DarkZero | HackTheBox
A hard-difficulty Windows AD box built around a cross-forest MSSQL trusted link, SeServiceLogonRight abuse to recover SeImpersonatePrivilege, and unconstrained TGT delegation …
Read More →In-depth research and notes on security technologies, tradecraft, and lab write-ups.
A hard-difficulty Windows AD box built around a cross-forest MSSQL trusted link, SeServiceLogonRight abuse to recover SeImpersonatePrivilege, and unconstrained TGT delegation …
Read More →
An easy Windows box running Umbraco CMS. Creds leak from a world-readable NFS share, an authenticated Umbraco exploit gets a foothold, and a Print Spooler abuse gets SYSTEM.
Read More →
A walkthrough of GroundWorm, a hard-rated DFIR Sherlock on HackTheBox, tracing a simulated APT attack from initial access through ransomware deployment using Splunk and API …
Read More →