xsspresso
xsspresso
Tags/ DCSync

DCSync

4 writeups tagged with DCSync

ADHardWindows

HTB — Blackfield

ASREPRoasting yields crackable hash. ForceChangePassword on account via BloodHound. Volatility lsass dump reveals backup operator for DCSync.

#AD#ASREPRoasting#BloodHound
Jan 23, 2025HackTheBox
ADEasyWindows

HTB — Sauna

ASREPRoasting on user names enumerated from the bank website. DCSync attack via GenericAll rights for Domain Admin hash dump.

#AD#ASREPRoasting#DCSync
Jan 20, 2025HackTheBox
ADMediumWindows

HTB — Monteverde

Azure AD Connect with user enumeration via RPC. Password spraying finds default creds. Azure AD Sync password extraction for Domain Admin.

#AD#Azure AD#Password Spray
Jan 20, 2025HackTheBox
ADMediumWindows

HTB — Administrator

FTP credentials from initial account. Targeted Kerberoasting via BloodHound paths, GenericWrite abuse, DCSync for Domain Admin hash.

#AD#Kerberoasting#BloodHound
Jan 8, 2025HackTheBox