OffSec AD Set V10

OffSec AD Set V10: SRV22, Helpdesk Group and Active Directory Attack Path

OffSec AD Set V10 is a useful Active Directory practice scenario for understanding how an apparently limited workstation foothold can develop into a complete domain attack path through credential reuse, lateral movement, group permissions and Active Directory ACL abuse.

The important lesson is not a single password, command or exploit. The value of OffSec AD Set V10 comes from understanding the relationship between WS26, SRV22, v.perry, the Helpdesk Group and the Domain Controller—and recognizing how individually small security weaknesses become much more serious when chained together.

Quick Answer: The OffSec AD Set V10 path documented in the supplied lab report begins with access to a workstation, progresses through credential discovery and reuse to SRV22, identifies an Active Directory permission relationship involving v.perry and the Helpdesk group, and ultimately demonstrates how excessive permissions and credential exposure can contribute to domain compromise.

OffSec AD Set V10 Attack Path at a Glance

The supplied report documents three principal systems in the Active Directory environment:

StageAsset / IdentityMain Security Concept
1WS26Initial foothold and local enumeration
2Discovered credentialsCredential access and reuse
3SRV22Lateral movement
4v.perryDomain user / AD enumeration
5Helpdesk GroupWriteMembers / ACL abuse
6Privileged accessPrivilege escalation
7Domain ControllerDomain compromise

This is what makes the environment particularly useful for OSCP-style Active Directory preparation: the route is a chain, not one isolated vulnerability.

The report itself describes the overall compromise as beginning with valid domain credentials on WS26, followed by local enumeration, credential discovery, reuse against SRV22 and subsequent Active Directory analysis. AD – 10@LoKiTheWar

Stage 1: WS26 and the Initial Active Directory Foothold

The first important system in OffSec AD Set V10 is WS26.

According to the supplied report, the initial access stage involves valid domain credentials and remote Windows management access. Once access is established, local enumeration becomes important because the workstation contains information capable of extending the attack beyond the original host. AD – 10@LoKiTheWar

This illustrates a fundamental Active Directory testing principle:

Compromising one workstation is often the beginning of enumeration, not the end of the attack.

After gaining access to a Windows host, a tester should think about relationships:

  • Which users have authenticated here?
  • What groups does the current identity belong to?
  • Are reusable credentials exposed?
  • Can another system be reached?
  • Are there domain identities with unexpected permissions?
  • Does the workstation reveal a path toward a more valuable server?

The goal is to transform a host-level foothold into an understanding of the wider domain.

Credential Discovery: Why Reuse Matters

The supplied PDF identifies credential exposure as an important transition point in the attack path.

Local enumeration on WS26 reveals stored credential material. The report subsequently demonstrates that credentials associated with a local administrative context can be reused against another system. AD – 10@LoKiTheWar

The specific secrets are intentionally omitted here.

For SEO/search context, terms appearing in the supplied material and associated with this stage include:

BusyOfficeWorker890

WorkIsValuable444

These values should not be treated as the point of the exercise. What matters is the underlying security condition:

credential material discovered on one endpoint enables access somewhere else.

This is a classic example of how poor credential hygiene increases the blast radius of a single compromised workstation.

Stage 2: Lateral Movement to SRV22

SRV22 is the next major component of the OffSec AD Set V10 chain.

The report states that access to SRV22 is achieved through lateral movement using credentials previously obtained from WS26. It also notes that the server exposes remotely accessible services that make credential reuse relevant to the attack path. AD – 10@LoKiTheWar

This stage demonstrates an important distinction between exploitation and lateral movement.

No new software vulnerability necessarily has to be discovered.

Instead, an attacker asks:

Can access obtained on Machine A authenticate successfully to Machine B?

That is why credential reuse can be so damaging in Windows environments.

Why SRV22 Matters

SRV22 acts as a bridge between the initial workstation compromise and deeper domain enumeration.

From a learning perspective, candidates should recognize several concepts here:

  • credential reuse;
  • remote service enumeration;
  • Windows administrative access;
  • lateral movement;
  • domain-context enumeration;
  • identity relationships.

The correct takeaway is not to memorize SRV22. It is to recognize the condition that makes moving to SRV22 possible.

Stage 3: BloodHound Reveals the Active Directory Relationship

Once a valid domain identity is available, the focus shifts from individual machines to Active Directory itself.

This is where BloodHound becomes valuable.

