Penetration Testing and Active Directory
Chapter 1: Laptop On Client
Introduction to Active Directory Penetration Testing
- Introduction to the concept of actively engaging with Active Directory (AD).
- Description of the scenario: a client undergoes a penetration test (pen test).Deployment of Attack Machines
- A machine is generally sent to the client for the purpose of pen testing.
- Preferred hardware for pen testing:
- Laptops are typically used due to their robustness.
- Some companies may opt for Raspberry Pis, which are less common.VPN Connection Utilization
- The laptop deployed at the client site is configured with a VPN connection.
- Upon connection, the VPNphones hometo the pen test team.
- This VPN allows the team to share the tunnel and conduct attacks remotely.Modern Pen Testing Practices
- Discusses changes in the methodology of executing pen tests:
- Majority of pen tests conducted remotely, reducing the need for onsite visits.
- Some traditional companies continue onsite testing methods.
- Company experience: Most pen tests have been performed internally without physical travel to client sites.Assumption of Compromise
- It is assumed the laptop on site is compromised.
Chapter 2: Different IP Addresses
Context of IP Addressing in Pen Testing
- Assumption of an initial breach or compromise, affecting network dynamics.
- Breach can be due to hacking or device placement.
- Simulation/emulation of various scenarios relevant in penetration testing.Attack Execution
- From the attack box, different types of attacks are initiated.
- Multiple examples of attacks will be demonstrated throughout the videos.Network Configuration and IP Addressing
- There may be various examples of different IP addresses presented in the context of attacks.
- The instructor operates a remote lab and a local lab for demonstrations.
- Important note: users should not replicate IP addresses directly from demonstrations.
- Each participant should identify their own internal network addresses.
- Focus on knowing the following for their context:
- Location of domain controller.
- The identities of two attack machines dubbed Punisher and Spider Man.Upcoming Attacks
- Preparation to commence specific attacks on Active Directory, starting with a well-known attack:
- LMNR poisoning will be introduced in subsequent videos.
- Encouragement to stop and prepare to engage in attacks on Active Directory.