HTB Liberty Writeup: From Password Spray to Persistent Backdoor
A single misconfigured file share leads to an NTLM hash capture, RDP access, and a PowerShell Web Access backdoor. A full DFIR reconstruction of this retired HTB blue-team challenge using the registry, $MFT, Shellbags, and event logs.
Read post →