Methodology

We got an account, Now what?

1. Look for Quick Wins:

  • Kerberoasting

  • SecretsDump

  • Pass-the-Hash (PTH)

2. No Quick Wins? Go Deeper:

  • Enumerate ( BloodHound, etc. )

  • Check Your Account Memberships and Permissions

  • Old Vulnerabilities Never Die

3. Always Think Outside the Box:

Last updated