# Hack The Box (HTB) - Hercules writeup

**Hercules** is an Insane-level Windows Active Directory lab machine focused on advanced AD abuse, Active Directory Certificate Services (AD CS) exploitation, and Kerberos delegation attacks. Rather than relying on a single misconfiguration, it requires chaining multiple subtle weaknesses across OU permissions, Shadow Credentials, AD CS, and resource-based constrained delegation (RBCD).

Initial access centers on enumerating delegated rights within Organizational Units, where object ownership and `GenericAll` permissions establish the foundation for escalation. The attack path then progresses through modern AD abuse primitives, including Shadow Credentials, certificate template misconfigurations such as ESC3 and ESC15, and Enrollment Agent abuse. This demands careful reasoning about certificate trust relationships and enrollment workflows.

The machine further increases difficulty through disabled accounts, delegated password control, and smartcard-related privileges, requiring precise manipulation of user and computer objects instead of brute-force techniques. Exploitation culminates in abusing S4U2Self and S4U2Proxy via resource-based constrained delegation, enabling full impersonation of the Domain Administrator without ever knowing their password.

Hercules is a technically demanding lab that rewards a strong understanding of Kerberos internals, AD CS abuse, delegation mechanics, and BloodHound-driven attack path analysis. It is an excellent assessment of real-world Active Directory compromise techniques and is well suited for security practitioners aiming to master enterprise-grade Windows domain attacks

Following is the link of full walkthrough:

[Hercules Walkthrough](https://medium.com/@rafidahmed/chained-trust-a-full-compromise-of-htb-hercules-via-ldap-injection-credential-harvesting-and-c81a033c5dcc?source=friends_link&sk=3c12b9f28b36557b946521975a3855cb)
