HTB - TombWatcher
TL;DR - An assumed-breach Active Directory box. Starting from henry, I chain ACLs through BloodHound: a targeted Kerberoast on alfred, abusing AddSelf + ReadGMSAPassword to read the ansible_dev$ gMSA password, then a trail of ForceChangePassword and WriteOwner abuses to pivot sam → john and land a WinRM shell. For root, john controls an OU holding a deleted cert_admin account, so I restore it from the AD Recycle Bin, reset its password, and abuse an ESC15 (CVE-2024-49019) vulnerable certificate template to impersonate the Administrator. ...