Active Directory CVE Hunting
Before or during an AD assessment, always fetch the latest CVEs related to Windows Server versions, Kerberos, LDAP, RPC, or Exchange.
Objective
If only the active-directory testing type is selected, the agent must be able to independently look up the latest vulnerabilities (e.g., PrintNightmare, ZeroLogon, ProxyShell) to ensure no newly discovered flaws are missed.
Skills & Execution
- Use
search_webto query the latest CVEs for identified Windows services and domain controllers. - Monitor exploit databases and security advisories for recent Active Directory proofs of concept (PoCs).
- Cross-reference discovered OS build numbers and patch levels with known vulnerabilities.