// Active Directory Enumeration Report
Attack Overview
Full domain enumeration — RETRO.VL
3
Exploitable
10
Partial / Conditional
14
Secured
2
Not Tested
6
Users Found
6
Anon Shares
DOMAIN ADMINCOMPROMISEDClick for details
AD Environment
| Domain Name: | RETRO.VL |
| Domain Controller: | DC |
| Forest Level: | Windows Server 2016 |
| Domain Functional Level: | Windows Server 2016 |
| Machine Account Quota: | 0 |
6
Users
2
Computers
17
Groups
1
Domain Admins
3
Privileged Accounts
(AdminCount=1)
(AdminCount=1)
3
ACL Risks
// Environment
DomainRETRO.VL
DC IP10.129.234.44
Auth ModeAUTHENTICATED
FootholdYES — credentials loaded
PE GatesDCSync Check, ADCS
Pwned Users6
Pwned Machines3
// User Analysis
RID-bruted Users6
Machine Accounts4
Anon SMB SharesADMIN$, C$, NETLOGON, Notes, SYSVOL, Trainees
Credential Artifacts32
Kerberos Tickets3
Certificates2
// Privilege escalation paths
Attack Surface
Animated attack paths showing how each PE gate was reached
// Enumerated attack vectors
Attack Info
All 29 flows — status, phase, and outcome per vector
01
Zerologon
Anonymous (Pre-Step)
Not Vulnerable / Secured
The domain controller did not expose a usable Zerologon path.
02
Pre-Auth Spray
Anonymous (Pre-Step)
Not Tested
This flow was not executed in the current run.
03
AS-REP Roasting
Anonymous (Pre-Step)
Not Tested
AS-REP roasting did not expose roastable accounts.
04
SMB Shares
Anonymous (Pre-Step)
Partially / Conditionally Exploitable
6 anonymous share(s) exposed — Sensitive: NETLOGON, SYSVOL; Open: ADMIN$, C$, Notes, Trainees.
05
RID Brute
Anonymous (Pre-Step)
Partially / Conditionally Exploitable
Enumerated 6 user(s) and 4 machine account(s) via RID brute.
06
Password Policy
Anonymous (Pre-Step)
Partially / Conditionally Exploitable
Domain password policy was successfully enumerated.
07
LDAP Signing
Anonymous (Pre-Step)
Not Vulnerable / Secured
LDAP signing is enforced — relay attacks mitigated.
08
Kerberoast
Enumeration
Not Vulnerable / Secured
Kerberoast enumeration ran but found no roastable accounts.
09
ACL Abuse
Enumeration
Partially / Conditionally Exploitable
Writable ACLs were identified on domain objects — exploitation attempted.
10
Group Abuse
Enumeration
Not Vulnerable / Secured
No modifiable privileged group path was confirmed.
11
gMSA Read
Enumeration
Not Vulnerable / Secured
No gMSA objects or exposure were identified.
12
Machine Ownership
Enumeration
Not Vulnerable / Secured
No writable machine object or administrative path was available.
13
Local Admin Mapping
Enumeration
Partially / Conditionally Exploitable
Local admin paths identified — secretsdump attempted but not confirmed.
14
Delegation RBCD
Enumeration
Partially / Conditionally Exploitable
Potential RBCD candidates identified — exploitation conditions not met.
15
SYSVOL / GPP
Enumeration
Not Vulnerable / Secured
SYSVOL enumerated — no GPP credentials or sensitive files found.
16
LAPS Read
Enumeration
Not Vulnerable / Secured
LAPS is deployed but passwords are not readable by the current identity.
17
NoPac
Enumeration
Not Vulnerable / Secured
NoPac check completed — not vulnerable.
18
Unconstrained Delegation
Enumeration
Not Vulnerable / Secured
Unconstrained delegation enumeration completed.
19
Constrained Delegation
Enumeration
Exploitable
No constrained delegation (KCD) accounts found.
20
DCSync Check
Exploitation
Exploitable
DCSync replication rights confirmed — full domain credential extraction achieved.
21
ADCS
Exploitation
Exploitable
ADCS abuse succeeded and produced Domain Admin level authentication.
22
RBCD
Exploitation
Partially / Conditionally Exploitable
RBCD delegation write attempted — machine context not fully obtained.
23
S4U Impersonation
Exploitation
Not Vulnerable / Secured
S4U impersonation did not produce a usable privileged ticket.
24
Services Abuse
Exploitation
Partially / Conditionally Exploitable
Remote service abuse did not produce SYSTEM-level execution.
25
Scheduled Tasks
Exploitation
Partially / Conditionally Exploitable
Scheduled task was created — waiting for execution or confirmation failed.
26
GPO Abuse
Exploitation
Not Vulnerable / Secured
GPO abuse did not run in this context.
