Directory (Python collector) 23 * [coffeegist/bofhound](https://github.com/coffeegist/bofhound) for local Active Directory (Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel) 24 * [c3c/ADExplorerSnapshot.py](https://github.com/c3c/ADExplorerSnapshot.py) for local Active Directory (Generate BloodHound compatible JSON from AD Explorer snapshot) 25 * [CrowdStrike/sccmhound](https://github.com/CrowdStrike/sccmhound) for local Active Directory (C# collector using Microsoft Configuration Manager) 26 * [SpecterOps/MSSQLHound](https://github.com/SpecterOps/MSSQLHound) for MSSQL attack paths (BloodHound OpenGraph PowerShell collector) 27 * [SpecterOps/SnowHound](https://github.com/SpecterOps/SnowHound) for Snowflake attack paths (BloodHound OpenGraph PowerShell collector) 28 * [SpecterOps/GitHound](https://github.com/SpecterOps/GitHound) for GitHub attack paths (BloodHound OpenGraph PowerShell collector) 29 * [SpecterOps/1PassHound](https://github.com/SpecterOps/1PassHound) for 1Password attack paths (BloodHound OpenGraph PowerShell collector) 30 * [TheSleekBoyCompany/AnsibleHound](https://github.com/TheSleekBoyCompany/AnsibleHound) for Ansible WorX and Ansible Tower attack paths (BloodHound OpenGraph Go collector) 31 * [p0dalirius/sharehound](https://github.com/p0dalirius/sharehound) - for Network Shares attack paths (BloodHound OpenGraph Python collector) 32 * [C0KERNEL/SecretHound](https://github.com/C0KERNEL/SecretHound) - for secrets (BloodHound OpenGraph Python collector) 33 * [F41zK4r1m/GCP-Hound](https://github.com/F41zK4r1m/GCP-Hound) - for GCP attack path (BloodHound OpenGraph Python collector) 34 * [SpecterOps/ConfigManBearPig](https://github.com/SpecterOps/ConfigManBearPig) - for SCCM attack path (BloodHound OpenGraph PowerShell collector) 35 36 **Examples**: 37 38 * Use [BloodHoundAD/AzureHound](https://github.com/BloodHoundAD/AzureHound) (more info: [Cloud - Azure Pentest](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20Azure%20Pentest.md#azure-recon-tools)) 39 40 * Use [BloodHoundAD/SharpHound.exe](https://github.com/BloodHoundAD/BloodHound) - run the collector on the machine using SharpHound.exe 41 42 ```powershell 43 .\SharpHound.exe -c all -d active.htb --searchforest 44 .\SharpHound.exe -c all,GPOLocalGroup # all collection doesn't include GPOLocalGroup by default 45 .\SharpHound.exe --CollectionMethod DCOnly # only collect from the DC, doesn't query the computers (more stealthy) 46 47 .\SharpHound.exe -c all --LdapUsername <UserName> --LdapPassword <Password> --JSONFolder <PathToFile> 48 .\SharpHound.exe -c all --LdapUsername <UserName> --LdapPassword <Password> --domaincontroller 10.10.10.100 -d active.htb 49 50 .\SharpHound.exe -c All,GPOLocalGroup --outputdirectory C:\Windows\Temp --prettyprint --randomfilenames --collectallproperties --throttle 10000 --jitter 23 --outputprefix internalallthething 51 ``` 52 53 * Use [BloodHoundAD/SharpHound.ps1](https://github.com/BloodHoundAD/BloodHound/blob/master/Collectors/SharpHound.ps1) - run the collector on the machine using Powershell 54 55 ```powershell 56 Invoke-BloodHound -SearchForest -CSVFolder C:\Users\Public 57 Invoke-BloodHound -CollectionMethod All -LDAPUser <UserName> -LDAPPass <Password> -OutputDirectory <PathToFile> 58 ``` 59 60 * Use [ly4k/Certipy](https://github.com/ly4k/Certipy) to collect certificates data 61 62 ```ps1 63 certipy find 'corp.local/john:Passw0rd@dc.corp.local' -bloodhound 64 certipy find 