FeaturedEasy WindowsHack The Box
HTB — Fluffy
November 27, 2025 15 min read
An easy Windows Active Directory box: capture NTLM hashes via CVE-2025-24071, run a shadow credentials attack with BloodHound path analysis, then abuse ADCS ESC16 to escalate to Domain Administrator.
Active Directory CVE-2025-24071 Shadow Credentials ADCS ESC16 BloodHound
Read full writeup