Uploaded June 2025 | Updated September 2026, 3 weeks ago
00:00 - Introduction
01:00 - Start of nmap
03:30 - Discovering splunk is version 9.2.1 from port 8089 and searching CVE Databases to find CVE-2024-36991
06:30 - Looking at how the File Disclosure works in CVE-2024-36991
09:50 - Extracting Splunk Secrets to get a username and password
15:00 - The user is denied the ability to list users in Active Directory, using RID Brute to get a user list
15:45 - Alternative way to bypass user list ACL by using AddComputer to add a computer which will let us query a list of users and run RustHound with Kerberos
23:50 - Examining what our users can do in Bloodhound
26:20 - Performing a password spray
28:30 - Listing GMSA Accounts with Get-ADServiceAccount, then using PowerSploit's Find-InterestingDomainACL
35:00 - Showing BloodyAD's Get Writable option then performing Write Owner, Add GenericAll, Adding ourself to group and using Certipy to get Shadow Credentials
44:00 - Going over the Splunk Backup, which contains the Admin Password for Splunk, using a grep regular expression to find password hashes
48:30 - Adding a Malicious App to splunk to send us a reverse shell
52:00 - Using GodPotato to exploit the SeImpersonate Privilege and getting administrator
00:00 - Introduction
01:00 - Start of nmap
03:30 - Discovering splunk is version 9.2.1 from port 8089 and searching CVE Databases to find CVE-2024-36991
06:30 - Looking at how the File Disclosure works in CVE-2024-36991
09:50 - Extracting Splunk Secrets to get a username and password
15:00 - The user is denied the ability to list users in Active Directory, using RID Brute to get a user list
15:45 - Alternative way to bypass user list ACL by using AddComputer to add a computer which will let us query a list of users and run RustHound with Kerberos
23:50 - Examining what our users can do in Bloodhound
26:20 - Performing a password spray
28:30 - Listing GMSA Accounts with Get-ADServiceAccount, then using PowerSploit's Find-InterestingDomainACL
35:00 - Showing BloodyAD's Get Writable option then performing Write Owner, Add GenericAll, Adding ourself to group and using Certipy to get Shadow Credentials
44:00 - Going over the Splunk Backup, which contains the Admin Password for Splunk, using a grep regular expression to find password hashes
48:30 - Adding a Malicious App to splunk to send us a reverse shell
52:00 - Using GodPotato to exploit the SeImpersonate Privilege and getting administrator










