Forest
Overview
Reconnaissance
Port Scanning
$ nmap -Pn -n -sS -p- -T4 --min-rate 1000 <IP>
...
PORT STATE SERVICE
53/tcp open domain
88/tcp open kerberos-sec
135/tcp open msrpc
139/tcp open netbios-ssn
389/tcp open ldap
445/tcp open microsoft-ds
464/tcp open kpasswd5
593/tcp open http-rpc-epmap
636/tcp open ldapssl
1433/tcp open ms-sql-s
3268/tcp open globalcatLDAP
3269/tcp open globalcatLDAPssl
5985/tcp open wsman
9389/tcp open adws
49667/tcp open unknown
49689/tcp open unknown
49690/tcp open unknown
49702/tcp open unknown
50008/tcp open unknown
64429/tcp open unknown
...LDAP
Initial Access
Alfresco
AS-REP Roasting

WinRM
Miscellaneous
Golden Ticket Attack
Last updated
