The HTB CAPE Active Directory Guide focuses on the relationships that make advanced AD environments difficult: users, credentials, service accounts, delegated privileges, authentication protocols, and the attack paths connecting them.
In the servicecenter.evergreenhealth environment, accounts such as mbernand, svc_sqlqa, knelson, child_admin, SVC-SHIELDWALLAGENT, holmes, and sgarcia should not be treated as isolated enumeration results. Their value comes from understanding where they appear, what they can access, which services trust them, and how one identity may lead to another level of access.
That relationship-driven approach is particularly important for HTB CAPE preparation, where advanced Active Directory enumeration matters more than simply finding another credential.
Understanding servicecenter.evergreenhealth
The Active Directory domain:
servicecenter.evergreenhealth
provides the identity layer connecting users, services, hosts, and administrative boundaries.
Early enumeration may reveal accounts including:
mbernandknelsonholmessgarciasvc_sqlqachild_adminSVC-SHIELDWALLAGENT
Instead of immediately testing every account, classify them first.
A useful structure is:
| Account Type | What to Investigate |
|---|---|
| Standard user | Groups, shares, files, remote access |
| Service account | SPNs, services, privileges, credential exposure |
| Administrative account | Scope of control, ACLs, delegated rights |
| Application identity | Backend services, configuration, authentication |
| Domain/child administrator | Trusts, delegation and administrative boundaries |
The objective of the HTB CAPE Active Directory Guide methodology is to convert this identity inventory into an attack graph.
User → Group → Service → Host → Permission → Next Identity
That structure is considerably more useful than maintaining a flat username list.
User & Credential Enumeration
Users such as mbernand, knelson, holmes, and sgarcia may initially appear to be ordinary domain identities.
That does not make them unimportant.
A standard domain user can provide authenticated visibility into:
- SMB shares;
- LDAP information;
- internal files;
- domain groups;
- application resources;
- Kerberos services;
- internal systems unavailable anonymously.
References to an sgarcia document or other user-associated files should therefore be investigated in context. Internal documents can expose usernames, infrastructure details, application information, credentials, or operational relationships.
Credential discovery should follow the same principle.
Do not stop at:
“I found a password.”
Record:
Credential → Account → Discovery Source → Service → Authentication Result → Privilege
Then test only logically related services within the authorized environment.
Potential authentication surfaces may include SMB, WinRM, MSSQL, web applications, LDAP-connected services, and other Windows infrastructure.
This turns credential testing into evidence-driven enumeration instead of blind reuse.
Preparing for Advanced HTB Active Directory?
CAPE requires much more than basic domain enumeration. If you want structured preparation material covering advanced AD attack paths, credential relationships, Kerberos/NTLM techniques, lateral movement and complex enterprise scenarios, use our dedicated CAPE resources.
✓ Instant digital access · ✓ Free updates · ✓ CAPE-focused practical resources
Service Accounts: svc_sqlqa & SVC-SHIELDWALLAGENT
Service accounts deserve particular attention because they often connect Active Directory identities with applications and infrastructure.
The name svc_sqlqa, for example, suggests a relationship with SQL or QA infrastructure.
That gives you a hypothesis—not proof of privilege.
Investigate:
- SPN configuration;
- group membership;
- MSSQL access;
- service ownership;
- local privileges;
- remote authentication;
- configuration files;
- credential exposure;
- delegated permissions.
Likewise, SVC-SHIELDWALLAGENT and related svc_shieldwall references should be mapped to the systems and services where they actually appear.
Ask:
Which host uses this identity?
Which service runs under it?
Where are its credentials stored?
What permissions does it really have?
Can its authentication context reveal another relationship?
Service accounts may also become relevant when examining Kerberos.
An account with a Service Principal Name can create a different attack surface from an ordinary user, but the presence of an SPN alone does not establish exploitable risk. Verify the configuration and actual privileges before drawing conclusions.
The same rule applies throughout this HTB CAPE Active Directory Guide:
Names suggest. Enumeration proves.
child_admin and Delegated Privileges
child_admin deserves attention because its name suggests an administrative relationship involving a child domain or delegated boundary.
Again, do not assume full Domain Admin privileges from the username.
Verify:
- group memberships;
- domain membership;
- DACL relationships;
- object ownership;
- password-reset rights;
- group modification rights;
- delegated OU permissions;
- trust relationships;
- administrative access to specific hosts.
Advanced Active Directory environments frequently contain accounts that are highly privileged within one boundary without being universally privileged across the forest.
That distinction becomes particularly important when child domains and domain trusts are involved.
An account may control a critical object without belonging to Domain Admins.
Therefore, instead of asking:
“Is this account Domain Admin?”
ask:
“What can this account control?”
That question is much more useful for attack-path analysis.
Kerberos, NTLM and Authentication Relationships
CAPE-level Active Directory testing requires understanding the authentication mechanisms connecting identities to services.
The current HTB CAPE curriculum explicitly includes advanced abuse of Kerberos and NTLM, alongside ADCS, WSUS, Exchange, MSSQL, DACLs and Domain Trusts.
When investigating the servicecenter.evergreenhealth environment, authentication analysis should therefore include questions such as:
- Which accounts have SPNs?
- Which services accept domain authentication?
- Where is NTLM being used?
- Are credentials exposed through service configuration?
- Which accounts can authenticate remotely?
- Are there useful delegation relationships?
- Do ACLs expose control over another identity?
- Are domain or forest trust relationships present?
The goal is not to run every Active Directory technique you know.
Start with evidence.
If enumeration reveals an SPN, investigate Kerberos implications.
