Services & Features
LAPS
Commands
# Check if LAPS is activated
reg query "HKLM\Software\Policies\Microsoft Services\AdmPwd" /v AdmPwdEnabled
dir "C:\Program Files\LAPS\CSE"
# Get commands available
Get-Command *AdmPwd*
# List who can read LAPS password of the given OU
Find-AdmPwdExtendedRights -Identity Workstations | fl
# Read the password
Get-AdmPwdPassword -ComputerName wkstn-2 | flDumping Credentials via crackmapexec
Active Directory Certificate Services (ADCS)
Enumeration
Abusing COM & DCOM
Explanation of the Technologies
COM
DCOM
Exploitation
POC
References
Last updated