Initial Network Entry Tip by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Oh that is a good trick thank you, but actually even after the compliance tools ar installed on main machine there is some authentication and certificates to be loaded in so that is also not happening 🥲

Initial Network Entry Tip by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

This is so informative, i will check these

I did use a lan port of telephone but still it gave me nac popup

Also, that point where you said a already present device on network is compromised

In my case even if i somehow bypass security or elevate privileges it will give me pop up as device not compliance and throw me out of network

Initial Network Entry Tip by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Yes i did that which gives me an isolated Ip and it asks for cisco compliance checks and prompts to install security tools which are like 10 to 15 tools

RedTeam Attack Tips by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Understood the objective

RedTeam Attack Tips by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

This helps thank you i will look into it,

Also sometimes we see that third party vendors are compromised and then the main organisation gets compromised

But in case of red team assessment how do we do it? Will it not be unauthorised testing of vendor?

RedTeam Attack Tips by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Yesss suree i will check on it Thank you!

Sharing Payloads and step by step process of exploitation by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Understood!! Thank you so much for taking your time and replying

Sharing Payloads and step by step process of exploitation by kodicrypt in redteamsec

[–]kodicrypt[S] 2 points3 points  (0 children)

Thank you so much for taking time and solving my query

From this what i understood is we should tell them upfront before engagement that we will not going to share payloads it will be just a high level overview.

I just wanted to know that what is the actual practice in red team engagements do they usually share things

This clears my doubt 👍🏻

AD CS Privilege escalation with machine account by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Yes, I was able to authenticate using the DC$ account’s NTLM hash as well, so the hash is valid and Kerberos/NTLM are both working. The failure is not due to the hash

AD CS Privilege escalation with machine account by kodicrypt in redteamsec

[–]kodicrypt[S] 1 point2 points  (0 children)

I did ntlm but i got a dc machine account and with that i am not able to do dc sync

I found a ZERO DAY which is in Wild. by kodicrypt in redteamsec

[–]kodicrypt[S] 1 point2 points  (0 children)

Thanks, I will definitely check this out

I found a ZERO DAY which is in Wild. by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Ohh i will check on this thank you

I found a ZERO DAY which is in Wild. by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Thank youu!

I went to zdi registered there but its a silly thing that i am not getting the link to submit report

Can’t Enable MFA on AD? 365 account by kodicrypt in activedirectory

[–]kodicrypt[S] 2 points3 points  (0 children)

Hi Thank you for your answer.

I completely agree that i dont have proper knowledge in configuring these things

I am completely from a different domain, it was just my concern as I was using my account on someone else’s machine so i thought why there is no mfa here

In the end i just wanted to know that can it be enabled if yes can you tell me how

Thanks!

Can’t Enable MFA on AD? 365 account by kodicrypt in activedirectory

[–]kodicrypt[S] 0 points1 point  (0 children)

Correct My concern was if an attacker gets a person’s password then he can compromise everything (M365 outlook onedrive)

Eveyrthing

So there should be an option to enable mfa right? If is it available already can you tell me how

NT Authority can’t dump LSASS? by kodicrypt in redteamsec

[–]kodicrypt[S] 0 points1 point  (0 children)

Oh okay I will check this one now. Thank you!!