L3 — Coercion to Identity
Mission
Run AD CS ESC8 end to end: coerce a domain controller into authenticating to you as its machine account, relay that authentication into the certificate authority's web enrollment, and walk out holding a certificate minted in the DC's name. Use it to act as the domain controller you never owned.
Why this matters in 2026
Coercion-plus-relay into web enrollment is the live ESC8 path that turns one unauthenticated foothold into domain-controller-grade identity, and it remains one of the highest-impact misconfigurations in real Active Directory estates.
SSH Access
Host204.168.229.209 · Port 2247 · User specter3 · Password your L2 flagssh [email protected] -p 2247Clear L2 first, then paste the flag you recovered there at the SSH password prompt — the chain carries you forward. Each connection spawns a fresh ephemeral container — no shared shell, no cross-player residue. Disconnect tears it down.
Submit Flag
Log in to submit. Flag formatbl_spct2_l3_…