Pirate - HTB Machine Writeup
Difficulty: Hard | OS: Windows | Status: Completed
Exploit a Pre-Windows 2000 machine account to dump gMSA hashes, pivot through a Ligolo-ng tunnel, and chain RBCD relay with SPN injection to achieve full Domain Admin on a multi-host Active Directory environment.
Tags: Active Directory, Kerberos Delegation, NTLM Relay
[ LOADING MACHINE DATA... ]
_