OffSec Employee: m.hayes, Anonymous FTP, SAM and WinRM Attack Path

OffSec Employee is a Windows machine where a simple service-enumeration mistake—anonymous access to an FTP server—exposes sensitive Windows registry backups and creates a path from unauthenticated access to full administrative compromise.

The supplied assessment shows why OffSec Employee is particularly useful as a methodology exercise. There is no need to begin with an exotic exploit. Instead, the path develops through service enumeration, exposed files, offline credential analysis and an existing Windows management service.

The machine also contains the local account m.hayes, which appears during credential extraction from the exposed registry data. The important lesson, however, is not an individual username or hash. It is understanding how one badly exposed backup can undermine several otherwise separate security controls.

Quick Answer: OffSec Employee exposes FTP on port 21, HTTP on 80, RDP on 3389 and WinRM on 5985. Anonymous FTP access reveals backup copies of the Windows SAM and SYSTEM registry hives. Offline analysis exposes local account credential material, and the Administrator NTLM credential can then be used through WinRM to obtain privileged access.

OffSec Employee Attack Path at a Glance

The PDF documents the following progression:

Nmap Enumeration
↓
Anonymous FTP — Port 21
↓
SAM + SYSTEM Registry Backups
↓
Offline Credential Analysis
↓
Administrator + m.hayes Identified
↓
Administrator NTLM Credential
↓
WinRM — Port 5985
↓
Pass-the-Hash
↓
Administrative Windows Session

This chain is important because OffSec Employee does not depend on breaking several unrelated vulnerabilities.

The initial configuration mistake provides information that makes an already exposed administrative service substantially more dangerous.

OffSec Employee Ports

The supplied report identifies four principal TCP services:

PortServiceSignificance
21Microsoft FTPAnonymous authentication enabled
80HTTPWeb service
3389RDPMicrosoft Remote Desktop
5985WinRMWindows Remote Management

The PDF explicitly identifies anonymous FTP as the primary initial attack vector. 111 -Offsec Employee NEW @Loki…

This is a useful enumeration lesson: an open port alone is not necessarily interesting; its configuration is.

Port 21 becomes more important than simply knowing that an FTP daemon exists because the server permits unauthenticated access.

Port 21: Anonymous FTP Is the Initial Weakness

The first major discovery in OffSec Employee is the Microsoft FTP service.

According to the supplied assessment, anonymous authentication is accepted.

That immediately raises several questions:

  • Which directories can anonymous users access?
  • Are files downloadable?
  • Are backups exposed?
  • Are configuration files present?
  • Is anonymous upload permitted?
  • Do filenames reveal information about the host?

Directory enumeration provides the answer.

The FTP-accessible area contains backup material associated with critical Windows registry hives.

That turns what initially appears to be a relatively simple FTP misconfiguration into a credential-exposure problem.

SAM and SYSTEM Registry Hives

The two important files documented in the PDF are:

SAM

and

SYSTEM

The Windows Security Account Manager contains local account information, while information from the SYSTEM hive is required when recovering locally stored credential material from an offline Windows installation or backup.

The key security problem in OffSec Employee is therefore not that these registry components exist. Every Windows installation needs its security infrastructure.

The problem is that copies of sensitive registry data became downloadable through unauthenticated FTP access.

This distinction matters when reporting the vulnerability.

A better description is:

Unauthenticated Exposure of Sensitive Windows Registry Backups

rather than simply:

SAM File Found

The former describes the security boundary that failed.

Why Registry Backups Are So Sensitive

Backups frequently receive weaker access controls than the live systems from which they originated.

That can be dangerous.

A live registry hive may be protected by Windows access controls while an administrator-created copy stored elsewhere can lose those protections entirely.

In the OffSec Employee scenario, the exposed backup effectively creates an offline credential-analysis opportunity.

Once the relevant files have been downloaded, authentication against the target is no longer required simply to examine them.

This demonstrates a broader penetration-testing principle:

Always enumerate backups, archives, exports and configuration copies with the same attention you give the live application.

Security controls around production data mean little if equivalent sensitive data is publicly accessible somewhere else.

Offline Credential Analysis

The supplied PDF demonstrates offline processing of the downloaded registry hives with Impacket’s secretsdump functionality.

The resulting output identifies several local accounts, including:

  • Administrator
  • Guest
  • m.hayes

The PDF contains actual NTLM values. I am deliberately not reproducing those values here.

For SEO and technical context, m.hayes remains relevant because the username is genuinely present in the supplied assessment. The associated authentication material does not need to be published for the article to explain the attack path.

This is also an important distinction when studying OffSec Employee:

credential discovery does not automatically mean password recovery is required.

