Active Directory
00. Basics
+----------------------------------------------+
│ SID Structure │
+----------------------------------------------+
│ S-1-5-21-343818398-2089392276-30300820-544 │
+----------------------------------------------+
│ │ │ └──── Subauthority Values ─────┘ │
│ │ │ └───────| RID (Relative Identifier)
│ │ │
│ │ └─────────────── Identifier Authority (e.g., NT Authority = 5)
│ │
│ └─────────── Revision (Always "1")
│
└───────── "S" identifies as a SID string
- Identifier Authority: Defines the authority under which the SID was created.
- 0 = Null Authority (Represents an empty or undefined authority.)
- 1 = World Authority (epresents "everyone" or all users.)
- 2 = Local Authority (Defines local machine accounts and groups.)
- 3 = Creator Authority (Represents the creator or owner of an object.)
- 4 = Non-Unique Authority (Rarely used; identifies non-unique entities.)
- 5 = NT Authority (Represents the Windows NT security subsystem.)
- RID: Relative Identifier, unique to each account or group.
- 500 = Administrator account.
- 501 = Guest account.
- 502 = KRBTGT account - used for Kerberos authentication.
- 512 = Domain Administrators group.
- 513 = Domain Users group.
- 514 = Domain Guests group.
- 515 = Domain Computers group.
- 516 = Domain Controllers group.
- 517 = Cert Publishers group.
- 518 = Schema Admins group.
- 519 = Enterprise Admins group.
- 520 = Group Policy Creator Owners group.
- 521 = Read-only Domain Controllers group.
- 522 = Cloneable Domain Controllers group.
- 525 = Protected Users group.
- 544 = Administrators group.
- 545 = Users group.
- 546 = Guests group.
- 547 = Power Users group.
- 548 = Account Operators group.
- 549 = Server Operators group.
- 550 = Print Operators group.
- 551 = Backup Operators group.
- 552 = Replicator group.
- 554 = Remote Desktop Users group.
- 559 = Windows Authorization Access group.
- 573 = RDS Remote Access Servers group.
- 574 = RDS Endpoint Servers group.
- 575 = RDS Management Servers group.
- 577 = Access Control Assistance Operators group.
- 578 = Remote Management Users group.
- 580 = Storage Replica Administrators group.
- 1000 = The first user account created manually after Windows installation.01. Exploitations & Attacks
01.1 Kerberoasting
01.2 AS-REP Roasting
01.3 Silver Ticket
01.4 Golden Ticket
01.5 DCSync Attack
01.6 Password Spraying
01.6 Pass The Hash [PTH] - Extended
02. PowerView
03. Abusing ACLs
03.1 WriteOwner
03.2 ForceChangePassword
03.3 GenericAll
03.4 GenericWrite
03.5 AddKeyCredentialLink
03.6 ADCSESC4
04. PowerMAD
05. Impacket's Collection
05.1 getPac
05.2 getTGT
05.3 GetADUsers
05.4 GetUserSPNs
05.5 GetNPUsers
05.6 RPCDump
05.7 gMSADumper
06. Evil-WinRm
07. PsExec
08. Mimikatz
09. RustHound-CE
10. SharpHound
11. BloodHound
12. Certipy
13. Krbrelayx
14. Covenant
15. Other Commands
16. Other Exploits
BadSuccessor
ADCS ESC16
Unconstrained Delegation + The PrinterBug = DCSync
Resource Based Constrained Delegation [Domain Escalation]
Last updated
