VulnLab: Breach

Active Directory machine demonstrating NTLM hash capture through a writable SMB share, Kerberoasting, MSSQL Silver Ticket abuse, and SeImpersonatePrivilege escalation.

March 23, 2026 · 7 min

VulnLab: Baby2

Active Directory machine demonstrating SMB user enumeration, weak password reuse, writable logon script abuse, and GPO-based privilege escalation.

March 22, 2026 · 8 min

VulnLab: Baby

Active Directory machine demonstrating anonymous LDAP enumeration, password reset abuse, SeRestorePrivilege execution, and manual NTDS extraction.

March 21, 2026 · 6 min

HTB: Escape

Active Directory machine demonstrating MSSQL abuse leading to credential leakage and AD CS certificate abuse for full domain compromise.

November 9, 2025 · 7 min

HTB: Cicada

Active Directory machine demonstrating exposed SMB data, credential reuse, and Backup Operators abuse to dump domain hashes.

November 7, 2025 · 6 min

HTB: Forest

Active Directory machine demonstrating anonymous LDAP enumeration, AS-REP Roasting, nested group abuse, and DCSync-based domain compromise.

November 5, 2025 · 6 min

HTB: Return

Active Directory machine demonstrating LDAP credential capture through a printer admin panel, WinRM access, and Server Operators abuse leading to DCSync.

November 5, 2025 · 4 min

HTB: Blackfield

Active Directory machine demonstrating AS-REP Roasting, BloodHound-driven lateral movement, LSASS credential extraction, and Backup Operators abuse.

November 4, 2025 · 7 min

HTB: Flight

Active Directory machine demonstrating NTLM hash capture, SMB abuse, password reuse, IIS pivoting, and SeImpersonatePrivilege escalation.

November 1, 2025 · 9 min

HTB: Timelapse

Active Directory machine demonstrating exposed SMB backups, certificate-based WinRM access, PowerShell history credential discovery, and LAPS abuse.

October 31, 2025 · 5 min