Offensive Active Directory with PowerShell
WEareTROOPERS via YouTube
Overview
Syllabus
Introduction
Agenda
Why PowerShell
What is Active Directory
Why not use PowerShell
PowerView
Pipeline
Identifying and Hunting
Powershell Commandments
VOC User Hunter
Stealth User
Raw Data
Local Admin Enumeration
Local Group Enumeration
Process
GPO Abuse
Group Policy Preferences
Get GPP Password
Get Organizational Units
Group Policy Objects
Fine GPO Location
Active Directory CL
Active Directory ACL
Invoke ACL Scanner
Admin SD Holder
Downgrades
Power View
Domain Trust
Why Trust Matters
Trust Enumeration
Trust Mesh
Map Domain Trust
Domain Trust Explorer
CID histories
Golden Tickets
Kerberos
Trustpocalypse
Cheat Sheets
Credits
Questions
Taught by
WEareTROOPERS