27
Shadow Credentials
Exploitation
Not Vulnerable / Secured
Shadow credential abuse did not produce a usable outcome.
28
NTLM Relay
Exploitation
Not Vulnerable / Secured
NTLM relay did not produce a usable outcome.
29
Ticket Reuse
Exploitation
Partially / Conditionally Exploitable
A reusable Kerberos ticket cache was identified.
// Staged execution flow
Attack Chain
Pre-step → Enumeration → Exploitation — step-by-step
Pre-Step — Initial Reconnaissance
5
Enumeration — Attack Surface Discovery
12
Exploitation — Privilege Escalation Attempts
10
// Risk assessment
Conclusion & Risk
Risk distribution, attack path summary, and per-flow breakdown
Constrained Delegation — 100% (Exploitable)
DCSync Check — 100% (Exploitable)
ADCS — 100% (Exploitable)
RBCD — 80% (Partially / Conditionally Exploitable)
Delegation RBCD — 78% (Partially / Conditionally Exploitable)
Ticket Reuse — 75% (Partially / Conditionally Exploitable)
ACL Abuse — 72% (Partially / Conditionally Exploitable)
Services Abuse — 72% (Partially / Conditionally Exploitable)
Scheduled Tasks — 70% (Partially / Conditionally Exploitable)
Password Policy — 65% (Partially / Conditionally Exploitable)
Local Admin Mapping — 64% (Partially / Conditionally Exploitable)
SMB Shares — 63% (Partially / Conditionally Exploitable)
RID Brute — 60% (Partially / Conditionally Exploitable)
Initial Foothold Discovery
Password Policy
65%
Password Policy — Attack surface identified with partial exploitation potential — requires hardening.
Domain password policy was successfully enumerated.
SMB Shares
63%
SMB Shares — Attack surface identified with partial exploitation potential — requires hardening.
6 anonymous share(s) exposed — Sensitive: NETLOGON, SYSVOL; Open: ADMIN$, C$, Notes, Trainees.
RID Brute
60%
RID Brute — Attack surface identified with partial exploitation potential — requires hardening.
Enumerated users: administrator, guest, jburley, krbtgt, tblack, trainee
Credential Compromise
DCSync Check
100%
DCSync Check — Critical vulnerability confirmed and successfully exploited — immediate remediation required.
DCSync replication rights confirmed — full domain credential extraction achieved.
Post-Foothold Attack Surface
Constrained Delegation
100%
Constrained Delegation — Critical vulnerability confirmed and successfully exploited — immediate remediation required.
No constrained delegation (KCD) accounts found.
ADCS
100%
ADCS — Critical vulnerability confirmed and successfully exploited — immediate remediation required.
ADCS abuse succeeded and produced Domain Admin level authentication.
RBCD
80%
RBCD — Attack surface identified with partial exploitation potential — requires hardening.
RBCD delegation write attempted — machine context not fully obtained.
Delegation RBCD
78%
Delegation RBCD — Attack surface identified with partial exploitation potential — requires hardening.
Potential RBCD candidates identified — exploitation conditions not met.
Ticket Reuse
75%
Ticket Reuse — Attack surface identified with partial exploitation potential — requires hardening.
A reusable Kerberos ticket cache was identified.
ACL Abuse
72%
ACL Abuse — Attack surface identified with partial exploitation potential — requires hardening.
Writable ACLs were identified on domain objects — exploitation attempted.
Services Abuse
72%
Services Abuse — Attack surface identified with partial exploitation potential — requires hardening.
Remote service abuse did not produce SYSTEM-level execution.
Scheduled Tasks
70%
Scheduled Tasks — Attack surface identified with partial exploitation potential — requires hardening.
Scheduled task was created — waiting for execution or confirmation failed.
Local Admin Mapping
64%
Local Admin Mapping — Attack surface identified with partial exploitation potential — requires hardening.
Local admin paths identified — secretsdump attempted but not confirmed.
Not Vulnerable / Secured
Zerologon
3%
Zerologon — No exploitable path identified in the current assessment scope.
The domain controller did not expose a usable Zerologon path.
LDAP Signing
8%
LDAP Signing — No exploitable path identified in the current assessment scope.
LDAP signing is enforced — relay attacks mitigated.
Kerberoast
8%
Kerberoast — No exploitable path identified in the current assessment scope.
Kerberoast enumeration ran but found no roastable accounts.
Group Abuse
8%
Group Abuse — No exploitable path identified in the current assessment scope.
No modifiable privileged group path was confirmed.
gMSA Read
3%
gMSA Read — No exploitable path identified in the current assessment scope.
No gMSA objects or exposure were identified.
Machine Ownership
3%
Machine Ownership — No exploitable path identified in the current assessment scope.
