Active Directory Security
PRACTICE ! PRACTICE ! PRACTICE !
Last updated
PRACTICE ! PRACTICE ! PRACTICE !
Last updated
If anonymous user has READ permissions over the $IPC share, then
Meanwhile, run the enum4linux in the background
If rpcclient has anonymous login then
After finding valid usernames, try to check if there is any way to AS-REP roast
Enumerate Shares with those creds - cme
Try dumping the secrets with it - impacket-secretsdump
Try dumping the sam and lass - crackmapexec
Check for winrm, smb and other services till it gets Pwn3d