'corp.local/john:Passw0rd@dc.corp.local' -old-bloodhound 65 certipy find 'corp.local/john:Passw0rd@dc.corp.local' -vulnerable -hide-admins -username user@domain -password Password123 66 ``` 67 68 * Use [NH-RED-TEAM/RustHound](https://github.com/OPENCYBER-FR/RustHound) 69 70 ```ps1 71 # Windows with GSSAPI session 72 rusthound.exe -d domain.local --ldapfqdn domain 73 # Windows/Linux simple bind connection username:password 74 rusthound.exe -d domain.local -u user@domain.local -p Password123 -o output -z 75 # Linux with username:password and ADCS module for @ly4k BloodHound version 76 rusthound -d domain.local -u 'user@domain.local' -p 'Password123' -o /tmp/adcs --adcs -z 77 ``` 78 79 * Use [FalconForceTeam/SOAPHound](https://github.com/FalconForceTeam/SOAPHound) 80 81 ```ps1 82 --buildcache: Only build cache and not perform further actions 83 --bhdump: Dump BloodHound data 84 --certdump: Dump AD Certificate Services (ADCS) data 85 --dnsdump: Dump AD Integrated DNS data 86 87 SOAPHound.exe --buildcache -c c:\temp\cache.txt 88 SOAPHound.exe -c c:\temp\cache.txt --bhdump -o c:\temp\bloodhound-output 89 SOAPHound.exe -c c:\temp\cache.txt --bhdump -o c:\temp\bloodhound-output --autosplit --threshold 1000 90 SOAPHound.exe -c c:\temp\cache.txt --certdump -o c:\temp\bloodhound-output 91 SOAPHound.exe --dnsdump -o c:\temp\dns-output 92 ``` 93 94 * Use [fox-it/BloodHound.py](https://github.com/fox-it/BloodHound.py) 95 96 ```ps1 97 pip install bloodhound 98 bloodhound-python -d domain.local -u username -p password -gc LAB2008DC01.domain.local -c all 99 ``` 100 101 * Use [c3c/ADExplorerSnapshot.py](https://github.com/c3c/ADExplorerSnapshot.py) to query data from SysInternals/ADExplorer snapshot (ADExplorer remains a legitimate binary signed by Microsoft, avoiding detection with security solutions). 102 103 ```py 104 ADExplorerSnapshot.py <snapshot path> -o <*.json output folder path> 105 ``` 106 107 Then import the zip/json files into the Neo4J database and query them. 108 109 ```powershell 110 root@payload$ apt install bloodhound 111 112 # start BloodHound and the database 113 root@payload$ neo4j console 114 # or use docker 115 root@payload$ docker run -itd -p 7687:7687 -p 7474:7474 --env NEO4J_AUTH=neo4j/bloodhound -v $(pwd)/neo4j:/data neo4j:4.4-community 116 117 root@payload$ ./bloodhound --no-sandbox 118 Go to http://127.0.0.1:7474, use db:bolt://localhost:7687, user:neo4J, pass:neo4j 119 ``` 120 121 NOTE: Currently BloodHound Community Edition is still a work in progress, it is highly recommended to stay on the original [BloodHoundAD/BloodHound](https://github.com/BloodHoundAD/BloodHound/) version. 122 123 ```ps1 124 git clone https://github.com/SpecterOps/BloodHound 125 cd examples/docker-compose/ 126 cat docker-compose.yml | docker compose -f - up 127 # UI: http://localhost:8080/ui/login 128 # Username: admin 129 # Password: see your Docker logs 130 ``` 131 132 You can add some custom queries like : 133 134 * [BloodHound Queries For All - SpecterOps](https://queries.specterops.io/) 135 * [Bloodhound-Custom-Queries from @hausec](https://github.com/hausec/Bloodhound-Custom-Queries/blob/master/customqueries.json) 136 * [BloodHoundQueries from CompassSecurity](https://github.com/CompassSecurity/BloodHoundQueries/blob/master/customqueries.json) 137 * [BloodHound Custom Queries from Exegol - @ShutdownRepo](https://raw.githubusercontent.com/ThePorgs/Exegol-images/main/sources/assets/bloodhound/customqueries.json) 138 * [Certipy BloodHound Custom Queries from ly4k](https://github.com/ly4k/Certipy/blob/main/customqueries.json) 139 140 Replace the customqueries.json file located at `/home/username/.config/bloodhound/customqueries.json` or `C:\Users\USERNAME\AppData\Roaming\BloodHound\customqueries.json`. 