Vigilant (Chain)
This is not a writeup, just my notes about the machine.

Credentials
Username
Password
Method
Scope
Information Gathering
Service enumeration
vigilant.vl
DNS
SMB (enum4linux-ng)

10.10.145.214
HTTP:80

Compromise SRV
Initial Foothold on SRV
Discovering a sensitive files on SMB
Discovering a domain user credentials in the ADAudit.dll

Decrypting pdf

Authenticating on Elastic

Discovering Pamela.clark is a superuser

Getting a reverse shell using

Creating a synthetics project
Creating a malicious monitor

Compromise SRV via Docker Breakout
Discovering docker.sock was exposed
Escaping to the container via Docker breakout using SOCK method

Compromising Domain Controller
Initial foothold on DC
Discovering cache credentials
Cracking hash discovered hash
Changing Gabriel.Steward's password
Compromise domain controller via ESC13
Discovering a vulnerable template to ESC13

Requirements

Abusing ESC13 using Certipy
Last updated