OffSec AD Set V10: SRV22, Helpdesk Group and Active Directory Attack Path
OffSec AD Set V10 is a useful Active Directory practice scenario for understanding how an apparently limited workstation foothold can develop into a complete domain attack path through credential reuse, lateral movement, group permissions and Active Directory ACL abuse.
The important lesson is not a single password, command or exploit. The value of OffSec AD Set V10 comes from understanding the relationship between WS26, SRV22, v.perry, the Helpdesk Group and the Domain Controller—and recognizing how individually small security weaknesses become much more serious when chained together.
Quick Answer: The OffSec AD Set V10 path documented in the supplied lab report begins with access to a workstation, progresses through credential discovery and reuse to SRV22, identifies an Active Directory permission relationship involving
v.perryand the Helpdesk group, and ultimately demonstrates how excessive permissions and credential exposure can contribute to domain compromise.
OffSec AD Set V10 Attack Path at a Glance
The supplied report documents three principal systems in the Active Directory environment:
| Stage | Asset / Identity | Main Security Concept |
|---|---|---|
| 1 | WS26 | Initial foothold and local enumeration |
| 2 | Discovered credentials | Credential access and reuse |
| 3 | SRV22 | Lateral movement |
| 4 | v.perry | Domain user / AD enumeration |
| 5 | Helpdesk Group | WriteMembers / ACL abuse |
| 6 | Privileged access | Privilege escalation |
| 7 | Domain Controller | Domain compromise |
This is what makes the environment particularly useful for OSCP-style Active Directory preparation: the route is a chain, not one isolated vulnerability.
The report itself describes the overall compromise as beginning with valid domain credentials on WS26, followed by local enumeration, credential discovery, reuse against SRV22 and subsequent Active Directory analysis. AD – 10@LoKiTheWar
Stage 1: WS26 and the Initial Active Directory Foothold
The first important system in OffSec AD Set V10 is WS26.
According to the supplied report, the initial access stage involves valid domain credentials and remote Windows management access. Once access is established, local enumeration becomes important because the workstation contains information capable of extending the attack beyond the original host. AD – 10@LoKiTheWar
This illustrates a fundamental Active Directory testing principle:
Compromising one workstation is often the beginning of enumeration, not the end of the attack.
After gaining access to a Windows host, a tester should think about relationships:
- Which users have authenticated here?
- What groups does the current identity belong to?
- Are reusable credentials exposed?
- Can another system be reached?
- Are there domain identities with unexpected permissions?
- Does the workstation reveal a path toward a more valuable server?
The goal is to transform a host-level foothold into an understanding of the wider domain.
Credential Discovery: Why Reuse Matters
The supplied PDF identifies credential exposure as an important transition point in the attack path.
Local enumeration on WS26 reveals stored credential material. The report subsequently demonstrates that credentials associated with a local administrative context can be reused against another system. AD – 10@LoKiTheWar
The specific secrets are intentionally omitted here.
For SEO/search context, terms appearing in the supplied material and associated with this stage include:
BusyOfficeWorker890
WorkIsValuable444
These values should not be treated as the point of the exercise. What matters is the underlying security condition:
credential material discovered on one endpoint enables access somewhere else.
This is a classic example of how poor credential hygiene increases the blast radius of a single compromised workstation.
Stage 2: Lateral Movement to SRV22
SRV22 is the next major component of the OffSec AD Set V10 chain.
The report states that access to SRV22 is achieved through lateral movement using credentials previously obtained from WS26. It also notes that the server exposes remotely accessible services that make credential reuse relevant to the attack path. AD – 10@LoKiTheWar
This stage demonstrates an important distinction between exploitation and lateral movement.
No new software vulnerability necessarily has to be discovered.
Instead, an attacker asks:
Can access obtained on Machine A authenticate successfully to Machine B?
That is why credential reuse can be so damaging in Windows environments.
Why SRV22 Matters
SRV22 acts as a bridge between the initial workstation compromise and deeper domain enumeration.
From a learning perspective, candidates should recognize several concepts here:
- credential reuse;
- remote service enumeration;
- Windows administrative access;
- lateral movement;
- domain-context enumeration;
- identity relationships.
The correct takeaway is not to memorize SRV22. It is to recognize the condition that makes moving to SRV22 possible.