No writable machine object or administrative path was available.
SYSVOL / GPP
8%
SYSVOL / GPP — No exploitable path identified in the current assessment scope.
SYSVOL enumerated — no GPP credentials or sensitive files found.
LAPS Read
8%
LAPS Read — No exploitable path identified in the current assessment scope.
LAPS is deployed but passwords are not readable by the current identity.
NoPac
8%
NoPac — No exploitable path identified in the current assessment scope.
NoPac check completed — not vulnerable.
Unconstrained Delegation
8%
Unconstrained Delegation — No exploitable path identified in the current assessment scope.
Unconstrained delegation enumeration completed.
S4U Impersonation
8%
S4U Impersonation — No exploitable path identified in the current assessment scope.
S4U impersonation did not produce a usable privileged ticket.
GPO Abuse
3%
GPO Abuse — No exploitable path identified in the current assessment scope.
GPO abuse did not run in this context.
Shadow Credentials
8%
Shadow Credentials — No exploitable path identified in the current assessment scope.
Shadow credential abuse did not produce a usable outcome.
NTLM Relay
8%
NTLM Relay — No exploitable path identified in the current assessment scope.
NTLM relay did not produce a usable outcome.
Not Tested
Pre-Auth Spray
N/A
Pre-Auth Spray — Not evaluated during this assessment cycle.
This flow was not executed in the current run.
AS-REP Roasting
N/A
AS-REP Roasting — Not evaluated during this assessment cycle.
AS-REP roasting did not expose roastable accounts.
// Classified security findings — OWASP / MITRE ATT&CK
Security Findings
Vulnerabilities ranked by severity: Critical → High → Medium → Low → Informational. Each finding maps to industry-standard frameworks.
CRITICAL3
#1
NTLM Hashes Exposed via DCSync
CRITICAL
Affected Component
Authentication Services
VULNERABILITY DESCRIPTION
Directory replication rights allowed full extraction of all domain account NTLM hashes. An attacker with these hashes can impersonate any domain account.
FINDING RISK
IMPACT
High
LIKELIHOOD
High
OVERALL RISK
Critical
RISKS
Immediate and complete compromise of domain integrity. All domain accounts, services, and systems are at risk. An attacker can maintain persistent, undetectable access.
RECOMMENDATIONS
- Restrict DCSync rights, monitor replication events
EVIDENCE
#2
RBCD Delegation Abuse Path
CRITICAL
Affected Component
Active Directory
VULNERABILITY DESCRIPTION
Resource-Based Constrained Delegation write permissions exist that could allow an attacker to impersonate privileged accounts against target services.
FINDING RISK
IMPACT
High
LIKELIHOOD
High
OVERALL RISK
Critical
RISKS
Immediate and complete compromise of domain integrity. All domain accounts, services, and systems are at risk. An attacker can maintain persistent, undetectable access.
RECOMMENDATIONS
- Restrict who can write msDS-AllowedToActOnBehalfOfOtherIdentity
EVIDENCE
#3
ADCS ESC1 — Vulnerable Template (RetroClients)
CRITICAL
Affected Component
Active Directory Certificate Services
VULNERABILITY DESCRIPTION
A certificate template with dangerous enrollment settings allows any authenticated user to request certificates for arbitrary principals, enabling privilege escalation to Domain Admin.
FINDING RISK
IMPACT
High
LIKELIHOOD
High
OVERALL RISK
Critical
RISKS
Immediate and complete compromise of domain integrity. All domain accounts, services, and systems are at risk. An attacker can maintain persistent, undetectable access.
RECOMMENDATIONS
- Review certificate template enrollment rights and EKU settings
EVIDENCE
HIGH3
#4
Weak Password Policy
HIGH
Affected Component
Authentication Services
VULNERABILITY DESCRIPTION
The domain password policy does not meet security best practices. Minimum length, complexity requirements, or lockout thresholds are insufficient to prevent brute-force and spray attacks.
FINDING RISK
IMPACT
High
LIKELIHOOD
Medium
OVERALL RISK
High
RISKS
Significant security exposure that could lead to privilege escalation or lateral movement. Exploitation requires minimal additional access or conditions.
RECOMMENDATIONS
- Enforce 14+ char minimum, enable complexity, set lockout to 5-10 attempts
EVIDENCE
#5
Weak Credentials Discovered
HIGH
Affected Component
Authentication Services
VULNERABILITY DESCRIPTION
Domain account credentials were recovered through hash extraction. These credentials grant authenticated access to domain resources and can be used for lateral movement.
FINDING RISK
IMPACT
High
LIKELIHOOD
Medium
OVERALL RISK
High
RISKS
Significant security exposure that could lead to privilege escalation or lateral movement. Exploitation requires minimal additional access or conditions.
RECOMMENDATIONS
- Enforce strong passwords, implement MFA, review password policy
EVIDENCE
#6
ACL Misconfigurations — Writable AD Objects
HIGH
Affected Component
Active Directory
VULNERABILITY DESCRIPTION
Active Directory objects have overly permissive access control lists. Write permissions on sensitive objects can be abused to escalate privileges or modify security-critical attributes.
FINDING RISK
IMPACT
High
LIKELIHOOD
Medium
OVERALL RISK
High
RISKS
Significant security exposure that could lead to privilege escalation or lateral movement. Exploitation requires minimal additional access or conditions.
RECOMMENDATIONS
- Audit and remove unnecessary write permissions on AD objects
EVIDENCE
MEDIUM2
#7
Anonymous SMB Share Access
MEDIUM
Affected Component
Network Services
VULNERABILITY DESCRIPTION
SMB file shares are accessible without authentication. Sensitive shares (SYSVOL, NETLOGON) and custom shares may expose configuration files, scripts, or credentials.
FINDING RISK
IMPACT
Medium
LIKELIHOOD
Medium
OVERALL RISK
Medium
RISKS
Moderate security weakness that increases the overall attack surface. Exploitation may require additional conditions or chaining with other findings.
RECOMMENDATIONS
- Disable anonymous access, tighten share and NTFS permissions
EVIDENCE
#8
Stale Passwords Detected
MEDIUM
Affected Component
Authentication Services
VULNERABILITY DESCRIPTION
This finding was identified during automated security assessment of the authentication services component.
FINDING RISK
IMPACT
Medium
LIKELIHOOD
Medium
OVERALL RISK
Medium
RISKS
Moderate security weakness that increases the overall attack surface. Exploitation may require additional conditions or chaining with other findings.
RECOMMENDATIONS
- Enforce maximum password age policy (90–180 days)
- Review and rotate stale credentials
LOW3
#9
WinRM Service Exposed
LOW
Affected Component
Network Services
VULNERABILITY DESCRIPTION
The Windows Remote Management service is accessible on the network. While expected on servers, unrestricted access increases lateral movement risk.
FINDING RISK
IMPACT
Low
LIKELIHOOD
Low
OVERALL RISK
Low
RISKS
Minor security observation with limited direct impact. May contribute to information gathering or be useful in combination with other findings.
RECOMMENDATIONS
- Restrict WinRM access to admin networks, use HTTPS (5986)
#10
RDP Service Exposed
LOW
Affected Component
Network Services
VULNERABILITY DESCRIPTION
Remote Desktop Protocol is accessible on the network. Unrestricted RDP access increases the attack surface for brute-force and credential-based attacks.
FINDING RISK
IMPACT
Low
LIKELIHOOD
Low
OVERALL RISK
Low
RISKS
Minor security observation with limited direct impact. May contribute to information gathering or be useful in combination with other findings.
RECOMMENDATIONS
- Restrict RDP access, enforce NLA, use VPN/jump hosts
#11
Inactive Domain Accounts
LOW
Affected Component
Authentication Services
VULNERABILITY DESCRIPTION
This finding was identified during automated security assessment of the authentication services component.
FINDING RISK
IMPACT
Low
LIKELIHOOD
Low
OVERALL RISK
Low
RISKS
Minor security observation with limited direct impact. May contribute to information gathering or be useful in combination with other findings.
RECOMMENDATIONS
- Disable or remove inactive accounts
- Implement automated account lifecycle management
FINDINGS
3
CRITICAL
3
HIGH
2
MEDIUM
3
LOW
#1◆
#2◆
#3◆
#4◆
#5◆
#6◆
#7◆
#8◆
#9◆
#10◆
#11◆
// Remediation guidance
Mitigation Playbook
Per-flow remediation, hardening references, and MITRE mappings
Zerologon
Not Vulnerable / Secured
Patch and enforce Netlogon secure channel protections, monitor machine authentication anomalies.
Pre-Auth Spray
Not Tested
Enforce strong passwords, smart lockout, MFA, and remove predictable password patterns.
AS-REP Roasting
Not Tested
Require Kerberos pre-authentication for all accounts that do not explicitly need legacy settings.
SMB Shares
Partially / Conditionally Exploitable
Remove anonymous access, tighten share and NTFS permissions, audit SYSVOL and NETLOGON.
RID Brute
Partially / Conditionally Exploitable
Restrict anonymous SAMR/RPC enumeration and monitor repeated SID probing.
Password Policy
Partially / Conditionally Exploitable
Enforce minimum 14-character passwords, smart lockout (5-10 attempts), fine-grained password policies, and MFA.
LDAP Signing
Not Vulnerable / Secured
Enforce LDAP signing and channel binding on all domain controllers to prevent relay attacks.
