Active Directory Attacks Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Active Directory Attacks flashcards as text
What is BloodHound used for during Active Directory penetration testing in OSCP?
Answer: Visualizing Active Directory relationships and attack paths to Domain Admin using graph analysis
BloodHound uses graph theory to visualize Active Directory relationships and automatically identifies the shortest attack paths to high-value targets like Domain Admin.
What tool is used to collect Active Directory data for BloodHound?
Answer: SharpHound (or BloodHound.py)
SharpHound (C# .NET assembly) or BloodHound.py (Python for Linux) are the data collectors (ingestors) that enumerate Active Directory and produce JSON files that BloodHound ingests.
What does AS-REP Roasting target in Active Directory?
Answer: Accounts with Kerberos pre-authentication disabled, whose AS-REP can be cracked offline
AS-REP Roasting targets accounts where Kerberos pre-authentication is disabled; the KDC responds with an AS-REP encrypted with the account's hash, which can be cracked offline without any credentials.
What is the purpose of the 'net user /domain' command in Active Directory enumeration?
Answer: Lists all user accounts in the current Active Directory domain
The 'net user /domain' command queries the domain controller and returns a list of all user accounts in the Active Directory domain, useful for user enumeration.
What is DCSync and what privilege is required to perform it?
Answer: A technique that mimics domain controller replication to extract all password hashes; requires Replicating Directory Changes All privilege
DCSync uses Mimikatz to simulate a domain controller replication request (DRS protocol), extracting all password hashes from Active Directory; it requires the 'Replicating Directory Changes All' privilege typically held by Domain Admins.
What is a Golden Ticket attack in Active Directory?
Answer: Forging Kerberos TGTs using the krbtgt account's NTLM hash, granting persistent domain-wide access
A Golden Ticket is a forged Kerberos Ticket Granting Ticket created using the krbtgt account's hash, allowing persistent, domain-wide access even after password resets of other accounts.