> For the complete documentation index, see [llms.txt](https://hackhunter-hacking.gitbook.io/hackhunter-hacking/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hackhunter-hacking.gitbook.io/hackhunter-hacking/hack-smarter-labs/martiniad-active-directory.md).

# MartiniAD - Active Directory

Easy Rated - Hack Smarter Labs

## Objective

* An adult beverage company "Martini Bars" recently had a corporate breach and the compliance and risk team dictates they perform a penetration test at one of their branch offices. The Hack Smarter team has been authorized to perform an internal black box pentest.
* The client has provided you with VPN access to their internal network, but no credentials.

## Initial Scan

### RustScan

{% code overflow="wrap" expandable="true" %}

```
PORT      STATE SERVICE       REASON          VERSION
53/tcp    open  domain        syn-ack ttl 126 Simple DNS Plus
88/tcp    open  kerberos-sec  syn-ack ttl 126 Microsoft Windows Kerberos (server time: 2026-05-22 13:37:33Z)
135/tcp   open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
139/tcp   open  netbios-ssn   syn-ack ttl 126 Microsoft Windows netbios-ssn
389/tcp   open  ldap          syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: DRY.MARTINI.BARS, Site: Default-First-Site-Name)
445/tcp   open  microsoft-ds? syn-ack ttl 126
464/tcp   open  kpasswd5?     syn-ack ttl 126
593/tcp   open  ncacn_http    syn-ack ttl 126 Microsoft Windows RPC over HTTP 1.0
636/tcp   open  tcpwrapped    syn-ack ttl 126
3268/tcp  open  ldap          syn-ack ttl 126 Microsoft Windows Active Directory LDAP (Domain: DRY.MARTINI.BARS, Site: Default-First-Site-Name)
3269/tcp  open  tcpwrapped    syn-ack ttl 126
3389/tcp  open  ms-wbt-server syn-ack ttl 126
| ssl-cert: Subject: commonName=DC01.DRY.MARTINI.BARS
| Issuer: commonName=DC01.DRY.MARTINI.BARS
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-01-16T01:19:23
| Not valid after:  2026-07-18T01:19:23
| MD5:     e45f 2ccb 66e0 e93a ce42 62b8 4f09 0850
| SHA-1:   2ffc e1c5 3163 c9dd cf69 e82a b091 67a3 1324 0dc7
| SHA-256: 5feb bdd8 fd0f 4eee 431f 0658 cd02 b0aa 582b c3f3 95f9 ad43 ec76 3c28 03dd dfa6
| -----BEGIN CERTIFICATE-----
| MIIC7jCCAdagAwIBAgIQTPVeL4Dy9LpJHK+XV9l0XTANBgkqhkiG9w0BAQsFADAg
| MR4wHAYDVQQDExVEQzAxLkRSWS5NQVJUSU5JLkJBUlMwHhcNMjYwMTE2MDExOTIz
| WhcNMjYwNzE4MDExOTIzWjAgMR4wHAYDVQQDExVEQzAxLkRSWS5NQVJUSU5JLkJB
| UlMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDJ/g3psOOQlBbVnAig
| rAYTEQ8FxugvGM5s7YHuxmG/gP5Iv8bXE0vUo8XbK5ycmrnRbmFfqMM6VWNHqMHt
| J1hZj8Lrg0++mn+fAO4yoelcTIZqMp+zdXlkKZJZMUjarKz3QJPBMLJPDIbP9FZI
| j9p/UldHNLJ2IUKYk13YRq3tHwiUJcIvZYp7cGGwhCBE1j5jrNYPl2wFEFh8T52k
| zDK3AvqPF8GrMrdeMM8XfbfG4XqFksw6Th0hbLErFlwDu9wqR9gVJNwtR0Ax4UKV
| KGbFxwB/H8EQjTiRIs9V7oRp2Faimv9DhgeNcs1nx2JsJaYR0zIRdpMg+XqvWUlK
| +GMVAgMBAAGjJDAiMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIEMDAN
| BgkqhkiG9w0BAQsFAAOCAQEAJCrr+jqxs05xpZsTgAAU0PM+kz8a7vfYPxCqGQnJ
| xq88r8WEm9czyGx5YEzF9dRhQdPJvYjXQTsyhqqi/Jo1GklBczktoSSF/BtPGh5f
| abY/WNHhSDxTvdRSXB2VTY1EuU5JOJZZF0gilntX8xw3WnWPlBVKQAIAnFU2Qtsr
| Tgb+xv6Qat3PlC6d3R/zYAGUyRCsHfz95743eZzQhouns47XUevMRAG+2BEDyeDI
| Cpw1SvP5JoRG4uC5vPcbJ1ZOzLTnZN88hdSv4ysqLY8fSZli7deTaGMm7HG6pQKe
| qJJ/d0iwa+CuGAsG4RziqAuWJ1qOdwh3AjaGd1no7kXmxQ==
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
| rdp-ntlm-info: 
|   Target_Name: DRY
|   NetBIOS_Domain_Name: DRY
|   NetBIOS_Computer_Name: DC01
|   DNS_Domain_Name: DRY.MARTINI.BARS
|   DNS_Computer_Name: DC01.DRY.MARTINI.BARS
|   Product_Version: 10.0.26100
|_  System_Time: 2026-05-22T13:38:30+00:00
5985/tcp  open  http          syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp  open  mc-nmf        syn-ack ttl 126 .NET Message Framing
49664/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
49667/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
49670/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
49672/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
49679/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
49680/tcp open  ncacn_http    syn-ack ttl 126 Microsoft Windows RPC over HTTP 1.0
49697/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
49713/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
63329/tcp open  msrpc         syn-ack ttl 126 Microsoft Windows RPC
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port3389-TCP:V=7.98%I=7%D=5/22%Time=6A105C22%P=x86_64-pc-linux-gnu%r(Te
SF:rminalServerCookie,13,"\x03\0\0\x13\x0e\xd0\0\0\x124\0\x02\?\x08\0\x02\
SF:0\0\0");
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
No OS matches for host
TCP/IP fingerprint:
SCAN(V=7.98%E=4%D=5/22%OT=53%CT=%CU=%PV=Y%DS=3%DC=T%G=N%TM=6A105C80%P=x86_64-pc-linux-gnu)
SEQ(SP=103%GCD=1%ISR=110%TI=I%TS=A)
SEQ(SP=FE%GCD=1%ISR=106%TI=I%TS=A)
OPS(O1=M510NW8ST11%O2=M510NW8ST11%O3=M510NW8NNT11%O4=M510NW8ST11%O5=M510NW8ST11%O6=M510ST11)
WIN(W1=FFFF%W2=FFFF%W3=FFFF%W4=FFFF%W5=FFFF%W6=FFFF)
ECN(R=Y%DF=Y%TG=80%W=FFFF%O=M510NW8NNS%CC=Y%Q=)
T1(R=Y%DF=Y%TG=80%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=N)
U1(R=N)
IE(R=N)

Uptime guess: 0.019 days (since Fri May 22 09:12:23 2026)
Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=259 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled but not required
| smb2-time: 
|   date: 2026-05-22T13:38:32
|_  start_date: N/A
| p2p-conficker: 
|   Checking for Conficker.C or higher...
|   Check 1 (port 30684/tcp): CLEAN (Timeout)
|   Check 2 (port 13438/tcp): CLEAN (Timeout)
|   Check 3 (port 50675/udp): CLEAN (Timeout)
|   Check 4 (port 23940/udp): CLEAN (Timeout)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
|_clock-skew: mean: 0s, deviation: 0s, median: 0s
```

