21 pages
Attack Paths
End-to-end chains: the specific misconfiguration, the tooling, and the walk from foothold to domain dominance.
Page Kind Tags Updated
GPO Edit Rights → Code Exec on DCs → Domain Admin
DCSync AES128 → Diamond Ticket → Durable Domain Admin
Enrollment Rights on ESC1 Template → Domain Admin Cert
Constrained Delegation
TrustedToAuth + high-priv SPN
DCSync → Golden Ticket → Domain Admin
AS-REP Roasting
preauth-disabled account
Forest A Compromise → SID History Trust Pivot → Forest B
ESC8
PetitPotam → NTLM relay → AD CS machine cert
Kerberoasting → Cracked Service Account → DCSync → Domain Admin
GenericWrite/ACL → Shadow Credentials → DCSync
LAPS Password Read → Local Admin on a Tier-0 Box → DCSync → Domain Admin
mitm6
IPv6/ARP coercion
Overpass the Hash → local admin on a target
Pass-the-Hash
dumped NT hash
LSASS Key → Pass the Key → DCSync → Domain Admin
RBCD on a Domain Controller → impersonate a Domain Admin on the DC → DCSync → Domain Admin
SCCM Client → Network Access Account → Domain Admin
Shadow Credentials
GenericWrite → msDS-KeyCredentialLink
GenericWrite on a User → SID History → Enterprise Admin
Silver Ticket
forged TGS with a service/machine secret
Coercion → Unconstrained Delegation → DCSync → Persistence
21 pages in this section