Windows Pentest Tutorial (Active Directory Game Over!)

Поділитися
Вставка
  • Опубліковано 25 лис 2024

КОМЕНТАРІ • 242

  • @reluchan
    @reluchan Рік тому +55

    please get this guy back for more tutorials, really great video

  • @kevinneufeld3195
    @kevinneufeld3195 Рік тому +20

    For me as a sysadmin this video has shown sooooo many things that I will give attention even more in the future and double check and change. Thanks so so much for that awesome and free content.

  • @godadawgashaw4965
    @godadawgashaw4965 Рік тому +11

    David you always coming with intersting guests and tech explanation .thanks

    • @davidbombal
      @davidbombal  Рік тому +3

      Thank you! It always fun to learn from different people in the industry :)

  • @Saint_Staunch
    @Saint_Staunch Рік тому +13

    A Couple of retired machines on Hack The Box are good active directory practice machines with good walk through's if you get stuck 'Hathor' and 'Sekhmet'.

  • @Arcadiality
    @Arcadiality Рік тому +19

    This vid is a gem, and Remi is a breath of fresh air. Great explains along the way, but not too much to put off viewers with reasonable knowledge in some areas. More id definitely required from you guys if possible. Never change Remi, people who work with you must love it!!

  • @delta666SoT
    @delta666SoT Рік тому +5

    wow this is absolutely jam packed for a youtube video. Killer video David, I'm blown away by the depth of knowledge your guests have.

  • @personalPickle
    @personalPickle Рік тому +23

    Nice work Dr Bombal - great content as always, we appreciate your service

    • @davidbombal
      @davidbombal  Рік тому +2

      Thank you Billy! I appreciate that!

  • @johnnieparker2271
    @johnnieparker2271 Рік тому +2

    Very indepth and intriguing video. I'd like to see Remy provide more explanations to OffSec practices and again, with he explanations.

  • @Lleanlleawrg
    @Lleanlleawrg Рік тому +1

    Right.
    But seriously, good content and I appreciate taking the time to make this and posting it publicly too.

  • @VacentViscera
    @VacentViscera Рік тому +1

    I watched this video and immediately went and checked like 20 files on various systems. LOL. Good wake-up for anyone that might not be thinking about these attacks.

  • @mohammadalihanfi8237
    @mohammadalihanfi8237 Рік тому +1

    best video to overview what is a pentest and how they approach it thank you david for this king of content on youtube we are very happy to see you again with the videos like this :)))

  • @healthvative5315
    @healthvative5315 Рік тому +5

    Thanks David for a great channel. From Cyber security, hacking, pen testing, networking … all in one. Also thanks to Remi for the excellent demo

  • @RmDGaming77
    @RmDGaming77 Рік тому +4

    Really great to see this all done. Thanks for the video 🎉 I’m so used to seeing this done with bloodhound etc. it was really refreshing seeing it done this way.

  • @elmeromero303
    @elmeromero303 Рік тому +2

    High valuable content. Looking forward for more stuff like this. Thank you 👍

  • @muyangli348
    @muyangli348 Рік тому +1

    This vid is brilliant, Remy explained things so well and David you asked the questions popping right into my mind. Great job! Thanks!

  • @ibrahimiam
    @ibrahimiam Рік тому +1

    Greater job have been achieved inside this content. David, thanks again for contribution. You always try to provide the best content for your audience. Thanks

  • @ДмитрийКузнецов-я4д

    David, you are doing fascinating content , you help me drastically to gain my knowledge in this new sphere for me

  • @KryptoWooks
    @KryptoWooks Рік тому

    u always have good people as guests your good too Bombal enjoy seeing and learning from good people the best Knowledge is free God bless😇

  • @BarryBazzawillWilliams
    @BarryBazzawillWilliams Рік тому +1

    Thank you so much this is the video I have always been wanted the full pentest from initial access to lateral movement, escalation and persistence. Pretty much the whole package. Great stuff.

  • @owenk8203
    @owenk8203 Рік тому

    So awesome. Asked about this on your Managed vs Unmanaged switch UA-cam Short. Thanks David.

