HTB: Bounty

Windows machine demonstrating IIS upload bypass with web.config abuse and kernel exploit privilege escalation.

March 1, 2026 · 5 min

HTB: Flight

Active Directory machine demonstrating NTLM hash capture, SMB abuse, password reuse, IIS pivoting, and SeImpersonatePrivilege escalation.

November 1, 2025 · 9 min

VulnLab: Lock

Windows machine demonstrating Gitea access token exposure, repository-backed web deployment, mRemoteNG credential recovery, and PDF24 local privilege escalation.

October 16, 2025 · 7 min

VulnLab: Job

Windows machine demonstrating phishing through a malicious LibreOffice document, IIS web root abuse, SeImpersonatePrivilege, and local administrator access through GodPotato and RunasCs.

October 13, 2025 · 6 min