Depending on the authentication mechanism available, credential material may itself become useful.

m.hayes in OffSec Employee

The m.hayes account appears among the local account records extracted from the registry data.

This gives us useful host-enumeration information: the target contains an additional named local account alongside built-in Windows accounts.

However, the supplied report does not demonstrate m.hayes as the account ultimately used to establish the privileged WinRM session.

That distinction should remain clear.

The documented administrative path instead relies on credential material belonging to the local Administrator account.

This is why OffSec Employee m.hayes should be treated as an enumeration keyword and account-discovery finding rather than artificially presented as the main privilege-escalation mechanism.

Port 5985: WinRM Changes the Value of the Credential

Credential material becomes considerably more useful when the machine exposes a compatible remote-management interface.

The supplied scan identifies TCP/5985.

Microsoft documents TCP 5985 as the default HTTP port for WinRM 2.0. Microsoft Learn

That makes the relationship between the earlier findings important:

Exposed Registry Backup → Administrator Credential Material → WinRM

None of these findings should be evaluated entirely in isolation.

If WinRM were not remotely accessible, the credential might require a different path.

If credential material had not been exposed, WinRM alone would not provide authentication.

The risk emerges from chaining the conditions.

Pass-the-Hash and Administrative Access

The PDF documents the next stage as Pass-the-Hash authentication through WinRM.

Instead of first recovering the Administrator’s plaintext password, the recovered NTLM credential material is used for authentication.

The resulting remote PowerShell session runs with elevated administrative authority, and the supplied report shows successful verification of the privileged session. 111 -Offsec Employee NEW @Loki…

For OffSec Employee, the conceptual progression is more important than copying the exact command:

Offline credential material → compatible authentication mechanism → remote administrative session

Understanding that relationship transfers to other Windows penetration-testing environments much better than memorizing a single Evil-WinRM command.

Why Password Cracking Was Not Necessary

This is one of the most useful lessons from OffSec Employee.

Finding a password hash often causes candidates to immediately think:

“How do I crack this?”

That is not always the best question.

First ask:

“Can this credential material already be used?”

The PDF specifically notes that cracking the plaintext password was unnecessary because the extracted Administrator credential could be used through the available authentication path.

That saves time and demonstrates better attack-path reasoning.

In practical labs, credentials should therefore trigger another enumeration cycle:

  • What account does this belong to?
  • Is it local or domain-based?
  • Which services accept authentication?
  • What privileges does the account possess?
  • Is remote management exposed?
  • Does the environment permit a hash-based authentication path?

The credential is only one part of the puzzle.

Why Port 3389 Is Not the Primary Route

TCP/3389 indicates Microsoft Remote Desktop.

It is therefore a legitimate enumeration target.

However, the supplied OffSec Employee assessment does not use RDP as the main compromise path.

This is another useful lesson.

Just because a recognizable remote-access service exists does not mean you need to force the attack through it.

The combination of exposed registry credentials and WinRM already provides a cleaner route.

Good penetration testing is not about exploiting every service. It is about identifying the most reliable path that demonstrates the risk.

What About Port 80?

The supplied scan also shows HTTP on TCP/80.

However, the four-page report does not provide enough evidence to claim that the HTTP service is involved in the documented compromise.

Therefore, I would not invent a web vulnerability simply to make the walkthrough longer.

For this specific assessment:

Port 21 is the initial attack surface.

Port 5985 is the remote-management path.

Port 80 remains an enumeration target, but the supplied material does not establish it as part of the successful chain.

That keeps the article aligned with what the PDF actually supports.

OffSec Employee Attack Path Explained

The entire OffSec Employee route can be understood through four security failures or conditions.

1. Anonymous Access

An external or otherwise unauthorized user can access the FTP service without a legitimate account.

2. Sensitive Backup Exposure

The anonymous-accessible location contains copies of critical Windows registry hives.

3. Credential Material Can Be Recovered Offline

The exposed files provide sufficient information to obtain local account authentication material.

4. Remote Management Is Reachable

WinRM is accessible on TCP/5985 and provides a route for privileged remote authentication.

The impact is therefore much greater than the severity of an ordinary anonymous FTP finding.

The full chain turns unauthenticated file access into administrative compromise.

What OffSec Employee Teaches for OSCP Preparation

OffSec Employee is useful because it reinforces several PEN-200/OSCP skills simultaneously.

OffSec’s current authoritative reference list explicitly includes remote-system enumeration and remote-service enumeration under vulnerability identification. Active Directory, privilege escalation and documentation also form substantial parts of the current OSCP+ knowledge domains. OffSec Destek Portalı

The transferable lessons from this machine are straightforward:

Enumerate Before Exploiting

The initial breakthrough comes from understanding how FTP is configured, not from launching a complicated exploit.

