Part 1. Victim Client

1. ๊ธฐ๋ณธ ์ •๋ณด ํ™•์ธํ•˜๊ธฐ (Reconnaisance)

  1. ๋‚ด ์ปดํ“จํ„ฐ ์ •๋ณด ํ™•์ธํ•˜๊ธฐ

    msinfo32
  2. ๋‚ด๊ฐ€ ์†ํ•œ ๊ทธ๋ฃน ์ •์ฑ…(Group Policy) ํ™•์ธํ•˜๊ธฐ โ†’ AD DS ์„œ๋ฒ„, ๋„๋ฉ”์ธ ๋“ฑ ํ™•์ธ ๊ฐ€๋Šฅ

    gpresult /r
    COMPUTER SETTINGS
    ------------------
    
        Last time Group Policy was applied: 2/11/2025 at 5:10:16 PM
        Group Policy was applied from:      EC2AMAZ-6E3DNME.pbl-waffle.swu
        Group Policy slow link threshold:   500 kbps
        Domain Name:                        AD-WAFFLE
        Domain Type:                        Windows 2008 or later
    
        Applied Group Policy Objects
        -----------------------------
            RDP deploy
            SSH deploy
            Default Domain Policy
            RDP deploy
            SSH deploy
    
        The computer is a part of the following security groups
        -------------------------------------------------------
            BUILTIN\\Administrators
            Everyone
            BUILTIN\\Users
            NT AUTHORITY\\NETWORK
            NT AUTHORITY\\Authenticated Users
            This Organization
            CLIENT$
            Domain Computers
            Authentication authority asserted identity
            System Mandatory Level

2. RDP์—์„œ BR1 ํ™•์ธ

3. BR3 Credential ํš๋“

mimikatz๋กœlsass dump ๋ฐ ๋ถ„์„

Tip: mimikatz

4. PtH ๊ณต๊ฒฉ ์ˆ˜ํ–‰

Impacket psexec.py

Last updated