![ADCS + PetitPotam NTLM Relay: Obtaining krbtgt Hash with Domain Controller Machine Certificate - Red Team Notes ADCS + PetitPotam NTLM Relay: Obtaining krbtgt Hash with Domain Controller Machine Certificate - Red Team Notes](https://2603957456-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LFEMnER3fywgFHoroYn%2F-Mfxl7_D4W2be9XDj2Rh%2F-Mfy8kaq6fVwYKGU-5Gj%2Fimage.png?alt=media&token=e7d49874-374b-4abe-be0b-142377c80882)
ADCS + PetitPotam NTLM Relay: Obtaining krbtgt Hash with Domain Controller Machine Certificate - Red Team Notes
![AD CS/PKI template exploit via PetitPotam and NTLMRelayx, from 0 to DomainAdmin in 4 steps | Franky's WebSite AD CS/PKI template exploit via PetitPotam and NTLMRelayx, from 0 to DomainAdmin in 4 steps | Franky's WebSite](https://www.bussink.net/wp-content/uploads/2021/07/ADCS5.png)
AD CS/PKI template exploit via PetitPotam and NTLMRelayx, from 0 to DomainAdmin in 4 steps | Franky's WebSite
![AD CS/PKI template exploit via PetitPotam and NTLMRelayx, from 0 to DomainAdmin in 4 steps | Franky's WebSite AD CS/PKI template exploit via PetitPotam and NTLMRelayx, from 0 to DomainAdmin in 4 steps | Franky's WebSite](https://www.bussink.net/wp-content/uploads/2021/07/lab_diagram-1.png)
AD CS/PKI template exploit via PetitPotam and NTLMRelayx, from 0 to DomainAdmin in 4 steps | Franky's WebSite
![mpgn on Twitter: "It becomes more and more simpler to get an account on the domain without any prerequisite ! thanks to @BlWasp_ 💪 Add a computer using SMB protocol: 1⃣ Responder - mpgn on Twitter: "It becomes more and more simpler to get an account on the domain without any prerequisite ! thanks to @BlWasp_ 💪 Add a computer using SMB protocol: 1⃣ Responder -](https://pbs.twimg.com/media/FPBALq7XEAknYpX.jpg:large)