141 142 ## Using PowerView 143 144 * **Get Current Domain:** `Get-NetDomain` 145 * **Enum Other Domains:** `Get-NetDomain -Domain <DomainName>` 146 * **Get Domain SID:** `Get-DomainSID` 147 * **Get Domain Policy:** 148 149 ```powershell 150 Get-DomainPolicy 151 152 #Will show us the policy configurations of the Domain about system access or kerberos 153 (Get-DomainPolicy)."system access" 154 (Get-DomainPolicy)."kerberos policy" 155 ``` 156 157 * **Get Domain Controlers:** 158 159 ```powershell 160 Get-NetDomainController 161 Get-NetDomainController -Domain <DomainName> 162 ``` 163 164 * **Enumerate Domain Users:** 165 166 ```powershell 167 Get-NetUser 168 Get-NetUser -SamAccountName <user> 169 Get-NetUser | select cn 170 Get-UserProperty 171 172 #Check last password change 173 Get-UserProperty -Properties pwdlastset 174 175 #Get a specific "string" on a user's attribute 176 Find-UserField -SearchField Description -SearchTerm "wtver" 177 178 #Enumerate user logged on a machine 179 Get-NetLoggedon -ComputerName <ComputerName> 180 181 #Enumerate Session Information for a machine 182 Get-NetSession -ComputerName <ComputerName> 183 184 #Enumerate domain machines of the current/specified domain where specific users are logged into 185 Find-DomainUserLocation -Domain <DomainName> | Select-Object UserName, SessionFromName 186 ``` 187 188 * **Enum Domain Computers:** 189 190 ```powershell 191 Get-NetComputer -FullData 192 Get-DomainGroup 193 194 #Enumerate Live machines 195 Get-NetComputer -Ping 196 ``` 197 198 * **Enum Groups and Group Members:** 199 200 ```powershell 201 Get-NetGroupMember -GroupName "<GroupName>" -Domain <DomainName> 202 203 #Enumerate the members of a specified group of the domain 204 Get-DomainGroup -Identity <GroupName> | Select-Object -ExpandProperty Member 205 206 #Returns all GPOs in a domain that modify local group memberships through Restricted Groups or Group Policy Preferences 207 Get-DomainGPOLocalGroup | Select-Object GPODisplayName, GroupName 208 ``` 209 210 * **Enumerate Shares** 211 212 ```powershell 213 #Enumerate Domain Shares 214 Find-DomainShare 215 216 #Enumerate Domain Shares the current user has access 217 Find-DomainShare -CheckShareAccess 218 ``` 219 220 * **Enum Group Policies:** 221 222 ```powershell 223 Get-NetGPO 224 225 # Shows active Policy on specified machine 226 Get-NetGPO -ComputerName <Name of the PC> 227 Get-NetGPOGroup 228 229 #Get users that are part of a Machine's local Admin group 230 Find-GPOComputerAdmin -ComputerName <ComputerName> 231 ``` 232 233 * **Enum OUs:** 234 235 ```powershell 236 Get-NetOU -FullData 237 Get-NetGPO -GPOname <The GUID of the GPO> 238 ``` 239 240 * **Enum ACLs:** 241 242 ```powershell 243 # Returns the ACLs associated with the specified account 244 Get-ObjectAcl -SamAccountName <AccountName> -ResolveGUIDs 245 Get-ObjectAcl -ADSprefix 'CN=Administrator, CN=Users' -Verbose 246 247 #Search for interesting ACEs 248 Invoke-ACLScanner -ResolveGUIDs 249 250 #Check the ACLs associated with a specified path (e.g smb share) 251 Get-PathAcl -Path "\\Path\Of\A\Share" 252 ``` 253 254 * **Enum Domain Trust:** 255 256 ```powershell 257 Get-NetDomainTrust 258 