xsspresso
xsspresso
Tags/ BloodHound

BloodHound

5 writeups tagged with BloodHound

ADEasyWindows

HTB — Puppy

AD enumeration with BloodHound reveals a password reset path. HR share credential reuse and GenericWrite abuse to reach Domain Admin.

#AD#BloodHound#GenericWrite
May 21, 2025HackTheBox
ADMediumWindows

HTB — TheFrizz

Active Directory machine exploiting misconfigured LAPS and ACL abuse chain to escalate from low-privileged user to Domain Admin.

#AD#LAPS#ACL Abuse
Mar 18, 2025HackTheBox
ADHardWindows

HTB — Blackfield

ASREPRoasting yields crackable hash. ForceChangePassword on account via BloodHound. Volatility lsass dump reveals backup operator for DCSync.

#AD#ASREPRoasting#BloodHound
Jan 23, 2025HackTheBox
ADEasyWindows

HTB — Support

Custom .NET info collector binary contains obfuscated LDAP password. GenericAll on DC via Resource-Based Constrained Delegation for Domain Admin.

#AD#RBCD#BloodHound
Jan 23, 2025HackTheBox
ADMediumWindows

HTB — Administrator

FTP credentials from initial account. Targeted Kerberoasting via BloodHound paths, GenericWrite abuse, DCSync for Domain Admin hash.

#AD#Kerberoasting#BloodHound
Jan 8, 2025HackTheBox