πŸ–₯️Active Directory

DNS

To try to leak dns info:

Powershell DNS config:

LDAP(389)

Then use -b to select and then filter,etc ..

Ex:

To use kerberos authentication:

To get list of users:

EXAMPLES:

RPC

Then can do multiple commands:

If valid users list is present use this to password spray:

WinRM(5985)

SMB(445,139)

CrackMapExec

To check password policy(from kali):

To get TGT hashes for users with

For enumeration as it handles proxied traffic better:

To use kerberos authentication

Last updated

Was this helpful?