Cicada
Cicada HTB Detailed Walkthrough
Initial Enumeration with Nmap
sudo nmap -p- -sVC 10.129.190.226Enumerate SMB Shares (Anonymous)
nxc smb 10.129.190.226 --sharesAccess HR Share
RID Brute Force Users
Prepare User List and Password Spray
Enumerate More Users (with Valid Creds)
Access DEV Share with david.orelious
Access C$ and Retrieve user.txt
Spawn Shell with Evil-WinRM
Dump Local Hashes (SAM & SYSTEM)
Confirm Administrator Access
Exploit SeBackupPrivilege (VSS Shadow Copy)
Dump Domain Secrets
Administrator WinRM Access & Root Flag
Last updated