pentestPromedium
Наследие (Legacy)
hackerlab
Task: Windows AD DC with FTP anonymous access, password spray, lateral movement, and privilege escalation. Solution: FTP anonymous → ZIP comment password → kerbrute spray → WinRM → PS history creds → RunasCs lateral movement → winPEAS AutoLogon registry creds → Administrator SMB access.
$ ls tags/ techniques/
lateral_movementprivilege_escalationwinrmactive_directorypowershell_historyftp_anonymouswindows_server_2022password_sprayautologon
ftp_anonymous_accesszip_comment_passwordkerbrute_password_spraywinrm_shellpowershell_history_credential_harvestingrunascs_lateral_movementwinpeas_enumerationautologon_credential_extractionsmb_admin_share_access
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [infra][Pro]Потерянный (Lost)— hackerlab
- [infra][Pro]Революция (Revolution)— hackerlab
- [infra][Pro]Пространство (Expanse)— hackerlab
- [infra][Pro]Грань (Fringe/Edge)— hackerlab
- [infra][Pro]Основа (Foundation)— hackerlab