DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Fluffy - HTB
Easy Windows AD chain starting from provided creds, NTLM capture via CVE-2025-24071, shadow credentials to WinRM, then ADCS abuse to Administrator.
Domain Admin
Domain Admin techniques and commands for Active Directory security assessment.
Previous - HTB
Medium Linux box using Next.js auth middleware bypass, LFI to extract NextAuth credentials, and Terraform provider override abuse for root.
BigBang - HTB
Hard Linux box chaining WordPress LFI, DB creds, Grafana hash cracking, and an Android API command injection for root.