Active Directory, LDAP, Kerberos, and internal network hacking writeups from global enterprise CTFs and ProLabs. Organized by year and event.


2025 Challenges

HTB Cyber Apocalypse 2025

HTB Cyber Apocalypse 2025

ESC-Relay

Hard

Category: Active Directory · Points: 480 · Solves: 34

Exploit AD CS ESC8 vulnerability. Coerce HTTP NTLM authentication from a domain controller using MS-RPRN Printer Bug, and relay it to the AD CS Web Enrollment endpoint to request a Domain Admin certificate.

AD CSESC8NTLM RelayingPrinter BugCoercion

DEF CON 2024 Quals

DEF CON 2024 Quals

Kerberoast-Showdown

Medium

Category: Active Directory · Points: 300 · Solves: 110

Read Active Directory SPNs without domain credentials by abusing unauthenticated LDAP queries, then execute Kerberoasting against target service accounts.

KerberoastingLDAP QuerySPNImpacket