  • @MdSameullSoykot
    @MdSameullSoykot Рік тому +1

    Great video about AD pentest. Love it. Want to see more videos like this.

  • @antonioesposito3662
    @antonioesposito3662 Рік тому

    finally i found two hours to watch the video, it was saved in my "watch later" list for 2 months now... awesome video, tried all the stuff directly in my productive Active Directory and was able to undertand it deep dive...

  • @criptovida
    @criptovida Рік тому +1

    Good piece of information, it gives us great tips to protect ADs. Bring him for more topics maybe exploiting some Cloud IAMs (Azure AD, Okta etc)

  • @usshauler
    @usshauler Рік тому +1

    Really great video and full of good information. I appreciate you both for taking the time to explain this and upload this video, thank you !!!

  • @SnedgeJohn
    @SnedgeJohn Рік тому +1

    This was just really great! Big thank you for showing this!

  • @_olamideolakunle
    @_olamideolakunle Рік тому +1

    Awesome 👍 content , knowledge filled,
    Thanks David.

  • @ppetrix
    @ppetrix Рік тому

    Thank you guys ! It will be nice to see and the remediotion steps for this vulnerabilities.

  • @CyberProfessional-eb4tv
    @CyberProfessional-eb4tv Рік тому

    Great stuff. Thanks @David for make this happen. I need to re-watch and take more notes. Thank you!!

  • @malikusman9901
    @malikusman9901 Рік тому

    Really Enjoy a lot and learn as well. Great demo. And Thanks David for Such informative Videos.

  • @rogersteele2835
    @rogersteele2835 Рік тому +2

    Great demo! Very informative for system administrators on things to look out for in the environment.

  • @autohmae
    @autohmae Рік тому +1

    I knew the theory but had never really put it all together, thanks for this demo.

  • @solicearc
    @solicearc Рік тому +4

    Excellent demo and insightful comments David and Remi. Would be interesting to see how this can be detected by Blue Team members. Maybe something for another video?

  • @Manavetri
    @Manavetri Рік тому

    Really nice video!!!. Keep posting this kind of material

  • @PhayulInspires
    @PhayulInspires Рік тому

    Thanks David & Remi, this is probably the best demo on AD hacking, I will watch this repeatedly until I get good grasp of AD hacking.

  • @rithvikrajraapeti4877
    @rithvikrajraapeti4877 Рік тому +73

    Awesome video i am a 12 year old l am learing coding i know python i a learn networking,and new hacking tools from this channel you make great videos

    • @paccovdr
      @paccovdr Рік тому +10

      I started hacking/coding at 12 mate. Your future is bright!

    • @GGGAMER-jt2es
      @GGGAMER-jt2es Рік тому +13

      Be quieter listen more

    • @notmything6629
      @notmything6629 Рік тому +4

      Here you have it: your audience

    • @pravupritamlenka9215
      @pravupritamlenka9215 Рік тому +3

      Very good 👍 keep it up
      Keep learning keep growing

    • @MedicalStudentChannel
      @MedicalStudentChannel Рік тому +6

      You can study computer sciences in university, that will be great

  • @luddekn
    @luddekn Рік тому +7

    So cool to see a fellow Norwegian has come this far in this field, wish there was more red teaming here in Norway... Really cool video great job!😎

    • @HK-Asia-IQ
      @HK-Asia-IQ Рік тому

      And we thought Norwegians were good for herding Reindeers and that is about it 😂

    • @royeriksen103
      @royeriksen103 Рік тому

      @@HK-Asia-IQ No, no... We have icebears in the streets and we used to kill whales also

  • @lRemoved
    @lRemoved Рік тому

    You're the best David. This channel is a UA-cam mine.

  • @zadoknyamboga2939
    @zadoknyamboga2939 Рік тому

    awesome presentation and demo. David and Remi

  • @bulent1062
    @bulent1062 Рік тому

    it was awesome. thanks for the demonstration. don't forget resetting krbgt password 2 times :)

  • @MrNomadBrad
    @MrNomadBrad Рік тому +2

    Great demo! Would love to see more from Remy.

