Attacking Active Directory

Note: This documentation is mostly made from my notes on TCM Security Academy It will be complemented with notes from my practice and from other classes like the one from HTB Academy

Methodology

  • Useful tool to install in kali is pimpmykali (choose 0 in option menu)

  • First thing to do is launch responder (along with scans to generate traffic)

  • LLMNR Poisoning

  • SMB Relay Attack

  • Look for websites in scope

  • Check for default credentials (printers, tomcat, jenkins,...)

  • Compromise a machine (as many as possible with lateral movement)

  • Enumerate (network) with tools for post-compromise attack

  • Get Domain Admin with post-compromise attacks

  • Dump with mimikatz

Resources

An Amazing offensive AD interactive Cheat sheet by John Woodman
Hacktricks - Active Directory Methodology
TCM-Security Academy
Top Five Ways I Got Domain Admin - Adam Toscher
Active Directory Security Blog
Harmj0y Blog
Top Five Ways I Got Domain Admin on Your Internal Network before Lunch (2018 Edition) Adam Toscher
Active Directory Attacks - PayloadsAllTheThings
Azure AD - Attack and Defense Playbook - Cloud Architekt
Active Directory Exploitation Cheat Sheet - Integration IT
Cheat Sheet - Attack Active Directory - drak3hft7
Active Directory Exploitation Cheat Sheet - S1ckB0y1337
Pentesting active directory - Orange Cyberdéfense
BUILDING AND ATTACKING AN ACTIVE DIRECTORY LAB WITH POWERSHELL - 1337RED
GOAD (Game Of Active Directory) - Orange Cyberdéfense
Attack Methods for Gaining Domain Admin Rights in Active Directory - Sean Metcalf - adsecurity
hackndo - Pixis
The Hacker Recipes - Shutdown
Dirk-jan Mollema's blog

Last updated