OSOUMA SYDENincyberagent.dev·Jun 5, 2024 · 1 min readDumping Domain Controller Hashes via wmic and Vssadmin Shadow CopyThis quick labs hows how to dump all user hashes from the DC by creating a shadow copy of the C drive using vssadmin — remotely. This lab assumes the attacker has already gained administratrative access to the domain controller. Execution Create a sh...00
OSOUMA SYDENincyberagent.dev·Jun 5, 2024 · 10 min readLateral movement and on-prem NT hash dumping with Microsoft Entra Temporary Access PassesTemporary Access Passes are a method for Microsoft Entra ID (formerly Azure AD) administrators to configure a temporary password for user accounts, which will also satisfy Multi Factor Authentication controls. They can be a useful tool in setting up ...00
OSOUMA SYDENincyberagent.dev·Jun 5, 2024 · 3 min readEmpire Shells with NetNLTMv2 RelayingYour Security is Our Mission. This lab will perform a NetNLTM authentication relay attack where a victim1 host will try to authenticate to our attacking system, which will be listening for authentication attemps and relaying them to victim2 host with...00