[{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/Touch OS Windows Severity Easy Creator TheCyberGeek Release date 2026 Oct 04 (JST) Information In the Layover machine, you uncovered a name and a booking confirmation code. Maybe they\u0026amp;rsquo;ll come in handy here? Jenny Crawford / KS7X2M This content is encrypted. ","date":"2026-10-04","permalink":"/posts/htb-touch/","section":"posts","summary":"Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed through the device's API, leading to a restricted user session that requires creative exploitation to break out of its locked-down environment and reach a full shell. Privilege escalation involves abusing misconfigured service permissions and exposed database credentials to escalate to full administrative control.","title":"HTB: Touch","type":"page"},{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/Layover OS Linux Severity Medium Creator TRX Release date 2026 Sep 27 (JST) Information As is common in real life pentests, you will start the Layover box with credentials for the following account contractor / Contractor2026! This content is encrypted. ","date":"2026-09-27","permalink":"/posts/htb-layover/","section":"posts","summary":"Layover is a Medium-rated Linux machine that chains WiFi traffic sniffing and CMS RCE to pivot from a contractor foothold into a web portal's internal secrets, landing user access via password reuse. Root falls to a local CUPS vulnerability that leaks an admin token, used to write privileged files and fully compromise the box.","title":"HTB: Layover","type":"page"},{"content":"bloodyAD is a Python LDAP-based Swiss-army knife created by Baptiste Crépin aka CravateRouge for AD privilege escalation. It reads and writes AD objects directly over LDAP/LDAPS/GC, so it works from Linux with no Windows host required. The verb (add / get / set / remove) is the action. The noun (genericAll, shadowCredentials, groupMember, uac, rbcd\u0026amp;hellip;) is the abuse primitive. Warning The …","date":"2026-09-12","permalink":"/posts/bloodyad/","section":"posts","summary":"Active Directory privilege escalation swiss-army knife. Quick reference for common bloodyAD operations.","title":"bloodyAD","type":"page"},{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/Trustfall OS Windows Severity Insane Creator EmSec \u0026amp;amp; ctrlzero Release date 2026 Aug 16 (JST) \u0026amp;ndash;\u0026amp;gt; Cancelled \u0026amp;ndash;\u0026amp;gt; Fixed \u0026amp;amp; Released again 2026 Sep 11 (JST) This content is encrypted. ","date":"2026-09-12","permalink":"/posts/htb-trustfall/","section":"posts","summary":"TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and ADCS abuse. Initial access requires chaining an osTicket arbitrary file read with a legacy telnetd vulnerability to compromise a Linux pivot host. Lateral movement involves intricate ACL/OU inheritance abuse, AS-REP roasting, and a sophisticated WSUS Man-in-the-Middle attack powered by a rogue certificate (ESC17) for local privilege escalation. The endgame tests cryptographic weaknesses and PKI administration, requiring the prediction of a time-seeded VBScript PRNG to compromise a PKI Manager, ultimately leading to full Certificate Authority takeover (ESC7) and Domain Admin compromise via DCSync.","title":"HTB: TrustFall","type":"page"},{"content":"This page picks up where the main NetExec cheatsheet leaves off. It covers techniques that need more context, carry more risk, or are simply used less often — the kind of thing you reach for once you\u0026amp;rsquo;re comfortable with the basics. Nothing here is repeated from the main sheet. Operational flags # Route all output through nxc\u0026amp;#39;s SQLite DB into your engagement workspace (see main …","date":"2026-08-28","permalink":"/posts/netexec-advanced/","section":"posts","summary":"Follow-up to the NetExec cheatsheet: deeper Active Directory abuse techniques, delegation attacks, and operational tooling for experienced operators.","title":"NetExec Advanced","type":"page"},{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/DanglingTree OS Windows Severity Medium Creator EmSec Release date 2026 Aug 9 (JST) This content is encrypted. ","date":"2026-08-09","permalink":"/posts/htb-danglingtree/","section":"posts","summary":"DanglingTree is a Medium-difficulty