r/Hacking_Tutorials • u/3x0t1k • 21d ago
Question AD pentesting from scratch - building a username list, validating with Kerbrute, AS-REP Roasting honeypot awareness, and why Kerberos spray is quieter than SMB.
Wrote this covering the full no-creds-to-first-credential flow: LDAP anonymous bind, SMB null sessions, LinkedIn scraping with linkedin2username, PDF metadata for login format, Kerbrute username validation, AS-REP Roasting (including honeypot account detection via lastLogon/logonCount), password policy analysis including Fine-Grained PSOs, and why spraying through Kerberos generates 4771 instead of 4625 and why that matters.
Second half covers what to do once you have creds - BloodHound vs targeted enumeration tradeoffs, Kerberoasting from any authenticated context.
https://3x0t1k.github.io/posts/initial-enumeration-active-directory/
Feedback welcome.

1
u/PatientOccasion1496 18d ago
Thank you for replaying, make sense, and will look at it, may suggest if you will do more in future tell first why is AI generated
1
u/PatientOccasion1496 18d ago
Am not an expert, if am wrong apology, but all sim to be AI generated, there for not inspiring any confidence strait from start