Hacking Articles
Read post

Shadow Credentials Attack

The post explains the Shadow Credentials attack, which exploits Active Directory Certificate Services (AD CS) to inject custom certificates into a user account, allowing attackers persistent access by modifying the msDS-KeyCredentialLink attribute. It provides details on lab setup, various exploitation methods, and mitigation techniques. Additionally, the post covers Kerberos authentication and its PKINIT extension, and lists tools for both exploitation and post-exploitation. Finally, it describes methods for effectively detecting and mitigating these attacks.

    #security#microsoft#active-directory#kerberos
Feb 12, 2025•15m read time•From hackingarticles.in
Post cover image
Table of contents
Table of ContentsIntroduction to Kerberos AuthenticationPrerequisitesLab SetupExploitationBloodhound – Hunting for Weak PermissionMethod for ExploitationPyWhiskerCertipy-adNTLMRelayxBloodyADMetasploitLdap_shellPost-ExploitationImpacket -psexecEvil-winrmDetection & MitigationDetectionMitigation
83 Impressions
Hacking Articles's image
Hacking Articles

Hacking Articles IN is a platform or publication dedicated to cybersecurity research, tutorials, and...

98 Followers

•

50 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard