Exploiting CVE-2019-1040 - Combining relay vulnerabilities for RCE and Domain Admin -
Using a combination of these vulnerabilities, it is possible to relay SMB authentication to LDAP. This allows for Remote code execution as SYSTEM on any unpatched Windows server or workstation (even those that are in different Active Directory forests), and for instant escalation to Domain Admin via any unpatched Exchange server (unless Exchange permissions were reduced in the domain).
4 days ago by whip_lash
GitHub - porterhau5/BloodHound-Owned: A collection of files for adding and leveraging custom properties in BloodHound.
A collection of files for adding and leveraging custom properties in BloodHound. A thorough overview of the ideas that led to these Custom Queries & Ruby script can be found in this blog post:

These are intended, although not required, to be used with a forked version of BloodHound found here:
9 days ago by whip_lash
Jessica Payne on Twitter: "If you want to see if a domain admin has logged in somewhere and exposed credentials…"
"If you want to see if a domain admin has logged in somewhere and exposed credentials (logon types 2,4,5,10) and track down accounts at risk or what might break if you reduce service account privileges you don’t even need fancy tools:"
4 weeks ago by ahall
GitHub - l0ss/Grouper2: Find vulnerabilities in AD Group Policy
Grouper2 is a tool for pentesters to help find security-related misconfigurations in Active Directory Group Policy.
5 weeks ago by whip_lash
Documentation - PingCastle
This report produce a map of all Active Directory that PingCastle knows about. This map is built based on existing health check reports or when none is available, via a special mode collecting the required information as fast as possible.
5 weeks ago by whip_lash
Impersonating Service Accounts with Silver Tickets | Insider Threat Blog
Now that we have compromised at least one service account and extracted its password, this post will explore how to further exploit that account using Silver Tickets.
5 weeks ago by whip_lash

