โ† All OSCP Flashcard Decks

Active Directory Attacks Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Active Directory Attacks flashcards as text
  1. What is a Pass-the-Ticket (PtT) attack in Active Directory?

    Answer: Injecting a captured or forged Kerberos TGT or TGS into the current session to authenticate as that user

    Pass-the-Ticket injects a captured or forged Kerberos ticket into the current Windows session using Mimikatz's kerberos::ptt, allowing authentication to services as the ticket owner.

  2. What does the PowerView cmdlet 'Get-DomainUser -SPN' retrieve in Active Directory?

    Answer: All user accounts with Service Principal Names registered (Kerberoastable accounts)

    The 'Get-DomainUser -SPN' command retrieves all Active Directory user accounts that have one or more Service Principal Names (SPNs) registered, identifying Kerberoastable targets.

  3. What is a domain trust and how can it be abused during OSCP multi-domain scenarios?

    Answer: A domain trust allows authentication across domains; it can be abused with inter-realm tickets to pivot between trusted domains

    Domain trusts establish authentication relationships between domains; attackers with Domain Admin in one domain can forge inter-realm trust tickets (e.g., Extra SID attack) to authenticate in trusted domains.

  4. What is NTDS.DIT and why is it a critical target during Active Directory attacks?

    Answer: The Active Directory database file containing all user accounts, groups, and password hashes for the entire domain

    NTDS.DIT is the Active Directory database file stored on domain controllers, containing all domain objects including user accounts and their NTLM hashes, making it the ultimate credential store for the domain.

  5. What is the primary purpose of running 'Invoke-Kerberoast' in a PowerShell session during OSCP?

    Answer: To request TGS tickets for all SPN-registered accounts and output them in hashcat-crackable format

    Invoke-Kerberoast requests service tickets for all accounts with registered SPNs and outputs the tickets in a format directly usable with hashcat (-m 13100) for offline cracking.

  6. What does 'constrained delegation' mean in Active Directory and how does it differ from unconstrained delegation?

    Answer: Constrained delegation limits which services a host can delegate to, while unconstrained delegation allows delegation to any service

    Constrained delegation specifies exactly which target services a host/account can impersonate users to, unlike unconstrained delegation which allows impersonation to any service in the domain.