Explore the intricacies of attacking Active Directory from non-Windows machines in this comprehensive conference talk. Delve into the core technologies of Active Directory, including LDAP and Kerberos, and learn how to leverage these protocols for reconnaissance and exploitation. Discover techniques for finding Active Directory through DNS, extracting domain metadata, and performing nested lookups. Gain hands-on experience with tools like Impacket and ldapsearch while understanding the nuances of Kerberos authentication and authorization. Master advanced tactics such as password spraying, over-pass-the-hash attacks, and forging Kerberos tickets. Examine logging mechanisms and understand how to minimize detection. By the end of this talk, acquire valuable insights into attacking AD from non-Windows environments, equipping yourself with practical skills for penetration testing and security assessments.
Fun with LDAP and Kerberos - Attacking AD from Non-Windows Machines