created: "2025-03-16 11:55"
tags:
- 渗透姿势库
- moc
Type:
- Note
title: 【MOC】活动目录
aliases:
- 【MOC】ActiveDirectory
updated: "2025-10-07 20:25"
comment:
cssclasses:
- moc-kanban
icon: 📚
📂 未分类
| 内网AD域&Kerberos点&黄金票据&白银票据&钻石票据&蓝宝石票据 | 2025-03-14 21:19 | #AD域, #内网安全, #黄金票据, #白银票据, #钻石票据, #蓝宝石票据 |
| AD CS | 2025-03-14 21:19 | #域渗透, #证书, #委派安全 |
| CDN绕过技巧 | 2025-03-14 21:19 | #CDN, #信息收集 |
| CTF中各种花式绕过 | 2025-03-14 21:19 | #ctf, #bypass |
| HasSession | 2025-03-14 21:19 | #HasSession, #域渗透, #Bloodhound分析 |
| SIDHistory | 2025-03-14 21:19 | #域渗透, #Bloodhound分析 |
| rbash绕过 | 2025-03-14 21:19 | #rbash, #shell |
| Redis dll劫持 | 2025-03-14 21:19 | #dll劫持 |
| SeLoadDriverPrivilege | 2025-03-14 21:19 | #SeLoadDriverPrivilege, #windows提权 |
| 代理池搭建与爆破 | 2025-03-14 21:19 | #隧道代理, #代理池, #爆破 |
| 绕过 AppLocker | 2025-03-14 21:19 | #AppLocker, #应用程序控制策略 |
| 默认受保护组 | 2025-03-14 21:19 | #默认受保护组 |
| 水坑攻击 | 2025-04-27 22:29 | #水坑攻击, #权限维持 |
| SNMP利用 | 2025-08-04 23:38 | #SNMP |
| 【收集】 | 2025-09-21 00:06 | #input |
📁 0-About
📁 6-补充
📁 7-sudo提权
📁 Movement/1-Credentials
📁 Movement/1-Credentials/1-Dumping
📁 Movement/2-MITM coerced-auths
📁 Movement/3-NTLM
📁 Movement/4-Kerberos
| 11.Pass the Certificate | 2025-03-14 21:19 | #PTC |
| 7.AS-REP-Roasting | 2025-03-14 21:19 | #AS-REPRoasting, #域渗透, #kerberos安全 |
| kerbeos暴力破解 | 2025-03-14 21:19 | #域渗透, #横向移动, #kerbrute爆破, #kerberos安全 |
| 8.Kerberoast | 2025-03-14 21:19 | #域渗透, #SPN, #kerberos安全 |
| Kerberos原理 | 2025-03-14 21:19 | #kerberos, #域渗透, #票据, #kerberos安全 |
| 1.Pre-auth bruteforce | 2025-05-25 23:33 | |
| 2.Pass the key | 2025-05-25 23:34 | |
| 3.Overpass the hash | 2025-05-25 23:35 | |
| 4.Pass the ticket | 2025-05-25 23:35 | |
| 5.Pass the cache | 2025-05-25 23:36 | |
| 6.Kerberos relay | 2025-05-25 23:36 | |
| 9.Shadow Credentials(影子凭据) | 2025-05-25 23:47 | |
| 10.UnPAC the hash | 2025-05-25 23:48 | |
| 12.sAMAccountName spoofing | 2025-05-25 23:50 | |
| 13.SPN-jacking | 2025-05-25 23:51 | |
📁 Movement/4-Kerberos/Delegations
📁 Movement/4-Kerberos/Forged tickets
| 黄金白银票据 | 2025-03-14 21:19 | #票据, #权限维持, #kerberos安全 |
| 2.Golden Ticket | 2025-05-12 12:05 | #kerberos, #域渗透, #票据, #权限维持, #横向移动 |
| 1.silver ticket | 2025-05-12 12:16 | #横向移动, #权限维持, #域渗透, #票据 |
| 3.钻石票据 | 2025-05-25 23:38 | |
| 4.蓝宝石票据 | 2025-05-25 23:39 | |
| 5.RODC黄金票据 | 2025-05-25 23:40 | |
| 6.MS14-068 | 2025-05-25 23:42 | #kerberos, #trcket |
📁 Movement/5-DACL abuse
📁 Movement/6-Netlogon
📁 Movement/7-Trusts
📁 Movement/8-组策略
📁 Movement/9-AD-CS
📁 Movement/9-AD-CS/ESC
| ESC16 | 2025-05-26 00:03 | #AD-CS, #ESC16 |
| ESC3 | 2025-06-25 15:31 | #ESC3, #AD-CS |
| ESC15 | 2025-06-27 19:52 | #AD-CS, #ESC15 |
| ESC9 | 2025-07-07 23:04 | #AD-CS, #ESC9 |
| ESC14 | 2025-07-08 11:18 | #AD-CS, #ESC14 |
| ESC10 | 2025-07-21 17:12 | #ESC10, #AD-CS |
| ESC1 | 2025-08-08 00:19 | #ESC1, #AD-CS |
| ESC2 | 2025-10-13 16:55 | #ESC2, #AD-CS |
| ESC4 | 2025-10-13 17:00 | #ESC4, #AD-CS |
| ESC5 | 2025-10-13 17:00 | #ESC5, #AD-CS |
| ESC6 | 2025-10-13 17:04 | #ESC6, #AD-CS |
| ESC7 | 2025-10-13 17:04 | #ESC7, #AD-CS |
| ESC8 | 2025-10-13 17:04 | #AD-CS, #ESC8 |
| ESC11 | 2025-10-13 17:06 | #ESC11, #AD-CS |
📁 Privilege Escalation/User Rights
📁 Reconnaissance
| Domain Recon | 2025-05-09 23:41 | #信息收集, #内网安全, #域渗透 |
| DHCP | 2025-05-09 23:42 | #DHCP, #信息收集, #域渗透 |
| DNS | 2025-05-09 23:43 | #信息收集, #域渗透, #DNS |
| NBT-NS | 2025-05-09 23:43 | #信息收集, #域渗透, #NBT-NS |
| Responder | 2025-05-09 23:43 | #域渗透, #Responder, #NTLM-relay |
| LDAP | 2025-05-09 23:43 | #LDAP, #信息收集, #域渗透 |
| BloodHound | 2025-05-09 23:44 | #域渗透, #信息收集, #Bloodhound分析 |
| MS-RPC | 2025-05-09 23:45 | #MS-RPC, #信息收集, #域渗透, #RID-Cycling, #IObjectExporter |
| Enum4linux | 2025-05-09 23:45 | #Enum4linux, #域渗透, #信息收集 |
| 密码策略 | 2025-05-09 23:45 | #信息收集, #域渗透, #密码策略 |
| Common AD Ports | 2025-05-09 23:51 | #端口扫描, #信息收集, #域渗透 |
| NFS | 2025-07-20 22:55 | #nfs, #信息收集 |
| SMB Null Session | 2025-08-07 22:13 | #SMB, #信息收集, #SMB空会话 |
| ISAKMP udp(500) | 2025-09-21 11:35 | #ISAKMP, #IPSEC, #IKE |