Get-NetDomainTrust -Domain <DomainName> 259 ``` 260 261 * **Enum Forest Trust:** 262 263 ```powershell 264 Get-NetForestDomain 265 Get-NetForestDomain Forest <ForestName> 266 267 #Domains of Forest Enumeration 268 Get-NetForestDomain 269 Get-NetForestDomain Forest <ForestName> 270 271 #Map the Trust of the Forest 272 Get-NetForestTrust 273 Get-NetDomainTrust -Forest <ForestName> 274 ``` 275 276 * **User Hunting:** 277 278 ```powershell 279 #Finds all machines on the current domain where the current user has local admin access 280 Find-LocalAdminAccess -Verbose 281 282 #Find local admins on all machines of the domain: 283 Invoke-EnumerateLocalAdmin -Verbose 284 285 #Find computers were a Domain Admin OR a specified user has a session 286 Invoke-UserHunter 287 Invoke-UserHunter -GroupName "RDPUsers" 288 Invoke-UserHunter -Stealth 289 290 #Confirming admin access: 291 Invoke-UserHunter -CheckAccess 292 ``` 293 294 ## Using AD Module 295 296 * **Get Current Domain:** `Get-ADDomain` 297 * **Enum Other Domains:** `Get-ADDomain -Identity <Domain>` 298 * **Get Domain SID:** `Get-DomainSID` 299 * **Get Domain Controlers:** 300 301 ```powershell 302 Get-ADDomainController 303 Get-ADDomainController -Identity <DomainName> 304 ``` 305 306 * **Enumerate Domain Users:** 307 308 ```powershell 309 Get-ADUser -Filter * -Identity <user> -Properties * 310 311 #Get a specific "string" on a user's attribute 312 Get-ADUser -Filter 'Description -like "*wtver*"' -Properties Description | select Name, Description 313 ``` 314 315 * **Enum Domain Computers:** 316 317 ```powershell 318 Get-ADComputer -Filter * -Properties * 319 Get-ADGroup -Filter * 320 ``` 321 322 * **Enum Domain Trust:** 323 324 ```powershell 325 Get-ADTrust -Filter * 326 Get-ADTrust -Identity <DomainName> 327 ``` 328 329 * **Enum Forest Trust:** 330 331 ```powershell 332 Get-ADForest 333 Get-ADForest -Identity <ForestName> 334 335 #Domains of Forest Enumeration 336 (Get-ADForest).Domains 337 ``` 338 339 * **Enum Local AppLocker Effective Policy:** 340 341 ```powershell 342 Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections 343 ``` 344 345 ## User Hunting 346 347 Sometimes you need to find a machine where a specific user is logged in. 348 You can remotely query every machines on the network to get a list of the users's sessions. 349 350 * netexec 351 352 ```ps1 353 nxc smb 10.10.10.0/24 -u Administrator -p 'P@ssw0rd' --sessions 354 SMB 10.10.10.10 445 WIN-8OJFTLMU1IG [+] Enumerated sessions 355 SMB 10.10.10.10 445 WIN-8OJFTLMU1IG \\10.10.10.10 User:Administrator 356 ``` 357 358 * Impacket Smbclient 359 360 ```ps1 361 $ impacket-smbclient Administrator@10.10.10.10 362 # who 363 host: \\10.10.10.10, user: Administrator, active: 1, idle: 0 364 ``` 365 366 * PowerView Invoke-UserHunter 367 368 ```ps1 369 # Find computers were a Domain Admin OR a specified user has a session 370 Invoke-UserHunter 371 Invoke-UserHunter -GroupName "RDPUsers" 372 Invoke-UserHunter -Stealth 373 ``` 374 375 ## RID cycling 376 377 In Windows, every security principal (user, group, etc.) has a Security Identifier (SID). The SID is a unique identifier used for access control. 378 379 ```ps1 380 S-1-5-21-<domain>-<RID> 381 ``` 382 383 * `S-1-5-21-<domain>` = Base domain SID 384 * `<RID>` = Unique ID assigned to a user/group 385 386 RID cycling involves brute-forcing a range of RIDs (like 500–1500) by appending them to the known domain SID, and attempting to resolve each SID into a username. 