Domain Takeover Without Domain Admin Permissions

Joe Helle
The Mayor
Published in
4 min readJun 29, 2023

--

Introduction

About a year ago I was conducting an internal assessment, and it was clear that the network was vulnerable to man in the middle attacks (in this case, IPv6 was vulnerable). Despite the network vulnerability, the client did a fairly decent job of limiting domain administrator usage across the network, and I wasn’t relaying anything of value.

At some point ntlmrelayx started getting me excited by saying that user privileges were found, and that it would attempt to add a new user with enterprise…

--

--

Father | Husband | Army Veteran | Former Mayor | Chief Operating Officer | Red Team Lead | CISM | PNPT | OSCP | Retired Moonshiner | Twitter @joehelle