Kerberoast
Not Vulnerable / Secured
Use long random service account passwords, prefer gMSA, reduce unnecessary SPNs.
ACL Abuse
Partially / Conditionally Exploitable
Audit and remove unnecessary write, owner, and DACL rights on privileged objects.
Group Abuse
Not Vulnerable / Secured
Restrict who can modify privileged group membership and alert on changes.
gMSA Read
Not Vulnerable / Secured
Reduce PrincipalsAllowedToRetrieveManagedPassword to only required systems.
Machine Ownership
Not Vulnerable / Secured
Review computer object ACLs, machine password reset rights, and local admin boundaries.
Local Admin Mapping
Partially / Conditionally Exploitable
Reduce local admin sprawl, use tiering, monitor remote admin access from lower-trust identities.
Delegation / RBCD
Partially / Conditionally Exploitable
Audit delegation settings, restrict who can write delegation-related attributes.
SYSVOL / GPP
Not Vulnerable / Secured
Remove GPP passwords from SYSVOL, audit Group Policy Preferences, apply MS14-025.
LAPS Read
Not Vulnerable / Secured
Restrict LAPS password read permissions to designated admin groups only.
NoPac
Not Vulnerable / Secured
Apply KB5008380 and KB5008602. Set ms-DS-MachineAccountQuota to 0.
Unconstrained Delegation
Not Vulnerable / Secured
Remove unconstrained delegation from all accounts except domain controllers. Use constrained delegation or RBCD instead.
Constrained Delegation
Exploitable
Audit constrained delegation settings and restrict protocol transition where not needed.
DCSync Check
Exploitable
Remove unnecessary DS-Replication-Get-Changes-All rights. Monitor for non-DC replication requests. Implement tiered administration.
ADCS
Exploitable
Review certificate templates for dangerous enrollment rights, SAN abuse, and privileged EKUs.
RBCD
Partially / Conditionally Exploitable
Remove machine/object write paths that enable resource-based constrained delegation.
S4U Impersonation
Not Vulnerable / Secured
Constrain delegation, minimize services trusted for delegation.
Services Abuse
Partially / Conditionally Exploitable
Lock down service control rights, review writable service binaries and paths.
Scheduled Tasks
Partially / Conditionally Exploitable
Restrict remote task creation, review writable task actions, monitor Task Scheduler logs.
GPO Abuse
Not Vulnerable / Secured
Restrict who can edit GPOs, review SYSVOL permissions, monitor GPO modifications.
Shadow Credentials
Not Vulnerable / Secured
Restrict write access to key credential material and monitor msDS-KeyCredentialLink changes.
NTLM Relay
Not Vulnerable / Secured
Require signing, reduce NTLM exposure, enforce LDAP signing/channel binding.
Ticket Reuse
Partially / Conditionally Exploitable
Protect ticket material in memory and storage, rotate exposed sessions quickly.
// Recovered credentials
Spoils: Credentials
Passwords, hashes, tickets, certificates, and domain compromise artifacts
Credentials
Valid user account
Administrator - :123f689a8d551f42706ec952b1aeee9a
Valid user account
Guest - :31d6cfe0d16ae931b73c59d7e0c089c0
Valid user account
krbtgt - :e11fffd0ed83eedde12611fc2fbb8650
Valid user account
retro.vl\trainee - :2a217a32bde94a23b26a8eea26c70874
Valid user account
retro.vl\jburley - :25c3464d4e99d340122f3a360bbd7c6c
Valid user account
retro.vl\tblack - :0adf9f3819565a0d0f3890290ecc3919
Valid machine account
banking$ - DOMAINator1337!##&
Valid machine account
DC$ - :12c876af4deb1aedf56306edde6530b3
Valid machine account
BANKING$ - :a0da35556323d8cc8bed2c4638cbaf28
Discovered credential
Administrator:CERTIFICATE_AUTH (ADCS_ESC1)
Ticket
Kerberos cache
banking$.ccache
Kerberos cache
Administrator.ccache
Domain Compromise
Domain Admin
CONFIRMED — Full domain compromise achieved
Attack Path
PE Chain
DCSync (domain)
Enumeration
RID-bruted users
administrator, guest, jburley, krbtgt, tblack, trainee
RID-bruted machine accounts
banking$, dc$, banking$, banking$
Anonymous SMB shares
ADMIN$, C$, NETLOGON, Notes, SYSVOL, Trainees
Domain Hashes
Secretsdump — 8 account(s)
Administrator → aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a Guest → aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 krbtgt → aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650 trainee → aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874 jburley → aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c tblack → aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919 DC$ → aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3 BANKING$ → aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28
Compromised Users
4 user account(s) with recovered credentials
Administrator → :123f689a8d551f42706ec952b1aeee9a retro.vl\trainee → :2a217a32bde94a23b26a8eea26c70874 retro.vl\jburley → :25c3464d4e99d340122f3a360bbd7c6c retro.vl\tblack → :0adf9f3819565a0d0f3890290ecc3919
Compromised Machines
3 machine account(s)
banking$ → DOMAINator1337!##& DC$ → :12c876af4deb1aedf56306edde6530b3 BANKING$ → :a0da35556323d8cc8bed2c4638cbaf28
Flow Finding
RID Brute — Partially / Conditionally Exploitable
Domain accounts discovered via adaptive enumeration chain.
