TombWatcher - HackTheBox
A full walkthrough of TombWatcher (HTB) from a targeted Kerberoast all the way to Domain Admin via a chained ESC15 → ESC3 ADCS exploit, with a deleted-object restoration twist in the middle.
Master the Art of Penetration Testing
Comprehensive walkthroughs, detailed explanations, and practical insights for CTF challenges across multiple platforms. Level up your cybersecurity skills one machine at a time.
Designed with both beginners and advanced practitioners in mind
Step-by-step guides with commands, screenshots, and comprehensive explanations for every challenge.
Spoiler protection for active CTF challenges with smart lock system during competition periods.
Find walkthroughs by platform, difficulty, tags, or search terms to quickly locate what you need.
Latest challenges solved and documented
A full walkthrough of TombWatcher (HTB) from a targeted Kerberoast all the way to Domain Admin via a chained ESC15 → ESC3 ADCS exploit, with a deleted-object restoration twist in the middle.
Easy-difficulty Linux box featuring CVE-2025-47812 unauthenticated RCE against Wing FTP Server 7.4.3 for initial access, offline cracking of a salted SHA-256 password hash for lateral movement, and CVE-2025-4517 PATH_MAX tarfile bypass via a malicious tarball to escalate privileges to root.
Master advanced Linux commands with OverTheWire Bandit Part 2 (Levels 5-9). Learn find with multiple criteria, grep for pattern matching, sort & uniq for data processing, and strings for binary file analysis. Includes regex basics!
Master essential Linux commands through OverTheWire Bandit Levels 0-4. Learn to handle dashed filenames, spaces in filenames, hidden files, and file type detection. Beginner-friendly with practical examples and multiple solution methods.
Medium-difficulty Windows box featuring unauthenticated Jenkins exploitation via Groovy Script Console, followed by SeImpersonatePrivilege abuse with JuicyPotato for privilege escalation. Root flag hidden in NTFS Alternate Data Streams.
Easy-difficulty Windows Active Directory box featuring CVE-2025-24071 SMB coercion for initial access, Shadow Credentials attacks via GenericWrite abuse for lateral movement, and ADCS ESC16 exploitation for privilege escalation to Domain Admin.
Walkthroughs from the most popular CTF platforms
Start exploring comprehensive walkthroughs and master the techniques used by professionals.
Start Learning Now