<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://3x0t1k.github.io/</id><title>3x0t1k</title><subtitle>Security notes, write-ups and research by Andrii Horodov.</subtitle> <updated>2026-08-17T07:37:15+00:00</updated> <author> <name>Andrii Horodov</name> <uri>https://3x0t1k.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://3x0t1k.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://3x0t1k.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Andrii Horodov </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Active Directory Penetration Testing: Local Privilege Escalation - From User to SYSTEM</title><link href="https://3x0t1k.github.io/posts/local-privesc/" rel="alternate" type="text/html" title="Active Directory Penetration Testing: Local Privilege Escalation - From User to SYSTEM" /><published>2026-08-15T00:00:00+00:00</published> <updated>2026-08-16T08:44:00+00:00</updated> <id>https://3x0t1k.github.io/posts/local-privesc/</id> <content type="text/html" src="https://3x0t1k.github.io/posts/local-privesc/" /> <author> <name>Andrii Horodov</name> </author> <category term="Active Directory" /> <category term="Privilege Escalation" /> <summary>Introduction At this point in our engagement we have credentials for r.nilson - obtained through password spraying, as covered in the first post. With those credentials we ran Kerberoasting against the domain and cracked svc_sql. That gives us access to the SQL server - svc_sql is the account we’ll use there, not r.nilson directly. This post covers an alternative path. In the previous post we...</summary> </entry> <entry><title>Active Directory Penetration Testing: Kerberos, AS-REP Roasting &amp; Kerberoasting Explained</title><link href="https://3x0t1k.github.io/posts/kerberos-asreproasting-kerberoasting/" rel="alternate" type="text/html" title="Active Directory Penetration Testing: Kerberos, AS-REP Roasting &amp;amp; Kerberoasting Explained" /><published>2026-08-12T00:00:00+00:00</published> <updated>2026-08-14T06:27:21+00:00</updated> <id>https://3x0t1k.github.io/posts/kerberos-asreproasting-kerberoasting/</id> <content type="text/html" src="https://3x0t1k.github.io/posts/kerberos-asreproasting-kerberoasting/" /> <author> <name>Andrii Horodov</name> </author> <category term="Active Directory" /> <category term="Credential Attacks" /> <summary>Introduction In Active Directory Penetration Testing: How It All Starts I mentioned both AS-REP Roasting and Kerberoasting as techniques for getting a first credential. But I glossed over the details - what they actually are, how they differ from each other, and how Kerberos authentication differs from NTLM in the first place. This post fills in that gap. We’ll cover how Kerberos actually wor...</summary> </entry> <entry><title>Active Directory Penetration Testing: ACL Abuse - From a Helpdesk Account to DCSync</title><link href="https://3x0t1k.github.io/posts/acl-abuse-dcsync/" rel="alternate" type="text/html" title="Active Directory Penetration Testing: ACL Abuse - From a Helpdesk Account to DCSync" /><published>2026-08-12T00:00:00+00:00</published> <updated>2026-08-14T06:28:10+00:00</updated> <id>https://3x0t1k.github.io/posts/acl-abuse-dcsync/</id> <content type="text/html" src="https://3x0t1k.github.io/posts/acl-abuse-dcsync/" /> <author> <name>Andrii Horodov</name> </author> <category term="Active Directory" /> <category term="Privilege Escalation" /> <summary>Introduction We’ve covered the path from a Linux foothold to Active Directory enumeration and getting first credentials in Active Directory Penetration Testing: How It All Starts. From there, we went deeper into specific techniques - how Responder, LLMNR, and NBT-NS actually work in that post, and the mechanics behind AS-REP Roasting and Kerberoasting in this one. Now the question becomes: we...</summary> </entry> <entry><title>Active Directory Penetration Testing: LLMNR &amp; NBT-NS Poisoning - Stealing Credentials from the Network</title><link href="https://3x0t1k.github.io/posts/llmnr-nbtns-poisoning/" rel="alternate" type="text/html" title="Active Directory Penetration Testing: LLMNR &amp;amp; NBT-NS Poisoning - Stealing Credentials from the Network" /><published>2026-08-11T00:00:00+00:00</published> <updated>2026-08-14T06:25:50+00:00</updated> <id>https://3x0t1k.github.io/posts/llmnr-nbtns-poisoning/</id> <content type="text/html" src="https://3x0t1k.github.io/posts/llmnr-nbtns-poisoning/" /> <author> <name>Andrii Horodov</name> </author> <category term="Active Directory" /> <category term="Credential Attacks" /> <summary>Introduction In the previous post - Active Directory Penetration Testing: How It All Starts - I briefly showed how Responder fits into the picture when you’re stuck in a network segment with nothing useful to work with. We captured a NetNTLMv2 challenge-response, cracked it with hashcat, and got a valid credential. But what if the hash doesn’t crack? And more importantly - why does any of thi...</summary> </entry> <entry><title>Active Directory Penetration Testing: How It All Starts (Enumeration &amp; First Credentials)</title><link href="https://3x0t1k.github.io/posts/initial-enumeration-active-directory/" rel="alternate" type="text/html" title="Active Directory Penetration Testing: How It All Starts (Enumeration &amp;amp; First Credentials)" /><published>2026-08-11T00:00:00+00:00</published> <updated>2026-08-14T06:28:55+00:00</updated> <id>https://3x0t1k.github.io/posts/initial-enumeration-active-directory/</id> <content type="text/html" src="https://3x0t1k.github.io/posts/initial-enumeration-active-directory/" /> <author> <name>Andrii Horodov</name> </author> <category term="Active Directory" /> <category term="Enumeration" /> <summary>Introduction If we’re talking about Active Directory pentesting, we’re already inside the client’s internal network. (Not a victim’s network - that would be illegal, and also a very different kind of blog post.) Most of the time, in my personal experience, the foothold machine is a Linux host. That’s because the most common path in is through a poorly written web application running on Apache...</summary> </entry> </feed>
