root@jean:~#

SOC Analyst → Pentester. Breaking boxes, documenting the process.

45+ boxes rooted | eJPT | eCPPT | OSCP target: May 2026

HTB Active Writeup — Kerberoasting & GPP Passwords (2026)

My first AD box ever. Null session on SMB → GPP password in SYSVOL → Kerberoasting the Administrator → Domain Admin.

March 24, 2026 · 2 min

HTB Blackfield Writeup — LSASS Dump & VSS Shadow Copies (2026)

Hard AD box. AS-REP Roasting → BloodHound → ForceChangePassword → lsass.DMP → SeBackupPrivilege → VSS snapshot → NTDS.dit → Domain Admin.

March 24, 2026 · 4 min

HTB Forest Writeup — AS-REP Roasting, BloodHound & DCSync (2026)

Second AD box. AS-REP Roasting with no creds, BloodHound attack path through 5 nested groups, ACL abuse to DCSync.

March 24, 2026 · 3 min

HTB Monteverde Writeup — Azure AD Connect Exploit (2026)

Active Directory box — password spraying → Azure AD Connect credential extraction → Domain Admin.

March 24, 2026 · 2 min

HTB Querier Writeup — MSSQL Exploitation (2026)

SMB guest access → Excel macro with MSSQL creds → Responder hash steal via xp_dirtree → xp_cmdshell → reverse shell.

March 24, 2026 · 3 min

PG Algernon Writeup — SmarterMail Deserialization RCE (2026)

Proving Grounds box — anonymous FTP, SmarterMail on a weird port, .NET deserialization RCE straight to SYSTEM. No privesc needed.

March 24, 2026 · 4 min