My Quest for Privileged Identity to Own Your Domain
Overview
Syllabus
Introduction
Active Directory vulnerabilities
Story time
Kill chain
Detective
Intrusions
Group Policy Preferences
AES Encryption Key
Mitigation
Internal Reconnaissance
LDAP Global Catalog
Bloodhound
Bloodhound Demo
Intelligence Gathering
Reconnaissance
NTLM
Windows 10 workaround
Custom SSP
NTDs
KDC
Registry Keys
Backups
hashes
SMB authentication
HTML image tag
Custom forms
Mitigation for stealing hashes
LLM in our
Attack
Disable
SMP Signing
SMP Relay Attack
Enable SMP Signing
Kerberos
Kerberos in Active Directory
High Privileged Users
Golden Ticket
Instructions
The Golden Ticket
SPN
Active Directory
TGS Ticket
Silver Ticket
NIST
Seed History
Known Seats
Injection Attack
Shadow Attack
Shadow Mitigation
Replicating Directory
Domain Controller
Replication
The common denominator
Kerberos is more secure
Stolen credentials
Password guidelines
The principle of least privilege
Separation of privilege
Multifactor authentication
Adaptive enforcement
Aggregate attack service
Summary
Taught by
BSidesLV