Status: 🔒 Private – writeup will be published once the machine retires
Difficulty: Hard
Category: Active Directory | Windows | Kerberos | RBCD
Date Completed: 2025-06-29
A domain full of policies, delegation edge cases, and a rusty trust chain…
Can you untangle a messy AD forest where support is protected, but old credentials remain dangerous?
🪛 Bring your favorite tools:
getST.py, smbexec.pyYou’ll need to:
![RustyKey Proof] 
📌 Full writeup will be published here when the box is retired.