DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
MonitorsFour - HTB
Easy Windows host running Cacti in Docker. Exploit Cacti auth RCE, then escape Docker Desktop via its exposed API to reach the host.
Era - HTB
Medium Linux machine with IDOR, FTP config exposure, PHP stream wrapper RCE, and signed-binary bypass privesc.
SCCM
SCCM techniques and commands for Active Directory security assessment.
Cobblestone - HTB
Linux target with SQL injection in a voting app, webshell access, local credential harvesting, and Cobbler XML-RPC abuse to read root files.