← Return to All Security Writeups
HackTheBox MEDIUM • 12 min read • October 1, 2026 • 7 views • 0 likes

Forest (HackTheBox): Active Directory Kerberoasting & BloodHound Privilege Escalation

#Active Directory #BloodHound #Kerberos #AS-REP Roasting #Pass-the-Hash
Forest (HackTheBox): Active Directory Kerberoasting & BloodHound Privilege Escalation
Executive Synopsis

Comprehensive intrusion walkthrough against a Windows Active Directory domain controller. Covers roasting pre-authentication disabled accounts (AS-REP Roasting), BloodHound shortest path ingestion, and Domain Admin takeover via WriteDacl abuse on Exchange Windows Permissions.

Executive Overview



Forest is a Windows Active Directory machine demonstrating severe misconfigurations in Kerberos pre-authentication policies and Active Directory Access Control Lists (ACLs). This writeup details the end-to-end compromise: from initial reconnaissance to Domain Admin takeover.

---

Phase 1: Port Reconnaissance & Service Fingerprinting



Initial full TCP port scan executed with Nmap revealed a standard enterprise Active Directory Domain Controller topology:

# Nmap Initial Reconnaissance Command
nmap -sC -sV -p- -oN nmap_forest.txt 10.10.10.161


**Identified Attack Surface:** - **Port 88 (Kerberos):** Active Directory Kerberos service - **Port 135 (RPC):** Windows Remote Procedure Call endpoint mapper - **Port 389 / 636 (LDAP/LDAPS):** Active Directory directory services - **Port 445 (SMB):** Microsoft-DS service - **Port 5985 (WinRM):** Windows Remote Management

---

Phase 2: AS-REP Roasting (No Pre-Authentication)



We utilized Impacket's GetNPUsers.py against a harvest of potential domain user accounts to identify any principals without Do not require Kerberos preauthentication enforced.

# AS-REP Roasting Enumeration
python3 GetNPUsers.py htb.local/ -usersfile users.txt -format hashcat -no-pass -dc-ip 10.10.10.161


Target user **sebastien** returned a valid Kerberos AS-REP hash ($krb5asrep$23$...). We cracked this hash using Hashcat mode 18200 against rockyou.txt in under 3 minutes.

---

Phase 3: BloodHound Ingestion & ACL Abuse Path



After obtaining valid credentials, we ingested the domain structure using SharpHound and visualized the attack path in BloodHound.

# Remote SharpHound Ingest via Python
bloodhound-python -u 'sebastien' -p 'cracked_pass' -d htb.local -ns 10.10.10.161 -c All


**Shortest Path to Domain Admin:** 1. sebastien is a member of Service Accounts. 2. Service Accounts has generic membership in Exchange Windows Permissions. 3. Exchange Windows Permissions possesses WriteDacl rights over the root Domain Object (DC=htb,DC=local).

---

Phase 4: DCSync Attack & Domain Dominance



By abusing the WriteDacl privilege, we granted our user account DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights on the domain root, enabling a remote DCSync extraction of the Administrator NTLM hash:

# DCSync Attack with Impacket
python3 secretsdump.py htb.local/sebastien:'cracked_pass'@10.10.10.161 -just-dc-user Administrator


With the Administrator NTLM hash in hand, we gained a high-integrity SYSTEM shell via WinRM using Evil-WinRM Pass-the-Hash.

---





Mitigation & Hardening Blueprint

1. **Enforce Pre-Authentication:** Audit all AD user accounts to ensure DONT_REQ_PREAUTH flag is unset. 2. **Review Delegated ACLs:** Restrict WriteDacl permissions on critical domain containers and adhere to Tiered Administration architecture.
Did this research assist your operations?

React with a like to endorse this technical walk-through and help fellow security researchers.

Authored By
Omar Adel Mahmoud
Penetration Tester & Security Researcher