{"id":435,"date":"2021-02-28T22:43:26","date_gmt":"2021-02-28T22:43:26","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=435"},"modified":"2021-03-10T13:15:51","modified_gmt":"2021-03-10T13:15:51","slug":"ad-information-gathering","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/ad-information-gathering\/","title":{"rendered":"AD Information Gathering"},"content":{"rendered":"<h1>Lab: Maintaining Access<\/h1>\n<h2>Step 4 &#8211; AD Information Gathering &amp; Analysis<\/h2>\n<p><strong>Teamwork \u2013 Team DaMa<\/strong><\/p>\n<h2>Description<\/h2>\n<blockquote>\n<p>In this challenge we will query the Active Directory for vital information and gather data about valuable targets and possible further attacks. While the main tool will be Bloodhound, we will also use PingCastle to perform a quick AD health check.<\/p>\n<\/blockquote>\n<h2>Procedure<\/h2>\n<p><strong>Ping Castle<\/strong><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/ping_castle.png\" alt=\"\" \/><\/p>\n<p><strong>BloodHound  <\/strong><br \/>\nRunning the Ingestor<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-1.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-2.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-3.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-4.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-5.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-6.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/bh-7.png\" alt=\"\" \/><\/p>\n<h2>Questions to Answer<\/h2>\n<p><strong>Q1:<\/strong><br \/>\nBased on what you learned from Bloodhound, what is your next target?<br \/>\n<strong>A1:<\/strong><br \/>\nBased on the analysis we assume that FS1 is a file server and would be the final target. But to get there the first\/next target\/step is to own AALFORT. Aalfort is member of the FS1ADMINS group and has an acitve session on CLIENT1 we already own.<\/p>\n<hr>\n<p><strong>Q2:<\/strong><br \/>\nWhat is required to get the credentials for the next target?<\/p>\n<p><strong>A2 (updated):  <\/strong><br \/>\nBecause AALFORT has an active session on CLIENT1 the NTLM hash on this logon session can provide the<br \/>\nkey to the final target (credential abuse).<br \/>\nTo process the credential abuse the attacker should have the following permissions:<\/p>\n<ul>\n<li>administrative privileges &#8211; Integrity level high or system on CLIENT1 (required to access<br \/>\nLSASS memory)<\/li>\n<li>SeDebugPrivileges enabled for Mimikatz to dump the LSASS memory. Mimikatz requires this<br \/>\nprivilege as it interacts with processes such as LSASS. (The debug privilege determines which users<br \/>\ncan attach a debugger to any process or to the kernel. By default this privilege is given to Local<br \/>\nAdministrators. In a default installation of Windows Server 2016 the group policy is not defined which<br \/>\nmeans that only Local Administrators have this permission.)<\/li>\n<\/ul>\n<p>Reference:<br \/>\n<a href=\"https:\/\/medium.com\/blue-team\/preventing-mimikatz-attacks-ed283e7ebdd5\">Preventing Mimikatz Attacks<\/a><\/p>\n<hr>\n<p><strong>Q3: <\/strong><br \/>\nHow do we get the credentials for the next target?<br \/>\n<strong>A3 (updated):  <\/strong><br \/>\nWith the active session from AALFORT on CLIENT1 an credential dump with a tool like Mimikatz can provide<br \/>\nthe credentials. The mimikatz process can be splitted into the following steps:  <\/p>\n<ol>\n<li>\n<p>Logon as backdoor user (required to have administrative privileges as described in Q&amp;A 2)<\/p>\n<\/li>\n<li>\n<p>Use mimikatz and verify if the tool has the necessary privilidges (SeDebugPrivileges).<\/p>\n<\/li>\n<li>\n<p>Perform the LSASS dump to get the credentials (NTLM hash).<\/p>\n<blockquote>\n<p>sekurlsa::logonpasswords<\/p>\n<\/blockquote>\n<\/li>\n<li>\n<p>Verify the values (NTLM hash) in the output (see: msv : * NTLM :).<\/p>\n<\/li>\n<\/ol>\n<p>Note:<br \/>\nBecause AALFORT performed a Non-Network Logons authentication to CLIENT1 we expect the<br \/>\ncredentials in the LSASS memory (by this logon session the credentials are sent to the server and stored in<br \/>\nLSASS memory)<\/p>\n<hr>\n<p><strong>Q4:<\/strong><br \/>\nWhy do you think the query &quot;Shortest Paths to Domain Admins from Owned Principals&quot; does not show any<br \/>\nresults?<\/p>\n<p><strong>A4:  <\/strong><br \/>\nThe fact that the owned principals aren&#8217;t member of the domain admin group nor have an active session (at<br \/>\nthe moment) it&#8217;s not possible to find a valid path to the Domain Admins.<\/p>\n<p>PDF Report<br \/>\n<a href=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Readme-Step4-v2.pdf\" class=\"mtli_attachment mtli_pdf\" title=\"Readme-Step4-v2\">Readme-Step4-v2<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lab: Maintaining Access Step 4 &#8211; AD Information Gathering &amp; Analysis Teamwork \u2013 Team DaMa Description In this challenge we will query the Active Directory for vital information and gather data about valuable targets and possible further attacks. While the main tool will be Bloodhound, we will also use PingCastle to perform a quick AD [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-435","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=435"}],"version-history":[{"count":5,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/435\/revisions"}],"predecessor-version":[{"id":610,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/435\/revisions\/610"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}