Valid User (No Password)
Valid User (No Password) techniques and commands for Active Directory security assessment.
Trusts
Trusts techniques and commands for Active Directory security assessment.
SCCM
SCCM techniques and commands for Active Directory security assessment.
Persistence
Persistence techniques and commands for Active Directory security assessment.
Pterodactyl - HTB
Medium Linux box exploiting a Pterodactyl Panel locale RCE, then escalating via polkit/udisks chained CVEs on openSUSE.
Era - HTB
Era is a medium Linux machine that chains an IDOR in a file portal, FTP config exposure, a PHP stream wrapper RCE via file preview, and a signed-binary bypass for root.
Admin Access
Admin Access techniques and commands for Active Directory security assessment.
NanoCorp - HTB
Hard Windows AD chain starting with NTLM leakage via a ZIP upload, then AD privilege hops and a Checkmk Agent MSI repair LPE to SYSTEM.