Administrator HTB - Writeup
this was MUCH easier than i thought it was, just goes to show... bloodhound is really quite powerful!
you get the creds to the box instantly and can use winrm to access a shell as olivia, where you can then use sharphound and collect

here are all the users of the domain - we have olivia, who has GenericAll rights on michael

just change the password of michael:

michael's able to change benjamin's password


who can access a FTP file:

which contains a pwsafe file that can be cracked!


now we can access emily and get the user flag

to get to admin, we have to get to ethan first, who we can kerberoast


ethan is able to dcsync into admin:

so, just secrets-dump and grab the hash:

