Active Directory Attacks Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Active Directory Attacks flashcards as text
What PowerShell module is commonly used for Active Directory enumeration without BloodHound in OSCP?
Answer: PowerSploit / PowerView
PowerView (part of PowerSploit) provides cmdlets for enumerating users, groups, computers, trusts, and ACLs in Active Directory without requiring RSAT or AD module installation.
What is LDAP anonymous bind and why is it a security concern in Active Directory?
Answer: It allows querying Active Directory without authentication, potentially exposing user accounts and organizational structure
Anonymous LDAP bind allows unauthenticated queries to Active Directory, potentially exposing user accounts, groups, computer names, and organizational structure that aids attackers in reconnaissance.
What is a Silver Ticket attack and how does it differ from a Golden Ticket?
Answer: A Silver Ticket forges a TGS for a specific service using that service account's hash, bypassing the KDC; a Golden Ticket forges the TGT itself
A Silver Ticket forges a TGS (service ticket) for a specific service using the service account's hash, bypassing the KDC entirely; a Golden Ticket forges the TGT (master ticket) using the krbtgt hash.
What is the significance of finding 'GenericAll' ACL permission on a user object in BloodHound?
Answer: It grants full control over the object, enabling password reset, adding to groups, or configuring Kerberos delegation
GenericAll is the highest-privilege ACL right, granting full control over an AD object, including the ability to reset passwords, add group memberships, or configure Kerberos-based attacks.
What is Unconstrained Delegation in Active Directory and why is it dangerous?
Answer: It allows a service account to delegate to any other service, caching users' TGTs which can be extracted and reused
Unconstrained Delegation allows a service to authenticate to any other service as the connecting user; Windows caches the user's TGT on the delegating host, where it can be extracted with Mimikatz and reused.
What Impacket tool is used to retrieve a list of all usernames from a domain controller via Kerberos?
Answer: GetNPUsers.py
GetNPUsers.py from Impacket enumerates accounts with Kerberos pre-authentication disabled (for AS-REP Roasting) and can also enumerate valid usernames through Kerberos error responses.