{% endcode %}

## Initial Enumeration

* From the initial scan, I can see that this is a pretty standard DC running Kerberos, SMB, LDAP, and the like. What interests me and might come into play later is I see 'message signing enabled but not required'. Possibility for ntlmrelay? This will be something that we can come back to and explore later if needed.
* First, I will check to see if the user 'guest' is enabled. I will see if we can establish connection over SMB and list out shares. We can see that the guest user is enabled and has R/W permissions on a 'notes' share. Possibility for a malicious LNK file to capture a hash since we have Write access?:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FOO7yAKl2Y6AI0oX5xy0W%2Fimage.png?alt=media&amp;token=5cb4c5e4-c32a-431c-9576-a714049c9212" alt=""><figcaption></figcaption></figure>

* I will now use SMBMAP to list out the contents within the 'notes' share:

{% code overflow="wrap" expandable="true" %}

```
smbmap -H 10.1.107.50 -u guest -p '' -r notes --depth 10
```

{% endcode %}

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F9u2boIjGqtOaftSKsWC7%2Fimage.png?alt=media&amp;token=aee813d3-ac76-47ef-b1bc-d2334917f297" alt=""><figcaption></figcaption></figure>

* We can now grab that file and review it:

{% code overflow="wrap" expandable="true" %}

```
smbmap -H 10.1.107.50 -u guest -p '' --download 'notes\notes.txt'
```

{% endcode %}

* We can see that we are able to gain access to creds for user 'mprice':

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FKZpoLa5KANV6ZN5kPvRk%2Fimage.png?alt=media&amp;token=d8e09958-519b-426a-845d-67108c070d45" alt=""><figcaption></figcaption></figure>

## LDAP Enumeration

* Bloodhound collection was not working and thus we need to manually enumerate LDAP. We can start by checking for users within the domain using Netexec:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2Fs3RHhBqUiieQbkymYQVn%2Fimage.png?alt=media&amp;token=0fcab42a-4254-4c4d-9abc-7c1fcaf3ec5b" alt=""><figcaption></figcaption></figure>

* We can see that the Athena\_SVC user is a member of the Remote Desktop Users and Remote Management Users groups:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FqlpapDJO2sdzaRangepc%2Fimage.png?alt=media&amp;token=90b8ba08-d861-4513-9207-11c4cf24b94a" alt=""><figcaption></figcaption></figure>

* User Athena.t0 appears to be a Tier0 asset and is a member of the Domain Admins group:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2F3eYEslcGWT69IddeG3ql%2Fimage.png?alt=media&amp;token=86a6959c-eddf-4c7e-833e-03aa82fc269e" alt=""><figcaption></figcaption></figure>

* Trying to enumerate with impacket-dacledit is also proving difficult. Time to pivot.

## Gaining Access as User 'ATHENA\_SVC'

* Ok, at this point, we know that attempting to query ldap and dacledit is proving to be a bit difficult. Bloodhound collection is not working either. We need to determine the best path moving forward. We know that there is a service account of 'ATHENA\_SVC' running. Perhaps we could Kerberoast this account as it should have an SPN set. If we can gain access to the RC4 hash, we might be able to crack it and then gain access.

### Kerberoasting

* We will attempt a Kerberoast attack. We are able to gain access to 'ATHENA\_SVC' RC4 hash. Let's try and crack it now:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FcdDTJMZYNaUXlOLKZchB%2Fimage.png?alt=media&amp;token=324da71f-6de8-4347-9dcf-fcf6d2c52d60" alt=""><figcaption></figcaption></figure>

* Attempting to crack it with rockyou.txt, we can see that we get a password:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FqCOdKbPGYDTauC2vBOeX%2Fimage.png?alt=media&amp;token=08626aaf-c725-4f47-8b4c-ad6e795024ac" alt=""><figcaption></figcaption></figure>

## Remote Access as User 'ATHENA\_SVC'

* After trying to gain RDP access, I was denied as the user needed to be in the administrator group, which ATHENA\_SVC is not. No matter, we can gain access via Evil-WinRM and enumerate the host. I will list out the users privileges:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FJcMQqFn4GXK3pW6XFJ1Q%2Fimage.png?alt=media&amp;token=eb7a1e8f-fd68-451a-98d3-ba89d2639904" alt=""><figcaption></figcaption></figure>

* Enumerating the host, we can see entries in the ConsoleHost\_history.txt that appears to provide a password for the administrator account:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FPDdPbXnhoq2uSUL7AsfU%2Fimage.png?alt=media&amp;token=6941cac5-9935-4cb5-abf0-8fc71c28b0b7" alt=""><figcaption></figcaption></figure>

## Privilege Escalation

* We will now verify the login and see we can pwn this host:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FNMXURRqEZuphtq3rAJfZ%2Fimage.png?alt=media&amp;token=619df092-09ab-46b2-842d-9ff1f46a10d2" alt=""><figcaption></figcaption></figure>

* We can now gain access via RDP as the Administrator if we wanted to. However, we need to gain access to the KRBTGT hash. This is as simple as dumping the NTDS.dit with Netexec. I will run the following command and dump this. BOOM full DC compromise:

<figure><img src="https://3310166020-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FK0Ny7JEeHiZzpI1LeGhC%2Fuploads%2FRbr2BCkNeGKUwKSVxmXP%2Fimage.png?alt=media&amp;token=93428d77-7e97-4ee6-bd43-9c915b0f1972" alt=""><figcaption></figcaption></figure>
