<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Chains on WE ARE THE BUG</title><link>https://wearethebug.dev/categories/chains/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 08 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/categories/chains/index.xml" rel="self" type="application/rss+xml"/><item><title>ERTLabs: Calipendula</title><link>https://wearethebug.dev/posts/ertlabs-calipendula/</link><pubDate>Sat, 08 Nov 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-calipendula/</guid><description>Calipendula is a hybrid GCP and Active Directory breach scenario, pushing you through cloud IAM enumeration, service account chaining, RBCD relay attacks, multi-hop tunnelling in a segmented network.</description></item><item><title>ERTLabs: Chains</title><link>https://wearethebug.dev/posts/ertlabs-chains/</link><pubDate>Sat, 30 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-chains/</guid><description>4 Chains which consist of 2-3 machines that are meant to be exploited together.</description></item><item><title>ERTLabs: MailService</title><link>https://wearethebug.dev/posts/ertlabs-mailservice/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-mailservice/</guid><description>MailService is a multi-stage internal penetration test scenario that required chaining several techniques across both Linux and Windows domains.</description></item><item><title>ERTLabs: Ifix-Tcen-Tcen</title><link>https://wearethebug.dev/posts/ertlabs-ifix-tcen-tcen/</link><pubDate>Sat, 09 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-ifix-tcen-tcen/</guid><description>Ifix-Tcen-Tcen is a famous Italian onomatopoeia and cultural reference originating from the erotic *fotoromanzi* (photo-novels) of the 1970s and 1980s. In our case it's a multi-stage internal penetration test scenario focus on Active Directory.</description></item><item><title>VULNLAB: Chain Master</title><link>https://wearethebug.dev/posts/vl-chains/</link><pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-chains/</guid><description>17 Chains which consist of 2-3 machines that are meant to be exploited together.</description></item><item><title>VULNLAB: Mythical</title><link>https://wearethebug.dev/posts/vl-mythical/</link><pubDate>Wed, 06 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-mythical/</guid><description>Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging windows environment.</description></item><item><title>VULNLAB: Puppet</title><link>https://wearethebug.dev/posts/vl-puppet/</link><pubDate>Tue, 22 Oct 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-puppet/</guid><description>Puppet is a Medium-rated small active directory chain in which you start with an already running Sliver C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging hybrid environment.</description></item><item><title>VULNLAB: Heron</title><link>https://wearethebug.dev/posts/vl-heron/</link><pubDate>Thu, 13 Jun 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-heron/</guid><description>Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting with an enumeration of the internal website for domain users and performing AS-REP roasting, decrypting GPP password from the sysvol share, leading to smb share having write access to web.config, gaining a shell by using AspNetCoreModule for executing powershell commands which lead to finding linux admin’s credentials, reusing the same password that will lead to another user which has WriteAccountRestrictions on dc that leads to resource based delegation</description></item><item><title>VULNLAB: Klendathu</title><link>https://wearethebug.dev/posts/vl-klendathu/</link><pubDate>Fri, 24 May 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-klendathu/</guid><description>Klendathu is an Insane difficulty chain hosted on Vulnlab, involved coercion with an undocumented function/procedure on MSSQL, forging a silver ticket, spoofing domain users on linux with GSSAPI authentication, and decrypting RDCMan credentials with domain backup keys.</description></item><item><title>VULNLAB: Unintended</title><link>https://wearethebug.dev/posts/vl-unintended/</link><pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-unintended/</guid><description>Unintended is an Medium chain that provides a hands-on experience with common missteps in Active Directory deployments, demonstrating how attackers can pivot between services to escalate privileges. It blends Linux privilege escalation techniques with Active Directory attack paths, making it a valuable practice ground for both offensive and defensive security practitioners.</description></item><item><title>VULNLAB: Vigilant</title><link>https://wearethebug.dev/posts/vl-vigilant/</link><pubDate>Mon, 15 Apr 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-vigilant/</guid><description>Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.