// CyberDefenders  ·  writeup

RoastToRoot

CyberDefenders WiresharkNotepad++JohnTheRipper7zip

Scenario

A Linux host inside the Wowza Enterprise environment was compromised and used as a pivot point into the Windows domain. The attacker reached the domain controller, deployed ransomware across the infrastructure, and wiped all recoverable backups. Network traffic captured on the first day of intrusion — specifically traffic between the Linux pivot and the DC — was preserved for analysis. The goal is to reconstruct the full attack chain from initial reconnaissance through to data exfiltration and cleanup.

The sole artefact is domainmess_evidence.pcapng.


Methodology

Orientation — Protocol Hierarchy and Conversation Map

Opening the PCAP in Wireshark, Statistics → Protocol Hierarchy immediately tells the story. SMB2 dominates at 35% of bytes, LDAP sits at 24% (261 packets — far too many for normal traffic), Kerberos is present, and there’s meaningful HTTP component. The conversation map pins two IPs as the primary actors:

The DNS filter confirms the target domain immediately — Kerberos AS-REQ packets contain the realm field, and LDAP baseObject queries show DC=wowza,DC=local.

Reconnaissance — Anonymous and Guest SMB Authentication

Before any credential-based attack, the attacker probed the DC using null sessions and guest authentication to enumerate shares and test connectivity. Filtering smb2 && ip.src == 192.168.189.172 and sorting by time, the earliest activity is a Negotiate Protocol Request at packet 79, followed by the first NTLMSSP_AUTH at packet 102 with User: \ — a blank username indicating a null session.

Expanding the frame details on packet 102 confirms the UTC arrival time of 2025-11-25 10:53:27.

Credential Access — AS-REP Roasting

AS-REP Roasting targets accounts with Kerberos pre-authentication disabled. When pre-auth is off, the KDC returns an AS-REP containing an encrypted blob derived from the account’s password with no authentication required to request it. An attacker with a username list can request AS-REPs for all of them and attempt offline cracking against any that succeed.

Filtering kerberos.msg_type == 10 || kerberos.msg_type == 11 shows a spray of AS-REQs followed by only three AS-REP responses — most accounts returned KRB_ERROR because pre-auth was enabled. The three accounts with pre-auth disabled are visible in the cname field of the AS-REP packets: hthomas, owright, and cgarcia.

To crack the hashes, tshark extracts the cipher values directly from the PCAP:

tshark -r domainmess_evidence.pcapng -Y "kerberos.msg_type == 11" -T fields -e kerberos.CNameString -e kerberos.cipher > asrep_raw.txt

The tshark kerberos.cipher field outputs two comma-separated blobs per packet — the ticket cipher and the enc-part cipher. The enc-part (post-comma portion) is what hashcat needs for mode 18200. The john/hashcat AS-REP format splits the cipher at byte 16: the first 32 hex chars become the checksum after the colon, the remainder is the body after the $.

After testing all three accounts with the pre-comma cipher first and then the post-comma portion, cgarcia’s post-comma hash cracks:

hashcat -m 18200 hash2.txt /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt --force

cgarcia : whatisit

Share Enumeration and Write Testing

With cgarcia’s credentials in hand, the attacker enumerated all file shares on the DC and tested write access by creating a randomly named folder and text file on each share — standard NetExec --shares module behaviour.

The share enumeration is visible in the SMB2 Create Request stream, but the write-test filenames are only visible after decrypting the SMB3 session. SMB3 encrypts traffic by default, but Wireshark can decrypt it given the user’s plaintext password. Adding cgarcia’s credentials under Edit → Preferences → Protocols → NTLMSSP unlocks the session and reveals the randomly generated artefacts repeated across each share.

The folder created for write testing is gufEnJlCMD and the accompanying text file is AyUXwZSYKV.txt — both randomly generated by NetExec. After the automated sweep, the attacker manually connected to one specific share. Filtering SMB2 Tree Connect requests (smb2.cmd == 3 && ip.src == 192.168.189.172) shows the attacker navigating to \\192.168.189.191\Finance — the only share accessed interactively beyond the automated enumeration.

