HTB: Monteverde

Azure AD Connect misconfiguration leading to credential extraction and domain compromise.

October 27, 2025 · 5 min

HTB: Sauna

Active Directory machine demonstrating username generation, AS-REP Roasting, AutoLogon credential discovery, and DCSync-based domain compromise.

October 27, 2025 · 5 min

HTB: Active

Classic Active Directory machine demonstrating GPP credential exposure leading to Kerberoasting and domain compromise.

October 17, 2025 · 4 min

VulnLab: Lock

Windows machine demonstrating Gitea access token exposure, repository-backed web deployment, mRemoteNG credential recovery, and PDF24 local privilege escalation.

October 16, 2025 · 7 min

VulnLab: Job2

Windows machine demonstrating macro-based phishing, hMailServer database credential recovery, lateral movement over RDP, and Veeam Backup exploitation.

October 15, 2025 · 8 min

VulnLab: Job

Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.

October 13, 2025 · 6 min

VulnLab: Escape

Windows kiosk-style machine demonstrating RDP access, file-system browsing through Edge, binary restriction bypass via renaming, password recovery from Remote Desktop Plus, and GUI-based UAC elevation.

October 12, 2025 · 6 min

VulnLab: Data

Linux machine demonstrating Grafana arbitrary file read, Grafana credential cracking, SSH access, and Docker privileged container abuse.

May 20, 2025 · 6 min

VulnLab: Sync

Linux machine demonstrating anonymous rsync access, salted MD5 cracking, FTP-based SSH key placement, password reuse, and cronjob abuse.

May 12, 2025 · 5 min