
HTB Shibuya CTF Writeup
Hard-rated Windows Active Directory box from VulnLab. A WIM image exposes SAM hashes for lateral movement. ADCS ESC1 impersonates a privileged user via certificate abuse. RemotePotato0 performs a cross-session Net-NTLMv2 relay to capture and crack hashes for domain compromise.








