This investigation is currently active on HackTheBox, thus is required to be password protected. You will need to wait until the investigation is retired for the full solution.

Conclusion

This box felt a lot more difficult than medium to me. In fact, this isn't even my first draft. I first attempted this box a week ago and had 300 lines of notes/output and never made it out of the credentials we were given.

This one took several hours to get on the box for the user flag. It required compromising multiple accounts. It required chaining a relatively recent vulnerability, a custom shell, and a novel tool to extract hashes to priv-esc.

I learned a lot more about Active Directory, and some new tools. Unfortunately, I got the admin flag a few hours after the window closed, so missed the season points, but still got some great experience.

#Pwned