Enumeration
| |
Port Scanning
| |
| |

Looking at the open ports (53, 88, …) this is clearly a Domain Controller.
SMB Shares
| |

We can read the non-default Replication share with null authentication.
Let’s read it with smbclient:
| |

Get all files:
| |

Look at the all files with tree ., we see that there is a Groups.xml file. It may contains cpassword:

Read it:
The credential belongs to svc_tgs.
Decrypt the cpassword
| |

Test it with netexec:

Kerberoasting
Observe the owned user is a service account, we can use it kerberoasting:
| |

Request the ticket:
| |

Get the hash into a file:
| |
Then crack it with hashcat:
| |

We got the Administrator credentials.
Connect with psexec:
| |

Key Takeaways
- Check SMB shares accessible via null session for GPP files like
Groups.xml; usegpp-decryptto crack cpassword values. - If the compromised account is a service account (has an SPN), attempt Kerberoasting to obtain hashes of more privileged accounts.
- Recognize Domain Controller indicators by open ports (53, 88, 389, 636); these ports directly define the AD attack surface.