Active Directoy
Last updated
Last updated
Active Directory is a directory service developed by Microsoft for Windows domain networks. It is included in most Windows Server operating systems as a set of processes and services. Initially, Active Directory was only in charge of centralized domain management.
--
Domain Admins group
Domain Controller
Display permissions using PowerShell
List local accounts
List domain accounts
Details about specific user
List domain groups
Show domain's account policy
Alternative approach (probably gets flagged by AV)
Copy & execute mimikatz.exe
on DC
OR
Copy generated *BloodHound.zip
OR
Connect to database
Import data
Upload Data
select .csv
, .json
or .zip
file(s)
1. sniff KRB auth packet 2. crack using hashcat
-> If no pre auth is required, just use to pull hashes from AD.
BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment.