~/mbt
back to writeups
This machine is currently active on the platform. Full writeup is not available.
hack the-boxmachineinsaneWindows active

TrustFall - HackTheBox

Approach

01

CVE-2026-22200

02

CVE-2026-24061

03

Local tunneling to reach internal network

04

Ntlmrelayx relays that captured RDP auth straight into AD CS HTTP Web Enrollment

05

WinSCP credentials decryption

06

Minio and Windows Credential Manager export

07

Wsuks MITM

08

Dump the LSA credentials

09

VBScript's time-seed to generate password

10

ManageCA rights (ESC7 --> Domain Admin)

Full writeup is restricted while this machine is active.

The writeup will be published here once the machine is retired.