GS-035: BITSTREAM (P6) — bloodyAD + DCSync to Domain Admin (HackSmarter) | 2026-07-30

GS-035: BITSTREAM (P6) — bloodyAD + DCSync to Domain Admin (HackSmarter) | 2026-07-30

Source: YouTube · HaxrByte · published Jul 31, 2026 · 3:16:55

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The Bitstream machine was compromised by pivoting through a workstation via a Legalo VPN tunnel to run BloodHound, extracting Louisa's credentials from cookies, resetting James's password using Generic All permissions, and performing a DCSync attack with the SVC Backup service account credentials.

Key Takeaways:
• Initial foothold was gained on the SQL server via XML command shell, allowing OS command execution 02:45
• Legalo was used to create a VPN tunnel from the attacker machine to the target network, enabling seamless access to internal services like the Domain Controller 15:00
• BloodHound analysis revealed that user Louisa had "Generic All" permissions over user James 26:40
• Louisa's password was recovered from Chrome cookies using Cookie Monster, allowing login via RDP 30:30
• James's password was reset using BloodAD due to the Generic All permission, providing access to a file share 33:45
• A script on the share revealed the password for the SVC Backup service account 50:30
• The SVC Backup credentials were used to perform a DCSync attack, extracting the Administrator NTLM hash to compromise the domain 54:30

Sources:

  • 02:45 Initial SQL Server exploitation and foothold
  • 15:00 Setting up Legalo for network pivoting
  • 26:40 BloodHound analysis showing Louisa's permissions
  • 30:30 Extracting Louisa's password from browser cookies
  • [33:45](https://www.youtube.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 2 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi everyone. Hello. Hi. I hope everyone is okay. And we are live. Dog trace. Yo, what's up? Hope everything is well. Um, I uh just want to check if everything is okay. I've done all the posts. So, [sighs] I think I'm basically ready to go. Let's just see. Making sure all the things are live. Hi, Muel. Hello, Dolce. Hi. How are you? Apologies if I sound nasal. My for some reason my I don't know, my nose is just like closed closed now. I don't know. I was fine until like like an hour before streaming. But anyway, so apologies for sounding nasal. Um I think I'm going to dive right in if that's okay. Uh I was I was looking at some some things and just trying to get ready for the stream, but uh Oh, yeah. Dark Trace. Which one? Let me share my screen. Let's get the range booted up. Can I get to …