Privileged Access

ko-fi

To get all data in Bloodhound, use SharpHond.exe - Exegol compatible version https://github.com/BloodHoundAD/SharpHound/releases/download/v1.0.4/SharpHound-v1.0.4.zip

Bloodhound.py don't get all data, probably because of DNS resolution

Remote Desktop Users Group

PS C:\htb> Get-NetLocalGroupMember -ComputerName ACADEMY-EA-MS01 -GroupName "Remote Desktop Users"

ComputerName : ACADEMY-EA-MS01
GroupName    : Remote Desktop Users
MemberName   : INLANEFREIGHT\Domain Users
SID          : S-1-5-21-3842939050-3880317879-2865463114-513
IsGroup      : True
IsDomain     : UNKNOWN

Bloodhound Query

MATCH p=(g:Group {name:"DOMAIN USERS@INLANEFREIGHT.LOCAL"})-[:CanRDP]->(c:Computer) WHERE c.operatingsystem CONTAINS "Server" return p

WinRM

PS C:\htb> Get-NetLocalGroupMember -ComputerName ACADEMY-EA-MS01 -GroupName "Remote Management Users"

ComputerName : ACADEMY-EA-MS01
GroupName    : Remote Management Users
MemberName   : INLANEFREIGHT\forend
SID          : S-1-5-21-3842939050-3880317879-2865463114-5614
IsGroup      : False
IsDomain     : UNKNOWN

Bloodhound Query

EnterPSSession

Double Hop Problem:

Kerberos Double Hop Problem

Evil-WinRM

Evil-WinRM

MSSQL

Bloodhound Query

PowerUpSQL

mssqlclient.py

MSSQL (1433)

Last updated