🇷🇴 cristi Profile picture
cyber/AI/biomed

Dec 5, 2022, 6 tweets

5 PRO tips to use in your enumeration for Active Directory pentesting:

(thread)

1. Leverage LDAP queries and enumeration tools such as ADRecon and BloodHound to gather as much information as possible about the Active Directory environment, including user accounts, group memberships, and access rights.

2. Look for common misconfigurations, such as weak passwords and unsecured administrative accounts, as well as access controls that allow users to elevate their privileges or access sensitive data.

3. Use Kerberos enumeration techniques, such as AS-REP Roasting and golden tickets, to bypass authentication controls and gain access to the domain controller.

4. Once you're inside the network, use Mimikatz to extract passwords and other sensitive information from memory, providing access to otherwise secure resources.

5. Use trust relationships to move laterally within the network, without having to compromise additional accounts or exploit vulnerabilities.

#infosec #cybersecurity #pentesting #cybersecuritytips

Like, RT, and follow me @CristiVlad25 for more.

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling