~/mbt
back to writeups
Full writeup loaded from GitHub repository.
tryhackmemediumWindows retired

Attacktive Directory

Attacktive Directory - tryhackme retired machine walkthrough.

Approach

01

Enumerated AD environment using BloodHound

02

Identified Kerberoastable service accounts

03

Extracted TGS tickets and cracked offline with hashcat

04

Used cracked credentials for lateral movement

05

Abused delegation rights for domain escalation

Full Writeup

Loading writeup from GitHub...