← LibraryTechnique entry
AD-NOPACPrivilege Escalation
sAMAccountName Spoofing — noPac (CVE-2021-42278/42287)
Rename a low-priv computer account to a DC's name, request a TGS as it, then S4U2self to DA.
§ Where this technique fits
AD-NOPAC is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01DCSyncseen 1×T1003.006 · Credential Access
- 02Steal or Forge Kerberos Ticketsseen 1×T1558 · Credential Access