Impacket Offense Basics With an Azure Lab
ID: bf597fe5-44ea-57a0-9f53-3274721b0b02
STIX ID: report--bf597fe5-44ea-57a0-9f53-3274721b0b02
Feed Name: Black Hills Infosec Blog
This blog-style lab walkthrough demonstrates how to use Impacket tools (ntlmrelayx.py, GetADUsers.py, Get-GPPPassword.py, GetUserSPNs.py, secretsdump.py) to perform NTLM relay attacks (including SMB and LDAPS relays), credential enumeration and dumping, and AD manipulation in a controlled Azure lab. The author maps each technique to MITRE ATT&CK, provides command examples and outputs, and highlights impacts such as domain credential harvests and potential domain takeover while noting defensive considerations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
