88/tcp open kerberos-sec Microsoft Windows Kerberos
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: htb.local)
445/tcp open microsoft-ds Windows Server 2016 Standard 14393
464/tcp open kpasswd5
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
3268/tcp open ldap Microsoft Windows Active Directory LDAP
3269/tcp open tcpwrapped
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (WinRM)
9389/tcp open mc-nmf .NET Message Framing
Key Observation: This is a Windows Server 2016 Domain Controller (hostname: FOREST, domain: htb.local). WinRM on port 5985 is open — this will be our foothold and lateral movement channel.
::RPC Username Enumeration
Since this is a Domain Controller, we can enumerate domain users anonymously via RPC:
Target Identified:svc-alfresco is a service account — prime candidate for Kerberos attacks. Also note the Exchange-related infrastructure hints (Exchange Windows Permissions groups exist in the domain).
_
Initial Access — AS-REP Roasting
::AS-REP Roast Attack
svc-alfresco has Kerberos pre-authentication disabled (UF_DONT_REQUIRE_PREAUTH). This means anyone can request an AS-REP for this account and crack the encrypted timestamp offline:
••••••••••••••••••••••••••••••••[ Click to reveal flag ]
_
Vulnerability Analysis with Pharaohound
This is where we pivot from manual enumeration to automated AD attack path analysis.
Why pharaohound over BloodHound?pharaohound eliminates the Neo4j database + BloodHound GUI overhead. It has its own LDAP collector, streams JSON files with parallel workers, and generates copy-paste-ready exploitation commands — no graph queries, no Neo4j OOM crashes, no manual path hunting.
[!] ms-Mcs-AdmPwd unsupported — retrying (no LAPS)
[✓] Computers: 2 objects (0.2s)
[✓] Gpos: 2 objects
[✓] Ous: 15 objects
[✓] Containers: 119 objects
[✓] Collection complete in1.8s
Total objects: 242
SID cache: 128 entries
pharaohound handled the legacy DC schema automatically. The retry mechanism dropped unsupported LAPS/msDS attributes and continued — 242 objects collected in under 2 seconds.
::Analysis
~ / bash
asbawy@kali:~$ pharaohound pha-collect/ -o pharaohound-report/ --format both --all --no-color
Key findings from the 30 analyzers:
~ / code
☥ R I S K A S S E S S M E N T
RiskLevel: HIGH — Multiple critical paths to DomainAdmin
▲ Critical │ 3
◆ High │ 4
● Medium │ 2
::Attack Path Identification
pharaohound distilled the analysis into 3 prioritized attack paths:
pharaohound correctly flagged Exchange Windows Permissions as an infrastructure takeover primitive and Exchange Trusted Subsystem as a WriteDacl carrier. This directed our attention to the exact ACL chain needed.
_
Exploitation: ACL Abuse Chain
::Step 1: Verify Nested Group Memberships
~ / powershell
whoami /groups | findstr /i "account"
~ / code
BUILTIN\Account Operators Alias S-1-5-32-548
HTB\Privileged IT Accounts Group S-1-5-21-...-1149
HTB\Service Accounts Group S-1-5-21-...-1148
svc-alfresco is nested into Account Operators via Service Accounts → Privileged IT Accounts.
::Step 2: Check Exchange Windows Permissions Rights
Using PowerView to verify that Exchange Windows Permissions has WriteDacl + DeleteTree on the domain:
Red Team Consultant · Penetration Tester · Bug Bounty Hunter
Offensive security professional with 250+ vulnerabilities reported across 50+ organizations including Atlassian, Vimeo, and AT&T. Sharing research, tools, and field notes.