Voleur

Overview Voleur is a medium-difficulty Windows machine built around an Active Directory environment with NTLM authentication fully disabled. The challenge begins as an assumed breach, with low-privileged credentials for ryan.naylor provided as the starting point. The full attack chain covers: Kerberos setup and SMB enumeration leading to a password-protected Excel file whose cracked contents expose service account credentials; BloodHound-driven discovery of a WriteSPN misconfiguration enabling targeted Kerberoasting against svc_winrm; Active Directory Recycle Bin abuse to restore a deleted user; offline DPAPI credential decryption to recover a higher-privileged account; and finally, pivoting through a Windows Subsystem for Linux instance to extract backup copies of ntds.dit, SYSTEM, and SECURITY - yielding the Administrator NT hash and full domain compromise. ...

Hack The BoxVoleurWindowsMedium
Released July 5, 2025 · 12 min