HTB: Cicada

Active Directory machine demonstrating exposed SMB data, credential reuse, and Backup Operators abuse to dump domain hashes.

November 7, 2025 · 6 min

HTB: Blackfield

Active Directory machine demonstrating AS-REP Roasting, BloodHound-driven lateral movement, LSASS credential extraction, and Backup Operators abuse.

November 4, 2025 · 7 min

HTB: Monteverde

Azure AD Connect misconfiguration leading to credential extraction and domain compromise.

October 27, 2025 · 5 min

HTB: Active

Classic Active Directory machine demonstrating GPP credential exposure leading to Kerberoasting and domain compromise.

October 17, 2025 · 4 min