Password Policy — Partially / Conditionally Exploitable
Domain password policy retrieved — review lockout threshold before spraying. SMB 10.129.234.44 445 DC [+] Dumping password info for domain: RETRO SMB 10.129.234.44 445 DC Minimum password length: 5 SMB 10.129.234.44 445 DC Password history length: 24 SMB 10.129.234.44 445 DC Maximum password age: 41 days 23 hours 53 minutes SMB 10.129.234.44 445 DC Password Complexity Flags: 000000 SMB 10.129.234.44 445 DC Domain Refuse Password Change: 0 SMB 10.129.234.44 445 DC Domain Password Store Cleartext: 0
ACL Abuse — Partially / Conditionally Exploitable
Writable directory objects were identified but only limited attribute permissions are exposed.
Delegation RBCD — Partially / Conditionally Exploitable
Resource-based constrained delegation candidates were identified and can be evaluated by downstream RBCD and S4U exploitation flows. RBCD candidates: Present
Constrained Delegation — Exploitable
STATUS: VULNERABLE
DCSync Check — Exploitable
STATUS: VULNERABLE
ADCS — Exploitable
STATUS: VULNERABLE
RBCD — Partially / Conditionally Exploitable
Delegation write succeeded but no machine password was obtained for ownership takeover.
ACL Abuse Surface
Writable AD objects discovered
distinguishedName: CN=TPM Devices,DC=retro,DC=vl permission: CREATE_CHILD distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=retro,DC=vl permission: WRITE distinguishedName: CN=banking,CN=Computers,DC=retro,DC=vl permission: CREATE_CHILD; WRITE
Delegation Targets
RBCD delegation candidates
banking
Certificate
Certificate file
admin.pfx
Certificate file
admin_orig.pfx
// Spidered files
Spoils: Files
Sensitive files discovered across accessible SMB shares
15
FILES CAPTURED
6
SHARES ENUMERATED
// Shell evidence
Spoils: Evidence
Command execution proof — whoami, ipconfig, and tool output per owned identity
Shell Evidence (12 sessions)
Admin Shell📄
retro\administrator
Administrator (Da Proof)👑 DA
═══════════════════════════════════════════════ DOMAINATOR — Domain Admin Proof User: Administrator Target: 10.129.234.44 Domain: retro.vl ═══════════════════════════════════════════════ whoami /all USER INFORMATION ---------------- User Name SID =================== ============================================ retro\administrator S-1-5-21-2983547755-698260136-4283918172-500 GROUP INFORMATION ----------------- Group Name Type SID Attributes ============================================ ================ ============================================ =============================================================== Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group BUILTIN\Administrators Alias S-1-5-32-544 Mandatory group, Enabled by default, Enabled group, Group owner BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554 Mandatory group, Enabled by default, Enabled group BUILTIN\Certificate Service DCOM Access Alias S-1-5-32-574 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group RETRO\Domain Admins Group S-1-5-21-2983547755-698260136-4283918172-512 Mandatory group, Enabled by default, Enabled group RETRO\Group Policy Creator Owners Group S-1-5-21-2983547755-698260136-4283918172-520 Mandatory group, Enabled by default, Enabled group RETRO\Enterprise Admins Group S-1-5-21-2983547755-698260136-4283918172-519 Mandatory group, Enabled by default, Enabled group RETRO\Schema Admins Group S-1-5-21-2983547755-698260136-4283918172-518 Mandatory group, Enabled by default, Enabled group RETRO\Denied RODC Password Replication Group Alias S-1-5-21-2983547755-698260136-4283918172-572 Mandatory group, Enabled by default, Enabled group, Local Group NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group Mandatory Label\High Mandatory Level Label S-1-16-12288 PRIVILEGES INFORMATION ---------------------- Privilege Name Description State ========================================= ================================================================== ======= SeIncreaseQuotaPrivilege Adjust memory quotas for a process Enabled SeMachineAccountPrivilege Add workstations to domain Enabled SeSecurityPrivilege Manage auditing and security log Enabled SeTakeOwnershipPrivilege Take ownership of files or other objects Enabled SeLoadDriverPrivilege Load and unload device drivers Enabled SeSystemProfilePrivilege Profile system performance Enabled SeSystemtimePrivilege Change the system time Enabled SeProfileSingleProcessPrivilege Profile single process Enabled SeIncreaseBasePriorityPrivilege Increase scheduling priority Enabled SeCreatePagefilePrivilege Create a pagefile Enabled SeBackupPrivilege Back