🗺️ AD Attack Flow
Every engagement follows this pattern. Master each step.
Reconnaissance & Enumeration
First contact with AD. Identify domain, users, groups, and attack surface.
Initial Domain Discovery
⚠️ SMB Signing Disabled?
You can relay credentials! Check: nxc smb <ip> --gen-relay-list targets.txt
✓ Pro Tip
Add DC hostname to /etc/hosts for Kerberos attacks to work properly
User Enumeration
DNS Enumeration
Password Spraying
After enumerating users and password policy, spray common passwords. Stay under lockout threshold!
⚠️ Lockout Warning
Check password policy first with nxc smb <DC> -u user -p pass --pass-pol. If lockout threshold is 5, spray max 3-4 passwords per round, then wait the lockout observation window before next round.
Comprehensive Enumeration
🔥 Quick Win: Password Policy
Check --pass-pol output for lockout threshold. If no lockout → spray passwords! If 5 attempts → spray 4 passwords, wait, repeat.
Share & GPP Password Hunting
🔍 PowerView Enumeration (Windows)
When you have Windows access, PowerView gives you deep AD enumeration capabilities.
💡 Pro Tip: Description Goldmine
Always check user descriptions! Lazy admins often store passwords there: Get-NetUser | ? {$_.description} | select name,description
BloodHound - Attack Path Mapping
BloodHound visualizes AD relationships and finds attack paths you'd never discover manually. Always run this with valid creds.
What BloodHound collects:
Group memberships, ACLs, sessions, trusts, GPO links, and object properties. It then graphs relationships to find "attack paths" - chains of permissions that lead from your current access to Domain Admin. Edges like "GenericAll", "ForceChangePassword", "AddMember" show exploitable relationships.
Data Collection
Critical BloodHound Queries
Shortest Path to DA
Find Shortest Paths to Domain Admins
Kerberoastable Users
List all Kerberoastable Accounts
AS-REP Roastable
Find AS-REP Roastable Users
Unconstrained Delegation
Find Computers with Unconstrained Delegation
DCSync Rights
Find Principals with DCSync Rights
Owned → DA Path
Shortest Paths from Owned Principals
💡 Mark users as "Owned" in BloodHound as you compromise them. New paths will appear!
Key Attack Edges to Look For
These edges in BloodHound represent exploitable permissions from one principal to another.
GenericAll
Full control over object. Can reset passwords, modify group membership, write SPNs for Kerberoasting.
WriteDACL
Modify object permissions. Grant yourself GenericAll then exploit.
WriteOwner
Change object owner. Make yourself owner → grant WriteDACL → grant GenericAll.
ForceChangePassword
Reset user password without knowing current one. Immediate compromise.
AddMember
Add principals to a group. Add yourself to "Domain Admins".
GenericWrite
Write any non-protected property. Can set SPN for Kerberoasting, scriptPath for execution.
AllExtendedRights
Includes User-Force-Change-Password and membership changes.
AddKeyCredentialLink
Shadow Credentials attack. Add certificate to user/computer object.
Useful Custom Cypher Queries
🎯 BloodHound Pro Tips
- Mark compromised objects as "Owned" with right-click → Mark User as Owned
- Use "Pathfinding" to find routes between any two objects
- Check "Node Info" (bottom panel) for valuable metadata: pwdlastset, description, etc.
- Look for computers with Unconstrained Delegation - coerce DC auth = Golden Ticket
- GPO abuse: Users/computers in OU → affected by GPO → GPO can be modified by you = RCE
Kerberos Attacks
🔥 Kerberoasting
Any domain user can request TGS tickets for service accounts. These tickets are encrypted with the service account's password hash - crack offline!
How it works:
When you request a service ticket (TGS), the KDC encrypts part of it with the service account's NTLM hash. The KDC doesn't verify you'll actually use the ticket - it just gives it to you. You then crack the encrypted portion offline with hashcat. Service accounts often have weak passwords and high privileges.
🎫 AS-REP Roasting
Target accounts with "Do not require Kerberos preauthentication" enabled. No creds needed to request!
How it works:
Normally, Kerberos requires you prove identity (preauthentication) before issuing tickets. When disabled, the KDC gives you an AS-REP encrypted with the user's hash - no proof needed. You only need valid usernames. This setting is sometimes enabled for legacy apps or misconfiguration.
🎟️ Pass-the-Ticket (PtT)
Steal Kerberos tickets from memory and reuse them. Tickets (TGT/TGS) are valid credentials!
🔑 Over-Pass-the-Hash (Pass-the-Key)
Use NTLM hash or AES key to request a Kerberos TGT. Converts hash → ticket.
Kerberoasting
- • Requires valid domain creds
- • Targets service accounts with SPNs
- • Hash mode: 13100
AS-REP Roasting
- • NO creds needed (just usernames)
- • Targets accounts without preauth
- • Hash mode: 18200
💡 Kerberos Attack Flow
1. AS-REP Roast (no creds) or Password Spray → 2. Kerberoast service accounts → 3. Crack hashes → 4. Use hash for Over-Pass-the-Hash → 5. Request TGT → 6. Pass-the-Ticket to access resources
Credential Access
🌧️ Password Spraying
Try common passwords against all users. Check lockout policy first!
💡 Common Spray Passwords
Season+Year (Winter2024!), CompanyName123!, Password1, Welcome1, Changeme1
💀 Credential Dumping
📡 LLMNR/NBT-NS Poisoning (Responder)
Poison name resolution requests to capture NTLMv2 hashes. Works when LLMNR/NBT-NS enabled (Windows default)!
⚠️ OPSEC Note
Responder is VERY noisy. In mature environments, ResponderGuard or similar tools will detect poisoning immediately. Use cautiously!