Discovery — BloodHound LDAP Enumeration

The attacker ran BloodHound to map the domain’s trust relationships, group memberships, and attack paths. BloodHound’s collection phase begins with an LDAP Bind Request and ends with an LDAP Unbind Request. Filtering ldap && ip.src == 192.168.189.172 shows the cgarcia simple bind at packet 4794 followed by a large volume of SASL GSS-API encrypted search results — consistent with BloodHound’s characteristic bulk LDAP queries.

During this same LDAP session, the attacker recovered credentials stored in a user’s description attribute — a misconfiguration that exposes plaintext credentials to any authenticated domain user. Searching for Temp within LDAP traffic and expanding the PartialAttributeList item description on the CN=temp object reveals the stored credential:

tempadmin : Admin@9999999!

The attacker immediately attempted to authenticate to the DC over SMB using these credentials. The account existed but had been disabled — filtering for the tempadmin SMB session and following the TCP stream shows the DC returning STATUS_ACCOUNT_DISABLED at packet 4778.

The BloodHound collection concludes at the LDAP Unbind Request, identifiable with ldap.protocolOp == 2 — packet 5175.

Credential Access — Kerberoasting

With a full BloodHound map of the domain, the attacker identified service accounts with SPNs registered and performed Kerberoasting — requesting TGS tickets for those accounts and extracting the encrypted portions for offline cracking. Filtering kerberos.msg_type == 13 shows five TGS-REP packets returned, one for each targeted service account.

tshark -r domainmess_evidence.pcapng -Y "kerberos.msg_type == 13" -T fields -e kerberos.SNameString -e kerberos.cipher > tgs_raw.txt

The five targeted service accounts are svc_backup, svc_dhcp, svc_defender, svc_sharepoint, and svc_dpm. Using the same pre-comma cipher extraction approach as AS-REP Roasting, the svc_backup TGS hash cracks with hashcat mode 13100:

hashcat -m 13100 tgs.txt /usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt --force

svc_backup : 1180200022358

Privilege Escalation — Account Re-enablement via LDAP Modify

With svc_backup’s credentials, the attacker had sufficient AD permissions to modify user objects. The LDAP bind for svc_backup is visible at packet 6765, followed by encrypted SASL payloads containing the modify operation that re-enabled the tempadmin account by flipping its userAccountControl attribute. The bind success at packet 6766 timestamps the modification:

2025-11-25 11:03

Collection and Exfiltration — rclone via SFTP

With tempadmin re-enabled and full DC access established, the attacker staged an exfiltration toolkit in the IT share. The SMB2 Create Request at packet 7083 shows exfil.zip being written to \\192.168.189.191\IT. Extracting the zip via File → Export Objects → SMB and hashing it confirms the SHA256.

The archive contains three files: rclone.exe, exfil.ps1, and include.txt. Opening include.txt reveals the 14 file extensions rclone was configured to target during collection: .doc, .docx, .pdf, .htm, .html, .xls, .xlsx, .jpg, .jpeg, .png, .pst, .msg, .edb, .mbox.

The exfil.ps1 script configures rclone with an SFTP remote pointing back to the attacker’s Linux pivot at 192.168.189.172 on port 2222, authenticating as johnattan:johnattan, then archives matching files from C:\Shares and transfers the zip.

Execution — smbexec Remote Shell

To execute commands on the DC interactively, the attacker used Impacket’s smbexec — a tool that obtains a semi-interactive shell by creating a Windows service that executes commands via %COMSPEC%, writing output to a UNC path (\\%COMPUTERNAME%\C$\__output). Each command execution follows the same pattern: a randomly named batch file is written to %SYSTEMROOT%, executed, then immediately deleted.

