Part 4: Hacking BitStream - (Active Directory)

Part 4: Hacking BitStream - (Active Directory)

Source: YouTube · Tyler Ramsbey - Hack Smarter · published Jun 25, 2026 · 23:05

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This video covers privilege escalation and post-exploitation on a compromised SQL server in an Active Directory environment, demonstrating how to leverage Sliver C2's execute-assembly feature to run God Potato without transferring files to the target 1:02-1:04.

Key Takeaways:
• After obtaining a shell via Sliver, the presenter enumerates privileges using get privs and identifies the SEImpersonatePrivilege, which signals that a "potato" attack can be used for local privilege escalation 2:21-3:10.
• Using Sliver's execute-assembly command, God Potato is executed directly from the attacker's machine (no file transfer required) by wrapping command arguments in single quotes, successfully elevating to NT AUTHORITY\SYSTEM 5:53-6:08.
• Unlike standard CTFs, post-exploitation here focuses on finding domain credentials for lateral movement rather than grabbing a simple flag, as no AD credentials have been obtained yet 10:48-11:13.
• The presenter uses Sliver's NanoDump extension to create a minidump of the LSASS process (PID 728) to extract cached domain credentials, downloading the dump to parse with PyPyKatz 15:05-19:31.
• A PyPyKatz bug prevents successfully parsing Bob's domain hash from the LSASS dump in this session, but alternative methods like Mimikatz or other Bitstream-specific techniques will be explored in the next video 20:01-22:07.

The video effectively demonstrates advanced C2 usage and LSASS dumping, while emphasizing the importance of pivoting to alternative tools when encountering errors.

Sources:

  • 1:02-1:04 Introduction to enumeration on the SQL server
  • 2:21-3:10 Identifying SEImpersonatePrivilege for potato attacks
  • 5:53-6:08 Executing God Potato remotely without file transfer
  • 10:48-11:13 Post-exploitation goals in an AD environment
  • 15:05-19:31 Dumping LSASS using NanoDump
  • 20:01-22:07 PyPyKatz error and alternative extraction methods

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hey everyone, welcome back to another video. This is part four of us working through the Bitstream range from the Hack Motor platform. Just like before, you're going to learn a lot by watching me. You're going to learn even more by hacking alongside of me. So, go ahead, get your black hoodie on. I know I got a gray one today, but black hoodie on, boot up your Kali VM, boot up the range, and get ready to hack all of the things. You might also notice there's chat on the screen. I make these videos while I live stream. I live stream all the time. There are over 80 people right now in the live studio audience, but you are missing. So, hit the subscribe button, hit the bell notification so you're notified the next time I am live. And yo, the Blues just gave a $5 super chat on YouTube. Thanks fo…