June 17, 2026

Checkpoint HackTheBox Writeup - Season11

Share
HackTheBox Checkpoint machine walkthrough

SUMMARY

This write-up covers the Checkpoint machine from HackTheBox Season 11. Starting from provided credentials for alex.turner, bloodyAD enumeration of writable objects uncovered a deleted account inside Deleted Objects, over which alex held write permissions. The object was restored and BloodHound (collected via Kerberos due to LDAPS enforcement) confirmed a GenericWrite edge from alex to mark. Credential reuse unlocked the account without additional exploitation, and SMB enumeration revealed mark had write access to a DevDrop share described as a VS Code extension drop zone for .vsix packages targeting engine version 1.118.0. A malicious extension embedding a PowerShell reverse shell was packaged with vsce, uploaded to the share, and after a brief wait it was picked up by an automated process, delivering a shell as ryan.brooks.

BloodHound analysis of ryan’s position showed GenericWrite over the service account svc_deploy, paired with CreateChild rights on the OU=DMSAHolder container, the exact combination required for a BadSuccessor attack. A delegated Managed Service Account (dMSA) was created inside that OU and linked to svc_deploy as its superseded target. Because the DC ran a patched build (≥ 26100.4946), the msDS-Superseded* attributes had to be written on svc_deploy itself, which ryan’s GenericWrite satisfied. The KDC treated the migration as legitimate and returned svc_deploy’s Kerberos keys, exposing the account’s NT hash, which was then used to open a WinRM session.

As svc_deploy, a previously inaccessible VMBackups SMB share became readable, containing nightly VMDK snapshots of the domain controller itself. The backup was mounted locally via qemu-nbd, and the underlying NTFS partition was attached read-only. With direct filesystem access to C:\, the SAM, SYSTEM, and SECURITY hive files were extracted and fed to impacket-secretsdump. The recovered Administrator hash was still valid against the live target, completing the box with a Administrator shell via evil-winrm.


PATH TO FOLLOW

  1. Reconnaissance
  2. BloodyAD Enumeration
  3. Discovery and Restore Deleted Objects
  4. BloodHound Collection
  5. Password Reuse - Access as mark.davies
  6. SMB Enumeration - DevDrop Share Write Access
  7. Malicious .vsix Extension - PowerShell Reverse Shell
  8. Shell as ryan.brooks
  9. GenericWrite on svc_deploy + CreateChild on DMSAHolder
  10. Rubeus TGT Delegation → ccache Export
  11. BadSuccessor - dMSA Creation and svc_deploy Supersession
  12. NT Hash Recovery → WinRM as svc_deploy
  13. VMBackups Share - VMDK Snapshot Access
  14. qemu-nbd Mount + NTFS Partition Identification
  15. SAM / SYSTEM / SECURITY Extraction via secretsdump
  16. Shell as Administrator

CONTENT WILL BE RELEASED ONCE THE MACHINE IS RETIRED