HackTheBox Pro Lab: Klendathu — Terraform State Exfil, AWS SSRF & AD Golden Ticket

Complete walkthrough of HackTheBox Klendathu Pro Lab — exploiting an exposed Terraform state file for cloud credentials, AWS IMDSv1 SSRF to steal EC2 IAM role tokens, lateral movement into hybrid AD via AWS SSO, and forging a Golden Ticket for complete domain persistence.

lazyhackers
Mar 28, 2026 · 1 min read · 0 views

Related Articles