Attacking Active Directory
search
⌘Ctrlk
Attacking Active Directory
  • Reconnaissance
  • Exploiting With Poison and Relay
  • User Enumeration Exploit
  • Exploiting with Users
  • WSUS Exploit
  • Active Directory Certificate Services (ADCS)
  • Metasploit
  • Privilege Escalation
  • User ACL Exploits
  • MSSQL servers Exploitation
  • Delegations
  • Trust
    • Enumerate Trust
    • Domain Trust - child/parent (north.newyork.local -> newyork.local)
    • Forest Trust (newyork.local -> maryland.local)
      • Foreign group and users
      • Use unconstrained delegation
      • Mssql Trusted link
      • Golden ticket with external forest, sid history ftw ( Maryland-> NewYork)
      • Trust ticket with external forest ( maryland.local-> newyork.local)
      • Exploit acl with external trust golden ticket
  • Exploiting IIS & Privilege escalation
  • Impacket
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Trust

Forest Trust (newyork.local -> maryland.local)

Foreign group and userschevron-rightUse unconstrained delegationchevron-rightMssql Trusted linkchevron-rightGolden ticket with external forest, sid history ftw ( Maryland-> NewYork)chevron-rightTrust ticket with external forest ( maryland.local-> newyork.local)chevron-rightExploit acl with external trust golden ticketchevron-right
PreviousTrust ticket - forge inter-realm TGTchevron-leftNextForeign group and userschevron-right

Last updated 2 years ago