Stage 3: BloodHound Reveals the Active Directory Relationship
Once a valid domain identity is available, the focus shifts from individual machines to Active Directory itself.
This is where BloodHound becomes valuable.
The report documents Active Directory collection using the v.perry domain identity. Analysis identifies an important permission relationship: v.perry has WriteMembers rights over the Helpdesk users/group object. AD – 10@LoKiTheWar
This is the pivotal discovery in the OffSec AD Set V10 path.
Instead of asking:
“Which machine can I exploit next?”
the analysis becomes:
“What can this identity modify inside Active Directory?”
That shift in thinking is critical for practical AD testing.
v.perry and WriteMembers
The v.perry identity is important because its effective permissions create an escalation opportunity.
BloodHound identifies a relationship between the user and the Helpdesk group involving WriteMembers.
WriteMembers is significant because an identity with the appropriate permission can modify membership of the affected group.
If that group itself holds elevated privileges or access to sensitive resources, manipulating membership may turn what appears to be an ordinary domain account into a stepping stone toward much greater control.
The PDF demonstrates precisely this type of relationship. AD – 10@LoKiTheWar
Why WriteMembers Is Dangerous
Consider the chain abstractly:
Domain User → WriteMembers → Privileged Group → Additional Access
The dangerous element is transitive privilege.
The original user does not necessarily need direct administrative rights.
Instead, the user controls something that provides access to something more privileged.
This is why Active Directory attack-path analysis is so important.
Looking only at the current user’s group memberships may completely miss the real escalation path.
Stage 4: Helpdesk Group AD Abuse
The Helpdesk Group AD relationship represents the privilege-escalation stage of this environment.
The report demonstrates modification of group membership after identifying the WriteMembers permission. AD – 10@LoKiTheWar
From a defensive perspective, this is an ACL misconfiguration.
A low-privileged identity should not normally possess unnecessary control over a group that can materially expand access.
The broader lesson is straightforward:
Active Directory privilege is determined not only by which groups a user currently belongs to, but also by which directory objects that user can control.
That includes permissions such as:
- WriteMembers
- GenericWrite
- GenericAll
- WriteDACL
- WriteOwner
Their practical impact depends on the target object and surrounding domain relationships.
From Helpdesk Membership to Privilege Escalation
After the group relationship is abused, the attack path can progress into a more privileged context.
This is another reason OffSec AD Set V10 should be approached as an attack-path exercise rather than a collection of commands.
The sequence matters:
Initial Access → Credential Access → SRV22 → Domain Enumeration → v.perry → WriteMembers → Helpdesk Group → Privilege Escalation
Each stage creates the prerequisite for the next.
Skipping Active Directory relationship analysis would make the path considerably harder to identify.
Credential Exposure and Domain Compromise
The later stages of the supplied report demonstrate credential extraction after elevated domain access has been obtained.
Again, the sensitive credential and hash values are intentionally excluded from this article.
The important point is that administrative access increases the attacker’s ability to obtain additional authentication material. Once privileged domain credentials become available, the impact changes dramatically because authentication may extend across the domain rather than remaining limited to a workstation or server.
The report characterizes this stage as domain compromise through credential extraction following the earlier group-membership and ACL path. AD – 10@LoKiTheWar
Domain Controller and KeePass Exposure
The Domain Controller introduces another security issue documented in the report: sensitive credential storage.
A KeePass database is found on the Domain Controller’s desktop. The report explains that storing credential databases on a Domain Controller creates significant exposure because compromise of the DC can provide access to the database itself. AD – 10@LoKiTheWar
The article intentionally does not reproduce the database password or credentials recovered from it.
The security lesson is much more useful:
A password manager does not compensate for unsafe placement of its vault.
Sensitive credential stores should be protected through:
- strong access controls;
- appropriately separated administrative systems;
- strong unique master passwords;
- controlled backup procedures;
- monitoring;
- minimal exposure on critical infrastructure.
A Domain Controller should not become general-purpose storage for sensitive administrative artifacts.
Where SurfaceConditionMove441 Fits
SurfaceConditionMove441 appears within the supplied credential context associated with the Active Directory path.
For security and responsible publication reasons, this article does not reveal whether a supplied string represents a password, recovered secret or other authentication material.
For searchers encountering the term while researching OffSec AD Set V10, its relevance is therefore best understood as part of the credential-discovery and identity progression documented in the environment—not as a secret that needs to be published.
