A beginner-level walkthrough of post-compromise attacks in an Active Directory lab environment. Covers using CrackMapExec to validate stolen credentials across a subnet via SMB, dumping SAM hashes with the --sam flag and Impacket's secretsdump, gaining a shell via psexec.py, and cracking NTLM hashes with Hashcat. The lab uses Windows Server 2016 with two Windows Enterprise machines, and credentials were initially obtained via LLMNR poisoning.
Table of contents
Using Crackmapexec to validate credentialsDumping SAM hashesGet Kavin Jindal’s stories in your inboxHash cracking109 Impressions