grep -l "Active Directory" ./machines (3)

Overwatch [Windows]
Medium
Windows AD DC with anonymous SMB share leaking .NET app credentials, MSSQL linked server DNS poisoning for credential capture, and WCF SOAP service command injection for SYSTEM access.
Active DirectoryMSSQLWCFCommand InjectionDNS PoisoningLinked Server +1
● pwned
Baby [Windows]
Easy
LDAP anonymous bind leaks an initial password in a user description; the target user (Caroline.Robinson) has STATUS_PASSWORD_MUST_CHANGE set, allowing password reset via SAMR; Backup Operators group membership enables direct flag read via FILE_OPEN_FOR_BACKUP_INTENT over SMB.
active-directoryldappassword-must-changebackup-operatorssebackupprivilegewindows-server-2022
● pwned
Eighteen [Windows]
Easy
Windows Server 2025 DC with MSSQL impersonation leading to credential extraction, password spray for WinRM access, and BadSuccessor dMSA privilege escalation to Domain Admin.
MSSQLSQL ImpersonationPBKDF2dMSABadSuccessorActive Directory +1
● pwned