ADExplorer on Engagements
ID: ea847c4d-fdaa-5140-9908-1c675c557081
STIX ID: report--ea847c4d-fdaa-5140-9908-1c675c557081
Feed Name: TrustedSec blog
This post is a practical walkthrough showing how to use ADExplorer from a local Windows host over a SOCKS proxy (Cobalt Strike) by injecting a machine account NTLM hash with Mimikatz to authenticate against a domain controller; it covers proxy setup (Proxifier), launching ADExplorer with a pass-the-hash process, and offline snapshotting, and provides reconnaissance tips for locating sites, domain settings (including ms-DS-MachineAccountQuota), trusts, LAPS passwords, and other attributes that may contain plaintext credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
