Search

Home

PNPT Studies

PJPT Studies

AD CS / Certificate Attacks (ESC1-15) (1, 8, 11 for now)

Report Writing / Client Presentation

Operationalizing Cybercrime Data (June 2025)

POST-COMPROMISE STRAT

image

No need for shells

  • Quick wins:
    • Kerberoasting is quick and easy hash to crack
    • Secretsdump can also get you quick hashes to crack
    • Pass the cracked pass or spray the hash
  • No quick wins:
    • Enum!

Attacks to Research:

  • Certificate Attack
    • tool: certipy