HTB Writeup – TombWatcher
Posted on 2025-06-08
Classic AD lateral and privesc with ESC15 / ESC3
CVE-2025-24071 to spoof Windows File Explorer & ESC16 in ADCS
Windows AD CS exploitation for Red Teaming practise with ESC4
Post-exploitation on AD CS, with PKINITtools and abusing ESC9