Skip to content

Latest commit

 

History

History
79 lines (40 loc) · 2.51 KB

Blackfield.md

File metadata and controls

79 lines (40 loc) · 2.51 KB

Blackfield HACKTHEBOX

Enumeration

NMAP

image

AD ENUM

My own tool: https://github.com/S12cybersecurity/AD-Pentest

I try to get users from this domain with module users

image

RPC Blocked but LookUPSID works!!

image

ASREPRoasting attack!!

I have credentials:

image

I can't access with EVIL-WINRM, i need BloudHound:

Bloodhound

image

I upload in bloodhound GUI:

image

I put my user:

image

I can change password to audit2020 user:

image

image

New password is 'Password123'

image

I found new SMB Folders

image

I found one interesting file named lsass.zip

image

I run pypykatz and i found hash

image

I can connect with evil-winrm

image

I have user.txt

image

Privilieges...

image

PERFECT!! SeBackupPriviliege...

image