CRTE - Before Exam
Check for Restricted Groups and their members -
HANDS-ON 2Check for Domain Admin ACLs, User ACLs, User Group ACLs -
HANDS-ON 3Check for Nested Groups ACLs -
HANDS-ON 5Check for LAPS Permissions -
HANDS-ON 8Extracting Credentials Using Mimikatz -
HANDS-ON 9Check for MailBoxes read permissions -
HANDS-ON 10Bypassing CLM & WDAC -
HANDS-ON 10Check for Unconstrained Delegation -
HANDS-ON 11Copying Files to remote machine -
HANDS-ON 11Check for Constrained Delegation -
HANDS-ON 12Check for Resource Based Constrained Delegation -
HANDS-ON 13Check for Remote local admin access
HANDS-ON 13Golden Ticket Using winrs & BetterSafetykatz -
HANDS-ON 14Golden Ticket Using Invoke-Mimikatz.ps1 and PowerShell Remoting -
HANDS-ON 14Sliver Ticket -
HANDS-ON 15Check for DCSync Rights ( add the rights for the user ) -
HANDS-ON 16Check for Exchange Groups membership -
HANDS-ON 17Escalate to EA using Unconstrained Delegation -
HANDS-ON 18Check for Azure ADConnect machine -
HANDS-ON 19Escalate to EA using Trust key -
HANDS-ON 20Escalate to EA using krbtgt hash -
HANDS-ON 21Escalate to EA using Constrained Delegation -
HANDS-ON 23Escalate to a trusted domain using Unconstrained Delegation -
HANDS-ON 24Accessing Shares between Two Forest -
HANDS-ON 25Bypassing SID Filtering -
HANDS-ON 25Check for DB Links & Enabling RPC-Out -
HANDS-ON 26Cross Forest Attacks - Foreign Security Principals -
HANDS-ON 27Cross Forest Attack - Check for Interesting ACLs in EACH domains -
HANDS-ON 27PAM Trust -
HANDS-ON 28Golden Ticket that bypassing ATA -
HANDS-ON 29
Last updated
Was this helpful?