mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-09-03 23:10:50 +03:00
1.0 KiB
1.0 KiB
Standards and References - noPac CVE-2021-42278/42287
MITRE ATT&CK References
| Technique ID | Name | Tactic |
|---|---|---|
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
| T1136.002 | Create Account: Domain Account | Persistence |
| T1078.002 | Valid Accounts: Domain Accounts | Initial Access |
| T1558 | Steal or Forge Kerberos Tickets | Credential Access |
| T1003.006 | OS Credential Dumping: DCSync | Credential Access |
CVE References
- CVE-2021-42278: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278
- CVE-2021-42287: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287
- Microsoft KB5008380: November 2021 Kerberos PAC fix
- Microsoft KB5008602: November 2021 sAMAccountName fix
Key Research
- CrowdStrike: noPac Exploit - Latest Microsoft AD Flaw
- Fortinet: From User to Domain Admin in 60 Seconds
- TrustedSec: Attack Path Mapping Approach to CVEs 2021-42287/42278
- cube0x0 noPac: https://github.com/cube0x0/noPac
- Ridter noPac: https://github.com/Ridter/noPac