Scenario
- Enumeration
- Active Directory enumeration and attacks
- Exploiting DevOps infrastructure
- Lateral movement
- Local privilege escalation
- Situational awareness
- C2 Operations
These are the servers that we will be interacting with
Network Architecture
Overall View
The Architecture Theory: "Tiered Puppet Infrastructure"
1. The "Identity" Layer (Tier 0)
- Machine: DC01.puppet.vl (Windows)
- Role: The Domain Controller.
- Link: It authenticates the Service Accounts but does not let them log in interactively.
2. The "Windows Infrastructure" Layer (Tier 1)
- Machine: FILE01.puppet.vl (Windows Server)
-
Role: This appears to be a Repository / Distribution Point.
- Evidence: You found C:\Files containing puppet-agent...msi and puppet-update.exe.
- Function: Windows machines in the network likely connect here to download the Puppet Agent software so they can be managed.
3. The "Configuration Master" Layer (Tier 1 - Linux)
- Machine: PUPPET.puppet.vl (Linux)
- Role: The Puppet Master.
- Function: This is the "Brain." It pushes instructions (manifests) to all other servers (including the DC). If you control this, you can push a malicious "configuration" to the Domain Controller to add yourself as an admin.
- Why Linux? Puppet Masters run natively on Linux.
Nmap Scan
Bash
Network Enumeration
Bash
Process Enumeration
Bash
Privilege Escalation
Service Enumeration
Bash
Getting a session
Powershell
Bash
One Step Away
Elevating UAC integrity token
Bash
Credential Dumping
Bash
Bash
The Real Deal
Bash
Pivoting To svc_puppet_win_t1
Bash
Service Account enumeration
Bash
Bash
Pivoting to svc_puppet_lin_t1
Bash
Bash
Connecting to the Puppet Master
Bash
Situational Awareness
Bash
The Last Dance
Bash
Bash
Bash
Bash
Bash
Bash
Bash
Bash
Bash