  • @ahmedahmedx9600
    @ahmedahmedx9600 Рік тому +1

    David, you are amazing! God bless your family bro,
    It would be fun if you bring a guest specialised in ransomware and malwares attacks.

  • @collinsbaffour7397
    @collinsbaffour7397 Рік тому +1

    Excellent and interesting demo as always i would like to watch him do the enumeration as he documented

  • @norvin1107
    @norvin1107 Рік тому +1

    Indeed a great video David! I've learned so much in this video and it would such be a greater help if Remy can also demonstrate on how to prevent this kind of attacks and/or persistent attacks from happening again. Like what Remy said that it is not advisable to go and change the password of your krbtgt immediately.. It would really be of great help teaching sysadmins on how to protect they're network environment. I really appreciate this video because a lot of knowledge has been demonstrated by Remy. Kudos to your videos David! Looking forward for a lot more educational and exciting videos regarding offensive security and hopefully for defensive security also. Thank you and God bless!

  • @ozzozz-r5z
    @ozzozz-r5z Рік тому

    Great video!
    helped me to prepare for PJPT/PNPT

  • @hmsss_909
    @hmsss_909 Рік тому

    Eye opening video... Didn't know there is so many open holes in the active directory

  • @viniciusmucuge
    @viniciusmucuge Рік тому

    Amazing video and demo! One of the best explanations on Golden Ticket exploitation I've seen. Thanks

  • @pepemunic3661
    @pepemunic3661 Рік тому +2

    like always, great great content, thanks you!

  • @arminbarzegar2171
    @arminbarzegar2171 Рік тому

    Thank You For The Content, Always Learn A Lot.

  • @fergie8076
    @fergie8076 Рік тому

    Awesome Video, I'd love to see more like this!!

  • @Dcthetruth85
    @Dcthetruth85 Рік тому +3

    Im trying to learn PLCs but this is mote fascinating to me.

  • @phillydee3592
    @phillydee3592 Рік тому

    Great vid as I've just started my AD course!!

  • @philipparker5291
    @philipparker5291 8 місяців тому

    This is bloody awesome. Thanks!

  • @Hartley94
    @Hartley94 Рік тому +1

    Thanks David.

  • @royeriksen103
    @royeriksen103 Рік тому

    Hi David. I find your videos very informational, and this one is so far "the best." Thanks for interviewing one of my country men. This presentation scares me :( Am for sure going to make a call to Remi

  • @Yuenix
    @Yuenix Рік тому

    i love these type of contents , I remember learning and understanding AD and also Group Policy etc. But yes Thank you David, also David you need to do a video and live stream with Ryan Montgomery, idk if youve seen that Ryan Shawn interviewing Ryan Montgomery, but it be awesome if you guys can show some awesome hack techniques or something. but thank you David as always 😁

  • @Saint_Staunch
    @Saint_Staunch Рік тому

    Awesome video mate, very impressive!

  • @chancymzama7478
    @chancymzama7478 4 дні тому

    one of a kind
    ...am supposed to do an internal pentest in my active directory i hope this will help me break things apart

  • @BossMlid
    @BossMlid Рік тому

    Wow. Extraordinary👏👏👏

  • @jonathanbarnham9268
    @jonathanbarnham9268 Рік тому

    Great video, loved every minute!

  • @chillydill4703
    @chillydill4703 Рік тому

    What a great video! Super interesting!

  • @AnbuReckz
    @AnbuReckz Рік тому

    GOLDEN TICKET of an explanation Remi was amazing

  • @cybeerninja
    @cybeerninja Рік тому

    thank you Remi and David. Great content as always. Appreciate the Kerberos vs NTLM breakdown. @Remi perfer nano also.

  • @232faizankurawle3
    @232faizankurawle3 Рік тому

    FINALLY YOUR CREATED CONTENT ON ACTIVE DIRECTORY 🎉

  • @omegadroidzero
    @omegadroidzero Рік тому

    Thank you for all that you do.

  • @CyberDevilSec
    @CyberDevilSec Рік тому

    I'm trhilled to see another episode of our legend David!

