🖥️ Challenge / Machine Info

  • Platform: tryhackme
  • Name / Title: post-exploitation-basics
  • Difficulty: Hard
  • Target OS / Environment: AD
  • Key Vulnerability Focus: BloodHound / Golden tickets / Token impersonation

Post-Exploitation Notes

  • Mimikatz: Dump LSA credentials from memory.
  • Golden Ticket: Forged Ticket Granting Ticket (TGT) signed by the Krbtgt account hash.
  • Token Impersonation: Stealing and assuming another logged-in user’s token context.