Started from the assumed-breach credentials.
Attack Chain:
→ "ESC13"
→ "WinRM Foothold on DC1"
→ "Hyper-V Pivot"
→ "Cross-Forest / Cross-Realm Kerberos"
→ "RID Enumeration"
→ "gMSA Managers Ownership"
→ "Foreign SID Injection"
→ "Read Pong_gMSA$ Password"
→ "JEA → XXE File Read"
→ "RBCD → MSSQL"
→ "GodPotato"
→ "Local Admin on DC2"
→ "DCSync → R.Martinelli"
→ "CA Managers"
→ "ESC4 → ESC1"
→ "PKINIT as Administrator"
→ Domain Admin
ESC13 provided the initial WinRM foothold. A Hyper-V pivot exposed the second forest and enabled cross-realm Kerberos.
Abusing gMSA Managers and Foreign SID Injection allowed access to the "Pong_gMSA$" password, leading to JEA abuse and an XXE file read.
From there, RBCD against MSSQL → GodPotato resulted in local admin on DC2. DCSync then compromised "R.Martinelli", providing access to CA Managers.
Finally, ESC4 → ESC1 → PKINIT yielded an Administrator certificate and Domain Admin.
One hell of an AD chain. 🏴☠️
#AD #HTB
