How to use AD misconfigurations and features in order to gain access or to escalate privileges. AD is in the heart of most of enterprise networks and is usually a main pilar for identity and access management. Owning AD usually means owning the complete enterprise, so it is quite interesting target for attacks. We will explore some of the most common attack venues against AD.
AD is everywhere and it is a cornerstone of enterprise identity management. Although new IAM technologies are expanding, it is still present in almost every internal network.
This talk will cover basics of ad and show some of the most common attacks and tools, both linux and powershell based.
This is based on a real life scenario as it occurred during the pentest. We will demonstrate how to gain initial access as unauthorized attacker, and how to escalate and own everything.
By leveraging misconfiguration of AD, bypassing windows defender in order to escalate privileges and expand domination to own full AD and even complete forest. We will shown techniques like kerberoasting, weak acl, user impersonation and similar.
Also, we will show how to use some of existing tools on machine in order to accomplish specific goals.