Tracks or Hunting Artifacts

Knowing your Environment

How they move is very important. Understanding how they will leave trails and track is essential for effective hunting. Most prey you hunt will have one common goal: travel to the Domain Controller or steal your crown jewel assets -> Knowing your environment will make you a better predator

No matter how they move they always leave something.

Which path leads to Domain Controller?

There is a tool called BloodHound, how can you hunt your prey when you don't know which path they will typically take? using this tool and you can answer that question.

Where should I run this tool you might ask and does it will affect my network traffic? you can run it anywhere you want.

Which is the easiest path?

When the prey finds a hole to hide, they have plenty of time to plan their next move, they will gather as much information as they can, and they will try to find the easiest, most effective, and stealthiest move:

Pass the hash

Activity: Dump lsass.exe for credentials

Tools: Mimikatz, Impacket, ... and so many tools and techniques to do this type of move

Look for:

  • Windows Error Reporting (WER) fault process -> could be use to dump the lsass hash (Application crashes are recorded in the Windows Application event log under Event ID 1000 and 1001)

Refs:

Last updated

Was this helpful?