    • @davidbombal
      @davidbombal  Рік тому +2

      Thank you! This is a long video, but a great demonstration.

    • @CyberDevilSec
      @CyberDevilSec Рік тому +1

      @@davidbombal The longer the better David i enjoy every single video :)

  • @ricseeds4835
    @ricseeds4835 Рік тому

    A video on enumeration/reconnaissance would be amazing!

  • @SuperRider-RS
    @SuperRider-RS Рік тому +1

    a real security architect would have SEIM, PAM, PIM and IAM in place, either commercial or opensource, you will never get that easily unless an insider is involved

  • @i_am_dumb1070
    @i_am_dumb1070 7 місяців тому

    WOW ... i understood everything... please bring him back

  • @davidbombal
    @davidbombal  Рік тому +14

    Get your 10% discount here: www.offsec.com/review/david-pwk-2023/
    Disclaimer: I was NOT paid for this interview. I wanted to make this video because it affects many of you watching and is a major topic on the OSCP exam. However, OffSec did give me access to Learn One for one year so I could see the course content. This has helped me prepare for the interview. Hopefully I'll be able to make more content covering what is in the PEN 200 course in future :)
    // GitHub Code //
    Commands: github.com/davidbombal/Ethical-Hacking/blob/main/Windows%20Pentesting%20with%20OffSec
    // Documentation //
    Changes: www.offsec.com/offsec/pen-200-2023/
    Course: www.offsec.com/courses/pen-200/
    // Offsec //
    Twitter: twitter.com/offsectraining
    Website: www.offsec.com/
    LinkedIn: www.linkedin.com/company/offsec-training/
    // Remi's SOCIAL //
    LinkedIn: no.linkedin.com/in/remi-solberg-8991b910a
    // David's SOCIAL //
    Discord: discord.gg/davidbombal
    Twitter: twitter.com/davidbombal
    Instagram: instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    // MENU //
    00:00 - Coming up
    01:31 - Disclaimer
    01:57 - Remi Solberg introduction & background
    03:37 - Jump to a timestamp (check in description below)
    03:57 - Simulated full-scale penetration test demo // Hacking Windows
    05:12 - OffSec Learn One discount!
    06:22 - Penetration test demo
    09:38 - Documentation & enumeration // Prepping for penetration test
    23:25 - Penetration test demo // Accessing users
    30:10 - Privilege escalation
    37:44 - Using ICACLS (Integrity Access Control Access List)
    43:59 - Privilege escalation (continued)
    52:14 - Getting around obstacles // Social engineering
    53:23 - Privilege escalation (continued)
    57:19 - Stealing credentials
    59:11 - Using Mimikatz tool // Kerberos and NTLM Authentication (theory)
    01:07:33 - Mimikatz tool demo
    01:06:05 - Penetration test demo (continued) // Exposing passwords & credentials
    01:23:25 - What a malicious hacker would do
    01:25:55 - The "Golden Ticket" // How to forge a ticket
    01:45:07 - Demo summary & tips
    01:48:05 - Conclusion
    // MY STUFF //
    www.amazon.com/shop/davidbombal
    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
    Disclaimer: This video is for educational purposes only.

    • @rationalbushcraft
      @rationalbushcraft Рік тому +7

      Am I missing it? I don't see a link to the commands. I think I know them all but I always like to add these to my obsidian so I can access them later if needed.

    • @4evercuber
      @4evercuber Рік тому +6

      @@rationalbushcraft I don't see a link to the commands either.

    • @ryanlea750
      @ryanlea750 Рік тому +2

      No commands below?

    • @munyaradzimunoz9536
      @munyaradzimunoz9536 Рік тому +2

      Great video Mr Bombal, I think you forgot to attach the commands, thank you in advance

    • @muiruri
      @muiruri Рік тому +1

      The link to the commands is missing.

  • @xxMTxxDEWxx
    @xxMTxxDEWxx Рік тому

    Great video. Love this.