Inspecting the DCE/RPC Service Control traffic via Wireshark’s Find function reveals the full command chain. The batch file created specifically during the exfil.ps1 execution:

%COMSPEC% /Q /c echo powershell -ep bypass -File C:\Shares\rclone-v1.71.2-windows-amd64\exfil.ps1 
^> \\%COMPUTERNAME%\C$\__output 2^>^&1 > %SYSTEMROOT%\RKhBcFrQ.bat & 
%COMSPEC% /Q /c %SYSTEMROOT%\RKhBcFrQ.bat & del %SYSTEMROOT%\RKhBcFrQ.bat

Defence Evasion — Cleanup

The final smbexec command executes clean.ps1, which removes all toolkit artefacts from disk and clears Windows event logs to hinder forensic analysis:

wevtutil cl "System"
wevtutil cl "Security"
wevtutil cl "Application"

The clean.ps1 execution batch file timestamp gives the final command time of 2025-11-25 11:10.


Attack Summary

PhaseAction
ReconnaissanceNull session and guest SMB auth against DC from 192.168.189.172 at 10:53 UTC
DiscoveryNetExec share enumeration with random write-test file/folder across all shares
Credential AccessAS-REP Roasting against hthomas, owright, cgarcia — cgarcia cracks to whatisit
DiscoveryBloodHound LDAP collection as cgarcia; tempadmin credentials found in description field
Lateral Movement AttemptTempadmin SMB auth fails — account disabled (STATUS_ACCOUNT_DISABLED)
Credential AccessKerberoasting 5 service accounts — svc_backup cracks to 1180200022358
Privilege Escalationsvc_backup re-enables tempadmin via LDAP modify at 11:03 UTC
Collectionrclone toolkit staged to IT share; 14-extension file collection configured
Exfiltrationrclone SFTP transfer to 192.168.189.172 as johnattan:johnattan
Executionsmbexec provides semi-interactive shell on DC for remote command execution
Defence Evasionclean.ps1 removes toolkit and rclone config; clears System/Security/Application logs at 11:10 UTC

IOCs

TypeValue
IP (Attacker/Pivot)192.168.189.172
IP (Domain Controller)192.168.189.191
Domainwowza.local
Credential (AS-REP cracked)cgarcia:whatisit
Credential (exposed in LDAP description)tempadmin:Admin@9999999!
Credential (Kerberoast cracked)svc_backup:1180200022358
Credential (SFTP exfil)johnattan:johnattan
Fileexfil.zip
Filerclone.exe
Fileexfil.ps1
Fileinclude.txt
Fileclean.ps1
SHA256 (exfil.zip)C9DD39E0E0C11A9F029DD31E9E47614AF4650D1853B55DD3F3D1C504F22B5F38
Share (staging)\192.168.189.191\IT
Share (manual access)\192.168.189.191\Finance
Write-test fileAyUXwZSYKV.txt
smbexec batch fileRKhBcFrQ.bat

MITRE ATT&CK

TechniqueIDDescription
Network Service DiscoveryT1046NetExec share enumeration across DC shares
AS-REP RoastingT1558.004Three accounts targeted; cgarcia hash cracked offline with rockyou
KerberoastingT1558.003Five SPN accounts targeted; svc_backup cracked to numeric password
Valid Accounts: Domain AccountsT1078.002cgarcia, svc_backup, and tempadmin all used for progressive access
Domain Account DiscoveryT1087.002BloodHound LDAP collection mapping all domain objects and memberships
Domain Trust DiscoveryT1482BloodHound maps trust relationships and attack paths within wowza.local
Unsecured CredentialsT1552.001tempadmin credentials stored in plaintext in LDAP description field
Account ManipulationT1098svc_backup re-enables disabled tempadmin account via LDAP modify
Archive Collected DataT1560.001Files zipped via PowerShell Compress-Archive before SFTP transfer
Data from Network Shared DriveT1039rclone collects files from C:\Shares with 14-extension filter
Exfiltration Over Alternative ProtocolT1048.002rclone SFTP exfil to attacker-controlled Linux host on port 2222
Windows ServiceT1543.003smbexec creates a service per command execution for remote shell
Indicator Removal: Clear Windows Event LogsT1070.001System, Security, Application logs cleared via wevtutil in clean.ps1

