<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>KERBEROASTING on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/kerberoasting/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/kerberoasting/index.xml" rel="self" type="application/rss+xml"/><item><title>bloodyAD</title><link>https://wearethebug.dev/posts/bloodyad/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/bloodyad/</guid><description>Active Directory privilege escalation swiss-army knife. Quick reference for common bloodyAD operations.</description></item><item><title>ERTLabs: MailService</title><link>https://wearethebug.dev/posts/ertlabs-mailservice/</link><pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/ertlabs-mailservice/</guid><description>MailService is a multi-stage internal penetration test scenario that required chaining several techniques across both Linux and Windows domains.</description></item><item><title>VULNLAB: Shinra</title><link>https://wearethebug.dev/posts/vl-shinra/</link><pubDate>Sun, 09 Mar 2025 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-shinra/</guid><description>Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.</description></item><item><title>VULNLAB: Breach</title><link>https://wearethebug.dev/posts/vl-breach/</link><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-breach/</guid><description>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</description></item><item><title>VULNLAB: Bruno</title><link>https://wearethebug.dev/posts/vl-bruno/</link><pubDate>Sat, 02 Jul 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-bruno/</guid><description>Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.</description></item><item><title>VULNLAB: Lustrous</title><link>https://wearethebug.dev/posts/vl-lustrous/</link><pubDate>Sat, 25 Dec 2021 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-lustrous/</guid><description>Lustrous is a Hard-rated chain consisting of 2 machines on vulnlab. Cevering AS-REP roasts, Kerberoasts, the main lesson on this chain is to demonstrate how silver tickets can be used with service accounts in a Active Directory environment.</description></item></channel></rss>