Lateral Movement
🔑 Pass-the-Hash (PtH)
Use NTLM hash directly - no need to crack!
💻 WinRM / PS Remoting
If WinRM enabled (port 5985/5986), use it for lateral movement. Requires valid creds or hash.
🖥️ RDP with Restricted Admin
Restricted Admin mode allows RDP with just a hash (no password). Not enabled by default.
Noisiest
PSExec → creates service, logs everywhere, very detectable
Moderate
WMIExec, SMBExec → some logs, moderate detection
Stealthiest
DCOMExec, WinRM → fewer logs, harder to detect
🎯 Pass-the-Hash Kill Chain
1. Dump LSASS/SAM → 2. Extract NTLM hashes → 3. Test with nxc smb → 4. Choose execution method (WMIExec for stealth, PSExec for reliability) → 5. Get shell → 6. Dump more creds → 7. Repeat
DACL & ACL Abuse
DACL misconfigurations allow privilege escalation through object permission abuse. BloodHound finds these automatically!
🔓 GenericWrite / GenericAll
Full control or write access to AD objects. Can modify attributes, reset passwords, or add Shadow Credentials.
👑 WriteOwner
Take ownership of an object → modify DACL → grant yourself full control!
👻 Shadow Credentials
With WriteProperty on a user/computer, add alternate credentials via msDS-KeyCredentialLink. No password change needed!
Why Shadow Creds?
- • No password change = no user lockout
- • No alerts about password reset
- • Stealthier than force password change
Windows Tool
Whisker.exe add /target:TargetUser
🔄 Self-Membership Abuse
Self-Membership ACE allows adding yourself to a group. Requires LDAP (net rpc fails)!
⚠️ Re-Authentication Required
After adding to group, you must re-authenticate (new Kerberos ticket) for group membership to take effect!
Delegation Attacks
🔓 Unconstrained Delegation
Computers with unconstrained delegation store TGTs of connecting users. Compromise one → steal tickets!
🔐 Constrained Delegation
🔄 Resource-Based Constrained Delegation (RBCD)
With GenericWrite on a computer, configure RBCD to impersonate any user to that computer!
💡 RBCD Requirements
Need GenericWrite/GenericAll on target computer + MachineAccountQuota > 0 (default is 10) OR existing controlled account with SPN
🎭 NoPAC / sAMAccountName Spoofing
CVE-2021-42278/42287 - Rename account to match DC, request TGT, revert name. KDC issues DC-level ticket!
⚠️ NoPAC Patched
Patched in Nov 2021 (KB5008102/KB5008380). Still works on unpatched systems - check with noPac scanner first!
ADCS Certificate Attacks
AD Certificate Services misconfigurations (ESC1-ESC13) allow privilege escalation through PKI abuse. Bypasses VBS/Credential Guard!
🔍 ADCS Enumeration
📜 ESC1 - SAN Impersonation
Template allows enrollee to specify Subject Alternative Name (SAN). Request cert as any user!
📜 ESC2 - Any Purpose EKU
Template with Any Purpose EKU or no EKU. Can be used for client authentication.
📜 ESC3 - Enrollment Agent Abuse
Request cert on behalf of another user using enrollment agent certificate.
📜 ESC4 - Vulnerable Template ACLs
With WriteDacl/WriteOwner on template, modify it to enable ESC1!
📜 ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2
CA flag allows SAN in all certificate requests, regardless of template settings.
📜 ESC7 - Vulnerable CA Access Control
ManageCA + ManageCertificates rights on CA = enable approval + issue denied requests.
📜 ESC8 - NTLM Relay to HTTP Enrollment
Relay NTLM authentication to certificate enrollment endpoint. Coerce DC machine account!
Template Misconfigs
- ESC1: Enrollee supplies SAN
- ESC2: Any Purpose EKU
- ESC3: Enrollment Agent abuse
- ESC9: No security extension
ACL & Relay Attacks
- ESC4: Writable template ACLs
- ESC7: CA ManageCA rights
- ESC8: NTLM relay to HTTP
- ESC11: RPC relay bypass
💡 Why ADCS Bypasses VBS/Credential Guard
ADCS attacks exploit certificate issuance logic, not credential storage. VBS protects LSASS memory; certs authenticate via PKINIT (different path).
Domain Dominance
You've reached Domain Admin or equivalent. Time to own everything.
💀 DCSync Attack
Replicate AD data as if you were a DC. Dump every hash in the domain!
How it works:
DCSync abuses the MS-DRSR replication protocol. Domain Controllers use this to sync AD data between each other. If you have DS-Replication-Get-Changes + DS-Replication-Get-Changes-All rights (Domain Admins have these by default), you can request replication of any user's password data - including the krbtgt hash for Golden Tickets.
🏆 Golden Ticket
With krbtgt hash, forge tickets for any user. Valid until krbtgt password changes (rarely happens)!
Why Golden Tickets are "game over":
The krbtgt account encrypts/signs all TGTs in the domain. With its hash, you can forge a TGT for any user (even non-existent ones!) with any group memberships. The KDC can't tell the difference. The krbtgt password rarely changes, so Golden Tickets persist through password resets. This is the ultimate persistence mechanism.
💡 Getting the krbtgt Hash
Use DCSync to get the krbtgt hash: lsadump::dcsync /domain:domain.local /user:krbtgt - look for the NTLM hash in output.
🚨 Persistence Warning
Golden tickets are incredibly powerful but may trigger alerts in mature environments. Use responsibly and only when authorized!
🥈 Silver Ticket
Forge service ticket using service account hash. Stealthier than Golden - no DC contact needed!
Golden vs Silver
- Golden: krbtgt hash → any service
- Silver: service hash → one service
Common Silver SPNs
CIFS, HTTP, MSSQLSvc, LDAP, HOST