Part 12: Hacking DarkHaven (Full Network) - Hack Smarter Labs

Part 12: Hacking DarkHaven (Full Network) - Hack Smarter Labs

Source: YouTube · Tyler Ramsbey - Hack Smarter · published Apr 24, 2026 · 16:27

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This episode details the compromise of the CA server in the Dark Haven range by leveraging the CA service account NTLM hash to gain admin access and establish a Sliver session 0:19-0:32. The creator demonstrates using NetExec for command execution to bypass Windows Defender, retrieve the flag, and identify post-exploitation paths toward the domain controller 0:42-1:10.

Key Takeaways:
• Ldeep was essential for retrieving the CA service account NTLM hash after NetExec and BloodyAD failed 0:19-0:29
• The CA server was compromised by passing the NTLM hash via NetExec, granting local admin access 0:32-0:42
• A Sliver session was established on the CA server using NetExec to execute PowerShell commands and download a payload 0:42-0:55
• Post-exploitation reveals the CA service machine account has outbound object control, enabling enrollment in the Dark Haven CA 0:58-1:03
• Viewers are advised to avoid ADCS rabbit holes and focus on credential history to progress to the domain controller 1:03-1:10

The creator challenges viewers to perform independent post-exploitation to find credentials and advance toward the domain controller before the next installment.

Sources:

  • 0:19 Recap of using Ldeep to retrieve CA service account NTLM hash
  • 0:22 Explanation that NetExec and BloodyAD failed
  • 0:32 Compromising the CA server via pass-the-hash
  • 0:42 Establishing Sliver session using NetExec command exec

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What is up everyone? Welcome back. This is going to be part 12 of working through the Dark Haven range on the Hack Smarter platform. Of course, it's part 12, not part one. So, don't start here. Start at part one and then hack alongside of me. Boot up Dark Haven, pull up the videos, get your black hoodie on, and let's hack all of the things together. Now, in part 11, at the very end of part 11, we were able to use L deep, a new tool that we discovered because NetExec was failing us, BloodyAD didn't work great, but L deep was able to retrieve the NTLM hash for the CA service account. Let me go ahead and share my screen and dive into it. You're also going to notice that there is chat on the screen and I make all of these videos while I'm live streaming. So, there's right now about 70 people i…