Latest

PenTest – Password – Spraying

Password spraying refers to the attack method that takes a large number of usernames and loops them with a single password. The builtin Administrator account (RID:500) cannot be
Read More

Pentest – Password – Shadow Credentials

Add Key Credentials to the attribute msDS-KeyCredentialLink of the target user/computer object and then perform Kerberos authentication as that account using PKINIT to obtain a TGT for that user. When trying to
Read More

PenTest – Password – LAPS

Reading LAPS Password Use LAPS to automatically manage local administrator passwords on domain joined computers so that passwords are unique on each managed computer, randomly generated, and securely
Read More

PEnTest – Password – GMSA

Reading GMSA Password User accounts created to be used as service accounts rarely have their password changed. Group Managed Service Accounts (GMSAs) provide a better approach (starting in
Read More

PenTest – Password – Group Policy Preferences

Find passwords in SYSVOL (MS14-025). SYSVOL is the domain-wide share in Active Directory to which all authenticated users have read access. All domain Group Policies are stored here: \\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\.
Read More