Internal Network Initial Access

No Creds

  1. Discover hosts
  2. Discover Open Ports
  3. Discover SCCM/MECM Infrastructure
  4. If SCCM/MECM environment:
  5. compile list of hosts with SMB signing disabled
    • netexec smb [ip/cidr] --gen-relay-list
  6. Start Network Poisoning Attacks
  7. TimeRoasting Time Roasting
  8. ASREPRoasting ASREP Roasting
  9. Check for null/anonymous authentication (unlikely)
  10. Enumerate Domain Users
  11. Password spraying with kerbrute
  12. Attempt WSUS techniques
  13. Attempt Coercion techniques

Related Notes