BOFHound
Data Collection (Beacon)
# Collect domains, OUs, GPOs with security descriptors
ldapsearch (|(objectClass=domain)(objectClass=organizationalUnit)(objectClass=groupPolicyContainer)) --attributes *,ntsecuritydescriptor
# Collect users, computers, groups with security descriptors
ldapsearch (|(samAccountType=805306368)(samAccountType=805306369)(samAccountType=268435456)) --attributes *,ntsecuritydescriptorProcessing Logs
# From Ubuntu/WSL - copy CS logs
cd /mnt/c/Users/Attacker/Desktop
scp -r attacker@TEAMSERVER:/opt/cobaltstrike/logs .
# Run BOFHound
bofhound -i logsRestricted Groups - Get Local Admins
Download GptTmpl.inf
Add Custom Edges in BloodHound
WMI Filters
Enumerate WMI Filters on GPOs
Get Filter Details
Key Takeaways
Last updated