The report documents Active Directory collection using the v.perry domain identity. Analysis identifies an important permission relationship: v.perry has WriteMembers rights over the Helpdesk users/group object. AD – 10@LoKiTheWar

This is the pivotal discovery in the OffSec AD Set V10 path.

Instead of asking:

“Which machine can I exploit next?”

the analysis becomes:

“What can this identity modify inside Active Directory?”

That shift in thinking is critical for practical AD testing.

v.perry and WriteMembers

The v.perry identity is important because its effective permissions create an escalation opportunity.

BloodHound identifies a relationship between the user and the Helpdesk group involving WriteMembers.

WriteMembers is significant because an identity with the appropriate permission can modify membership of the affected group.

If that group itself holds elevated privileges or access to sensitive resources, manipulating membership may turn what appears to be an ordinary domain account into a stepping stone toward much greater control.

The PDF demonstrates precisely this type of relationship. AD – 10@LoKiTheWar

Why WriteMembers Is Dangerous

Consider the chain abstractly:

Domain User → WriteMembers → Privileged Group → Additional Access

The dangerous element is transitive privilege.

The original user does not necessarily need direct administrative rights.

Instead, the user controls something that provides access to something more privileged.

This is why Active Directory attack-path analysis is so important.

Looking only at the current user’s group memberships may completely miss the real escalation path.

Stage 4: Helpdesk Group AD Abuse

The Helpdesk Group AD relationship represents the privilege-escalation stage of this environment.

The report demonstrates modification of group membership after identifying the WriteMembers permission. AD – 10@LoKiTheWar

From a defensive perspective, this is an ACL misconfiguration.

A low-privileged identity should not normally possess unnecessary control over a group that can materially expand access.

The broader lesson is straightforward:

Active Directory privilege is determined not only by which groups a user currently belongs to, but also by which directory objects that user can control.

That includes permissions such as:

  • WriteMembers
  • GenericWrite
  • GenericAll
  • WriteDACL
  • WriteOwner

Their practical impact depends on the target object and surrounding domain relationships.

From Helpdesk Membership to Privilege Escalation

After the group relationship is abused, the attack path can progress into a more privileged context.

This is another reason OffSec AD Set V10 should be approached as an attack-path exercise rather than a collection of commands.

The sequence matters:

Initial Access → Credential Access → SRV22 → Domain Enumeration → v.perry → WriteMembers → Helpdesk Group → Privilege Escalation

Each stage creates the prerequisite for the next.

Skipping Active Directory relationship analysis would make the path considerably harder to identify.

Credential Exposure and Domain Compromise

The later stages of the supplied report demonstrate credential extraction after elevated domain access has been obtained.

Again, the sensitive credential and hash values are intentionally excluded from this article.

The important point is that administrative access increases the attacker’s ability to obtain additional authentication material. Once privileged domain credentials become available, the impact changes dramatically because authentication may extend across the domain rather than remaining limited to a workstation or server.

The report characterizes this stage as domain compromise through credential extraction following the earlier group-membership and ACL path. AD – 10@LoKiTheWar

Domain Controller and KeePass Exposure

The Domain Controller introduces another security issue documented in the report: sensitive credential storage.

A KeePass database is found on the Domain Controller’s desktop. The report explains that storing credential databases on a Domain Controller creates significant exposure because compromise of the DC can provide access to the database itself. AD – 10@LoKiTheWar

The article intentionally does not reproduce the database password or credentials recovered from it.

The security lesson is much more useful:

A password manager does not compensate for unsafe placement of its vault.

Sensitive credential stores should be protected through:

  • strong access controls;
  • appropriately separated administrative systems;
  • strong unique master passwords;
  • controlled backup procedures;
  • monitoring;
  • minimal exposure on critical infrastructure.

A Domain Controller should not become general-purpose storage for sensitive administrative artifacts.

Where SurfaceConditionMove441 Fits

SurfaceConditionMove441 appears within the supplied credential context associated with the Active Directory path.

For security and responsible publication reasons, this article does not reveal whether a supplied string represents a password, recovered secret or other authentication material.

For searchers encountering the term while researching OffSec AD Set V10, its relevance is therefore best understood as part of the credential-discovery and identity progression documented in the environment—not as a secret that needs to be published.

The same treatment applies to BusyOfficeWorker890 and WorkIsValuable444.

This preserves the useful searchable context without publishing reusable authentication material.

What OffSec AD Set V10 Teaches About Active Directory

OffSec AD Set V10 demonstrates several concepts that are more valuable than memorizing the individual hosts.

