Pirate - HTB
Windows Active Directory challenge centered on delegation, Kerberos, and privilege escalation workflows.
Valid User (No Password)
Valid User (No Password) techniques and commands for Active Directory security assessment.
Trusts
Trusts techniques and commands for Active Directory security assessment.
SCCM
SCCM techniques and commands for Active Directory security assessment.
Interpreter - HTB
Medium Linux box exploiting Mirth Connect pre‑auth RCE, cracking DB hashes for SSH, then abusing a root Flask service with eval-based SSTI.
Lateral Movement
Lateral Movement techniques and commands for Active Directory security assessment.
TombWatcher - HTB
Active Directory chain using delegated rights to roast and pivot between users, recover gMSA secrets, and abuse ADCS/OU permissions to obtain Administrator access.
Soulmate - HTB
Easy Linux machine using CrushFTP auth bypass for admin access, webshell upload, leaked Erlang creds, and an Erlang SSH service to read root files.