</description></item><item><title>VULNLAB: Tengu</title><link>https://wearethebug.dev/posts/vl-tengu/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-tengu/</guid><description>Tengu is a medium-rated chained machine on VulnLab, features a mixed environment with two Windows hosts and one Linux host. Exploiting Node-RED on Linux (with MSSQL) grants command execution, decrypts service passwords, and pivots to dump NTLM hash. Constrained delegation allows impersonating MSSQL admin for local admin access then recover Domain Admin credentials via DPAPI and Kerberos to compromise the Domain Controller (DC).</description></item><item><title>VULNLAB: Kaiju</title><link>https://wearethebug.dev/posts/vl-kaiju/</link><pubDate>Fri, 02 Feb 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-kaiju/</guid><description>Kaiju is a Hard-rated Active Directory chain, from initial reconnaissance to full domain compromise, covering FileZilla exploitation, KeePass database extraction, NTLM relay attacks, and ADCS abuse (ESC8).</description></item><item><title>VULNLAB: Tea</title><link>https://wearethebug.dev/posts/vl-tea/</link><pubDate>Fri, 05 Jan 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-tea/</guid><description>Tea is a medium-rate small Active Directory chain that provides hands-on experience with common Active Directory and DevOps vulnerabilities and misconfigurations, demonstrating how attackers can pivot between services and retrieve sensitive data to move laterally and escalate privileges.</description></item><item><title>VULNLAB: Sidecar</title><link>https://wearethebug.dev/posts/vl-sidecar/</link><pubDate>Fri, 15 Dec 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-sidecar/</guid><description>Sidecar is a Hard-rated small Active Directory chain that contains 2 Windows machines, however, attacks are not for beginners on Active Directory Pentesting. From initial enumeration through to full domain compromise, including Shell via a .lnk file, NTLM relay, WebDAV coercion, Shadow Credentials, PKINIT abuse, and a Silver Ticket attack.</description></item><item><title>VULNLAB: Push</title><link>https://wearethebug.dev/posts/vl-push/</link><pubDate>Fri, 22 Sep 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-push/</guid><description>Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.</description></item><item><title>VULNLAB: Control</title><link>https://wearethebug.dev/posts/vl-control/</link><pubDate>Fri, 21 Jul 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-control/</guid><description>Control is a Hard-rated chains focus on a small multi-host Linux environment that simulates a realistic internal network and endpoint-management infrastructure. The lab contains two primary hosts (os.control.vl and intra.control.vl) and a variety of services (web apps, OSCTRL/osquery, SSH, nginx, Docker) that chain together to a full domain compromise. It focuses on exploiting web applications, abusing management tooling (OSCTRL / osquery), and leveraging operational misconfigurations to move from an initial foothold to full root on multiple hosts.</description></item><item><title>VULNLAB: Hybrid</title><link>https://wearethebug.dev/posts/vl-hybrid/</link><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-hybrid/</guid><description>Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a crafted email, escalated privileges via NFS, and abused AD CS with certipy to achieve Domain Admin.</description></item><item><title>VULNLAB: Reflection</title><link>https://wearethebug.dev/posts/vl-reflection/</link><pubDate>Sat, 10 Jun 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-reflection/</guid><description>Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.</description></item><item><title>VULNLAB: Trusted</title><link>https://wearethebug.dev/posts/vl-trusted/</link><pubDate>Tue, 20 Sep 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-trusted/</guid><description>Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web vulnerabilities, local privilege escalation, and cross-domain trust abuse. An internal network access is provided with no credentials, and the goal is to assess the security posture of the AD environment.</description></item><item><title>VULNLAB: Intercept</title><link>https://wearethebug.dev/posts/vl-intercept/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-intercept/</guid><description>Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and misconfigurations, demonstrating relay attacks and authentication coercion attacks can be used to get access to the domain.</description></item><item><title>VULNLAB: Lustrous</title><link>https://wearethebug.dev/posts/vl-lustrous/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous/</guid><description>Lustrous is a Hard-rated chain consisting of 2 machines on vulnlab. Cevering AS-REP roasts, Kerberoasts, the main lesson on this chain is to demonstrate how silver tickets can be used with service accounts in a Active Directory environment.</description></item></channel></rss>