#
Kerberos
3 posts
HTB Voleur: Medium Walkthrough – Kerberos-Only AD, Targeted Kerberoasting & Tombstone Revival to Domain Admin
A Kerberos-only domain controller forces every tool into Kerberos mode. An encrypted spreadsheet leaks service account passwords, a WriteSPN ACL enables targeted Kerberoasting, and AD's rarely-abused deleted-object restore feature resurrects a leaver account whose leftover DPAPI secrets cascade all the way to a WSL root shell holding a full NTDS.dit backup.
VulnCicada — ADCS ESC8 relay via PetitPotam coercion to Domain Admin
NFS share leaks a user password hidden in an image post-it note; NTLM is disabled forcing Kerberos-only auth; ESC8 web enrollment relay via PetitPotam coercion yields a DC certificate and full domain compromise.
Checkpoint — BadSuccessor CVE-2025-29810 + VM Memory Forensics
From a malicious VS Code extension to Domain Admin via a fresh 2025 AD privilege escalation — BadSuccessor (CVE-2025-29810) chained with VM memory forensics.