If MSSQL appears, determine who can authenticate and what access that identity provides.
If another domain appears, investigate the trust relationship.
If a certificate infrastructure appears, map ADCS.
Let the environment determine the next technique.
Mapping the CAPE Attack Path
Once users, services, and credentials have been identified, stop treating them as separate findings.
Build relationships.
A conceptual attack graph could look like:
Initial Domain Visibility
→ Standard User
→ Internal Share / Document
→ Credential Discovery
→ Service Account
→ MSSQL / Internal Service
→ Additional Domain Visibility
→ Delegated Permission
→ Administrative Identity
→ Child Domain / Trust Relationship
→ Expanded Domain Control
This is a methodology model rather than a claimed exact solution to the environment.
The real path should always come from verified evidence.
For example, mbernand or knelson may initially seem irrelevant. But if one account can access a share containing information related to svc_sqlqa, that relationship immediately changes its importance.
Similarly, child_admin may appear highly valuable from the beginning but remain unreachable until several earlier relationships have been discovered.
This is why advanced AD assessments rarely move in a straight line.
Re-Enumerate After Every New Identity
One of the most important habits in the HTB CAPE Active Directory Guide is repeated enumeration.
Use this cycle:
Enumerate → Authenticate → Re-enumerate → Correlate → Expand Access → Repeat
A new domain user changes what LDAP and SMB may reveal.
A service account may expose another application.
Administrative access to one host may reveal another identity.
A child-domain account may expose trust information unavailable earlier.
Never assume your initial enumeration represents the complete environment.
Maintain three compact inventories throughout the assessment:
Identity Map: User → Groups → Privileges → Services
Credential Map: Credential → Source → Valid Services → Access
Attack Map: Current Access → Relationship → Next Asset
Together, these make complex attack paths much easier to follow.
Need Deeper CAPE Attack-Path Practice?
Our CAPE preparation material is designed around the same type of advanced Active Directory relationships: users, services, authentication, lateral movement, delegated privileges and multi-stage attack paths.
→ Explore HTB CAPE Exam Material
Common CAPE Active Directory Mistakes
Treating every user equally.
Classify users by context, privileges, services, groups and relationships.
Assuming service accounts are automatically privileged.svc_sqlqa may be interesting, but actual permissions must be verified.
Trusting account names.child_admin suggests a role; it does not prove what the account controls.
Testing credentials everywhere.
Use evidence to determine where an identity is likely to authenticate.
Focusing only on Domain Admin.
Delegated rights, DACLs, service privileges and trust relationships can be more important than group names.
Ignoring documents and shares.
Internal information can expose the relationship that unlocks the next stage.
Running advanced techniques without context.
ADCS, Kerberos, NTLM relay, MSSQL, WSUS or trust abuse should follow evidence from enumeration.
Failing to re-enumerate.
Every new identity changes what you can see.
Why This Matters for HTB CAPE
HTB currently describes Certified Active Directory Pentesting Expert (CAPE) as an advanced hands-on certification focused on identifying and exploiting complex Active Directory vulnerabilities.
The official scope includes advanced Windows and AD penetration testing, complex attack paths, Kerberos and NTLM authentication abuse, ADCS, WSUS, Exchange, Domain Trusts, Linux/Windows AD tooling, and C2-assisted post-exploitation.
That makes the servicecenter.evergreenhealth environment valuable not because of any individual username or credential, but because it reinforces the central CAPE skill:
understanding relationships inside complex Active Directory environments.
For the current certification scope, modules and requirements, see the official HTB CAPE certification information.
HTB CAPE Active Directory Guide FAQ
What is servicecenter.evergreenhealth?
servicecenter.evergreenhealth is the Active Directory domain referenced in this CAPE-related environment. Its users, service accounts, services and administrative relationships form the core enumeration surface discussed in this guide.
Why are svc_sqlqa and SVC-SHIELDWALLAGENT important?
Their naming suggests service-related identities. Investigate their SPNs, services, group memberships, authentication scope, configuration and actual permissions rather than assuming they are privileged.
Why is child_admin interesting?
The name suggests delegated or child-domain administration, making group membership, ACLs, domain relationships and trust boundaries important areas to investigate. The username alone does not establish its privileges.
What should I focus on for HTB CAPE?
Prioritize advanced AD enumeration, Kerberos and NTLM, service accounts, DACL relationships, ADCS, MSSQL, WSUS, Exchange, Domain Trusts, lateral movement and attack-path analysis.
What is the most important CAPE enumeration habit?
Re-enumeration. Every new identity, credential, privilege level or domain relationship can expose information that was unavailable earlier.
Final Thoughts
The core lesson from this HTB CAPE Active Directory Guide is that advanced Active Directory compromise is rarely about one account or one vulnerability.
mbernand, knelson, holmes, sgarcia, svc_sqlqa, SVC-SHIELDWALLAGENT, and child_admin become meaningful when you understand how they relate to services, permissions, credentials and administrative boundaries inside servicecenter.evergreenhealth.
Think in relationships:
User → Credential → Service → Permission → Host → Domain Relationship
Enumerate first.
Verify privileges instead of assuming them.
Re-enumerate after every new identity.
Then build the attack path from evidence.
Ready to Prepare for HTB CAPE?
Get our advanced CAPE preparation resources covering Active Directory enumeration, complex attack paths, credential relationships, lateral movement and advanced enterprise AD scenarios.
✓ Instant digital delivery
✓ Free updates included
✓ Advanced AD-focused resources
✓ Practical CAPE preparation material
Use penetration-testing techniques only against systems you own or are explicitly authorized to assess.
Get the material: CAPE exam material
