#
Kerberoasting
2 posts
TombWatcher — AD Privilege Chain to ESC15 (CVE-2024-49019) Domain Takeover
A five-hop BloodHound chain — WriteSPN → Kerberoast → gMSA dump → password resets → WinRM — leads to a deleted AD account holding ESC15 (CVE-2024-49019) rights on an ADCS template, ultimately yielding Domain Admin via PassTheCert over Schannel.
HTB Fluffy: From Low-Priv Creds to Domain Admin via CVE-2025-24071 & Shadow Credentials
Starting with low-privileged domain credentials, the attack chain exploits CVE-2025-24071 to leak an NTLM hash, cracks it, abuses GenericAll ACLs, uses Shadow Credentials to take over service accounts, and finally forges an Administrator certificate via ADCS for Domain Admin.