OffSec Employee is a Windows machine where a simple service-enumeration mistake—anonymous access to an FTP server—exposes sensitive Windows registry backups and creates a path from unauthenticated access to full administrative compromise.
The supplied assessment shows why OffSec Employee is particularly useful as a methodology exercise. There is no need to begin with an exotic exploit. Instead, the path develops through service enumeration, exposed files, offline credential analysis and an existing Windows management service.
The machine also contains the local account m.hayes, which appears during credential extraction from the exposed registry data. The important lesson, however, is not an individual username or hash. It is understanding how one badly exposed backup can undermine several otherwise separate security controls.
Quick Answer: OffSec Employee exposes FTP on port 21, HTTP on 80, RDP on 3389 and WinRM on 5985. Anonymous FTP access reveals backup copies of the Windows SAM and SYSTEM registry hives. Offline analysis exposes local account credential material, and the Administrator NTLM credential can then be used through WinRM to obtain privileged access.
OffSec Employee Attack Path at a Glance
The PDF documents the following progression:
Nmap Enumeration
↓
Anonymous FTP — Port 21
↓
SAM + SYSTEM Registry Backups
↓
Offline Credential Analysis
↓
Administrator + m.hayes Identified
↓
Administrator NTLM Credential
↓
WinRM — Port 5985
↓
Pass-the-Hash
↓
Administrative Windows Session
This chain is important because OffSec Employee does not depend on breaking several unrelated vulnerabilities.
The initial configuration mistake provides information that makes an already exposed administrative service substantially more dangerous.
OffSec Employee Ports
The supplied report identifies four principal TCP services:
| Port | Service | Significance |
|---|---|---|
| 21 | Microsoft FTP | Anonymous authentication enabled |
| 80 | HTTP | Web service |
| 3389 | RDP | Microsoft Remote Desktop |
| 5985 | WinRM | Windows Remote Management |
The PDF explicitly identifies anonymous FTP as the primary initial attack vector. 111 -Offsec Employee NEW @Loki…
This is a useful enumeration lesson: an open port alone is not necessarily interesting; its configuration is.
Port 21 becomes more important than simply knowing that an FTP daemon exists because the server permits unauthenticated access.
Port 21: Anonymous FTP Is the Initial Weakness
The first major discovery in OffSec Employee is the Microsoft FTP service.
According to the supplied assessment, anonymous authentication is accepted.
That immediately raises several questions:
- Which directories can anonymous users access?
- Are files downloadable?
- Are backups exposed?
- Are configuration files present?
- Is anonymous upload permitted?
- Do filenames reveal information about the host?
Directory enumeration provides the answer.
The FTP-accessible area contains backup material associated with critical Windows registry hives.
That turns what initially appears to be a relatively simple FTP misconfiguration into a credential-exposure problem.
SAM and SYSTEM Registry Hives
The two important files documented in the PDF are:
SAM
and
SYSTEM
The Windows Security Account Manager contains local account information, while information from the SYSTEM hive is required when recovering locally stored credential material from an offline Windows installation or backup.
The key security problem in OffSec Employee is therefore not that these registry components exist. Every Windows installation needs its security infrastructure.
The problem is that copies of sensitive registry data became downloadable through unauthenticated FTP access.
This distinction matters when reporting the vulnerability.
A better description is:
Unauthenticated Exposure of Sensitive Windows Registry Backups
rather than simply:
SAM File Found
The former describes the security boundary that failed.
Why Registry Backups Are So Sensitive
Backups frequently receive weaker access controls than the live systems from which they originated.
That can be dangerous.
A live registry hive may be protected by Windows access controls while an administrator-created copy stored elsewhere can lose those protections entirely.
In the OffSec Employee scenario, the exposed backup effectively creates an offline credential-analysis opportunity.
Once the relevant files have been downloaded, authentication against the target is no longer required simply to examine them.
This demonstrates a broader penetration-testing principle:
Always enumerate backups, archives, exports and configuration copies with the same attention you give the live application.
Security controls around production data mean little if equivalent sensitive data is publicly accessible somewhere else.
Offline Credential Analysis
The supplied PDF demonstrates offline processing of the downloaded registry hives with Impacket’s secretsdump functionality.
The resulting output identifies several local accounts, including:
- Administrator
- Guest
m.hayes
The PDF contains actual NTLM values. I am deliberately not reproducing those values here.
For SEO and technical context, m.hayes remains relevant because the username is genuinely present in the supplied assessment. The associated authentication material does not need to be published for the article to explain the attack path.
