HTB: Touch
Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed …
Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed …
Layover is a Medium-rated Linux machine that chains WiFi traffic sniffing and CMS RCE to pivot from a contractor foothold into a web portal's internal secrets, …
TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and …
DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves …
Heron is an advanced Active Directory scenario featuring complex multi-step exploitation chains including web entry points (like SSTI leading to RCE), …
Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components …
SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold …
Heron is a small Active Directory scenario that involves typical vulnerabilities found in real word company environments. It's designed for penetration testers …
Calipendula is a hybrid GCP and Active Directory breach scenario, pushing you through cloud IAM enumeration, service account chaining, RBCD relay attacks, …
4 Chains which consist of 2-3 machines that are meant to be exploited together.
MailService is a multi-stage internal penetration test scenario that required chaining several techniques across both Linux and Windows domains.
Ifix-Tcen-Tcen is a famous Italian onomatopoeia and cultural reference originating from the erotic *fotoromanzi* (photo-novels) of the 1970s and 1980s. In our …
4 Red Team Labs with 10 or more machines, multiple subnets, multiple domains and forests. These are meant for Penetration Testers & Red Teamers to practice …
Shiva is an insane-difficulty Red Team lab on Vulnlab that simulates a hardened hybrid Active Directory environment (on-premises and Azure) with 10+ machines …
43 vulnerable standalone machines with various difficulties from easy to insane.
Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD …
17 Chains which consist of 2-3 machines that are meant to be exploited together.
Phantom is a medium-difficulty Windows AD exploitation machine. The foothold involves discovering a publicly accessible SMB share, cracking a VeraCrypt …
Atlas is a Hard-difficulty machine focusing on Java deserialization and .NET cryptographic analysis. The foothold involves exploiting a vulnerable Castor XML …
Baby2 is a medium-rated Active Directory machine on Vulnlab. The attack path involves initial SMB enumeration, password spraying to gain low-privileged domain …
Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected …
Flagsalad is a medium-severity crypto challenge where the flag is encoded as a vector, multiplied by a random matrix, and obscured with noise.
Share is an easy crypto challenge where the flag is encoded in a polynomial function f(x) = flag + a₁x + a₂x² + a₃x³, with 10 known points (x, f(x)) provided.
Warmup 1 is a easy misc challenge focus on Discord bot commands.
Warmup 2 is a easy misc challenge where the flag is hidden in a provided file.
Warmup 3 is a easy misc challenge where the flag is hidden on a webpage.
Barrier is a medium-rated machine that features exposed credentials and exploiting SSO authentication, privileged API access and CI/CD runners. Initial access …
Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. …
Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the …
Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is …
Puppet is a Medium-rated small active directory chain in which you start with an already running Sliver C2 beacon on an internal system. It is designed to …
Ten is a Hard difficulty Linux machine that simulates a misconfigured shared-hosting environment. Players enumerate a public sign-up portal that provisions FTP …
Baby is an easy difficulty Windows machine that features LDAP enumeration, password spraying and exposed credentials. For privilege escalation, the …
Cicada is a Medium-rated Windows Active Directory machine hosted on the VulnLab platform, that involves discovering a password inside an image on a public …
Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the …
Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with …
LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server …
Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing …
Wutai is a Medium-difficulty Red Team lab featuring 15+ machines across multiple networks, domains, and forests, challenging players to achieve Enterprise Admin …
Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to CVE-2024-22120, which allows an attacker to gain Remote Code Execution. After …
Manage is an easy Linux machine that features an exposed Java RMI service. Exploiting the underlying vulnerable JMX service leads to remote code execution and …
Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting …
Klendathu is an Insane difficulty chain hosted on Vulnlab, involved coercion with an undocumented function/procedure on MSSQL, forging a silver ticket, spoofing …
Build is an easy-level Linux machine hosted on the VulnLab platform. Its attack path relies primarily on exploiting a PowerDNSAdmin database, a configuration …
ReaperTwo is an Insane Windows machine that involves both browser and kernel exploitation. The attack chain begins with enumeration of exposed services and …
Unintended is an Medium chain that provides a hands-on experience with common missteps in Active Directory deployments, demonstrating how attackers can pivot …
Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a …
Tengu is a medium-rated chained machine on VulnLab, features a mixed environment with two Windows hosts and one Linux host. Exploiting Node-RED on Linux (with …
Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained …
Sweep is a medium difficulty Windows box that involves Active Directory and Lansweeper, a technology asset intelligence tool. The attacker abuses an enabled …
Escape is an Easy Windows machine where users can log in restricted Kiosk mode via RDP without a password. By exploiting the file:// scheme in Microsoft Edge, …
Reset is an Easy difficulty Linux machine which showcases abusing a password reset functionality in a web application following a log poisoning attack, to …
Kaiju is a Hard-rated Active Directory chain, from initial reconnaissance to full domain compromise, covering FileZilla exploitation, KeePass database …
Lock is an Easy-rated Windows machine that involves enumerating a Gitea repository to find a Personal Access Token. This token is then used to deploy an ASPX …
Tea is a medium-rate small Active Directory chain that provides hands-on experience with common Active Directory and DevOps vulnerabilities and …
Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, …
Sidecar is a Hard-rated small Active Directory chain that contains 2 Windows machines, however, attacks are not for beginners on Active Directory Pentesting. …
Forgotten is an Easy Linux machine on VulnLab that challenges players to exploit an unfinished LimeSurvey installation by deploying a controlled MariaDB …
Slonik is a Medium-difficulty Linux machine that focuses on NFS, PostgreSQL abuse, and privilege escalation through insecure backup automation. Initial access …
Media is a Medium-rated machine that features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a …
Delegate is a medium-rated Windows machine that involves Active Directory attacks. The machine has the guest account enabled, allowing the attacker to read …
Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack …
Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and …
Retro is an Easy Windows machine that showcases an Active Directory Domain Controller. Through SMB enumeration and pre-created machine account exploitation, we …
Control is a Hard-rated chains focus on a small multi-host Linux environment that simulates a realistic internal network and endpoint-management infrastructure. …
Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a …
Bamboo is an medium-rated Linux machine that begins with discovering a Squid proxy. The proxy is used to scan internal ports and reveals a PaperCut NG instance. …
Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access …
Job2 is a hard-rated Windows machine that involves a macro phishing attack for initial foothold. The machine has hMailServer installed, which includes a …
Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash …
Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download …
Store is a Hard difficulty box that hosts a Node.js web application, allowing file uploads and storage. The app is vulnerable to Arbitrary File Read, which lets …
Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes …
Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web …
Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain …
Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP …
Unchained is a Medium-rated Linux machine available on Vulnlab platform. Starting with NFS share enumeration then a source code analysis allows a JSONPICKLE …
Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users …
Data is an Easy Linux machine that involves exploiting CVE-2021-43798, an arbitrary file read via path traversal in Grafana. By exploiting this vulnerability, …
Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 & 8080 respectively. From the FTP server, we can retrieve the …
Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and …
Lustrous is a Hard-rated chain consisting of 2 machines on vulnlab. Cevering AS-REP roasts, Kerberoasts, the main lesson on this chain is to demonstrate how …
Feedback is an Easy-rated Linux machine centered around exploiting a vulnerable Log4j input field.
Job is a Medium-rated Windows box. It runs an SMTP server and its website accepts LibreOffice-compatible documents, providing a vector to deliver a document …
No posts match this tag.