June 2026
10 writeupsHTB: TombWatcher
A Medium Windows box where a BloodHound ACL chain reaches john, Reanimate-Tombstones restores a deleted cert_admin into an OU where you have GenericAll, and ESC15 issues a domain …
HTB: StreamIO
A Medium Windows box that chains SQL injection on a hidden subdomain through PHP eval RCE to a LAPS read. Firefox saved passwords and JDgodd's group ownership are the two pivots.
HTB: Pandora
An Easy Linux box where SNMP with the default community string leaks SSH creds from process arguments. An unauthenticated SQLi on Pandora FMS hijacks a session for RCE, and a SUID …
HTB: Scrambled
A Medium Windows box where NTLM is disabled domain-wide, forcing pure Kerberos. Kerberoasting yields sqlsvc, a silver ticket forged from its NT hash bypasses MSSQL access …
HTB: Escape
A Medium Windows box where a PDF on a public SMB share leaks MSSQL guest credentials. NTLM coercion via xp_dirtree cracks sql_svc, a mistyped login leaks Ryan.Cooper's password, …
HTB: Authority
A Medium Windows box where cracking Ansible Vault files on a public share leads to a PWM portal. Redirecting its LDAP config to Responder gets cleartext creds, and ESC1 via LDAPS …
HTB: Administrator
A Medium box built around a BloodHound ACL chain with starting credentials. Three password resets walk you down to a Password Safe on FTP, and a fake SPN plus targeted …
HTB: Return
An Easy Windows box where the printer admin panel's LDAP settings page leaks svc-printer's credentials to a netcat listener. Server Operators membership and a service binary hijack …
HTB: EscapeTwo
An Easy Windows box that starts with given credentials. A spreadsheet on an SMB share leaks the MSSQL sa password, a config file exposes ryan's, and WriteOwner over ca_svc chains …
HTB: Cicada
An Easy Windows box where one default password in an HR share starts a credential chain. An AD description field and a backup script leak two more accounts, and Backup Operators …