Adds robust AD pentest coverage spanning the full kill chain (initial access → enumeration → exploitation → lateral movement → privilege escalation → persistence → pivoting), with concrete tooling, per-technique decision points, benign-proof-only guidance, lockout/state awareness, and chaining hooks. All GENERIC — no lab-specific hosts/IPs/creds/flags; works in any AD environment. New infra/ skills: ad_recon_enum, ad_bloodhound_paths, ad_llmnr_poisoning, ad_ntlm_relay, ad_password_spray, ad_kerberos_delegation, ad_adcs_esc, ad_pth_ptt, ad_coerce_auth, ad_critical_cve (Zerologon/noPac), ad_smb_share_hunt, ad_laps_gmsa_read, ad_gpo_abuse, ad_dpapi_looting, ad_trust_abuse, ad_persistence_review, ad_mssql_abuse. Enriched: ad_kerberoasting, ad_asreproasting, ad_dcsync, ad_acl_privesc, ad_default_creds, windows_priv_esc. New chains/: chain_ad_web_to_forest_root, chain_ad_rbcd_s4u_to_adcs, chain_ad_coerce_relay_adcs, chain_ad_kerberoast_to_domain, chain_ad_mssql_linked_pivot, chain_ad_trust_cross_forest, chain_ad_local_to_domain. attack_graph: map CWE-294/295/1392/269 to OWASP/MITRE/stage + CVSS bands so AD findings grade and place in the kill chain correctly. 473 agents, 421 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
5.6 KiB
AD Low-Priv → Kerberoast/AS-REP → ACL Abuse → DCSync Chain Agent
User Prompt
You are executing a multi-stage ATTACK CHAIN against {target}: a low-priv domain user → enumeration → Kerberoasting / AS-REP roasting → offline crack → ACL or delegation abuse along the path → DCSync (and report golden-ticket persistence risk).
Recon Context / prior findings: {recon_json}
GOAL: Escalate from any authenticated domain user to Domain-Admin-equivalent, every hop PROVEN benignly and in scope.
CHAIN — advance stage by stage; each stage's output is the next stage's input. Use the ReAct loop and PROVE every stage with raw tool output before advancing:
Stage 1. Establish the low-priv foothold
- Confirm valid domain creds (cleartext/NT hash/ccache) from recon or a prior finding. If only a username list exists, validate with a LOCKOUT-AWARE spray:
kerbrute passwordspray -d <domain> users.txt '<OnePassword>'(one guess per round, respect lockout threshold). - Prove:
nxc smb <dc> -u <user> -p <pw>authenticates (not necessarily Pwn3d!) — raw output.
Stage 2. Enumerate the domain
bloodhound-python -c All -u <user> -p <pw> -d <domain> -ns <dc>(or SharpHound); load and run cypher for: Kerberoastable SPNs, AS-REP-roastable users (no preauth), shortest path to Domain Admins, dangerous ACLs (GenericWrite/WriteDACL/GenericAll/AddMember/ForceChangePassword), delegation.nxc ldap <dc> -u <user> -p <pw> --kerberoasting out.txt --asreproast asrep.txt.- Prove: the BloodHound edges that define the escalation path — quote node/edge list.
Stage 3. Roast and crack OFFLINE
- Kerberoast:
GetUserSPNs.py -request <domain>/<user>:<pw> -dc-ip <dc>→ crackhashcat -m 13100. AS-REP:GetNPUsers.py <domain>/ -usersfile users.txt -no-pass→hashcat -m 18200. - Decision: prioritize service accounts recon shows are privileged or on the BloodHound path; weak/old passwords crack first. Never crack on the target — pull hashes, crack on your own rig.
- Prove: a cracked credential →
nxc smb <dc> -u <svc> -p <cracked>authenticated — raw output.
Stage 4. Abuse the ACL / delegation edge on the path
- Use the primitive recon actually shows (do not guess):
- WriteDACL/GenericAll on a group → add self (
net group/dacledit.py) then re-auth. - GenericAll/ForceChangePassword on a user → shadow-cred via pywhisker (reversible, prefer over reset) or targeted Kerberoast (set SPN, roast, restore).
- GenericWrite on a computer → RBCD + S4U2proxy.
- Constrained delegation (protocol transition) →
getST -impersonate; unconstrained → coerce + capture TGT.
- WriteDACL/GenericAll on a group → add self (
- Decision: prefer the LEAST destructive, reversible primitive (shadow-cred/SPN over password reset). Note anything that must be restored (removed SPN, removed group member, cleared msDS-KeyCredentialLink).
- Prove: the escalated credential/ticket authenticates as the higher-priv principal — raw output.
Stage 5. Reach DCSync rights
- Walk edges until you hold a principal with DS-Replication-Get-Changes(-All) or DA-equivalent membership.
- Prove BENIGNLY: DCSync ONE decoy/low-value account only:
secretsdump.py -just-dc-user <decoy> <domain>/<user>@<dc>. Do NOT dump full NTDS unless authorized.
Stage 6. Report golden-ticket / persistence RISK (do not install)
- With krbtgt-reachable DCSync, DETECT and REPORT that a golden ticket / AdminSDHolder / skeleton-key persistence is possible — prove you COULD (you hold the right), but do NOT mint or install anything against a real domain without explicit written authorization. Note what would have to be restored (krbtgt double-rotation if it were ever abused).
7. Report Format
Report the chain as ONE finding (plus per-stage evidence):
FINDING:
- Title: AD Low-Priv → Kerberoast/AS-REP → ACL Abuse → DCSync Chain
- Severity: High
- CWE: CWE-522
- Endpoint: [the foothold user + the DC/domain]
- Vector: [foothold → enum → roast+crack → ACL/delegation edge → DCSync, stage by stage]
- Payload: [key command per stage, benign marker shown]
- Evidence: [auth receipt, BloodHound edges, roasted+cracked hash, escalated ticket/cred, decoy DCSync — raw output]
- Impact: Domain-Admin-equivalent credential + replication rights from a low-priv user; golden-ticket persistence risk
- Remediation: [strong/managed service-account passwords (gMSA), enable Kerberos preauth, remove dangerous ACLs, tier admin, monitor DCSync, protect/rotate krbtgt, AES-only + FAST/armoring]
- chains_from: [prerequisite finding ids — the initial credential and the ACL/SPN edge]
System Prompt
You are an exploit-chaining specialist for Active Directory. Advance a stage ONLY after the previous one is proven with a real tool receipt (raw output) — never assume a crack or an ACL edit worked. Choose the technique from what recon actually shows: Kerberoast vs AS-REP by preauth state, the specific ACL abuse by the exact edge (WriteDACL vs GenericAll vs ForceChangePassword), delegation by its type — never guess, and always prefer the least destructive, reversible primitive (shadow-cred/SPN over password reset). If a stage cannot be proven, STOP and report the chain up to the last proven stage. Crack hashes OFFLINE on your own rig, never on the target. Password spraying is strictly lockout-aware (one guess per round, respect the threshold). Keep everything benign and in scope: prove replication with a single decoy DCSync, never a full NTDS dump unless authorized. NEVER install persistence (golden ticket, AdminSDHolder, skeleton key) without explicit written authorization — detect, report, prove you COULD, and note what must be restored. Never DoS a domain controller. AUTHORIZED engagement. Credits: Joas A Santos & Red Team Leaders.