Sensitive content
This media may contain sensitive content.
Video yükleniyor...
Video Yüklenemedi
Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump Kerberos keys and NTLM hashes for every principal-krbtgt, users, machines. no DCSync required, no code execution on DC.
38,570 görüntüleme • 1 yıl önce •via X (Twitter)
8 Yorum

The relevant section on our blog:

In this Free eBook, we’ll walk you through Powershell scripting basics, show you Powershell commands and scripts for performing the most common administrative tasks, and explain how you can schedule your Powershell scripts and сommands. Get your free copy ⬇️

Jeez it's like MS is doing everything to eliminate on-prem AD 😂

Seems quite moderate.

Do you like mass-create dmsas or do you change the attributes for delegation over and over again?

One dMSA and repeatedly change the link attribute

Does the “weak” user need to run New-ADServiceAccount -CreateDelegatedServiceAccount directly on a Server 2025 DC? That parameter isn’t available in standard RSAT on workstations, so it seems the command must be run where the Server 2025 AD module is present?

It should be available in new versions of RSAT. In my lab I’m running from a 2025 server but I don’t see a reason it shouldn’t work from a workstation as well
