Welcome to Game of Active Directory (GOAD). While HBO has long abandoned Jon Snow, Arya Stark, and Daenerys Targaryen for new spinoffs, we’re putting them right to work inside an intentionally vulnerable Active Directory forest: sevenkingdoms.local, complete with north and essos domains.
In this walkthrough, we launch a full assault on the Seven Kingdoms. From Null Sessions and PrintNightmare to Child-to-Parent Trust Exploitation and forging Golden Tickets, we will systematically dominate Westeros — no dragons required.
The Wall: Initial Access Vectors
Our journey begins on the Kali infrastructure at 192.168.56.2. After pulling down the Mythic C2 framework, compiling GodPotato, and launching our HTTP servers, we hunt for our first foothold in the North.
We discover that north-mgmt (192.168.56.11) allows unauthenticated SMB guest access. Running smbclient reveals sensitive shares.
north-web01 is vulnerable to PrintNightmare (CVE-2021-1675). Delivering a malicious DLL directly downloads our Mythic stager as NT AUTHORITY\SYSTEM.
Mythic Stager & Situational Awareness
Once our Apollo agent checks into the Mythic UI, it’s time to see who is actually living in these domains.
shell net user /domain reveals our old friends: arya.stark, jon.snow, sansa.stark, samwell.tarly, tyrion.lannister, hodor, and daenerys.targaryen. HBO might have written them off, but they are fully active in our AD environment.
We deploy BloodHound (SharpHound) across the three domains (north.sevenkingdoms.local, child.sevenkingdoms.local, essos.local) to map out exactly how we can backstab our way to the Iron Throne.
The Kingslayer: Privilege Escalation
On north-web01, operating as the IIS app pool identity, we notice the coveted SeImpersonatePrivilege. It’s time to escalate using GodPotato.
With SYSTEM privileges secured, we wrap Mimikatz commands in GodPotato to extract SAM hashes, LSA secrets, and DPAPI keys.
Red Wedding: Child-to-Parent Escalation
The signature GOAD attack path mimics political betrayal: we will use a child domain compromise to hijack the root domain.
By dumping the krbtgt hash from child.sevenkingdoms.local, we forge an Inter-Realm TGT. We maliciously append the Enterprise Admins SID (S-1-5-21-<PARENT_SID>-519) of the parent domain (north.sevenkingdoms.local) via the /sids flag in Mimikatz.
north-dc01) with full administrative rights.
The Long Night: AS-REP & Kerberoasting
Not satisfied with just the North, we want Essos. We look for the weak links. We find that hodor and arya.stark have DONT_REQ_PREAUTH set.
With the extracted hashes, Hashcat makes quick work of them, revealing the plaintext passwords. To secure ultimate persistence across all domains, we perform a full NTDS.dit extraction and deploy Golden Tickets spanning north, child, and essos.
👑 Conclusion: Winter Has Come
By systematically chaining misconfigurations—from unauthenticated SMB null sessions to exploiting SID History in domain trusts—we have conquered the entire GOAD forest.
HBO may not be using the original Game of Thrones characters, but in the world of Active Directory penetration testing, they still provide an incredibly robust (and highly vulnerable) playground for refining our offensive tradecraft.
The Iron Throne is officially ours. NT AUTHORITY\SYSTEM reigns supreme.