Inspect Exposed Files Carefully

Backup files can be more valuable than an immediately exploitable service.

Understand Windows Credential Storage

Knowing why SAM and SYSTEM matter allows you to recognize the significance of exposed registry copies.

Re-enumerate After Obtaining Credentials

Credential discovery should trigger another review of exposed authentication services.

Don’t Crack Something You Can Already Use

Before spending time recovering plaintext, determine whether the credential representation itself is sufficient for an authorized lab authentication workflow.

Think in Chains

The machine is not:

FTP vulnerability + credential vulnerability + WinRM vulnerability

as three unrelated findings.

It is:

FTP exposure → sensitive backups → credential material → remote administration

That is the real attack path.

Defensive Lessons from OffSec Employee

The supplied PDF recommends several remediation measures, and these align well with current Windows security guidance.

First, anonymous FTP should be disabled when there is no explicit business requirement for it. Sensitive backups should never be stored in anonymously readable directories.

Second, access to registry backups such as SAM and SYSTEM copies should be tightly restricted.

Third, local Administrator passwords should be unique across endpoints.

Microsoft specifically warns that identical local-account passwords increase risk and recommends password randomization to mitigate Pass-the-Hash movement. Windows LAPS is Microsoft’s built-in mechanism for managing and rotating local administrator credentials. Microsoft Learn

Microsoft Windows LAPS documentation

Finally, WinRM exposure should be restricted to appropriate management networks and authorized administrative hosts rather than being unnecessarily reachable.

These mitigations attack different stages of the chain. Breaking even one of them can materially reduce the likelihood of the complete compromise path.

Practice OffSec Employee as a Methodology Exercise

When practicing OffSec Employee, avoid reducing the machine to:

anonymous FTP → download two files → run a tool → log in.

Instead, reproduce the reasoning.

Why is anonymous FTP dangerous?

Why are these particular files sensitive?

What information can be derived from them?

Why does port 5985 suddenly matter after credential discovery?

Why might cracking be unnecessary?

Which security control would have stopped the chain earliest?

Those questions build reusable penetration-testing methodology.

OffSec’s PEN-200 resources remain the authoritative reference for current OSCP preparation and exam-related expectations.

Official OffSec PEN-200 resources

Prepare for More OffSec Standalone Machines

If you’re using OffSec Employee as part of your OSCP preparation, additional standalone-machine practice can help reinforce Windows enumeration, credential analysis, privilege escalation and attack-path reasoning.

Get OSCP Exam Preparation Material

The objective should be to understand why each finding changes the next enumeration decision rather than memorize a machine-specific sequence.

OffSec Employee FAQ

What is OffSec Employee?

OffSec Employee is a Windows practice machine where anonymous FTP exposes sensitive registry backups. Analysis of the exposed SAM and SYSTEM data leads to local credential material that can be combined with the target’s WinRM service to obtain privileged access.

What ports are open on OffSec Employee?

The supplied assessment identifies TCP ports 21, 80, 3389 and 5985, corresponding to FTP, HTTP, RDP and WinRM-related functionality.

Who is m.hayes?

m.hayes is a local Windows account identified during offline analysis of the registry data in the supplied report. The documented final administrative-access path uses the local Administrator credential rather than presenting m.hayes as the primary compromise account.

Why are SAM and SYSTEM important?

The exposed registry hives contain information relevant to local Windows account authentication. When appropriate registry data is available offline, credential material associated with local accounts may be recovered without interacting with the live authentication process.

Does OffSec Employee require password cracking?

The supplied attack path does not require recovery of the Administrator plaintext password. The report instead demonstrates a hash-based authentication path using the credential material recovered from the registry backups.

Why is WinRM port 5985 important?

WinRM 2.0 uses TCP/5985 as its default HTTP port. In this scenario, the reachable WinRM service provides the remote-management channel that becomes useful after Administrator credential material is obtained. Microsoft Learn

Is RDP used to compromise OffSec Employee?

The supplied report identifies RDP on port 3389 but does not use it as the primary successful attack path. The documented route uses anonymous FTP, offline credential analysis and WinRM.

What is the main lesson from OffSec Employee?

The main lesson is attack chaining. Anonymous FTP alone is one issue, but when it exposes sensitive registry backups and the target also exposes remote administration, the combined conditions can turn unauthenticated file access into administrative compromise.

OffSec Employee m.hayes anonymous FTP SAM SYSTEM and WinRM attack path
Limited offer$2,279 $990Save 57%Ends in less than 24 hours

Sitting the OSCP exam?

43 products for the OSCP exam from $125. Walkthroughs, lab sets and ready-to-submit reports, delivered by email within about thirty seconds of payment.

OSCP exam materialHow it works


All OSCP guides

error: Content is protected !!
Contact Us - TG