TombWatcher - HackTheBox
A full walkthrough of TombWatcher (HTB) from a targeted Kerberoast all the way to Domain Admin via a chained ESC15 → ESC3 ADCS exploit, with a deleted-object restoration twist in the middle.
Browse through our comprehensive collection of CTF walkthroughs and security writeups
Showing walkthrough
A full walkthrough of TombWatcher (HTB) from a targeted Kerberoast all the way to Domain Admin via a chained ESC15 → ESC3 ADCS exploit, with a deleted-object restoration twist in the middle.
Medium-difficulty Windows box featuring unauthenticated Jenkins exploitation via Groovy Script Console, followed by SeImpersonatePrivilege abuse with JuicyPotato for privilege escalation. Root flag hidden in NTFS Alternate Data Streams.
Medium-difficulty Linux box featuring RCE through Brainfuck-encoded Python execution, followed by automated enumeration and privilege escalation via CVE-2021-4034 (PwnKit).
Medium Linux CTF combining Apache log poisoning, authentication bruteforcing, command injection filter bypass, and creative sudo exploitation. Multiple privilege escalation paths from web to root.
A medium-rated Linux machine, designed to provide hands-on experience with specific web application vulnerabilities(XSS, LFI, OS command Injection) and privilege escalation techniques.