root@z2r:~/blog/tags#grep -r "bloodhound" ./posts
<Tag: bloodhound />
Found 1 post with this tag.
CTF WRITEUPSACTIVE DIRECTORY
HackSmarter - ShadowGate
Compromising the ShadowGate Active Directory lab through a chained attack path — from AS-REP roasting and ACL abuse via Shadow Credentials, to coercing the Domain Controller with PetitPotam and relaying its authentication into a certificate-based DCSync — culminating in full domain compromise via the krbtgt hash.