Fun DA route 🧵:
1) No creds, poison the network, get some Proxy-Authentications flowing
2) Add a new computer via ntlmrelayx
3) Creds owned -> certipy find -> 2 CAs with ESC8
4) Can't relay DC, custom templates for computers
5) Relay CA1 to CA2 with the custom computer cert