RaiseMeUp - Escalate with impacket raiseChild

  • Ok now imagine you have pwn the domain north.newyork.local you have dump the ntds and you got all the NT hash of all the north domain users.

As said by Microsoft the domain trust is not a security boundary

RaiseMeUp - Escalate with impacket raiseChild

  • To escalate from child to parent the simplest way is with impacket raiseChild.py script, this will do all the work for us.

  • This create a golden ticket for the forest enterprise admin.

  • Log into the forest and get the target info (default administrator RID: 500)

  • All the job is done with one command, if you are lazy you don’t even need to understand x)

Authenticate with to verify the dump has is good

smbexec.py whoami????

Last updated