
Part 10: Hacking DarkHaven (Full Network) - Hack Smarter Labs
Source: YouTube · Tyler Ramsbey - Hack Smarter · published Apr 20, 2026 · 25:29
This episode of the Dark Haven series focuses on pivoting from the compromised web server to extract credentials for the 'kwarren' domain account using NetExec, while detailing failed attempts to utilize Sliver and SharpHound for Active Directory enumeration.
Key Takeaways:
• The attacker targets a Notepad++ session running as NT Authority System on the web server to find hardcoded credentials 1:56
• Sliver's SA Notepad module fails due to poor documentation, prompting a switch to NetExec which successfully retrieves the credentials 3:15
• The extracted credentials for 'kwarren' are validated against the domain controller, confirming access and revealing GMSA group membership 6:45
• Attempts to run SharpHound via Sliver Armory fail due to Defender detection and technical bugs, forcing a return to manual enumeration 12:30
The session highlights the reliability of NetExec over Sliver for credential dumping and sets up the next phase of attacking the Certificate Authority server via GMSA privileges.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What is up everyone? Welcome back to another video. We are continuing our very long, but hopefully super helpful series on the Dark Haven range from the Hack Smarter platform. This is part 10. This has been a long series and we are just getting started. So, if this is the first video that you're watching, you're going to be a little bit lost. I would suggest starting with part one and working your way through the series and launching Dark Haven from Hack Smarter and hacking right alongside of me. All that being said, let me share my screen and let's go ahead and dive in together. So, as a quick reminder, we have compromised a few different machines. So, we have compromised the SQL server, we have compromised the share server, and we have compromised the web server. I just need to go in and…