π₯οΈActive Directory
DNS
To try to leak dns info:
Powershell DNS config:
LDAP(389)
Then use -b to select and then filter,etc ..
Ex:
To use kerberos authentication:
To get list of users:
EXAMPLES:
RPC
Then can do multiple commands:
If valid users list is present use this to password spray:
WinRM(5985)
SMB(445,139)
CrackMapExec
To check password policy(from kali):
To get TGT hashes for users with
For enumeration as it handles proxied traffic better:
To use kerberos authentication
Last updated
Was this helpful?
