HackTheBox - Tombwatcher @ippsec
HackTheBox - Tombwatcher  @ippsec
Uploaded October 2025 | Updated September 2026, 2 weeks ago
00:00 - Introduction
00:45 - Start of nmap
03:50 - Running RustHound with the credentials we were given
06:40 - Clicking outbound control a few times from Henry to see an obvious (but long) attack path
09:30 - Using BloodyAD to perform the Targeted Kerberoast attack
13:20 - Using BloodyAD to add ourself to a group then NetExec to reaed GMSA Passwords
15:50 - Using BloodyAD to change the password of a user and then use Certipy to create a Shadow Credential for the next user
19:30 - Looking at certificates in Bloodhound and Certipy to see one certificate has a SID under Enrollers
21:30 - Using powershell to show and restore deleted objects
25:15 - Running Certipy with Cert_Admin to see it is vulnerable to ESC15
32:55 - Performing ESC15 by generating a certificate with Certificate Request Agent property, which then lets us generate an administrator certificate to get root
35:20 - Beyond Root: Fixing the CA_MD_TOO_WEAK error by creating a new OpenSSL Config and not using UV to run certipy
HackTheBox - TombwatcherHackTheBox - RustyKeyHackTheBox - PrincipalHackTheBox - YummyHackTheBox - CodifyHackTheBox - GiveBackHackTheBox - GoferHackTheBox - CatHackTheBox - GreenhornHackTheBox - EraIntercepting Android App Traffic with BurpSuiteHackTheBox - AppSanity
IppSec |

HackTheBox - Tombwatcher

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER