Domain Escalation — ShadowCoerce (MS-FSRVP)
Coercing the domain controller machine account to authenticate to a host which is under the control of a threat actor could lead to domain compromise. The most notable technique which involves coerced authentication is the PetitPotam attack which uses the Encrypting File System Remote Protocol (MS-EFSR). However, this is not the only protocol which could be utilized for domain escalation.
Research:
https://pentestlaboratories.com/2022/01/11/shadowcoerce/
PoC:
https://github.com/ShutdownRepo/ShadowCoerce
#ad #escalation #relay #redteam
Post #596
766
