Migrating to Domain Admin processes is a common way penetration testers are able to impersonate Domain Admin accounts on the network. However, before a pentester can do that, they need to know what systems those processes are running on. In this blog I’ll cover 5 techniques to help you do that. The techniques that will be covered include:
Checking Locally
Querying Domain Controllers for Active Domain User Sessions
Scanning Remote Systems for Running Tasks
Scanning Remote Systems for NetBIOS Information
PSExec Shell Spraying Remote Systems for Auth Tokens
Selective Symbolic Execution(S2E)
Today, 08:33 AM in Reverse Engineering and Application Cracking