up files and directories Enabled SeRestorePrivilege Restore files and directories Enabled SeShutdownPrivilege Shut down the system Enabled SeDebugPrivilege Debug programs Enabled SeSystemEnvironmentPrivilege Modify firmware environment values Enabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeRemoteShutdownPrivilege Force shutdown from a remote system Enabled SeUndockPrivilege Remove computer from docking station Enabled SeEnableDelegationPrivilege Enable computer and user accounts to be trusted for delegation Enabled SeManageVolumePrivilege Perform volume maintenance tasks Enabled SeImpersonatePrivilege Impersonate a client after authentication Enabled SeCreateGlobalPrivilege Create global objects Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Enabled SeTimeZonePrivilege Change the time zone Enabled SeCreateSymbolicLinkPrivilege Create symbolic links Enabled SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled USER CLAIMS INFORMATION ----------------------- User claims unknown. Kerberos support for Dynamic Access Control on this device has been disabled. ═══════════════════════════════════════════════
Administrator👑 DA
═══════════════════════════════════════════════
DOMAINATOR — Shell Evidence
User: Administrator
Target: 10.129.234.44
Domain: retro.vl
Method: WMIEXEC (NTLM)
Hash: 123f689a8d551f42706ec952b1aeee9a
═══════════════════════════════════════════════
whoami
retro\administrator
Windows IP Configuration
Host Name . . . . . . . . . . . . : DC
Primary Dns Suffix . . . . . . . : retro.vl
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : retro.vl
.htb
Ethernet adapter Ethernet0 2:
Connection-specific DNS Suffix . : .htb
Description . . . . . . . . . . . : vmxnet3 Ethernet Adapter
Physical Address. . . . . . . . . : 00-50-56-94-60-CA
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : dead:beef::d54d:eae:e4a3:f5e4(Preferred)
Link-local IPv6 Address . . . . . : fe80::823f:49f5:4782:4191%5(Preferred)
IPv4 Address. . . . . . . . . . . : 10.129.234.44(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Lease Obtained. . . . . . . . . . : Saturday, April 4, 2026 7:07:11 AM
Lease Expires . . . . . . . . . . : Saturday, April 4, 2026 5:07:10 PM
Default Gateway . . . . . . . . . : fe80::250:56ff:fe94:c01e%5
10.129.0.1
DHCP Server . . . . . . . . . . . : 10.10.10.2
DHCPv6 IAID . . . . . . . . . . . : 385896534
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-31-62-D3-65-00-50-56-94-60-CA
DNS Servers . . . . . . . . . . . : 1.1.1.1
═══════════════════════════════════════════════Cmd Acl Abuse.Txt📄
bloodyAD get writable distinguishedName: CN=TPM Devices,DC=retro,DC=vl permission: CREATE_CHILD distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=retro,DC=vl permission: WRITE distinguishedName: CN=banking,CN=Computers,DC=retro,DC=vl permission: CREATE_CHILD; WRITE
Cmd Adcs.Txt📄
[*] Requesting certificate via RPC [*] Request ID is 88 [*] Successfully requested certificate [*] Got certificate with UPN 'administrator@retro.vl' [*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500' [*] Saving certificate and private key to 'admin.pfx' [*] Wrote certificate and private key to 'admin.pfx' [*] Requesting certificate via RPC [*] Request ID is 89 [*] Successfully requested certificate [*] Got certificate with UPN 'administrator@retro.vl' [*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500' [*] Saving certificate and private key to 'admin.pfx' File 'admin.pfx' already exists. Overwrite? (y/n - saying no will save with a unique filename): [*] Wrote certificate and private key to 'admin.pfx'
Cmd Dcsync.Txt📄
Administrator:500:aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: krbtgt:502:aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650::: retro.vl\trainee:1104:aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874::: retro.vl\jburley:1107:aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c::: retro.vl\tblack:1109:aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919::: DC$:1000:aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3::: BANKING$:1106:aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28:::
Cmd Delegation.Txt📄
banking
Cmd Laps.Txt📄
Getting LAPS Passwords No result found with attribute ms-MCS-AdmPwd or msLAPS-Password !
Cmd Rbcd.Txt📄
bloodyAD set rbcd banking
Cmd Services.Txt📄
[*] Requesting shares on 10.129.234.44..... [-] share 'ADMIN$' is not writable. [-] share 'C$' is not writable. [-] share 'NETLOGON' is not writable. [-] share 'Notes' is not writable. [-] share 'SYSVOL' is not writable. [-] share 'Trainees' is not writable.
