10.9. Lateral movement

10.9.1. Domain

  • adidnsdump Active Directory Integrated DNS dump tool

  • BloodHound Six Degrees of Domain Admin

  • PlumHound Bloodhound for Blue and Purple Teams

  • windapsearch Python script to enumerate users, groups and computers from a Windows domain through LDAP queries

  • ldapdomaindump Active Directory information dumper via LDAP

  • Kerberoast a series of tools for attacking MS Kerberos implementations

  • ADRecon Active Directory Recon

  • Creds Some usefull Scripts and Executables for Pentest & Forensics

  • Lithnet Password Protection for Active Directory Active Directory password filter featuring breached password checking and custom complexity rules

  • ASREPRoast Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled.

10.9.2. LDAP

  • SharpHound3 Data Collector for the BloodHound Project

10.9.3. Container

  • CDK an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency

10.9.4. Microsoft-based product utilization

  • LyncSniper A tool for penetration testing Skype for Business and Lync deployments

  • MSOLSpray A password spraying tool for Microsoft Online accounts (Azure/O365)

  • MailSniper MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms

10.9.5. Azure AD

10.9.6. Exchange

10.9.7. PowerShell

10.9.8. Intranet Information Collection

  • nbtscan NetBIOS scanning tool

  • SharpShares Quick and dirty binary to list network share information from all machines in the current domain and if they’re readable

  • WinShareEnum Windows Share Enumerator

  • HackBrowserData platform-wide browser data export tool

10.9.9. Kerberos

  • Rubeus

  • kerbrute A tool to perform Kerberos pre-auth bruteforcing

  • kerberoast A series of tools for attacking MS Kerberos implementations

10.9.10. Automated Auditing

10.9.11. Bypass

  • SysWhispers AV/EDR evasion via direct system calls

  • SysWhispers2 AV/EDR evasion via direct system calls

  • Dumpert LSASS memory dumper using direct system calls and API unhooking

10.9.12. Intranet Scan

  • InScan Automated Penetration Tool After Boundary Dotting

  • fscan is a comprehensive intranet scanning tool, which is convenient for one-click automation and all-round missed scanning.