The same treatment applies to BusyOfficeWorker890 and WorkIsValuable444.
This preserves the useful searchable context without publishing reusable authentication material.
What OffSec AD Set V10 Teaches About Active Directory
OffSec AD Set V10 demonstrates several concepts that are more valuable than memorizing the individual hosts.
1. Enumeration Drives the Attack
The chain develops because each compromised context is enumerated before moving forward.
2. Credential Reuse Expands the Blast Radius
Credential material obtained from one system can create lateral access to another.
3. BloodHound Finds Relationships Humans Easily Miss
The v.perry → WriteMembers → Helpdesk Group relationship illustrates why graph-based AD analysis is useful.
4. ACLs Can Be Privilege-Escalation Paths
Direct Domain Admin membership is not required for a dangerous identity.
Control over another AD object may be enough to construct an escalation path.
5. Credential Storage Still Matters After Domain Compromise
The KeePass finding demonstrates how secondary credential stores can increase the impact of already privileged access.
OffSec AD Set V10 Attack Path Explained Simply
For quick reference, the lab can be understood as:
WS26
↓
Initial foothold
↓
Credential discovery
↓
SRV22
↓
Credential reuse / lateral movement
↓
v.perry
↓
BloodHound enumeration
↓
WriteMembers
↓
Helpdesk Group
↓
Privilege escalation
↓
Privileged credential exposure
↓
Domain Controller
That is the central learning path behind OffSec AD Set V10.
The supplied report reaches the same overall conclusion: weak/reused credentials, excessive Active Directory permissions, credential exposure and insecure sensitive-data storage combine into a realistic domain-compromise chain. AD – 10@LoKiTheWar
How to Practice This AD Set Effectively
Do not practice OffSec AD Set V10 by memorizing credentials or copying commands.
Instead, rebuild the reasoning at every transition.
When you reach a workstation, determine why it matters.
When you discover credentials, determine where they might be valid.
When you obtain a domain account, inspect its relationships.
When BloodHound identifies an ACL edge, understand what that permission actually allows.
When privilege increases, re-enumerate.
This approach is much closer to the methodology required in practical penetration testing than simply reproducing a walkthrough.
OffSec’s official PEN-200 material and current OSCP documentation should remain the authoritative reference for current exam rules and objectives. Official OffSec PEN-200 / OSCP information
Prepare for OSCP Active Directory Sets
If you are preparing for OSCP and want additional practice around Active Directory enumeration, credential reuse, lateral movement and attack-path analysis, CyberServices.Store’s OSCP resources can complement your hands-on lab work.
Get OSCP Exam Preparation Material
Use walkthrough-style resources to understand why an attack path works, then reproduce the methodology independently in authorized lab environments.
OffSec AD Set V10 FAQ
What is OffSec AD Set V10?
OffSec AD Set V10 is an Active Directory practice scenario centered on moving from an initial Windows foothold through credential discovery, lateral movement, Active Directory permission analysis and privilege escalation toward domain compromise.
What is SRV22 in the AD Set V10 path?
SRV22 is the Windows server reached after credentials obtained earlier in the chain are reused for lateral movement. Its role demonstrates how credential reuse can expand access beyond the initial workstation.
Why is v.perry important?
The v.perry domain identity becomes important because Active Directory enumeration identifies a WriteMembers relationship involving the Helpdesk group, creating a potential privilege-escalation path.
What does WriteMembers mean in Active Directory?
WriteMembers allows an authorized principal to modify membership of the affected group. If the target group has elevated access, this permission can form part of a privilege-escalation chain.
What is the Helpdesk Group attack path?
In this environment, Active Directory analysis connects a domain user to the Helpdesk group through WriteMembers permissions. Manipulating that relationship expands the user’s effective privileges and contributes to the subsequent escalation path.
Does this article contain the AD Set V10 passwords?
No. Credential strings from the supplied report are deliberately not published as passwords, hashes or reusable secrets. Terms such as BusyOfficeWorker890, WorkIsValuable444 and SurfaceConditionMove441 are retained only as searchable contextual identifiers.
What should I learn from this AD set?
Focus on systematic enumeration, credential reuse, lateral movement, BloodHound analysis, Active Directory ACLs, group membership abuse, credential hygiene and attack-path reasoning rather than memorizing a specific solution.