387 388 * Using [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) 389 390 ```ps1 391 netexec smb 10.10.11.231 -u guest -p '' --rid-brute 10000 --log rid-brute.txt 392 SMB 10.10.11.231 445 DC01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:rebound.htb) (signing:True) (SMBv1:False) 393 SMB 10.10.11.231 445 DC01 [+] rebound.htb\guest: 394 SMB 10.10.11.231 445 DC01 498: rebound\Enterprise Read-only Domain Controllers (SidTypeGroup) 395 SMB 10.10.11.231 445 DC01 500: rebound\Administrator (SidTypeUser) 396 SMB 10.10.11.231 445 DC01 501: rebound\Guest (SidTypeUser) 397 SMB 10.10.11.231 445 DC01 502: rebound\krbtgt (SidTypeUser) 398 ``` 399 400 * Using Impacket script [impacket/lookupsid.py](https://github.com/fortra/impacket/blob/master/examples/lookupsid.py) 401 402 ```ps1 403 lookupsid.py -no-pass 'guest@rebound.htb' 20000 404 ``` 405 406 ## Other Interesting Commands 407 408 * **Find Domain Controllers** 409 410 ```ps1 411 nslookup domain.com 412 nslookup -type=srv _ldap._tcp.dc._msdcs.<domain>.com 413 nltest /dclist:domain.com 414 Get-ADDomainController -filter * | Select-Object name 415 gpresult /r 416 $Env:LOGONSERVER 417 echo %LOGONSERVER% 418 ``` 419 420 ## References 421 422 * [Explain like I’m 5: Kerberos - Apr 2, 2013 - @roguelynn](https://www.roguelynn.com/words/explain-like-im-5-kerberos/) 423 * [Pen Testing Active Directory Environments - Part I: Introduction to netexec (and PowerView)](https://blog.varonis.com/pen-testing-active-directory-environments-part-introduction-netexec-powerview/) 424 * [Pen Testing Active Directory Environments - Part II: Getting Stuff Done With PowerView](https://blog.varonis.com/pen-testing-active-directory-environments-part-ii-getting-stuff-done-with-powerview/) 425 * [Pen Testing Active Directory Environments - Part III: Chasing Power Users](https://blog.varonis.com/pen-testing-active-directory-environments-part-iii-chasing-power-users/) 426 * [Pen Testing Active Directory Environments - Part IV: Graph Fun](https://blog.varonis.com/pen-testing-active-directory-environments-part-iv-graph-fun/) 427 * [Pen Testing Active Directory Environments - Part V: Admins and Graphs](https://blog.varonis.com/pen-testing-active-directory-v-admins-graphs/) 428 * [Pen Testing Active Directory Environments - Part VI: The Final Case](https://blog.varonis.com/pen-testing-active-directory-part-vi-final-case/) 429 * [Attacking Active Directory: 0 to 0.9 - Eloy Pérez González - 2021/05/29](https://zer1t0.gitlab.io/posts/attacking_ad/) 430 * [Fun with LDAP, Kerberos (and MSRPC) in AD Environments](https://speakerdeck.com/ropnop/fun-with-ldap-kerberos-and-msrpc-in-ad-environments) 431 * [Penetration Testing Active Directory, Part I - March 5, 2019 - Hausec](https://hausec.com/2019/03/05/penetration-testing-active-directory-part-i/) 432 * [Penetration Testing Active Directory, Part II - March 12, 2019 - Hausec](https://hausec.com/2019/03/12/penetration-testing-active-directory-part-ii/) 433 * [Using bloodhound to map the user network - Hausec](https://hausec.com/2017/10/26/using-bloodhound-to-map-the-user-network/) 434 * [PowerView 3.0 Tricks - HarmJ0y](https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993) 435 * [SOAPHound - tool to collect Active Directory data via ADWS - Nikos Karouzos - 01/26/204](https://medium.com/falconforce/soaphound-tool-to-collect-active-directory-data-via-adws-165aca78288c) 436 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)