HackTheBox | Search 🔎 (Windows | Hard) | Beginners Walkthrough

Опубликовано: 28 Март 2026
на канале: SecAura
566
24

Today we root the Search 🔎 (Windows | Hard) machine from HackTheBox! - Like and Subscribe :)

⏱️Timestamps/Steps:
➡️ 00:00 - Port scan
➡️ 01:20 - Web enum
➡️ 01:45 - Web app enum
➡️ 02:20 - Explanation of extracting user names for kerberos user name enum
➡️ 03:30 - Extracting usernames for use in kerberos brute forcing
➡️ 06:40 - Extracting username/password from image in web page
➡️ 09:00 - Dumping kerberos ticket via GetUserSPNs.py
➡️ 10:30 - Cracking hash with hashcat
➡️ 13:30 - Password spraying cracked hash with usernames
➡️ 16:00 - Forensics analysis of excel file, getting passwords
➡️ 21:00 - Password spraying leaked password
➡️ 23:00 - Dumping a certificate file from SMB and cracking it
➡️ 27:20 - Using certificate to authenticate to web app /staff
➡️ 28:00 - Getting remote windows web shell
➡️ 33:35 - Using sharphound
➡️ 42:00 - Using bloodhound
➡️ 46:00 - Pwning BIR-ADFS-GMSA$ user via ReadGMSAPassword access
➡️ 50:00 - Invoking commands as BIR-ADFS-GMSA$
➡️ 53:00 - Leveraging BIR-ADFS-GMSA$ creds, and writeOwner perms over tristan.davies to change their password
➡️ 56:00 - Getting root.txt :)
➡️ 56:20 - Outro

Wadcoms: https://wadcoms.github.io
For more Cyber security/hacking/pentesting beginner based content, check out the rest of my channel covering:
⭐️Web application security:
🔗Web Fundamentals for Cyber Security Series https://youtube.com/playlist?list=PLw...
🔗HackTheBox | Web/OSWE    • HackTheBox | Web/OSWE  
🔗OSWE "Build and Break it" Guide (Offensive Security Web Expert)    • OSWE "Build and Break it" Guide (Offensive...  
SQL injection, Server Side template Injection, XSS, remote code execution/Injection(RCE) XXE(XML Enternal Entity Injection) etc.

⭐️Linux Hacking + Priv esc -    • HackTheBox | Linux  
⭐️Windows Hacking + Priv esc-    • HackTheBox | Windows  
⭐️Active Directory Hacking -    • HackTheBox | ActiveDirectory  
⭐️GitHub: https://github.com/SecAuraYT/HackTheB...

⭐️Link to box:
🔗 https://app.hackthebox.com/machines/410