Responder to NORTH domain controller
north.sevenkingdoms.localA poisoned response became a cracked password, which carried Domain Admins reach, which became the NORTH directory itself.
- Network capturewinterfellresponder lane
- LLMNR / NBT-NS poisoning
- Hash capturednorth\robb.starkNetNTLMv2
- Offline cracking
- Credential crackedrobb.starksexywolfy
- Validate SMB · WMI · WinRM · RDP
- Privileged on DCwinterfellDomain Admins owner
- NTDS.dit extraction
- Directory dumpednorth\AdministratorNTLM recoveredDomain Admin
Network capture → domain-controller privileged access → full NORTH credential extraction.