<Tag: AD />
Found 2 posts with this tag.
HackSmarter - MartiniAD
MartiniAD is an Easy-difficulty Active Directory lab hosted by HackSmarter. The domain `DRY.MARTINI.BARS` is fronted by a single Domain Controller (`DC01`) that permits unauthenticated SMB null/guest sessions. This allows enumeration of a non-default share containing plaintext credentials for a low-privileged domain user. Those credentials are used to Kerberoast a service account, whose cracked password grants a foothold via WinRM. Password reuse between the service account and a linked human Tier-0 admin account (which sits in Domain Admins) then provides full domain compromise, culminating in a DCSync attack to extract the KRBTGT hash.
HackSmarter - ShadowGate
Compromising the ShadowGate Active Directory lab through a chained attack path — from AS-REP roasting and ACL abuse via Shadow Credentials, to coercing the Domain Controller with PetitPotam and relaying its authentication into a certificate-based DCSync — culminating in full domain compromise via the krbtgt hash.