This is also an important distinction when studying OffSec Employee:
credential discovery does not automatically mean password recovery is required.
Depending on the authentication mechanism available, credential material may itself become useful.
m.hayes in OffSec Employee
The m.hayes account appears among the local account records extracted from the registry data.
This gives us useful host-enumeration information: the target contains an additional named local account alongside built-in Windows accounts.
However, the supplied report does not demonstrate m.hayes as the account ultimately used to establish the privileged WinRM session.
That distinction should remain clear.
The documented administrative path instead relies on credential material belonging to the local Administrator account.
This is why OffSec Employee m.hayes should be treated as an enumeration keyword and account-discovery finding rather than artificially presented as the main privilege-escalation mechanism.
Port 5985: WinRM Changes the Value of the Credential
Credential material becomes considerably more useful when the machine exposes a compatible remote-management interface.
The supplied scan identifies TCP/5985.
Microsoft documents TCP 5985 as the default HTTP port for WinRM 2.0. Microsoft Learn
That makes the relationship between the earlier findings important:
Exposed Registry Backup → Administrator Credential Material → WinRM
None of these findings should be evaluated entirely in isolation.
If WinRM were not remotely accessible, the credential might require a different path.
If credential material had not been exposed, WinRM alone would not provide authentication.
The risk emerges from chaining the conditions.
Pass-the-Hash and Administrative Access
The PDF documents the next stage as Pass-the-Hash authentication through WinRM.
Instead of first recovering the Administrator’s plaintext password, the recovered NTLM credential material is used for authentication.
The resulting remote PowerShell session runs with elevated administrative authority, and the supplied report shows successful verification of the privileged session. 111 -Offsec Employee NEW @Loki…
For OffSec Employee, the conceptual progression is more important than copying the exact command:
Offline credential material → compatible authentication mechanism → remote administrative session
Understanding that relationship transfers to other Windows penetration-testing environments much better than memorizing a single Evil-WinRM command.
Why Password Cracking Was Not Necessary
This is one of the most useful lessons from OffSec Employee.
Finding a password hash often causes candidates to immediately think:
“How do I crack this?”
That is not always the best question.
First ask:
“Can this credential material already be used?”
The PDF specifically notes that cracking the plaintext password was unnecessary because the extracted Administrator credential could be used through the available authentication path.
That saves time and demonstrates better attack-path reasoning.
In practical labs, credentials should therefore trigger another enumeration cycle:
- What account does this belong to?
- Is it local or domain-based?
- Which services accept authentication?
- What privileges does the account possess?
- Is remote management exposed?
- Does the environment permit a hash-based authentication path?
The credential is only one part of the puzzle.
Why Port 3389 Is Not the Primary Route
TCP/3389 indicates Microsoft Remote Desktop.
It is therefore a legitimate enumeration target.
However, the supplied OffSec Employee assessment does not use RDP as the main compromise path.
This is another useful lesson.
Just because a recognizable remote-access service exists does not mean you need to force the attack through it.
The combination of exposed registry credentials and WinRM already provides a cleaner route.
Good penetration testing is not about exploiting every service. It is about identifying the most reliable path that demonstrates the risk.
What About Port 80?
The supplied scan also shows HTTP on TCP/80.
However, the four-page report does not provide enough evidence to claim that the HTTP service is involved in the documented compromise.
Therefore, I would not invent a web vulnerability simply to make the walkthrough longer.
For this specific assessment:
Port 21 is the initial attack surface.
Port 5985 is the remote-management path.
Port 80 remains an enumeration target, but the supplied material does not establish it as part of the successful chain.
That keeps the article aligned with what the PDF actually supports.
OffSec Employee Attack Path Explained
The entire OffSec Employee route can be understood through four security failures or conditions.
1. Anonymous Access
An external or otherwise unauthorized user can access the FTP service without a legitimate account.
2. Sensitive Backup Exposure
The anonymous-accessible location contains copies of critical Windows registry hives.
3. Credential Material Can Be Recovered Offline
The exposed files provide sufficient information to obtain local account authentication material.
4. Remote Management Is Reachable
WinRM is accessible on TCP/5985 and provides a route for privileged remote authentication.
The impact is therefore much greater than the severity of an ordinary anonymous FTP finding.
The full chain turns unauthenticated file access into administrative compromise.
What OffSec Employee Teaches for OSCP Preparation
OffSec Employee is useful because it reinforces several PEN-200/OSCP skills simultaneously.
