
Tombwatcher: Targeted Kerberoasting to AD Recycle Bin and ADCS ESC15
Hack The Box write-up for the Tombwatcher machine. WriteSPN over Alfred enables a targeted Kerberoast, cracked credentials chain through group self-enrollment, gMSA password extraction, a sequence of ACL abuses across four accounts, and a WinRM shell on the DC. GenericAll over the ADCS OU leads to the AD Recycle Bin, where a deleted cert_admin account maps to an unresolved SID with enrollment rights on a schema version 1 template, and an ESC15 enrollment agent hijack escalates to Domain Admin.
















