June 2026
2 writeupsHTB: Timelapse
An Easy Windows box where cracking a PFX from a guest-readable SMB share authenticates to WinRM via client certificate. PowerShell history leaks svc_deploy's credentials, and LAPS …
HTB: Sauna
An Easy Windows box where employee names on the bank website generate username variants for AS-REP roasting. Winlogon autologon keys hand over svc_loanmgr, who has DCSync rights …
May 2026
4 writeupsHackINI 2026: Shell-DC
Hard Active Directory box. Kerberoasting, BloodHound ACL abuse, Shadow Credentials, gMSA password extraction, tombstone reanimation, and pcap NTLM cracking chain to Domain Admin.
HackINI 2026: Legacy
Medium Linux box. Exposed .git directory identifies Anuko Time Tracker 1.20, exploited via CVE-2022-24707 SQL injection in the puncher plugin. Webmin on port 10000 hands over root …
HackINI 2026: IT Workstation
Medium Windows box. WinRM entry with harvested credentials, Autologon registry keys expose the local Administrator password in plaintext, and Mimikatz pulls a domain credential …
HackINI 2026: Corp Monitor
Medium Linux box. Anonymous FTP for recon, Drupalgeddon2 for the shell, then Grafana 8.2.6 path traversal reads root's SSH key. Credential harvest from the Drupal DB feeds the rest …
March 2026
2 writeupsHTB Season 10: CCTV
A Linux Easy machine themed around surveillance software. Getting to root means sniffing traffic and finding a service that wasn't meant to be found.
HTB: MonitorsFour
A Hard Linux box that chains an unauthenticated API leak, Cacti RCE, and a CVE-2025-9074 Docker Desktop escape to reach the host filesystem. The container escape is the highlight.