EscapeTwo is an easy Windows machine that demonstrates a full Active Directory domain compromise by chaining credential recovery, credential spraying, MSSQL and WinRM access, and the exploitation of a misconfigured ADCS deployment to obtain the Administrator hash.
# tag: Certipy
EscapeTwo
RetroComprehensive walk-through of the Retro machine, demonstrating a transition from guest SMB access to Domain Admin. The process involves credential harvesting from public shares, exploiting pre-created computer accounts via Kerberos TGT requests, and leveraging misconfigured AD CS templates (ESC2/ESC3) for identity impersonation.