Cicada
This is not a writeup, just my notes about the machine.

Credentials
Username
Password
Method
Scope
Information Gathering
Initial enumeration
DNS
NFS

User brute forcing
Bruforcing with Kerberos authentication
Requesting a TGT ticket
Discovering Vulnerable Certificate Templates (ESC8)
Compromise Domain Controller from Linux
Adding Malicious DNS Record
Setting Up krbrelayx Environment
Launching krbrelayx Attack
Triggering Coercion via DFS
Path: Certipy-ad tool
Retrieving domain controller NT Hash
Requesting domain controller Ticket Granting Ticket
Performing DCSync Attack against domain controller
Path: PKINITtools tools
Requesting TGT Using PKINIT and PFX Certificate
Dumping Domain Secrets with secretsdump
Compromise Domain Controller from Windows
Setting up DNS

Joining to the domain controller.

Launching RemoteKrbRelay attack
Writting the base64 string into a file.
Obtaining Domain Controller NT Hash
Performing DCSync Attack against Domain Controller.
Last updated