All Walkthroughs

Browse through our comprehensive collection of CTF walkthroughs and security writeups

Showing walkthrough

TombWatcher - HackTheBox
HackTheBox Medium
Aug 10, 2026 10 min read

TombWatcher - HackTheBox

A full walkthrough of TombWatcher (HTB) from a targeted Kerberoast all the way to Domain Admin via a chained ESC15 → ESC3 ADCS exploit, with a deleted-object restoration twist in the middle.

#ADCS #Active Directory #BloodHound #Certificate Abuse #ESC15
Read more
Wingdata - HackTheBox
HackTheBox Easy
Aug 08, 2026 4 min read

Wingdata - HackTheBox

Easy-difficulty Linux box featuring CVE-2025-47812 unauthenticated RCE against Wing FTP Server 7.4.3 for initial access, offline cracking of a salted SHA-256 password hash for lateral movement, and CVE-2025-4517 PATH_MAX tarfile bypass via a malicious tarball to escalate privileges to root.

#CVE-2025-4517 #CVE-2025-47812 #Hash Cracking #Linux #RCE
Read more
Jeeves - HackTheBox
HackTheBox Medium
Jan 18, 2026 5 min read

Jeeves - HackTheBox

Medium-difficulty Windows box featuring unauthenticated Jenkins exploitation via Groovy Script Console, followed by SeImpersonatePrivilege abuse with JuicyPotato for privilege escalation. Root flag hidden in NTFS Alternate Data Streams.

#Alternate Data Streams #Jenkins #Juicy-Potato #SeImpersonatePrivilege #Web
Read more
Fluffy - HackTheBox
HackTheBox Easy
Jan 16, 2026 15 min read

Fluffy - HackTheBox

Easy-difficulty Windows Active Directory box featuring CVE-2025-24071 SMB coercion for initial access, Shadow Credentials attacks via GenericWrite abuse for lateral movement, and ADCS ESC16 exploitation for privilege escalation to Domain Admin.

#Active Directory #BloodHound #CVE-2025-24071 #Certificate Abuse #ESC16
Read more
Imagery - HackTheBox
HackTheBox Medium
Dec 18, 2025 10 min read

Imagery - HackTheBox

A medium-rated Linux machine, designed to provide hands-on experience with specific web application vulnerabilities(XSS, LFI, OS command Injection) and privilege escalation techniques.

#Linux #Web
Read more