Active Directory

LLMNR

Cracking captured Hashes

SMB Relay Attacks (NTLM)

Gaining Shell Access

IPv6 DNS Takeover via mitm6

Domain Enumeration with Ldapdomaindump

Domain Enum with Bloodhound

Domain Enum with Plumhound

PingCastle

—POST COMPROMISE—

Kerberoasting

Token Impersonation

URL File Attacks

GPP Attacks (cPassword Attacks)

Mimikatz (there’s also Kiwi)

Pass Attacks (The Pass/The Hash)

POST-COMPROMISE STRAT

We Own the Domain, now what?

Dumping the NTDS.dit

Golden Ticket w/ Mimikatz

Shouldn’t Use Unless Approved

Reader ratings (none yet)

Ratings come from verified buyers only.