Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Domain-Controller-DC-Exploitation-with-Metasploit-Impacket — End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session. | Kitploit
Tools/GitHubGitHub/nyambiblaise/domain-controller-dc-exploitation-with-metasploit-impacket
ReconnaissanceExploit FrameworksPayload GenerationVulnerability AnalysisLateral MovementPost-ExploitationPenetration TestingLearning & EducationLabs & Practice

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHubnyambiblaise/domain-controller-dc-exploitation-with-metasploit-impacket

Domain-Controller-DC-Exploitation-with-Metasploit-Impacket

End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.

View Repository
1711 months agoNot yet reviewed
Share

Domain-Controller-DC-Exploitation-with-Metasploit-Impacket

End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.

Executive Summary This exercise demonstrates a complete, realistic attack chain against a domain controller that was vulnerable to CVE-2020-1472 (Zerologon). The engagement included discovery, service enrichment, exploitation, credential extraction, lateral movement, and post-exploitation validation. I successfully obtained SYSTEM-level access and established a persistent Meterpreter session on the DC using a combination of Zerologon, Impacket secretsdump + pass-the-hash, and msfvenom/meterpreter payloads. Screenshots and command artifacts were captured at each stage as evidence.

𝐋𝐚𝐛 𝐨𝐯𝐞𝐫𝐯𝐢𝐞𝐰: Simulated a full attack chain on a 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐃𝐨𝐦𝐚𝐢𝐧 𝐂𝐨𝐧𝐭𝐫𝐨𝐥𝐥𝐞𝐫 using 𝐌𝐞𝐭𝐚𝐬𝐩𝐥𝐨𝐢𝐭 and 𝐈𝐦𝐩𝐚𝐜𝐤𝐞𝐭 ; discovery, Zerologon, secretsdump, pass-the-hash, and a controlled Meterpreter session.

𝐖𝐡𝐲 𝐢𝐭 𝐦𝐚𝐭𝐭𝐞𝐫𝐬 𝐭𝐨 𝐨𝐫𝐠𝐚𝐧𝐢𝐳𝐚𝐭𝐢𝐨𝐧𝐬: Because the DC controls authentication, group policy, and identity for the entire domain, a compromise can cascade into full business disruption, account takeovers, data exfiltration, ransomware deployment, and loss of regulatory trust. Protecting DCs safeguards uptime, revenue, and reputation by preventing attackers from turning identity into a single point of failure.

Domain Controller (DC) Exploitation with Metasploit + Impacket

SCENARIO

You are provided with two machines in a contained lab network. One system is a Windows Domain Controller (DC) named DC10 that hosts core AD services. The other system is a Kali workstation placed in the same server subnet for testing. The DC is assumed to expose typical domain services (for example, LDAP, Kerberos, SMB) and may be vulnerable to known issues. The Kali host is expected to be used for reconnaissance, exploitation, credential access, lateral movement, and post-exploitation validation. The task is to identify the DC, confirm domain details, obtain an initial foothold using an applicable technique, extract credential material to enable administrative access, and then demonstrate control of the DC through a remote shell and a managed agent session, while adapting to any environmental constraints such as patched services, restricted egress, or endpoint defenses. DC: 10.1.16.1 Kali: 10.1.16.66

Key Findings

  • Critical vulnerability exploited: CVE-2020-1472 (Zerologon) was successfully exploited to reset the DC machine account password to empty.
  • Credential compromise: NTLM hashes were extracted from the DC (secretsdump), revealing Administrator credentials enabling pass-the-hash.
  • Complete domain control demonstrated: Using extracted hashes, a SYSTEM shell on DC10 was obtained (psexec), and a stable Meterpreter reverse shell was run, confirming remote code execution and persistence.
  • Exposed services: LDAP, Kerberos, SMB and related RPC services were reachable from the attacking host, enabling discovery and exploitation.
  • Attack surface risk: The DC accepted remote operations which allowed machine account manipulation and remote payload execution.

1) Discovery and Scoping

I used msfconsole with DB support, ran an nmap sweep from within MSF, imported results, and refined hosts and services to confirm DC10 exposure.

  • Launched msfconsole with DB support and confirmed database connectivity.
  • Ran an nmap scan across the subnet from msfconsole and imported results into the MSF DB.
  • Cleaned the hosts table to remove my Kali IP. Reviewed services to spot likely DC indicators.
  • Used MSF’s SYN port scanner with a constrained port range and global threading to refine service data.
  • Fingerprinted SMB on Windows hosts to enrich OS details.
  • Confirmed LDAP and Kerberos services on 10.1.16.1 and verified the domain name via an LDAP query.
  • Decision: Treat 10.1.16.1 as the DC focus for exploitation and credential access.
Image Image Image

2) Service Enrichment and DC Confirmation

I performed a SYN port scan in MSF, fingerprinted SMB, and confirmed LDAP and Kerberos on 10.1.16.1. I queried LDAP to retrieve the domain name.

Image Image Image Image Image ### SMB version check
  • I used the SMB version module in msfconsole: auxiliary/scanner/smb/smb_version.
  • I set the targets from the hosts table with hosts -R .
  • Got SMB dialect and OS details back.
  • Result: 10.1.16.1 showed Windows Server info, which lined up with it being the Domain Controller.
Image Image Image Image Image

LDAP query

  • For the LDAP query module , I usedauxiliary/gather/ldap_query.
  • et rhosts 10.1.16.1 to hit DC10 directly.
  • I ran it to pull basic directory info.
  • Result: Confirmed the domain name as “structureality” and that LDAP on the DC was responding.
Image Image Image Image
Download Tool