Defender Takeaways

Disable Kerberos pre-authentication on all accounts and audit regularly. AS-REP Roasting only works against accounts with pre-authentication disabled — a setting with almost no legitimate use in modern environments. Three accounts in this environment had it enabled, handing the attacker offline-crackable hashes with zero prior authentication required. Running Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} quarterly and remediating any findings immediately would have closed this initial access vector entirely.

Never store credentials in LDAP description or info fields. Any authenticated domain user can read these attributes, and BloodHound’s collection phase harvests them automatically. The tempadmin account’s description field contained plaintext credentials that gave the attacker a direct path to domain admin once the account was re-enabled. Audit all user description fields with Get-ADUser -Filter * -Properties Description | Where {$_.Description -ne $null} and establish policy prohibiting credential storage in any user attribute.

Enforce strong unique passwords on all SPN-bearing service accounts — or eliminate the problem with gMSAs. The svc_backup password 1180200022358 cracked from rockyou.txt in under two seconds. Service accounts with SPNs are permanently exposed to Kerberoasting because any authenticated user can request their TGS tickets. Group Managed Service Accounts eliminate this risk entirely by rotating 240-character passwords automatically. At minimum, enforce 25+ character randomised passwords on all service accounts with SPNs registered.

Decrypt and inspect SMB3 at the network boundary. The write-test filenames, smbexec service creation, and batch file execution were all invisible in the raw PCAP until SMB3 session keys were added to Wireshark. In production, solutions like Microsoft Defender for Identity — which operates at the DC level and sees activity pre-encryption — are needed to detect these patterns. The smbexec service creation signature (random 8-char service name, %COMSPEC% /Q /c wrapper, immediate deletion) is a reliable detection rule for any NDR or EDR platform.

Alert on anomalous Kerberos TGS request volume. A single account requesting TGS tickets for five different service accounts within seconds is not normal user behaviour. Honey-SPN accounts — service accounts with SPNs registered but never legitimately used — generate a high-fidelity alert the moment any TGS request is observed. Any SIEM with Kerberos event visibility (Event ID 4769) can implement this detection with a single rule.


