This is a domain penetration standard work recognized by the security industry. It comprehensively explains domain penetration attack and defense technologies and techniques from six dimensions: protocol principles, basic knowledge, tool usage, penetration techniques, vulnerability exploitation, and permission maintenance. It not only helps readers deeply understand the nature of domain attack and defense, but also provides a large number of practical cases. It is Sangfor's attack and defense penetration experts with many years of practical experience in front-line attack and defense. It has been highly praised and recommended by more than 30 experts from Alibaba, Tencent, JD. Com, Xiaomi, Meituan, Kingsoft, 360, Qi'anxin, Changting, NSFOCUS, Venus and other enterprises and institutions.
This book specifically includes the following six aspects:
(1) Agreement principle
The principles of the NTLM protocol, Kerberos protocol, and LDAP are analyzed in detail. Many vulnerabilities in domain penetration revolve around these three protocols.
(2) Basic knowledge
It comprehensively introduces the basic knowledge of various domains such as workgroups and domains, domain trust, domain setup and configuration, local accounts and active directory accounts, local groups and domain groups, access control lists, etc. To help readers lay a solid foundation.
(3) Tool use
The use and principles of more than 10 domain tools such as BloodHound, Adfind, Admod, Rubeus, Ldapsearch, PingCastle, Kekeo, and Impacket are explained in detail, allowing readers to understand various domain penetration techniques and domain vulnerability exploitation processes with ease.
(4) Penetration techniques
It summarizes and analyzes more than 10 attack techniques such as user enumeration, password spraying, AS-REP Roasting attack, Kerberoasting attack, NTLM Relay attack, and delegation attack and their corresponding detection methods and defense measures to help readers quickly grow in attacks and confrontations.
(5) Vulnerability exploitation
It provides a detailed analysis of nearly 10 high-risk domain vulnerabilities that have broken out in recent years, and introduces the background, affected versions, principles, recurrence processes, detection methods and defense measures of these high-risk vulnerabilities, allowing the red team and blue team to rapidly grow in offense and defense.
(6) Permission maintenance
It explains in detail how to maintain the highest authority in the domain and how to use this authority to obtain the credentials of the specified user.
In order to facilitate readers' understanding and operation, this book contains a large number of codes, screenshots and operation step instructions to ensure that readers can understand it at a glance and use it after understanding it!