Attacking Active Directory

Note: This documentation is mostly made from my notes on TCM Security Academyarrow-up-right It will be complemented with notes from my practice and from other classes like the one from HTB Academyarrow-up-right

Methodology

  • Useful tool to install in kali is pimpmykaliarrow-up-right (choose 0 in option menu)

  • First thing to do is launch responder (along with scans to generate traffic)

  • LLMNR Poisoning

  • SMB Relay Attack

  • Look for websites in scope

  • Check for default credentials (printers, tomcat, jenkins,...)

  • Compromise a machine (as many as possible with lateral movement)

  • Enumerate (network) with tools for post-compromise attack

  • Get Domain Admin with post-compromise attacks

  • Dump with mimikatz

Resources

An Amazing offensive AD interactive Cheat sheet by John Woodman
Hacktricks - Active Directory Methodology
TCM-Security Academy
Top Five Ways I Got Domain Admin - Adam Toscher
Active Directory Security Blog
Harmj0y Blog
Top Five Ways I Got Domain Admin on Your Internal Network before Lunch (2018 Edition) Adam Toscher
Active Directory Attacks - PayloadsAllTheThings
Azure AD - Attack and Defense Playbook - Cloud Architekt
Active Directory Exploitation Cheat Sheet - Integration IT
Cheat Sheet - Attack Active Directory - drak3hft7
Active Directory Exploitation Cheat Sheet - S1ckB0y1337
Pentesting active directory - Orange Cyberdéfense
BUILDING AND ATTACKING AN ACTIVE DIRECTORY LAB WITH POWERSHELL - 1337RED
GOAD (Game Of Active Directory) - Orange Cyberdéfense
Attack Methods for Gaining Domain Admin Rights in Active Directory - Sean Metcalf - adsecurity
hackndo - Pixis
The Hacker Recipes - Shutdown
Dirk-jan Mollema's blog

Last updated