Nullpath
21 pages

Attack Paths

End-to-end chains: the specific misconfiguration, the tooling, and the walk from foothold to domain dominance.

Page Kind Updated
GPO Edit Rights → Code Exec on DCs → Domain Admin
attack path 13 Jun
DCSync AES128 → Diamond Ticket → Durable Domain Admin
attack path 06 Sept
Enrollment Rights on ESC1 Template → Domain Admin Cert
attack path 13 Jun
Constrained Delegation
TrustedToAuth + high-priv SPN
attack path 06 Sept
DCSync → Golden Ticket → Domain Admin
attack path 06 Sept
AS-REP Roasting
preauth-disabled account
attack path 06 Sept
Forest A Compromise → SID History Trust Pivot → Forest B
attack path 13 Jun
ESC8
PetitPotam → NTLM relay → AD CS machine cert
attack path 06 Sept
Kerberoasting → Cracked Service Account → DCSync → Domain Admin
attack path 06 Sept
GenericWrite/ACL → Shadow Credentials → DCSync
attack path 17 Aug
LAPS Password Read → Local Admin on a Tier-0 Box → DCSync → Domain Admin
attack path 06 Sept
mitm6
IPv6/ARP coercion
attack path 06 Sept
Overpass the Hash → local admin on a target
attack path 06 Sept
Pass-the-Hash
dumped NT hash
attack path 06 Sept
LSASS Key → Pass the Key → DCSync → Domain Admin
attack path 06 Sept
RBCD on a Domain Controller → impersonate a Domain Admin on the DC → DCSync → Domain Admin
attack path 06 Sept
SCCM Client → Network Access Account → Domain Admin
attack path 13 Jun
Shadow Credentials
GenericWrite → msDS-KeyCredentialLink
attack path 06 Sept
GenericWrite on a User → SID History → Enterprise Admin
attack path 06 Sept
Silver Ticket
forged TGS with a service/machine secret
attack path 06 Sept
Coercion → Unconstrained Delegation → DCSync → Persistence
attack path 17 Aug
21 pages in this section