Cmd Ticket Reuse.Txt📄
Ticket cache: FILE:administrator.ccache Default principal: administrator@RETRO.VL Valid starting Expires Service principal 05/04/26 02:10:32 05/04/26 12:10:32 krbtgt/RETRO.VL@RETRO.VL renew until 06/04/26 02:10:32 session setup failed: NT_STATUS_INVALID_PARAMETER
Jburley📄
═══════════════════════════════════════════════
DOMAINATOR — Shell Evidence
User: jburley
Target: 10.129.234.44
Domain: retro.vl
Method: PSEXEC (NTLM)
Hash: 25c3464d4e99d340122f3a360bbd7c6c
═══════════════════════════════════════════════
whoami
nt authority\system
DC
Windows IP Configuration
Host Name . . . . . . . . . . . . : DC
Primary Dns Suffix . . . . . . . : retro.vl
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : retro.vl
.htb
Ethernet adapter Ethernet0 2:
Connection-specific DNS Suffix . : .htb
Description . . . . . . . . . . . : vmxnet3 Ethernet Adapter
Physical Address. . . . . . . . . : 00-50-56-94-60-CA
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : dead:beef::d54d:eae:e4a3:f5e4(Preferred)
Link-local IPv6 Address . . . . . : fe80::823f:49f5:4782:4191%5(Preferred)
IPv4 Address. . . . . . . . . . . : 10.129.234.44(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Lease Obtained. . . . . . . . . . : Saturday, April 4, 2026 7:07:12 AM
Lease Expires . . . . . . . . . . : Saturday, April 4, 2026 5:07:11 PM
Default Gateway . . . . . . . . . : fe80::250:56ff:fe94:c01e%5
10.129.0.1
DHCP Server . . . . . . . . . . . : 10.10.10.2
DHCPv6 IAID . . . . . . . . . . . : 385896534
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-31-62-D3-65-00-50-56-94-60-CA
DNS Servers . . . . . . . . . . . : 1.1.1.1
8.8.8.8
NetBIOS over Tcpip. . . . . . . . : Enabled
═══════════════════════════════════════════════// Active Directory attack graph
Domain Graph
BloodHound-style AD relationship map — all users, machines, groups, and privilege paths discovered during this engagement. Hover nodes to inspect edges. Double-click to pin. Scroll to zoom.
Loading graph data...
Legend
Owned / DA Member
High-Priv Group
Domain
DC
User / Computer
Group
Service Acct
Edges
Privilege
ACL
DCSync
LAPS / gMSA
MemberOf
Pre-Built Queries
BloodHound-style analysis
Find all Domain Admins
Principals with MemberOf edge to Domain Admins group
Administrator
administrator OWNED
jburley OWNED
Shortest Paths to Domain Admins from Owned Principals
BFS traversal from each owned node to Domain Admins — shows the minimum attack chain
krbtgt --[MemberOf]--> Domain Users --[MemberOf]--> administrator --[MemberOf]--> Domain Admins
banking$ --[ADCS ESC1]--> administrator --[MemberOf]--> Domain Admins
High Value Targets
Nodes with most inbound abusable edges (GenericAll, GenericWrite, DCSync, AllowedToAct, etc.)
administrator (1 edges)
banking$ (1 edges)
RETRO.VL (1 edges)
Domain Admins (1 edges)
Map All Abusable Relationships
All privilege escalation, ACL abuse, DCSync, and delegation edges in the graph
[PRIVILEGE] banking$ --[ADCS ESC1]--> administrator
[ACL] administrator --[GenericAll]--> banking$
[DELEGATION] administrator --[AllowedToAct]--> banking
[DCSYNC] administrator --[DCSync]--> RETRO.VL
[PRIVILEGE] administrator --[HasPrivilege]--> Domain Admins
Find Principals with DCSync Rights
Nodes with DCSync/AllExtendedRights edges to the domain
administrator OWNED
Kerberoastable Users
Users with servicePrincipalName set (SPN-based attack surface)
No Kerberoastable users identified
Graph Statistics
Nodes: 29 | Edges: 30 | Owned users: 6 | Owned machines: 3
// Cross-domain relationships
Domain Trusts
Trust relationships between domains — lateral movement opportunities
OS Distribution
// High-value targets
Privileged Accounts
Domain Admins, service accounts, and accounts with special privileges
8
ACCOUNTS
1
DOMAIN ADMINS
8
COMPROMISED
2
MACHINES
⚠ krbtgt hash extracted — Golden Ticket attacks possible. Rotate krbtgt password TWICE immediately.
👥 Group Memberships (5 users in security-relevant groups)
AdminCount=1 Accounts (3)
Administratorkrbtgtjburley
Password Age Per Account