To begin the investigation, we need to identify the target Active Directory environment that was compromised during this intrusion. Determining the domain name is essential for scoping the incident and understanding the environment under attack. What is the domain that was attacked by the threat actor?
Click flag to reveal wowza.local
Before launching credential-based attacks, threat actors often probe the target environment using anonymous and guest authentication to test connectivity and identify accessible resources. Determining when this reconnaissance began is essential for establishing the attack timeline. When did the threat actor begin interacting with the domain using anonymous and guest authentication over SMB?
Click to reveal answer 2025-11-25 10:53
The threat actor used employee data stolen from the compromised Linux machine to perform an AS-REP Roast attack. According to the packet capture, how many usernames were targeted in total, and what are the targeted sAMAccountNames in order?
Click flag to reveal 3, hthomas, owright, cgarcia
After capturing the AS-REP hashes, the threat actor attempted to crack them offline to obtain valid domain credentials. Successfully cracking one of these hashes would provide the attacker with initial authenticated access to the Windows domain. What was the password for the user whose hash was successfully cracked? (Hint: use rockyou.txt)
Click to reveal answer whatisit
Using the credentials obtained from the AS-REP Roasting attack, the threat actor enumerated file shares on the domain controller and tested write access by creating file and folder with the random name to those shares. What was the name of the text file that was used in this process?
Click flag to reveal AyUXwZSYKV.txt
After enumerating all file shares, what is the name of the share that the threat actor manually accessed?
Click to reveal answer Finance
LDAP is commonly abused by attackers to collect domain information, including user objects and their attributes. Organizations sometimes make the critical mistake of storing credentials in user description fields, which are readable by any authenticated domain user. During the LDAP enumeration phase, the threat actor discovered a temporary administrator account with credentials exposed in a user attribute. What were the username and password of this account that were leaked to the threat actor?
Click flag to reveal tempadmin:Admin@9999999!
The threat actor attempted to use this credential to authenticate to the domain controller over SMB. What NTSTATUS response did the domain controller return?
Click to reveal answer status_account_disabled
BloodHound is a powerful Active Directory reconnaissance tool that uses LDAP queries to map trust relationships, permissions, and attack paths within a domain. The collection phase begins with an LDAP Bind Request and concludes with an LDAP Unbind Request, signaling the end of data gathering. Identifying this boundary packet helps determine when the threat actor completed their domain enumeration. At which packet number does the LDAP Unbind Request occur, indicating the completion of the BloodHound collection?
Click flag to reveal 5175
Kerberoasting is a post-exploitation technique where an attacker requests Kerberos service tickets (TGS) for accounts with Service Principal Names (SPNs). The encrypted portion of these tickets can be extracted and cracked offline to recover service account passwords, which often have elevated privileges. After completing their initial reconnaissance, the threat actor performed a Kerberoasting attack to escalate their privileges. How many service account hashes were the threat actor able to retrieve?
Click to reveal answer 5
Following the Kerberoasting attack, the threat actor attempted to crack the captured service ticket hashes offline. Service accounts often have weaker passwords than expected, making them vulnerable to dictionary attacks. Successfully cracking one of these hashes would provide the attacker with elevated privileges within the domain. What was the username of the service account whose hash was successfully cracked, and what password was recovered?
Click flag to reveal svc_backup:1180200022358
With elevated privileges obtained from the cracked service account, the threat actor now possessed the ability to modify Active Directory objects. The attacker leveraged these privileges to re-enable temporary administrator account found earlier. When did this account modification take place?
Click to reveal answer 2025-11-25 11:03
With administrative access to the domain controller, the threat actor began preparing for data exfiltration. Attackers typically stage files in accessible network shares before transferring them to external infrastructure. Identifying the staging location helps understand the scope of data targeted for theft. What is the name of the file share accessed by the threat actor to stage the files prior to exfiltration?
Click flag to reveal IT
What is the SHA-256 hash of the compressed file uploaded by the threat actor to this share?
Click to reveal answer C9DD39E0E0C11A9F029DD31E9E47614AF4650D1853B55DD3F3D1C504F22B5F38
Analysis of the uploaded archive reveals the data exfiltration toolkit deployed by the threat actor. Understanding the exfiltration software and its configuration helps determine what data was targeted for theft. The tool was configured with a list of file extensions to specifically target during the collection phase. What is the name of the software used by the threat actor to perform data exfiltration, and how many file extensions was it configured to target?
Click flag to reveal rclone, 14
Which protocol did the threat actor use for data exfiltration, and what username and password were used to authenticate?
Click to reveal answer SFTP, johnattan:johnattan
To facilitate data exfiltration, the threat actor used a well-known tool from the Impacket toolkit to obtain a semi-interactive shell on the domain controller. What is the name of this tool?
Click flag to reveal smbexec
When the threat actor executed commands using the tool discovered earlier, it generated a temporary batch file on the domain controller to run the command and then removed it. What was the name of this temporary file created during the exfiltration script execution?
Click to reveal answer RKhBcFrQ.bat
After the data exfiltration stage, the threat actor executed a cleanup script. According to the script, which Windows event logs were cleared? (List them in the order they appear in the script.)
Click flag to reveal System, Security, Application
To understand the full timeline of the attack, it is important to determine when the threat actor completed their activity on the compromised system. Based on the remote execution tool activity (Q17), when was the final command executed by the threat actor on the domain controller?
Click to reveal answer 2025-11-25 11:10