🗺️ AD Attack Flow
Every engagement follows this pattern. Master each step.
Reconnaissance & Enumeration
First contact with AD. Identify domain, users, groups, and attack surface.
Initial Domain Discovery
⚠️ SMB Signing Disabled?
You can relay credentials! Check: nxc smb <ip> --gen-relay-list targets.txt
✓ Pro Tip
Add DC hostname to /etc/hosts for Kerberos attacks to work properly
User Enumeration
Comprehensive Enumeration
🔥 Quick Win: Password Policy
Check --pass-pol output for lockout threshold. If no lockout → spray passwords! If 5 attempts → spray 4 passwords, wait, repeat.
🔍 PowerView Enumeration (Windows)
When you have Windows access, PowerView gives you deep AD enumeration capabilities.
💡 Pro Tip: Description Goldmine
Always check user descriptions! Lazy admins often store passwords there: Get-NetUser | ? {$_.description} | select name,description
BloodHound - Attack Path Mapping
BloodHound visualizes AD relationships and finds attack paths you'd never discover manually. Always run this with valid creds.
What BloodHound collects:
Group memberships, ACLs, sessions, trusts, GPO links, and object properties. It then graphs relationships to find "attack paths" - chains of permissions that lead from your current access to Domain Admin. Edges like "GenericAll", "ForceChangePassword", "AddMember" show exploitable relationships.
Data Collection
Critical BloodHound Queries
Shortest Path to DA
Find Shortest Paths to Domain Admins
Kerberoastable Users
List all Kerberoastable Accounts
AS-REP Roastable
Find AS-REP Roastable Users
Unconstrained Delegation
Find Computers with Unconstrained Delegation
DCSync Rights
Find Principals with DCSync Rights
Owned → DA Path
Shortest Paths from Owned Principals
💡 Mark users as "Owned" in BloodHound as you compromise them. New paths will appear!
Kerberos Attacks
🔥 Kerberoasting
Any domain user can request TGS tickets for service accounts. These tickets are encrypted with the service account's password hash - crack offline!
How it works:
When you request a service ticket (TGS), the KDC encrypts part of it with the service account's NTLM hash. The KDC doesn't verify you'll actually use the ticket - it just gives it to you. You then crack the encrypted portion offline with hashcat. Service accounts often have weak passwords and high privileges.
🎫 AS-REP Roasting
Target accounts with "Do not require Kerberos preauthentication" enabled. No creds needed to request!
How it works:
Normally, Kerberos requires you prove identity (preauthentication) before issuing tickets. When disabled, the KDC gives you an AS-REP encrypted with the user's hash - no proof needed. You only need valid usernames. This setting is sometimes enabled for legacy apps or misconfiguration.
Kerberoasting
- • Requires valid domain creds
- • Targets service accounts with SPNs
- • Hash mode: 13100
AS-REP Roasting
- • NO creds needed (just usernames)
- • Targets accounts without preauth
- • Hash mode: 18200
Credential Access
🌧️ Password Spraying
Try common passwords against all users. Check lockout policy first!
💡 Common Spray Passwords
Season+Year (Winter2024!), CompanyName123!, Password1, Welcome1, Changeme1
💀 Credential Dumping
📡 LLMNR/NBT-NS Poisoning (Responder)
Poison name resolution requests to capture NTLMv2 hashes. Works when LLMNR/NBT-NS enabled (Windows default)!
⚠️ OPSEC Note
Responder is VERY noisy. In mature environments, ResponderGuard or similar tools will detect poisoning immediately. Use cautiously!
Lateral Movement
🔑 Pass-the-Hash (PtH)
Use NTLM hash directly - no need to crack!
PSExec
Noisy (creates service)
WMIExec
Moderate stealth
Evil-WinRM
Cleanest (needs 5985)
🔐 Additional PtH Methods
🔄 Overpass-the-Hash (Pass-the-Key)
Convert NTLM hash to Kerberos ticket - bypass NTLM-blocking controls!
💡 Why Overpass-the-Hash?
Some environments block NTLM auth but allow Kerberos. OPtH converts your hash to a Kerberos ticket, bypassing these controls!
🎫 Pass-the-Ticket (PtT)
DACL & ACL Abuse
DACL misconfigurations allow privilege escalation through object permission abuse. BloodHound finds these automatically!
🔓 GenericWrite / GenericAll
Full control or write access to AD objects. Can modify attributes, reset passwords, or add Shadow Credentials.
