logo

Admin’s Nightmare: Combining HiveNightmare/SeriousSAM and AD CS Attack Path’s for Profit

ID: d059d46d-c2fa-5579-9e1a-f611a86e7b19

STIX ID: report--d059d46d-c2fa-5579-9e1a-f611a86e7b19

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2021-08-06

Date Updated: 2026-04-27

Author: BHIS

...
...

This Black Hills InfoSec walkthrough demonstrates a complete AD compromise chain: starting from Cobalt Strike initial access, it abuses CVE-2021-36934 to dump registry hives and extract hashes, uses PetitPotam to coerce a domain controller into authenticating, relays those credentials to an AD CS server via a modified impacket to obtain a machine certificate, imports the certificate with Rubeus to impersonate the DC, and performs DCSync to extract domain credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.