tag

Windows

21 posts
machinemachine

Inject

Inject: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Vintage

Vintage: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Administrator

Administrator: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Certified

Certified: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Blazorized

Blazorized: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Mist

Mist: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Axlle

Axlle: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Compiled

Compiled: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Jarmis

Jarmis: use CVE-2021-38647 where it fits the service, gain a shell, and escalate to root.

machinemachine

YPuffy

YPuffy: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Help

Help: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

notesnotes

BloodHound

BloodHound: collect BloodHound data, read the AD graph, and prioritize attack paths.

machinemachine

Cicada

Cicada: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Soccer

Soccer: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Bastion

Bastion: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Active

Active: enumerate the AD surface, abuse the exposed credential or delegation path, and escalate to Administrator.

machinemachine

Paper

Paper: use CVE-2019-17671 and CVE-2021-3560 where it fits the service, gain a shell, and escalate to root.

machinemachine

Blog

Blog: abuse the WordPress foothold, stabilize the shell, and escalate through the local weakness.