DCSync and Domain Takeover
Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.
HackIndex
Language
Active Directory:
AD exploitation guides covering Kerberos attacks, NTLM relay, ADCS, and DCS
Exploits DCSync attack via replication privileges to extract password hashes from AD, enabling credential theft and full domain compromise.
Exploiting Windows authentication coercion techniques to capture or relay NTLM credentials via protocols like MS-RPRN, MS-EFSRPC, and PetitPotam.
Exploits Windows authentication coercion via MS-EFSRPC and other RPC protocols to force machine account credential relay attacks in AD environments.
Capture NTLM hashes by poisoning LLMNR/NBT-NS/mDNS traffic using Responder, enabling offline cracking or relay attacks against AD environments.
Exploiting misconfigured Group Policy Objects in AD to push malicious settings, execute code, or escalate privileges across domain-joined systems.
Exploits misconfigured AD group memberships to escalate privileges, move laterally, or gain unauthorized access to resources within a domain environment.
Exploit NTLM authentication weaknesses to relay captured credentials against AD services, bypassing direct password cracking to gain unauthorised access.
Covers low-and-slow authentication attacks against AD accounts using common passwords to evade lockout policies and gain initial domain access.
Exploiting misconfigured ADCS certificate templates and CA permissions (ESC2, ESC3, ESC5, ESC7) to escalate privileges or impersonate users in Active Directory.
Exploit NTLM relay attacks targeting AD CS HTTP enrollment endpoints to obtain certificates for arbitrary principals and achieve privilege escalation.
Exploits ADCS misconfigurations ESC9 (no-security-extension) & ESC10 (weak mapping) to abuse certificate templates for privilege escalation in AD environments.
Exploiting Active Directory Certificate Services misconfigurations (ESC1-ESC8) to escalate privileges or achieve domain compromise via certificate abuse.
Exploit accounts with Kerberos pre-authentication disabled to capture AS-REP hashes offline for password cracking without domain credentials.
Exploiting Active Directory misconfigurations using bloodyAD; covering privilege escalation, object manipulation, ACL abuse, and lateral movement techniques.
Exploit Kerberos S4U2Proxy/S4U2Self extensions to impersonate privileged users via misconfigured constrained delegation, enabling lateral movement within Active Directory environments.
Forge Kerberos TGTs (Golden) or service tickets (Silver) using stolen KRBTGT or service account hashes to achieve persistent, stealthy AD access.
Exploits Kerberos TGS ticket encryption to extract and offline brute-force service account password hashes in Active Directory environments.
Exploits CVE-2021-42278/42287 to spoof sAMAccountName, impersonate a DC, and obtain a TGT for privilege escalation in Active Directory.
Abuses msDS-AllowedToActOnBehalfOfOtherIdentity to gain delegated access, enabling impersonation of privileged users against target AD computer objects.
Abuse msDS-KeyCredentialLink attribute to forge certificate-based authentication, enabling stealthy privilege escalation and persistence within Active Directory environments.
Exploit unconstrained Kerberos delegation to capture TGTs from authenticating hosts, enabling lateral movement and privilege escalation within Active Directory environments.
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.