NMAP - Users
Course Content
0 / 100 completedIntroduction
More NMAP Enumeration
NMAP SMB
NMAP
winapsearch
NMAP - Users
LdapDomainDump
GetADUsers.py
Enumerating With Enum4Linux
CrackMapExec Intro
CrackMapExec - Password Spraying
CrackMapExec - ENUM 1.1
CrackMapExec - ENUM 1.2
CrackMapExec - Command Execution
crackmapexec - Command execution + Using Local Auth
Dumping SAM
Get PowerShell Reverse Shell
pth-winexe and xfreerdp
CrackMapExec CMEDB
CrackMapExec Modules
Dumping LSA + PTH with CME
BADDD No AUDIO Getting Shells with CrackMapExec
BloodHound Installation
Upload and Download
Basic commands
User, Group, and Network
PowerView.ps1
OS, AV, and Configuration
Build SharpSploit - Enumeration
Tools - Local Priv Esc
Sherlock and Watson
CVE-2019-1388
SEImpersonate
Unquoted Service Path
Getting a Shell + CME + Powershell
Basics and Installing
Getting a shell + Evil-WinRM + Bat File
Privilege Escalation 2 - Stager with NTSYSTEM
Privilege Escalation 3
Elevated with Empire - Mimikatz and pth
Failed to get + dcsync + dcshadow - 3
Pth + dcsync + dcshadow -1
Privilege Escalation 1 - ReverShell With Unquoted Path
Getting Shell with JenkinsAdmin
Troubleshooting Empire Pth + dcsync + dcshadow - 2
Finally Getting Dcsync + Persistent
Intro
Exploiting Ethernal Blue Metasploit
Enumeration 2 - Arp, Tokens, Patches
Enumeration 1 - User, Groups, Computers
Exploit Suggestor
Enumeration 3 - Shares, SMB, and More
Back door add user
Exploit Suggestor 2
HashDump With Metasploit
Lateral Movement - PTH With metasploit
DcSync With Metasploit
Steal Token and Dumping All Hashes - Metasploit
Lateral Movement To DC - Metasploit
BACKDOOR METERPRETER SERVICE 2
Golden Ticket With Metasploit
BACKDOOR METERPRETER SERVICE 1
Intro Domain Enumeration
Domain Group Enumeration
Domain ComputerServers Enumeration
Domain User Enumeration
PowerView - GPO and OU
Active Directory Recon
Domain Shares Enumeration
BloodHound Installation
PowerView - ACL
BloodHound Basics
Intro to Lateral Movement - RDP
SAM & LSA with MimiKatz
Dumping SAM and SYSTEM For Offline Cracking
PassTheHash with MimiKatz
Session Hijack
Pass the ticket with Rubeus
Passing the ticket
SMB Relay Attack
Intro - Domain Privilege Escalation
ACL - GenericAll on Group
Unconstrained delegation - Computer
Priv Esc – DNSAdmins
dcsync
constrained Delegation - Computer
ACL - GenericWrite on User
Targeted Kerberoasting - AS-REPs - FINDING
SET-SPN - Kerberoast
Targeted Kerberoasting - AS-REPs - SET
Intro Domain Persistence and Dominance - RDP
DCShadow - Change Attribute
DSRM
DCShadow - SIDHistory
Golden Ticket
Silver Ticket
DCShadow - hash
AdminSDHolder - Adding Permission
ZeroLogon -- Do This Last
AdminSDHolder - Abusing Permission