Repaso CRTP
Conceptos, técnicas y comandos que se recomienda entender antes de presentarse al examen
1. Enumeración
. .\Powerview.ps1Import-Module ActiveDirectory.ps1
. .\ActiveDirectory.ps1Get-NetDomain
Get-NetDomain -Domain powershell.localGet-ADDomain
Get-ADDomain -Identity powershell.local
(Get-ADDomain).DomainSID.ValueGet-NetDomainController
Get-NetDomainController -Domain powershell.localGet-ADDomainController
Get-ADDomainController -Discover -DomainName powershell.localGet-NetUser
Get-NetUser -Domain powershell.local
Get-NetUser –Username labuser
whoami /privGet-ADUser -Filter * -Properties *
Get-ADUser -Server ps-dc.powershell.local
Get-ADUser -Identity labuserGet-UserProperty
Get-UserProperty –Properties pwdlastset
Get-ADUser -Filter * -Properties * | select -First 1 | Get-Member -MemberType *Property | select Name
Get-ADUser -Filter * -Properties * | select name,@{expression={[datetime]::fromFileTime($_.pwdlastset)}}GPOs (Group Policy Object)
OU (Organizational Unit)
ACLs (Access Control List)
BloodHound
2. Escalada de Privilegios Local
3. Movimiento Lateral
Powershell Remoting
Mimikatz & tokens
Manipulación de tokens
4. Persistencia
Silver Ticket
Golden Ticket
5. Escalada de Privilegios
Kerberoast
AS-REP Roasting
SPN
Delegations
Unconstrained
Constrained
DNSAdmin
6. MSSQL Servers
Database Links
Last updated