OffSec’s current authoritative reference list explicitly includes remote-system enumeration and remote-service enumeration under vulnerability identification. Active Directory, privilege escalation and documentation also form substantial parts of the current OSCP+ knowledge domains. OffSec Destek Portalı
The transferable lessons from this machine are straightforward:
Enumerate Before Exploiting
The initial breakthrough comes from understanding how FTP is configured, not from launching a complicated exploit.
Inspect Exposed Files Carefully
Backup files can be more valuable than an immediately exploitable service.
Understand Windows Credential Storage
Knowing why SAM and SYSTEM matter allows you to recognize the significance of exposed registry copies.
Re-enumerate After Obtaining Credentials
Credential discovery should trigger another review of exposed authentication services.
Don’t Crack Something You Can Already Use
Before spending time recovering plaintext, determine whether the credential representation itself is sufficient for an authorized lab authentication workflow.
Think in Chains
The machine is not:
FTP vulnerability + credential vulnerability + WinRM vulnerability
as three unrelated findings.
It is:
FTP exposure → sensitive backups → credential material → remote administration
That is the real attack path.
Defensive Lessons from OffSec Employee
The supplied PDF recommends several remediation measures, and these align well with current Windows security guidance.
First, anonymous FTP should be disabled when there is no explicit business requirement for it. Sensitive backups should never be stored in anonymously readable directories.
Second, access to registry backups such as SAM and SYSTEM copies should be tightly restricted.
Third, local Administrator passwords should be unique across endpoints.
Microsoft specifically warns that identical local-account passwords increase risk and recommends password randomization to mitigate Pass-the-Hash movement. Windows LAPS is Microsoft’s built-in mechanism for managing and rotating local administrator credentials. Microsoft Learn
Microsoft Windows LAPS documentation
Finally, WinRM exposure should be restricted to appropriate management networks and authorized administrative hosts rather than being unnecessarily reachable.
These mitigations attack different stages of the chain. Breaking even one of them can materially reduce the likelihood of the complete compromise path.
Practice OffSec Employee as a Methodology Exercise
When practicing OffSec Employee, avoid reducing the machine to:
anonymous FTP → download two files → run a tool → log in.
Instead, reproduce the reasoning.
Why is anonymous FTP dangerous?
Why are these particular files sensitive?
What information can be derived from them?
Why does port 5985 suddenly matter after credential discovery?
Why might cracking be unnecessary?
Which security control would have stopped the chain earliest?
Those questions build reusable penetration-testing methodology.
OffSec’s PEN-200 resources remain the authoritative reference for current OSCP preparation and exam-related expectations.
Official OffSec PEN-200 resources
Prepare for More OffSec Standalone Machines
If you’re using OffSec Employee as part of your OSCP preparation, additional standalone-machine practice can help reinforce Windows enumeration, credential analysis, privilege escalation and attack-path reasoning.
Get OSCP Exam Preparation Material
The objective should be to understand why each finding changes the next enumeration decision rather than memorize a machine-specific sequence.
OffSec Employee FAQ
What is OffSec Employee?
OffSec Employee is a Windows practice machine where anonymous FTP exposes sensitive registry backups. Analysis of the exposed SAM and SYSTEM data leads to local credential material that can be combined with the target’s WinRM service to obtain privileged access.
What ports are open on OffSec Employee?
The supplied assessment identifies TCP ports 21, 80, 3389 and 5985, corresponding to FTP, HTTP, RDP and WinRM-related functionality.
Who is m.hayes?
m.hayes is a local Windows account identified during offline analysis of the registry data in the supplied report. The documented final administrative-access path uses the local Administrator credential rather than presenting m.hayes as the primary compromise account.
Why are SAM and SYSTEM important?
The exposed registry hives contain information relevant to local Windows account authentication. When appropriate registry data is available offline, credential material associated with local accounts may be recovered without interacting with the live authentication process.
Does OffSec Employee require password cracking?
The supplied attack path does not require recovery of the Administrator plaintext password. The report instead demonstrates a hash-based authentication path using the credential material recovered from the registry backups.
Why is WinRM port 5985 important?
WinRM 2.0 uses TCP/5985 as its default HTTP port. In this scenario, the reachable WinRM service provides the remote-management channel that becomes useful after Administrator credential material is obtained. Microsoft Learn
Is RDP used to compromise OffSec Employee?
The supplied report identifies RDP on port 3389 but does not use it as the primary successful attack path. The documented route uses anonymous FTP, offline credential analysis and WinRM.
What is the main lesson from OffSec Employee?
The main lesson is attack chaining. Anonymous FTP alone is one issue, but when it exposes sensitive registry backups and the target also exposes remote administration, the combined conditions can turn unauthenticated file access into administrative compromise.
