Kerberos based Enum and Attack Samples
ACL Abuse and Shadow Credential
Preparation
# Get TGT for a user
impacket-getTGT 'absolute.htb/d.klay:Darkmoonsky248girl' -dc-ip $RHOST
# Inject it into memory
export KRB5CCNAME=./d.klay.ccache Enumeration
LDAP
crackmapexec ldap dc.absolute.htb --use-kcache --users 
SMB

Bloodhound
Exploitation - ACL Abuse and Shadow Credential


Last updated