
End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.
End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.
Executive Summary This exercise demonstrates a complete, realistic attack chain against a domain controller that was vulnerable to CVE-2020-1472 (Zerologon). The engagement included discovery, service enrichment, exploitation, credential extraction, lateral movement, and post-exploitation validation. I successfully obtained SYSTEM-level access and established a persistent Meterpreter session on the DC using a combination of Zerologon, Impacket secretsdump + pass-the-hash, and msfvenom/meterpreter payloads. Screenshots and command artifacts were captured at each stage as evidence.
𝐋𝐚𝐛 𝐨𝐯𝐞𝐫𝐯𝐢𝐞𝐰: Simulated a full attack chain on a 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐃𝐨𝐦𝐚𝐢𝐧 𝐂𝐨𝐧𝐭𝐫𝐨𝐥𝐥𝐞𝐫 using 𝐌𝐞𝐭𝐚𝐬𝐩𝐥𝐨𝐢𝐭 and 𝐈𝐦𝐩𝐚𝐜𝐤𝐞𝐭 ; discovery, Zerologon, secretsdump, pass-the-hash, and a controlled Meterpreter session.
𝐖𝐡𝐲 𝐢𝐭 𝐦𝐚𝐭𝐭𝐞𝐫𝐬 𝐭𝐨 𝐨𝐫𝐠𝐚𝐧𝐢𝐳𝐚𝐭𝐢𝐨𝐧𝐬: Because the DC controls authentication, group policy, and identity for the entire domain, a compromise can cascade into full business disruption, account takeovers, data exfiltration, ransomware deployment, and loss of regulatory trust. Protecting DCs safeguards uptime, revenue, and reputation by preventing attackers from turning identity into a single point of failure.
You are provided with two machines in a contained lab network. One system is a Windows Domain Controller (DC) named DC10 that hosts core AD services. The other system is a Kali workstation placed in the same server subnet for testing. The DC is assumed to expose typical domain services (for example, LDAP, Kerberos, SMB) and may be vulnerable to known issues. The Kali host is expected to be used for reconnaissance, exploitation, credential access, lateral movement, and post-exploitation validation. The task is to identify the DC, confirm domain details, obtain an initial foothold using an applicable technique, extract credential material to enable administrative access, and then demonstrate control of the DC through a remote shell and a managed agent session, while adapting to any environmental constraints such as patched services, restricted egress, or endpoint defenses. DC: 10.1.16.1 Kali: 10.1.16.66
I used msfconsole with DB support, ran an nmap sweep from within MSF, imported results, and refined hosts and services to confirm DC10 exposure.
I performed a SYN port scan in MSF, fingerprinted SMB, and confirmed LDAP and Kerberos on 10.1.16.1. I queried LDAP to retrieve the domain name.
### SMB version check
auxiliary/scanner/smb/smb_version.
auxiliary/gather/ldap_query.
