Hacking NorthBridge Systems (Part 6) - Hack Smarter Labs

Hacking NorthBridge Systems (Part 6) - Hack Smarter Labs

Source: YouTube · Tyler Ramsbey - Hack Smarter · published Mar 24, 2026 · 22:19

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

Part six of the North Bridge Systems walkthrough on Hack Smarter demonstrates bypassing Active Directory protections by identifying an alternative user to impersonate via BloodHound, then pivoting through multiple tools to capture the first user flag 0:00.

Key Takeaways:
• After domain admins couldn't be impersonated due to protected user restrictions, BloodHound was used to enumerate tier-one admin accounts as alternative Kerberos impersonation targets 1:30.
• Successfully impersonated user G Cook T1 and confirmed admin access to the jump box using NetExec with Kerberos authentication 2:45.
• When WMIExec2 failed due to pre-authentication errors, the instructor pivoted to dumping SAM hashes via NetExec and used Evil-WinRM pass-the-hash to gain administrator access 5:00.
• The first user flag was retrieved from the jump box desktop, concluding part six with a challenge for viewers to attempt domain controller pivoting independently 6:10.

The video reinforces the importance of tool agility, demonstrating how to pivot when a primary tool fails during an Active Directory attack chain.

Sources:

  • 0:00 Recap of part five and AD restriction bypass
  • 1:30 BloodHound enumeration of admin accounts
  • 2:45 Kerberos impersonation of G Cook T1
  • 5:00 Pass-the-hash pivot after WMIExec2 failure
  • 6:10 User flag capture and challenge to viewers

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What is up everyone? Welcome back to another video. This is going to be part six of working our way through North Bridge systems on the Hack Smarter platform. And as I said, this is part six. So, if this is the first video that you're watching, you might feel a little bit lost. I would recommend starting with part one and then watching the series in order. Additionally, you'll learn a lot by watching me, but you'll learn even more by hacking right alongside of me. So, if you haven't already, make sure you join Hack Smarter at hacksmarter.org, launch North Bridge systems, hands on your keyboard, and do all of the commands right along with me. As usual, I have not actually solved this lab, which I know is a little bit confusing cuz it's on my own platform, but we have a volunteer QA team who…