Our chain starts by installing a Python networking library. We then stage and execute a Python script to extract Group Policy Preference passwords from a target host. Next, a second script is used to enumerate the users on the domain. Finally, we enumerate the Service Principal Names associated with a user account. Together, these scripts show some of the many ways Python can be used for AD discovery.
GET OUR PRODUCTS
Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg
JOIN OUR COMMUNITY
Discord: / discord
Reddit: / preludeorg
Twitter: / preludeorg
READ, WATCH, AND LISTEN
Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org/
Watch our live streams: / preludeorg
Watch our pre-recorded content: / preludeorg
FOLLOW OUR TEAM
David: / privateducky
Alex: / khyberspache
Kris: / xanthonus
Octavia: / vv_x_7
Sam: / wasupwithuman