Skip to content
From the blog

Pentesting - Active Directory @Lkys37en LAB - Part 3

Pentesting - Active Directory @Lkys37en LAB - Part 3
Active Directory1 min read
Julio Ureña
Julio Ureña

Chief Technology Officer

Active DirectoryPentestingLab

In Part 2 we had the opportunity to use several mechanisms to evade security controls in Active Directory, and with tools like Metasploit and CrackMapExec we enumerated various network resources. In this third and final part we will achieve Domain Admin access by taking advantage of a common bad practice — Domain Admins authenticating on machines that are not Domain Controllers. This time we will use tools for:

  • User Enumeration with PowerShell
  • File Server Infection to steal NetNTLM hashes
  • Enumerating machines vulnerable to NTLM Relay attacks
  • A brief explanation of the NTLMRelay attack
  • Using CrackMapExec to run Mimikatz and extract hashes/passwords from domain user memory
  • Lateral movement across the network
  • Group Policy Abuse with PowerView

Finally, we will obtain Domain Admin access.

Part #3 – Pentesting – @Lkys37en Lab – Part 3

Get Protected Today

Discover how we help your business protect itself. We strengthen your online presence and shield you against cyberattacks.

Contact us