Admin’s Nightmare: Combining HiveNightmare/SeriousSAM and AD CS Attack Path’s for Profit
ID: d059d46d-c2fa-5579-9e1a-f611a86e7b19
STIX ID: report--d059d46d-c2fa-5579-9e1a-f611a86e7b19
Feed Name: Black Hills Infosec Blog
Threat Score
This Black Hills InfoSec walkthrough demonstrates a complete AD compromise chain: starting from Cobalt Strike initial access, it abuses CVE-2021-36934 to dump registry hives and extract hashes, uses PetitPotam to coerce a domain controller into authenticating, relays those credentials to an AD CS server via a modified impacket to obtain a machine certificate, imports the certificate with Rubeus to impersonate the DC, and performs DCSync to extract domain credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
