Getting Roasted
DFIR
Last updated
Was this helpful?
DFIR
Last updated
Was this helpful?
You notice a zip file containing a lot of information about your Active Directory environment on a computer. Perhaps the attacker is planning their lateral movements. See if you can find the Object ID (sometimes known as "objectSID" or "SID") of a user susceptible to a technique known as "AS-REP Roasting". Flag format is FLAG{ObjectID}, for example if the ObjectID is "S-1-2-33-444", the flag would be FLAG{S-1-2-33-444}