
Red Team Cheatsheet in constant expansion.

You can support me here 🐱 :
This AD attacks CheatSheet, made by RistBS is inspired by the Active-Directory-Exploitation-Cheat-Sheet repo.
Powershell tools :
[⭐] Nishang -> https://github.com/samratashok/nishangnishang has multiples useful scripts for windows pentesting in Powershell environement.
powerview is a script from powersploit that allow enumeration of the AD architecture for a potential lateral mouvement.
Enumeration tools :
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeAD exploitation toolkit :
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoDumping Tools :
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/RubeusListener Tool :
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session :
#METHOD 1
$c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user
Enter-PSSession -Credential $c -ComputerName 10.10.13.100
# METHOD 2
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force
$cred = New-Object System.Management.Automation.PSCredential('$user, $pass')
Enter-PSSession -Credential $c -ComputerName 10.10.13.100
allow anyone with creds to connect to any machine and any config
[ ! ] this action require credentials.
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *
using PowerView :
Get-NetUser –SPN
using AD Module :
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName
MapTrust :
Invoke-MapDomainTrust
Domain trusts for the current domain :