  • @CyberABE
    @CyberABE Рік тому

    Amazing video content! Thanks

  • @lool7922
    @lool7922 Рік тому

    wonderful explanation

  • @NIGHTMARE-zy7tq
    @NIGHTMARE-zy7tq Рік тому

    Thank you very much for this sir.

  • @p1yuh37
    @p1yuh37 Рік тому +1

    This is the "video" I am waiting for !!

  • @i_Kruti
    @i_Kruti Рік тому +2

    The best part was "MY NAME IS JEFF" 😂🤣

  • @PrinceJohn84
    @PrinceJohn84 Рік тому

    Super, super video! Adoption of good credential isolation techniques, enabling LSA protection and use of the built in Protected Users group in AD would all be good first steps towards thwarting many of these types of privilege escalation attacks. Above all, don't let Jeff anywhere near your directory infrastructure 🤣🤣🤣

  • @treborsan5948
    @treborsan5948 Рік тому

    awesome sauce. Thank you!

  • @davidrobinson3236
    @davidrobinson3236 Рік тому

    I like this tutorials allow thanks for the gift!

  • @ehsnils
    @ehsnils Рік тому

    If you penetrate a system and gain domain admin right - change the background image on every account with a nice little message.

  • @ak_yt86
    @ak_yt86 Рік тому +1

    Awesome bro 😎👍

  • @Alain9-1
    @Alain9-1 Рік тому

    Just in time, thank you in advance

  • @jeremyjinglebell2762
    @jeremyjinglebell2762 Рік тому

    wow! great stuff

  • @josephjason7373
    @josephjason7373 Рік тому

    great content David

  • @447necro8
    @447necro8 10 місяців тому

    bros beard has opacity set to 0.75 - great content very knowledgable.

  • @paulscales9704
    @paulscales9704 Рік тому

    Amazing, I have been sysadmin for a long time, this is scary stuff, I did notice antivirus was not enabled and would also need to be bypassed before mimikatz could be run, but as in all things that's a whole other video that probably should not see the light of day 😂

  • @davidrobertson1980
    @davidrobertson1980 Рік тому

    Good stuff David - inside the mind of Remi ;)

  • @naesone2653
    @naesone2653 Місяць тому

    great demo thank you

  • @N4rutoUzumaki161
    @N4rutoUzumaki161 Рік тому

    This is too good!

  • @GodAboveAll777
    @GodAboveAll777 Рік тому +1

    I'm too scared to comment on this video 🤣 I just opened an attack vector lol love your vids David and co

  • @NahImPro
    @NahImPro Рік тому

    Wow david awesome vid!

    • @davidbombal
      @davidbombal  Рік тому +1

      Thank you! Glad you enjoyed the video!

  • @ehsnils
    @ehsnils Рік тому

    The Kerberos ticket lifetime of 10 years explains some weirdness I encountered at work recently where the Kerberos ticked had expired for some accounts.

  • @Feedback406
    @Feedback406 Рік тому +1

    Free Active Directory tutorial???
    Best IT channel by far!!!
    If I could subscribe twice to show my appreciation I would but I can’t😔
    But thanks for all your efforts🙂🫡

    • @davidbombal
      @davidbombal  Рік тому +1

      Thank you so much! I appreciate your support!

  • @simonroberts8001
    @simonroberts8001 10 місяців тому

    excellent demo

  • @xd37hx
    @xd37hx Рік тому

    Thanks david. Id like to see a walk through on how to set up the active directory lab he is using.

    • @kirsehir4041
      @kirsehir4041 11 місяців тому

      Look up on youtube how to create a local domain

  • @TcoDownLoad
    @TcoDownLoad Рік тому

    Awesome video

  • @mohamedselim77
    @mohamedselim77 Рік тому

    Really amazing

  • @LukeMorley-x9m
    @LukeMorley-x9m Рік тому

    Great video.

  • @RECREATIONALONLY
    @RECREATIONALONLY Рік тому

    Hello David can u make a video on wpa3 cracking it will be really helpful and i love ur channel man !!

  • @JuanBotes
    @JuanBotes Рік тому

    great video thanks \o/

  • @davesabra4320
    @davesabra4320 Рік тому

    it was fantastic