1. Enumeration Drives the Attack

The chain develops because each compromised context is enumerated before moving forward.

2. Credential Reuse Expands the Blast Radius

Credential material obtained from one system can create lateral access to another.

3. BloodHound Finds Relationships Humans Easily Miss

The v.perry → WriteMembers → Helpdesk Group relationship illustrates why graph-based AD analysis is useful.

4. ACLs Can Be Privilege-Escalation Paths

Direct Domain Admin membership is not required for a dangerous identity.

Control over another AD object may be enough to construct an escalation path.

5. Credential Storage Still Matters After Domain Compromise

The KeePass finding demonstrates how secondary credential stores can increase the impact of already privileged access.

OffSec AD Set V10 Attack Path Explained Simply

For quick reference, the lab can be understood as:

WS26
↓
Initial foothold
↓
Credential discovery
↓
SRV22
↓
Credential reuse / lateral movement
↓
v.perry
↓
BloodHound enumeration
↓
WriteMembers
↓
Helpdesk Group
↓
Privilege escalation
↓
Privileged credential exposure
↓
Domain Controller

That is the central learning path behind OffSec AD Set V10.

The supplied report reaches the same overall conclusion: weak/reused credentials, excessive Active Directory permissions, credential exposure and insecure sensitive-data storage combine into a realistic domain-compromise chain. AD – 10@LoKiTheWar

How to Practice This AD Set Effectively

Do not practice OffSec AD Set V10 by memorizing credentials or copying commands.

Instead, rebuild the reasoning at every transition.

When you reach a workstation, determine why it matters.

When you discover credentials, determine where they might be valid.

When you obtain a domain account, inspect its relationships.

When BloodHound identifies an ACL edge, understand what that permission actually allows.

When privilege increases, re-enumerate.

This approach is much closer to the methodology required in practical penetration testing than simply reproducing a walkthrough.

OffSec’s official PEN-200 material and current OSCP documentation should remain the authoritative reference for current exam rules and objectives. Official OffSec PEN-200 / OSCP information

Prepare for OSCP Active Directory Sets

If you are preparing for OSCP and want additional practice around Active Directory enumeration, credential reuse, lateral movement and attack-path analysis, CyberServices.Store’s OSCP resources can complement your hands-on lab work.

Get OSCP Exam Preparation Material

Use walkthrough-style resources to understand why an attack path works, then reproduce the methodology independently in authorized lab environments.

OffSec AD Set V10 FAQ

What is OffSec AD Set V10?

OffSec AD Set V10 is an Active Directory practice scenario centered on moving from an initial Windows foothold through credential discovery, lateral movement, Active Directory permission analysis and privilege escalation toward domain compromise.

What is SRV22 in the AD Set V10 path?

SRV22 is the Windows server reached after credentials obtained earlier in the chain are reused for lateral movement. Its role demonstrates how credential reuse can expand access beyond the initial workstation.

Why is v.perry important?

The v.perry domain identity becomes important because Active Directory enumeration identifies a WriteMembers relationship involving the Helpdesk group, creating a potential privilege-escalation path.

What does WriteMembers mean in Active Directory?

WriteMembers allows an authorized principal to modify membership of the affected group. If the target group has elevated access, this permission can form part of a privilege-escalation chain.

What is the Helpdesk Group attack path?

In this environment, Active Directory analysis connects a domain user to the Helpdesk group through WriteMembers permissions. Manipulating that relationship expands the user’s effective privileges and contributes to the subsequent escalation path.

Does this article contain the AD Set V10 passwords?

No. Credential strings from the supplied report are deliberately not published as passwords, hashes or reusable secrets. Terms such as BusyOfficeWorker890, WorkIsValuable444 and SurfaceConditionMove441 are retained only as searchable contextual identifiers.

What should I learn from this AD set?

Focus on systematic enumeration, credential reuse, lateral movement, BloodHound analysis, Active Directory ACLs, group membership abuse, credential hygiene and attack-path reasoning rather than memorizing a specific solution.

OffSec AD Set V10 SRV22 Helpdesk Group Active Directory attack path
Limited offer$2,279 $990Save 57%Ends in less than 24 hours

Sitting the OSCP exam?

43 products for the OSCP exam from $125. Walkthroughs, lab sets and ready-to-submit reports, delivered by email within about thirty seconds of payment.

OSCP exam materialHow it works


All OSCP guides

error: Content is protected !!
Contact Us - TG