// htb writeup HackTheBox 2026-06-21
Checkpoint
HackTheBox Medium HackTheBox
seasonal
root obtained // PWNED

⚛️ Checkpoint

Difficulty: Medium OS: Windows Release: HTB Season 11

Checkpoint is a Windows Active Directory box that chains together three distinct phases: recovering a deleted AD object to gain new access, abusing a writable SMB share to deliver a malicious VS Code extension and get a foothold, then exploiting delegated Managed Service Account (dMSA) permissions in their post-patch “mutual pairing” form to extract a service account credential — and finally pivoting through a VM backup share to perform memory forensics and recover the Administrator hash.


📸 Proof


🧠 Concepts Covered


💡 Hints (No Spoilers)

Foothold

User

Root


📚 Useful Reading


This box is part of HTB Season 11.