Fluffy
An assume-breach Windows AD box where a writable SMB share lets you plant a malicious .library-ms ZIP (CVE-2025-24071) to coerce a user's NetNTLMv2 hash; cracking it and abusing a GenericAll/GenericWrite ACL chain via shadow credentials yields a service account with WinRM access and the user flag.