DarkZeroReturns - HTB
A two-forest Active Directory maze that only starts at a Node.js web app.
Logging - HTB
Logging starts with a routine Active Directory assessment, where seemingly ordinary artifacts and a bit of intuition gradually reveal a chain of misconfigurations leading to full compromise.
Silentium - HTB
An easy Linux machine featuring web enumeration, password reset vulnerability, container escaping, and internal service access.
DevArea - HTB
A medium-difficulty Linux machine featuring SOAP services, middleware exploitation, and multiple privilege escalation vectors.
Puppy - HTB
A medium Windows Active Directory machine featuring SMB enumeration, KeePass database attack, privilege delegation abuse, and DPAPI credential theft for domain compromise.
Codetwo - HTB
Easy Linux box with a vulnerable js2py sandbox in a web editor, followed by DB hash cracking and npbackup-cli abuse for root.
Pirate - HTB
Windows Active Directory challenge centered on delegation, Kerberos, and privilege escalation workflows.
Editor - HTB
Easy Linux machine with XWiki Groovy RCE (CVE-2025-24893), credential reuse, and netdata SUID PATH hijacking for root.