Attacking Active Directory & NTDS.dit
Understanding Windows Domain Authentication
Key Authentication Components:
Dictionary Attacks on AD Accounts
Tools Used:
Common Username Conventions:
Format
Example for Jane Jill Doe
Username List Example:
Generate of usernames.
Launching the Dictionary Attack
CrackMapExec:
Event Logging of the Attack

Capturing NTDS.dit
What is NTDS.dit?
NTDS.dit?Connecting to a DC with Evil-WinRM
Check User Privileges:
Creating a Shadow Copy of NTDS.dit
Copy the File:
Quick Method: Dumping NTDS.dit with CrackMapExec
Cracking Hashes
Pass-the-Hash (PtH)
Defensive Takeaways
Last updated