Part 5: Hacking BitStream - (Active Directory)

Part 5: Hacking BitStream - (Active Directory)

Source: YouTube · Tyler Ramsbey - Hack Smarter · published Jun 30, 2026 · 22:11

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates how to overcome tool failures when extracting credentials from LSASS on Windows Server 2025 and establishes a SOCKS5 proxy pivot to reach an unreachable domain controller 0:42.

Key Takeaways:
• PyPyKatz and Mimikatz fail to parse LSASS dumps on the latest Windows Server 2025 build, requiring alternative tools 1:13
• By searching GitHub issues, the presenter discovered "KVC Forensics," a dependency-free tool that parses LSASS successfully and uses external JSON configs for easy future updates 2:26
• Using KVC Forensics, Bob's NT hash was extracted from the dump and cracked to the password "Pokemon" using Hashcat (mode 1000) and the rockyou.txt wordlist 9:05
• To reach the domain controller in a separate subnet, a SOCKS5 proxy was set up in Sliver C2 simply by running socks5 start 15:52
• Proxychains must be configured correctly (matching the Sliver port, default 1081) and prepended to commands like Nmap, using -Pn to bypass ICMP host discovery drops 17:02

The video ends with a challenge to use the established proxy tunnel to gather BloodHound loot from the domain controller for Active Directory enumeration 21:09.

Sources:

  • 0:42 Introduction to the LSASS parsing failure from Part 4
  • 1:13 Explanation of Windows Server 2025 breaking PyPyKatz and Mimikatz
  • 2:26 Finding KVC Forensics tool via GitHub issues
  • 9:05 Extracting and cracking Bob's NT hash
  • 15:52 Setting up SOCKS5 proxy pivot with Sliver C2
  • 17:02 Configuring proxychains and scanning through the tunnel

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hey everyone, welcome back to another video. This is part five of working through the Bitstream range from the Hack Smarter platform. And also, you may notice chat on the screen. I make these videos while I live stream. I live stream all the time. Right now, we have over 60 people in the live studio audience, but you're not here. So, make sure you subscribe and hit the bell notification, and you will be notified the next time I am live. All that being said, we're going to pick up right where we left off in part four. And I want to remind you, you will learn a lot by watching me. You're going to learn even more by hacking alongside of me. So, if you haven't already, get your black hoodie on, get your Hack Smarter hat on, boot up Bitstream, connect to the VPN, and get ready to hack all of th…