Operation Cypher-Knife · Full AD Takeover

Game of Active Directory:
The Old Gods and the New

HBO might have moved on from the original Game of Thrones cast for House of the Dragon, but we haven't. They're all fully employed in our Active Directory lab — and they're about to have a very bad day.

Domain Pwned Topology: north · child · essos Target: sevenkingdoms.local 2026

Welcome to Game of Active Directory (GOAD). While HBO has long abandoned Jon Snow, Arya Stark, and Daenerys Targaryen for new spinoffs, we’re putting them right to work inside an intentionally vulnerable Active Directory forest: sevenkingdoms.local, complete with north and essos domains.

In this walkthrough, we launch a full assault on the Seven Kingdoms. From Null Sessions and PrintNightmare to Child-to-Parent Trust Exploitation and forging Golden Tickets, we will systematically dominate Westeros — no dragons required.

01

The Wall: Initial Access Vectors

Our journey begins on the Kali infrastructure at 192.168.56.2. After pulling down the Mythic C2 framework, compiling GodPotato, and launching our HTTP servers, we hunt for our first foothold in the North.

We discover that north-mgmt (192.168.56.11) allows unauthenticated SMB guest access. Running smbclient reveals sensitive shares.

smbget -R smb://192.168.56.11/Share -U guest%
SMB Null Session
Pillaging the North's unauthenticated SMB shares for hardcoded credentials.
🐉
PrintNightmare on north-web01 In parallel, we detect north-web01 is vulnerable to PrintNightmare (CVE-2021-1675). Delivering a malicious DLL directly downloads our Mythic stager as NT AUTHORITY\SYSTEM.
02

Mythic Stager & Situational Awareness

Once our Apollo agent checks into the Mythic UI, it’s time to see who is actually living in these domains.

🐺
Checking the Roster Running shell net user /domain reveals our old friends: arya.stark, jon.snow, sansa.stark, samwell.tarly, tyrion.lannister, hodor, and daenerys.targaryen. HBO might have written them off, but they are fully active in our AD environment.

We deploy BloodHound (SharpHound) across the three domains (north.sevenkingdoms.local, child.sevenkingdoms.local, essos.local) to map out exactly how we can backstab our way to the Iron Throne.

03

The Kingslayer: Privilege Escalation

On north-web01, operating as the IIS app pool identity, we notice the coveted SeImpersonatePrivilege. It’s time to escalate using GodPotato.

execute-assembly GodPotato.exe -cmd "cmd /c whoami"
GodPotato execution
Executing GodPotato instantly elevates our session to NT AUTHORITY\SYSTEM.

With SYSTEM privileges secured, we wrap Mimikatz commands in GodPotato to extract SAM hashes, LSA secrets, and DPAPI keys.

04

Red Wedding: Child-to-Parent Escalation

The signature GOAD attack path mimics political betrayal: we will use a child domain compromise to hijack the root domain.

By dumping the krbtgt hash from child.sevenkingdoms.local, we forge an Inter-Realm TGT. We maliciously append the Enterprise Admins SID (S-1-5-21-<PARENT_SID>-519) of the parent domain (north.sevenkingdoms.local) via the /sids flag in Mimikatz.

⚔️
SID History Injection Injecting the parent’s Enterprise Admin SID into our child Golden Ticket allows us to immediately bypass trust boundaries and access the root DC (north-dc01) with full administrative rights.
05

The Long Night: AS-REP & Kerberoasting

Not satisfied with just the North, we want Essos. We look for the weak links. We find that hodor and arya.stark have DONT_REQ_PREAUTH set.

execute-assembly Rubeus.exe asreproast /domain:north.sevenkingdoms.local
AS-REP Roasting
Retrieving the AS-REP hashes. Hodor is easily cracked with rockyou.txt.

With the extracted hashes, Hashcat makes quick work of them, revealing the plaintext passwords. To secure ultimate persistence across all domains, we perform a full NTDS.dit extraction and deploy Golden Tickets spanning north, child, and essos.

👑 Conclusion: Winter Has Come

By systematically chaining misconfigurations—from unauthenticated SMB null sessions to exploiting SID History in domain trusts—we have conquered the entire GOAD forest.

HBO may not be using the original Game of Thrones characters, but in the world of Active Directory penetration testing, they still provide an incredibly robust (and highly vulnerable) playground for refining our offensive tradecraft.

The Iron Throne is officially ours. NT AUTHORITY\SYSTEM reigns supreme.