<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Active Directory - Tag - My Personal Blog</title><link>https://f0dh1l.github.io/blog/tags/active-directory/</link><description>Active Directory - Tag - My Personal Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>benhibafodhil@gmail.com (F0DH1L)</managingEditor><webMaster>benhibafodhil@gmail.com (F0DH1L)</webMaster><copyright>2025 F0DH1L</copyright><lastBuildDate>Tue, 10 Mar 2026 15:58:49 +0100</lastBuildDate><atom:link href="https://f0dh1l.github.io/blog/tags/active-directory/" rel="self" type="application/rss+xml"/><item><title>My CRTP Experience: Preparation, Lab, and Exam Review</title><link>https://f0dh1l.github.io/blog/posts/crtp_review/</link><pubDate>Tue, 10 Mar 2026 15:58:49 +0100</pubDate><author>benhibafodhil@gmail.com (F0DH1L)</author><guid>https://f0dh1l.github.io/blog/posts/crtp_review/</guid><description><![CDATA[<h2 id="crtp-certified">CRTP Certified</h2>
<h3 id="im-officially-crtp-certified">I&rsquo;m officially CRTP certified!</h3>
<p></p>
<h4 id="i-would-like-to-express-my-gratitude-to-nikhil-mittal-and-the-altered-security-team-for-delivering-this-great-certification-and-course-the-exceptional-support-they-provided-throughout-the-entire-journey-was-truly-impressive-here-is-the-link">I would like to express my gratitude to Nikhil Mittal and the Altered Security team for delivering this great certification and course. The exceptional support they provided throughout the entire journey was truly impressive. Here is the link:</h4>
<h4><a href="https://www.credential.net/9b36a171-479b-4885-b1c1-792528a07269#acc.ZcH7lUSE" target="_blank" rel="noopener noreffer ">https://www.credential.net/9b36a171-479b-4885-b1c1-792528a07269#acc.ZcH7lUSE</a></h4>
<h2 id="what-is-crtp">What Is CRTP?</h2>
<p></p>]]></description></item><item><title>HTB Machine Writeup "TombWatcher"</title><link>https://f0dh1l.github.io/blog/posts/htb_tombwatcher/</link><pubDate>Thu, 23 Oct 2025 14:01:34 +0100</pubDate><author>benhibafodhil@gmail.com (F0DH1L)</author><guid>https://f0dh1l.github.io/blog/posts/htb_tombwatcher/</guid><description><![CDATA[<h1 id="htb-machine-tombwatcher---writeup">HTB Machine: TombWatcher - Writeup</h1>
<h2 id="machine-information">Machine Information</h2>
<ul>
<li><strong>Difficulty</strong>: Medium</li>
<li><strong>Key Concepts</strong>: Kerberoasting, LDAP Enumeration, BloodHound Analysis, Active Directory Privilege Escalation, Deleted Object Recovery, ADCS ESC15 Vulnerability</li>
</ul>
<p></p>
<h2 id="overview">Overview</h2>
<p><strong>TombWatcher</strong> is a Medium Windows machine from HackTheBox that demonstrates a complex Active Directory attack path involving Kerberoasting, group membership manipulation, GMSA password extraction, ownership changes, recovering and restoring deleted AD objects, and ultimately exploiting an ADCS vulnerability (ESC15) to achieve domain administrator privileges.</p>]]></description></item></channel></rss>