TGViewer
Sec Note Sec Note @secnote · 2.89K subscribers
Post #349 1.36K
🔥 HTB PingPong — Insane | Pwned

Started from the assumed-breach credentials.

Attack Chain:
→ "ESC13"
→ "WinRM Foothold on DC1"
→ "Hyper-V Pivot"
→ "Cross-Forest / Cross-Realm Kerberos"
→ "RID Enumeration"
→ "gMSA Managers Ownership"
→ "Foreign SID Injection"
→ "Read Pong_gMSA$ Password"
→ "JEA → XXE File Read"
→ "RBCD → MSSQL"
→ "GodPotato"
→ "Local Admin on DC2"
→ "DCSync → R.Martinelli"
→ "CA Managers"
→ "ESC4 → ESC1"
→ "PKINIT as Administrator"
→ Domain Admin


ESC13 provided the initial WinRM foothold. A Hyper-V pivot exposed the second forest and enabled cross-realm Kerberos.

Abusing gMSA Managers and Foreign SID Injection allowed access to the "Pong_gMSA$" password, leading to JEA abuse and an XXE file read.

From there, RBCD against MSSQL → GodPotato resulted in local admin on DC2. DCSync then compromised "R.Martinelli", providing access to CA Managers.

Finally, ESC4 → ESC1 → PKINIT yielded an Administrator certificate and Domain Admin.

One hell of an AD chain. 🏴‍☠️

#AD #HTB
  • 🔥 12
  • 👾 3
  • 👍 2
More from @secnote
  1. Sep 27, 2026EDR Evasion: Process Injection Without WriteProcessMemory #EDR #maldev
  2. Sep 25, 2026سلام و درود لنگ ظهر جمعه تون بخیر فایل 4 دوره #SEC530 خدمت شما. واقعا طولانی شد 😅
  3. Sep 24, 2026Sec Note pinned a photo
  4. Sep 24, 2026My New Blog Post Evading Sysmon Dns Monitoring In 2026 | binary-win DNSevade : https://git…
  5. Sep 23, 2026Did Sysmon miss the DNS event?👀
  6. Sep 22, 2026fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →