Penetration Testing and Active Directory

Chapter 1: Laptop On Client

  • Introduction to Active Directory Penetration Testing
      - Introduction to the concept of actively engaging with Active Directory (AD).
      - Description of the scenario: a client undergoes a penetration test (pen test).

  • Deployment of Attack Machines
      - A machine is generally sent to the client for the purpose of pen testing.
      - Preferred hardware for pen testing:
        - Laptops are typically used due to their robustness.
        - Some companies may opt for Raspberry Pis, which are less common.

  • VPN Connection Utilization
      - The laptop deployed at the client site is configured with a VPN connection.
        - Upon connection, the VPN phones home to the pen test team.
        - This VPN allows the team to share the tunnel and conduct attacks remotely.

  • Modern Pen Testing Practices
      - Discusses changes in the methodology of executing pen tests:
        - Majority of pen tests conducted remotely, reducing the need for onsite visits.
        - Some traditional companies continue onsite testing methods.
      - Company experience: Most pen tests have been performed internally without physical travel to client sites.

  • Assumption of Compromise
      - It is assumed the laptop on site is compromised.

Chapter 2: Different IP Addresses

  • Context of IP Addressing in Pen Testing
      - Assumption of an initial breach or compromise, affecting network dynamics.
        - Breach can be due to hacking or device placement.
        - Simulation/emulation of various scenarios relevant in penetration testing.

  • Attack Execution
      - From the attack box, different types of attacks are initiated.
      - Multiple examples of attacks will be demonstrated throughout the videos.

  • Network Configuration and IP Addressing
      - There may be various examples of different IP addresses presented in the context of attacks.
        - The instructor operates a remote lab and a local lab for demonstrations.
      - Important note: users should not replicate IP addresses directly from demonstrations.
        - Each participant should identify their own internal network addresses.
      - Focus on knowing the following for their context:
        - Location of domain controller.
        - The identities of two attack machines dubbed Punisher and Spider Man.

  • Upcoming Attacks
      - Preparation to commence specific attacks on Active Directory, starting with a well-known attack:
        - LMNR poisoning will be introduced in subsequent videos.
      - Encouragement to stop and prepare to engage in attacks on Active Directory.