HardActive Directory

Kerberoast or Die

400 pointsEst. 1h 15m5,230 solved00:00 elapsed

Mission Briefing

You have low-privilege domain credentials. Escalate to Domain Admin using classic AD attack chains inside a live enterprise range.

Objectives

  • Enumerate the domain with BloodHound
  • Extract a Kerberoastable service account hash
  • Crack the service account password
  • Escalate to Domain Admin

Terminal Simulation

root@infoenc-range: ~
Infoenc Range v2.4 — target session established
Target: 10.10.14.22 | Type 'help' for available commands
$

Submit Flag

Hint: try cat flag.txt in the terminal above.

Hints

Skills Practiced

KerberoastingBloodHoundLateral Movement

Scoreboard

Base points400
Hint penalty-0
Net score400