GS-033: BITSTREAM (P4) + MIRAI — SQL + Mimikatz, Pi Root (HackSmarter/HTB) | 2026-07-16

GS-033: BITSTREAM (P4) + MIRAI — SQL + Mimikatz, Pi Root (HackSmarter/HTB) | 2026-07-16

Source: YouTube · HaxrByte · published Jul 17, 2026 · 4:09:01

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The streamer demonstrates penetration testing on the Hackmatt Bitstream range and Hack the Box "Marai" machine, highlighting Windows 2025 security changes and forensic recovery techniques.

Key Takeaways:
• Windows Server 2025 alters LSA secret storage, causing older Mimikatz versions to fail; alternative methods like ProcDump are required for hash extraction 14:15.
• Privilege escalation to SYSTEM on the SQL server was achieved using GodPotato, granting full machine control after initial foothold via SQL injection 33:35.
• The Adaptics C2 platform maintains state across range restarts, allowing beacons to reconnect automatically, a feature distinct from standard Hack the Box environments 20:15.
• The "Marai" machine is a Raspberry Pi running Pi-hole with default SSH credentials (pi/raspberry) exposed, allowing immediate access 30:25.
• Root access on "Marai" was gained by recovering deleted files from a mounted USB stick using the strings command after standard recovery tools failed 44:20.

The stream emphasizes that even experienced professionals encounter tooling failures and must adapt their methodology in real-time, highlighting the importance of understanding underlying OS behaviors.

Sources:

  • 14:15 Discussion on Windows 2025 blocking older Mimikatz versions for LSA dumping.
  • 33:35 Execution of GodPotato to escalate privileges to SYSTEM.
  • 20:15 Demonstration of Adaptics C2 state persistence and beacon reconnection.
  • 30:25 Identification of default SSH credentials o

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 2 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. Hi. I think we're live. Yeah, live. Hi. I hope everyone is well. [sighs] Um, welcome. Welcome to the stream. And um, yeah, we're going to get started shortly. Hey, Doc Trace. Hope you're doing well. Where's my chat? supposed to be there. [clears throat] Oh, it's probably probably going to roll in. We'll see. Are you dead? I I swear I saw a comment on YouTube. Um, I got a notification that you left a comment and then when I went and look, it was gone. Did you Did you delete that? Thought you would, I guess, get catch me on stream or what was the issue? Tell me then we can um we can play with it. Newer version of mimikat. So, it's not the pie cats. Um, remember the pi pie cats? uh we can actually dump the hash and then uh we couldn't extract that um any of the like the um pas…