
Active Directory1 min read
Active DirectoryPentestingLab
In Part 2 we had the opportunity to use several mechanisms to evade security controls in Active Directory, and with tools like Metasploit and CrackMapExec we enumerated various network resources. In this third and final part we will achieve Domain Admin access by taking advantage of a common bad practice — Domain Admins authenticating on machines that are not Domain Controllers. This time we will use tools for:
- User Enumeration with PowerShell
- File Server Infection to steal NetNTLM hashes
- Enumerating machines vulnerable to NTLM Relay attacks
- A brief explanation of the NTLMRelay attack
- Using CrackMapExec to run Mimikatz and extract hashes/passwords from domain user memory
- Lateral movement across the network
- Group Policy Abuse with PowerView
Finally, we will obtain Domain Admin access.
Part #3 – Pentesting – @Lkys37en Lab – Part 3
