Foreign group and users
Last updated
Last updated
On bloodhound we can see very easily that there is link between the domains with the following query (Careful this query is fine in a lab but this will certainly be a little too heavy in a real world AD)
On the lab you will find some specifics groups to pass from one domain to the other.
As you already have done the acl part previously you will easily find the way to exploit that.
newyork.local to maryland.local: group KGB
To do that just pick a user from the RadioCity and exploit with the KGB group
We can also to that with shadow credentials (but the auto will not work here, we will have to do that with two steps)
Maryland to NewYork : group MainMultiDoms
In the same way we can exploit the Maryland to NewYork foreign group