
Part 12: Hacking DarkHaven (Full Network) - Hack Smarter Labs
Source: YouTube · Tyler Ramsbey - Hack Smarter · published Apr 24, 2026 · 16:27
This episode details the compromise of the CA server in the Dark Haven range by leveraging the CA service account NTLM hash to gain admin access and establish a Sliver session 0:19-0:32. The creator demonstrates using NetExec for command execution to bypass Windows Defender, retrieve the flag, and identify post-exploitation paths toward the domain controller 0:42-1:10.
Key Takeaways:
• Ldeep was essential for retrieving the CA service account NTLM hash after NetExec and BloodyAD failed 0:19-0:29
• The CA server was compromised by passing the NTLM hash via NetExec, granting local admin access 0:32-0:42
• A Sliver session was established on the CA server using NetExec to execute PowerShell commands and download a payload 0:42-0:55
• Post-exploitation reveals the CA service machine account has outbound object control, enabling enrollment in the Dark Haven CA 0:58-1:03
• Viewers are advised to avoid ADCS rabbit holes and focus on credential history to progress to the domain controller 1:03-1:10
The creator challenges viewers to perform independent post-exploitation to find credentials and advance toward the domain controller before the next installment.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What is up everyone? Welcome back. This is going to be part 12 of working through the Dark Haven range on the Hack Smarter platform. Of course, it's part 12, not part one. So, don't start here. Start at part one and then hack alongside of me. Boot up Dark Haven, pull up the videos, get your black hoodie on, and let's hack all of the things together. Now, in part 11, at the very end of part 11, we were able to use L deep, a new tool that we discovered because NetExec was failing us, BloodyAD didn't work great, but L deep was able to retrieve the NTLM hash for the CA service account. Let me go ahead and share my screen and dive into it. You're also going to notice that there is chat on the screen and I make all of these videos while I'm live streaming. So, there's right now about 70 people i…