Ad Attack

Active Directory exploitation after domain credentials exist: Kerberos (AS-REP/Kerberoast including cracking the ticket then using the account), delegation, NTLM coercion/relay, lateral movement, ACL abuse, ADCS ESC1-ESC17 and CVE paths, dMSA/BadSuccessor, Kerberos reflection, identity confusion, management-plane, domain trust, and domain persistence. Own the current AD chain through crack-and-use to DA, equivalent domain control, or the targeted host SYSTEM. Do not stop after requesting TGS. Host C2 belongs to /post. Operator chooses next modules.

pale-knight 3c45f85 10 files · 51.7 KB Updated

File contents

pale-knight/redteam-skill/tree/main/skills/ad-attack commit 3c45f85874

Frequently asked questions

npx skillmds@latest add pale-knight/ad-attack