🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🕵️ SicherheitslückenCVE-2026-84651 | Jenkins Project up to 2.567.x REST API permission(13.09.2026 um 04:28 Uhr)
🕵️ SicherheitslückenCVE-2026-84652 | Jenkins Project up to 2.567.x session fixiation(13.09.2026 um 04:28 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🔧 AI Nachrichten ChatGPT automatically logged out [Fix](12.09.2026 um 17:09 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
🪟 Windows TippsServertimeout in Outlook über 10 Minuten verlängern(12.09.2026 um 15:10 Uhr)
🕵️ SicherheitslückenCVE-2026-84651 | Jenkins Project up to 2.567.x REST API permission(13.09.2026 um 04:28 Uhr)
🕵️ SicherheitslückenCVE-2026-84652 | Jenkins Project up to 2.567.x session fixiation(13.09.2026 um 04:28 Uhr)

🕵️ Hacking 🕛 vor 2 Monaten 3 Min Lesezeit
0

Post-Compromise Attacks in AD: Credential Validation with CrackMapExec

↗ Quelle (infosecwriteups.com)
🗣️ Stimme:
📑 Inhaltsübersicht

“P.S. I wrote this article while still learning Active Directory penetration testing myself, so there may be gaps or imperfections in places. Any kind of constructive feedback is welcome.”

In this write-up, I will demonstrate post-compromise attacks in an Active Directory environment. The attacks will be carried out on a local AD lab setup using Windows Server 2016 and two Windows Enterprise user machines THEPUNISHER and SPIDERMAN . The fcastle user has local administrative privileges on both machines for testing purposes.

Post-compromise attacks are only carried out after the attacker has gained initial access to the network. In this demonstration, we will assume access to a domain user credential that we obtained via LLMNR poisoning.

Using Crackmapexec to validate credentials

Here, we will use Crackmapexec and check if an already obtained credential can authenticate on other machines on the domain.

CrackMapExec is a popular tool used to pentest AD Environments. It’s no longer maintained and was replaced by NetExec, which is a fork of the tool with more modules.

Consider the user fcastleof whom we obtained the password via LLMNR poisoning and hash cracking. We will use it here to check if the credentials are valid for any other hosts on the network via the SMB protocol

crackmapexec smb 192.168.91.0/24 -u fcastle -p Password1 -d MARVEL.local

As you can see, CrackMapExec scans the whole subnet for targets and applies the credentials to all the available machines. Here we can see that the credentials can be used on two machines, i.e THEPUNISHER and SPIDERMAN . The Pwn3d! tag indicates that fcastle has local administrator privileges on both the machines as well.

Dumping SAM hashes

We can dump SAM hashes of the users on local machines. Keep in mind these hashes are of the local and not domain accounts.

We can also dump SAM hashes using the --sam flag.

As you can see in the above image, the SAM hashes of all the available accounts on the SPIDERMAN and THEPUNISHER machines were dumped successfully.

We can also usesecretsdump from the Impacket suite to dump the SAM hashes in case CME dumping does not work.

impacket-secretsdump marvel/fcastle:[email protected]

As you can see, the tool provides much more than just SAM hashes, such as LSA secrets.

We can further use the above information and gain access to a device via psexec.py from the Impacket suite.

impacket-psexec.py marvel/fcastle:[email protected]

As you can see, we have gained a shell on the target after validating the credentials using CME.

It should be noted that using psexec.py is a very noisy method to gain a shell on the target as it drops an executable binary on the system. These days it gets easily flagged by Microsoft Defender, and I myself had to disable virus protection just for the sake of demonstration.

Hash cracking

We can use the above-obtained SAM hashes and crack them using Hashcat.

hashcat -m 1000 hashes.txt rockyou.txt

I did not perform this process on my device, considering I don’t have the required hardware to conduct hash-cracking. But if you have a good device with a dedicated GPU, then conducting this process should be a breeze. Hash-cracking also depends heavily upon the complexity of the password and will take a lot less time if it is short in length or less complex.


on Medium, where people are continuing the conversation by highlighting and responding to this story.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf infosecwriteups.com.
↗ Original-Artikel auf infosecwriteups.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
ChatGPT automatically logged out [Fix]
1 Quelle
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Post-Compromise Attacks in AD: Credential Validation with CrackMapExec

Thematisch verwandte Begriffe: PostCompromise, Attacks, Credential, Validation · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...