👑 WriteOwner
Take ownership of an object → modify DACL → grant yourself full control!
👻 Shadow Credentials
With WriteProperty on a user/computer, add alternate credentials via msDS-KeyCredentialLink. No password change needed!
Why Shadow Creds?
- • No password change = no user lockout
- • No alerts about password reset
- • Stealthier than force password change
Windows Tool
Whisker.exe add /target:TargetUser
🔄 Self-Membership Abuse
Self-Membership ACE allows adding yourself to a group. Requires LDAP (net rpc fails)!
⚠️ Re-Authentication Required
After adding to group, you must re-authenticate (new Kerberos ticket) for group membership to take effect!
Delegation Attacks
🔓 Unconstrained Delegation
Computers with unconstrained delegation store TGTs of connecting users. Compromise one → steal tickets!
🔐 Constrained Delegation
🔄 Resource-Based Constrained Delegation (RBCD)
With GenericWrite on a computer, configure RBCD to impersonate any user to that computer!
💡 RBCD Requirements
Need GenericWrite/GenericAll on target computer + MachineAccountQuota > 0 (default is 10) OR existing controlled account with SPN
🎭 NoPAC / sAMAccountName Spoofing
CVE-2021-42278/42287 - Rename account to match DC, request TGT, revert name. KDC issues DC-level ticket!
⚠️ NoPAC Patched
Patched in Nov 2021 (KB5008102/KB5008380). Still works on unpatched systems - check with noPac scanner first!
ADCS Certificate Attacks
AD Certificate Services misconfigurations (ESC1-ESC13) allow privilege escalation through PKI abuse. Bypasses VBS/Credential Guard!
🔍 ADCS Enumeration
📜 ESC1 - SAN Impersonation
Template allows enrollee to specify Subject Alternative Name (SAN). Request cert as any user!
📜 ESC3 - Enrollment Agent Abuse
Request cert on behalf of another user using enrollment agent certificate.
📜 ESC4 - Vulnerable Template ACLs
With WriteDacl/WriteOwner on template, modify it to enable ESC1!
📜 ESC8 - NTLM Relay to HTTP Enrollment
Relay NTLM authentication to certificate enrollment endpoint. Coerce DC machine account!
Template Misconfigs
- ESC1: Enrollee supplies SAN
- ESC2: Any Purpose EKU
- ESC3: Enrollment Agent abuse
- ESC9: No security extension
ACL & Relay Attacks
- ESC4: Writable template ACLs
- ESC7: CA ManageCA rights
- ESC8: NTLM relay to HTTP
- ESC11: RPC relay bypass
💡 Why ADCS Bypasses VBS/Credential Guard
ADCS attacks exploit certificate issuance logic, not credential storage. VBS protects LSASS memory; certs authenticate via PKINIT (different path).
Domain Dominance
You've reached Domain Admin or equivalent. Time to own everything.
💀 DCSync Attack
Replicate AD data as if you were a DC. Dump every hash in the domain!
How it works:
DCSync abuses the MS-DRSR replication protocol. Domain Controllers use this to sync AD data between each other. If you have DS-Replication-Get-Changes + DS-Replication-Get-Changes-All rights (Domain Admins have these by default), you can request replication of any user's password data - including the krbtgt hash for Golden Tickets.
🏆 Golden Ticket
With krbtgt hash, forge tickets for any user. Valid until krbtgt password changes (rarely happens)!
Why Golden Tickets are "game over":
The krbtgt account encrypts/signs all TGTs in the domain. With its hash, you can forge a TGT for any user (even non-existent ones!) with any group memberships. The KDC can't tell the difference. The krbtgt password rarely changes, so Golden Tickets persist through password resets. This is the ultimate persistence mechanism.
💡 Getting the krbtgt Hash
Use DCSync to get the krbtgt hash: lsadump::dcsync /domain:domain.local /user:krbtgt - look for the NTLM hash in output.
🚨 Persistence Warning
Golden tickets are incredibly powerful but may trigger alerts in mature environments. Use responsibly and only when authorized!
🥈 Silver Ticket
Forge service ticket using service account hash. Stealthier than Golden - no DC contact needed!
Golden vs Silver
- Golden: krbtgt hash → any service
- Silver: service hash → one service
Common Silver SPNs
CIFS, HTTP, MSSQLSvc, LDAP, HOST