<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Active-Directory on João Vítor Moutinho Bonin</title>
    <link>https://joaobonin.com/tags/active-directory/</link>
    <description>Recent content in Active-Directory on João Vítor Moutinho Bonin</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 04 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://joaobonin.com/tags/active-directory/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HTB: Flight</title>
      <link>https://joaobonin.com/posts/htb-flight/</link>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-flight/</guid>
      <description>Flight is a Hard Windows Active Directory box from HackTheBox. An LFI on a PHP school subdomain escalates to NTLM hash capture via UNC path. Crack svc_apache&amp;#39;s hash, password spray to S.Moon, use ntlm_theft via the Shared share to coerce C.Bum&amp;#39;s hash, pivot through a PHP webshell to meterpreter, RunasCs to C.Bum, discover an internal IIS dev site, upload an ASPX webshell, and escalate to SYSTEM via SeImpersonatePrivilege and EfsPotato.</description>
    </item>
    <item>
      <title>HTB: Blackfield</title>
      <link>https://joaobonin.com/posts/htb-blackfield/</link>
      <pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-blackfield/</guid>
      <description>Blackfield is a Hard Windows Active Directory box from HackTheBox. ASREPRoasting lands the support account, BloodHound reveals a ForceChangePassword path to audit2020, whose forensic SMB share contains an lsass dump. pypykatz extracts svc_backup&amp;#39;s hash, and SeBackupPrivilege abuse via wbadmin extracts ntds.dit to dump the domain admin hash.</description>
    </item>
    <item>
      <title>HTB: Sauna</title>
      <link>https://joaobonin.com/posts/htb-sauna/</link>
      <pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-sauna/</guid>
      <description>ASREPRoasting a bank employee, cracking their hash, then following a chain of autologon credentials and DCSync rights to own the domain.</description>
    </item>
    <item>
      <title>HTB Monteverde - Azure AD Connect Password Extraction</title>
      <link>https://joaobonin.com/posts/htb-monteverde/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-monteverde/</guid>
      <description>Monteverde is a Medium Windows Active Directory box from HackTheBox. We enumerate domain users via null session, discover a username-as-password credential for SABatchJobs, find an Azure AD Connect config file containing plaintext credentials in an SMB share, and escalate to Administrator by decrypting the Azure AD Sync service account password from the local MSSQL Express database.</description>
    </item>
    <item>
      <title>HTB: Forest</title>
      <link>https://joaobonin.com/posts/htb-forest/</link>
      <pubDate>Sun, 31 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-forest/</guid>
      <description>Forest is an Easy Windows Active Directory box on HackTheBox. The path goes through AS-REP roasting a service account, then using BloodHound to find a WriteDacl abuse chain through Exchange groups to grant DCSync and dump the domain.</description>
    </item>
    <item>
      <title>HTB: Escape</title>
      <link>https://joaobonin.com/posts/htb-escape/</link>
      <pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-escape/</guid>
      <description>Escape is a Medium Windows Active Directory machine where a publicly readable SMB share leaks SQL Server credentials in a PDF. Those creds lead to MSSQL access, NTLM hash capture via xp_dirtree, and eventually an ESC1 ADCS attack to compromise the domain administrator.</description>
    </item>
    <item>
      <title>HTB Certified - Active Directory Certificate Services and ESC9</title>
      <link>https://joaobonin.com/posts/htb-certified/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://joaobonin.com/posts/htb-certified/</guid>
      <description>Certified is a Medium Windows AD box where you chain WriteOwner and GenericWrite ACL abuses to reach a certificate authority operator, then exploit ESC9 to forge an admin certificate and own the domain.</description>
    </item>
    <item>
      <title>HTB: Active - OSCP Prep Write-up</title>
      <link>https://joaobonin.com/posts/htb-active/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0300</pubDate>
      <guid>https://joaobonin.com/posts/htb-active/</guid>
      <description>Write-up for the HackTheBox machine Active - GPP credentials buried in the Replication share expose SVC_TGS, and Kerberoasting that account cracks the Administrator password.</description>
    </item>
    <item>
      <title>HTB: Administrator - OSCP Prep Write-up</title>
      <link>https://joaobonin.com/posts/htb-administrator/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0300</pubDate>
      <guid>https://joaobonin.com/posts/htb-administrator/</guid>
      <description>Write-up for the HackTheBox machine Administrator - a pure AD privilege escalation chain driven by BloodHound ACL abuse, a Password Safe cracking detour, targeted Kerberoasting, and a DCSync to finish the job.</description>
    </item>
    <item>
      <title>HTB: Cicada - OSCP Prep Write-up</title>
      <link>https://joaobonin.com/posts/htb-cicada/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0300</pubDate>
      <guid>https://joaobonin.com/posts/htb-cicada/</guid>
      <description>Write-up for the HackTheBox machine Cicada - a Windows AD box built around SMB enumeration, password spraying, credential leakage, and SeBackupPrivilege abuse.</description>
    </item>
    <item>
      <title>HTB: Return - OSCP Prep Write-up</title>
      <link>https://joaobonin.com/posts/htb-return/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 -0300</pubDate>
      <guid>https://joaobonin.com/posts/htb-return/</guid>
      <description>Write-up for the HackTheBox machine Return - capturing LDAP credentials via a printer settings page, then abusing Server Operators group membership to get SYSTEM.</description>
    </item>
  </channel>
</rss>
