HackPath

Master the Art of Penetration Testing

Your Guide Through Every Challenge

Comprehensive walkthroughs, detailed explanations, and practical insights for CTF challenges across multiple platforms. Level up your cybersecurity skills one machine at a time.

Everything You Need to Succeed

Designed with both beginners and advanced practitioners in mind

Detailed Walkthroughs

Step-by-step guides with commands, screenshots, and comprehensive explanations for every challenge.

Active Machine Protection

Spoiler protection for active CTF challenges with smart lock system during competition periods.

Smart Search & Filters

Find walkthroughs by platform, difficulty, tags, or search terms to quickly locate what you need.

Recent Walkthroughs

Latest challenges solved and documented

View All
TombWatcher - HackTheBox
HackTheBox Medium

TombWatcher - HackTheBox

A full walkthrough of TombWatcher (HTB) from a targeted Kerberoast all the way to Domain Admin via a chained ESC15 → ESC3 ADCS exploit, with a deleted-object restoration twist in the middle.

#ADCS #Active Directory #BloodHound
Aug 10, 2026 Read more →
Wingdata - HackTheBox
HackTheBox Easy

Wingdata - HackTheBox

Easy-difficulty Linux box featuring CVE-2025-47812 unauthenticated RCE against Wing FTP Server 7.4.3 for initial access, offline cracking of a salted SHA-256 password hash for lateral movement, and CVE-2025-4517 PATH_MAX tarfile bypass via a malicious tarball to escalate privileges to root.

#CVE-2025-4517 #CVE-2025-47812 #Hash Cracking
Aug 08, 2026 Read more →
Overthewire - Bandit 5-9
OverTheWire Easy

Overthewire - Bandit 5-9

Master advanced Linux commands with OverTheWire Bandit Part 2 (Levels 5-9). Learn find with multiple criteria, grep for pattern matching, sort & uniq for data processing, and strings for binary file analysis. Includes regex basics!

#Bandit #Linux #Regex
Apr 16, 2026 Read more →
Overthewire - Bandit 0-4
OverTheWire Easy

Overthewire - Bandit 0-4

Master essential Linux commands through OverTheWire Bandit Levels 0-4. Learn to handle dashed filenames, spaces in filenames, hidden files, and file type detection. Beginner-friendly with practical examples and multiple solution methods.

#Bandit #Linux #Wargames
Apr 16, 2026 Read more →
Jeeves - HackTheBox
HackTheBox Medium

Jeeves - HackTheBox

Medium-difficulty Windows box featuring unauthenticated Jenkins exploitation via Groovy Script Console, followed by SeImpersonatePrivilege abuse with JuicyPotato for privilege escalation. Root flag hidden in NTFS Alternate Data Streams.

#Alternate Data Streams #Jenkins #Juicy-Potato
Jan 18, 2026 Read more →
Fluffy - HackTheBox
HackTheBox Easy

Fluffy - HackTheBox

Easy-difficulty Windows Active Directory box featuring CVE-2025-24071 SMB coercion for initial access, Shadow Credentials attacks via GenericWrite abuse for lateral movement, and ADCS ESC16 exploitation for privilege escalation to Domain Admin.

#Active Directory #BloodHound #CVE-2025-24071
Jan 16, 2026 Read more →

Multi-Platform Coverage

Walkthroughs from the most popular CTF platforms

Ready to Level Up Your Skills?

Start exploring comprehensive walkthroughs and master the techniques used by professionals.

Start Learning Now