Search

POST-COMPROMISE STRAT

image

No need for shells

  • Quick wins:
    • Kerberoasting is quick and easy hash to crack
    • Secretsdump can also get you quick hashes to crack
    • Pass the cracked pass or spray the hash
  • No quick wins:
    • Enum!

Attacks to Research:

  • Certificate Attack
    • tool: certipy