Windows machine focusing on Windows Admin Center (WAC) exploitation and cryptographic analysis. The foothold involves exploiting CVE-2026-26119 in WAC to execute PowerShell commands and abusing SmarterMail vulnerabilities (CVE-2026-23760/CVE-2026-24423) to gain initial access. The path to root requires DLL decompilation for DES decryption, DPAPI credential recovery, ACL abuse, and ADCS exploitation to escalate privileges to Administrator.","title":"HTB: DanglingTree","type":"page"},{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/DarkZeroReturns OS Windows Severity Hard Creator 0xEr3bus \u0026amp;amp; Pho3o Release date 2026 Jul 26 (JST) Enumeration Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.129.xx.xx Starting Nmap 7.99 ( https://nmap.org ) at 2026-07-28 16:52 +0900 Nmap scan report for 10.129.xx.xx Host is up (0.18s latency). Not shown: 65533 filtered tcp ports …","date":"2026-07-28","permalink":"/posts/htb-darkzeroreturns/","section":"posts","summary":"Heron is an advanced Active Directory scenario featuring complex multi-step exploitation chains including web entry points (like SSTI leading to RCE), cross-realm Kerberos trust abuses, CI/CD runner pivots, and forest trust navigation.","title":"HTB: DarkZeroReturns","type":"page"},{"content":"Setup Dependencies Python 3 Rust (curl \u0026amp;ndash;proto \u0026amp;lsquo;=https\u0026amp;rsquo; \u0026amp;ndash;tlsv1.2 -sSf https://sh.rustup.rs | sh) Python arc4 dependency (pip install arc4 OR sudo apt policy python3-arc4 #on kali) Installation sudo apt install pipx git pipx ensurepath pipx install git+https://github.com/Pennyw0rth/NetExec netexec --version Update pipx upgrade netexec # Will update if there is a new version …","date":"2026-07-25","permalink":"/posts/netexec/","section":"posts","summary":"Swiss-army knife for Active Directory and network protocol enumeration/exploitation, successor to CrackMapExec.","title":"NetExec","type":"page"},{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/Reactor OS Linux Severity Easy Creator tejas3008 Release date 2026 May 24 (JST) Attack Paths Initial Access - React2Shell exploit via Next-Action header injection | [Shell as node] | v Credential Extraction - SQLite database dump → MD5 hashes | [39d97110eafe2a9a68639812cd271e8e] | v Hash Cracking - John|Hashcat + rockyou.txt | …","date":"2026-05-24","permalink":"/posts/htb-reactor/","section":"posts","summary":"Reactor is an Easy-rated Linux machine where initial access is gained by exploiting CVE-2025-55182 (React2Shell), a pre-auth RCE in React Server Components triggered via a crafted Next-Action header, yielding a shell as node. Credentials are extracted from a SQLite database dump, cracked to reveal valid SSH access for lateral movement to the user engineer. Privilege escalation abuses an exposed Node.js debug port (9229), reached via SSH tunnel, to call process.mainModule.require and execute commands as root.","title":"HTB: Reactor","type":"page"},{"content":"Overview Type Machines Direct https://app.hackthebox.com/machines/SmartHire OS Linux Severity Medium Creator redtrib3 Release date 2026 May 17 (JST) Attack Paths admin [MLflow Basic Auth] (weak credentials admin:password, models.smarthire.htb) └─ admin [MLflow pyfunc RCE] (CVE-2024-37054, cloudpickle payload) │ └─ svcweb [Trigger /predict endpoint] (smarthire.htb/predict) ← Initial access │ └─ …","date":"2026-05-17","permalink":"/posts/htb-smarthire/","section":"posts","summary":"SmartHire is a Medium-rated Linux machine that chains MLflow unsafe deserialization (CVE-2024-37054) to pivot from an unauthenticated web portal into a foothold as the svcweb user. Root falls to a Python .pth injection via a group-writable plugin directory, abused through a passwordless sudo misconfiguration to spawn a SUID shell and fully compromise the box.","title":"HTB: SmartHire","type":"page"},{"content":"Overview Type Mini Pro Labs OS Windows/Linux (Hybrid) Red Team Operator Level 1 Difficulty Advanced Creator xct HTB Release date 2025 Nov Showcased proficiency This Red Team Operator I lab will expose players to: Enumeration Active Directory enumeration and attacks Lateral movement Local privilege escalation Situational awareness Introduction You are tasked with performing a penetration test on …","date":"2025-11-14","permalink":"/posts/htb-heron/","section":"posts","summary":"Heron is a small Active Directory scenario that involves typical vulnerabilities found in real word company environments. It's designed for penetration testers and red teamers in search of a quick and challenging lab.","title":"HTB: Heron","type":"page"},{"content":"Overview Type Chains Direct https://extremeredlab.0x29a.it/chains OS Windows/Linux Severity Medium Target 10.0.9.0/24 Information In this lab, you won’t just face vulnerabilities — you’ll walk a hidden path, where someone is pulling strings behind the scenes. Their actions are subtle, but their presence is undeniable. Something — or someone — is at work. To move forward, you’ll have to pass …","date":"2025-11-08","permalink":"/posts/ertlabs-calipendula/","section":"posts","summary":"Calipendula is a hybrid GCP and Active Directory breach scenario, pushing you through cloud IAM enumeration, service account chaining, RBCD relay attacks, multi-hop tunnelling in a segmented network.","title":"ERTLabs: Calipendula","type":"page"},{"content":"Achievement Updated: 2025 AUG 30 Chain Name Operating System Difficulty Completion Type IFIX-TCEN-TCEN Windows/Linux Hard O Active Directory Chain MAILSERVICE Windows/Linux Medium O Active Directory Chain CALIPENDULA Windows/Linux Medium O Active Directory Chain SUMMUS Windows Hard/Insane X Active Directory Chain Chains ","date":"2025-08-30","permalink":"/posts/ertlabs-chains/","section":"posts","summary":"4 Chains which consist of 2-3 machines that are meant to be exploited together.","title":"ERTLabs: Chains","type":"page"},{"content":"Overview Type Chains Direct https://extremeredlab.0x29a.it/chains OS Windows/Linux Severity Medium Target 10.0.5.5 Information Step into a world like no other — a distorted digital landscape where the usual rules of cyberspace no longer apply. Here, email services are a chaotic mess: headers lie, messages twist the truth, and inboxes become traps. Clarity is an illusion, and every clue you find …","date":"2025-08-29","permalink":"/posts/ertlabs-mailservice/","section":"posts","summary":"MailService is a multi-stage internal penetration test scenario that required chaining several techniques across both Linux and Windows domains.","title":"ERTLabs: MailService","type":"page"},{"content":"Overview Type Chains Direct https://extremeredlab.0x29a.it/chains OS Windows/Linux Severity Hard Target 10.0.10.0/24 Information As you step into this lab, you’ll find yourself caught in a strange echo — a revival of characters from distant times: mischievous actresses from the \u0026amp;rsquo;80s, and extraterrestrials who once toyed with them in neon-lit dreams. But nostalgia quickly curdles into …","date":"2025-08-09","permalink":"/posts/ertlabs-ifix-tcen-tcen/","section":"posts","summary":"Ifix-Tcen-Tcen is a famous Italian onomatopoeia and cultural reference originating from the erotic *fotoromanzi* (photo-novels) of the 1970s and 1980s. In our case it's a multi-stage internal penetration test scenario focus on Active Directory.","title":"ERTLabs: Ifix-Tcen-Tcen","type":"page"},{"content":"Achievement Updated: 2025 APR 20 RTLab Name Environment Difficulty Completion Type Wutai Active Directory Medium O Red Team Lab Ifrit Active Directory Easy O Red Team Lab Shinra Active Directory Hard O Red Team Lab Shiva Hybrid (AD/ENTRA ID) Insane O Red Team Lab HALL OF FAME last update 2025 AUG 01 BYE BYE, THANKS \u0026amp;amp; HOPE I\u0026amp;rsquo;ve really missed Vulnlab ever since it closed on March 3, 2026, …","date":"2025-04-20","permalink":"/posts/vl-redteamlabs/","section":"posts","summary":"4 Red Team Labs with 10 or more machines, multiple subnets, multiple domains and forests. These are meant for Penetration Testers \u0026 Red Teamers to practice operations. There are modern defenses to bypass and various different AV \u0026 EDR products running.","title":"VULNLAB: RedTeam Master","type":"page"},{"content":"Overview Type Red Team Labs OS Mixed Severity Insane Creator xct Release date 2023 Nov 25 Showcased proficiency Exploiting a hardened Hybrid-AD Environment without relying on publicly known vulnerabilities (CVEs) Exploiting Azure cloud services Bypassing modern EDR, WDAC \u0026amp;amp; other security controls Exploiting common enterprise software No CVEs Rule of Engagement (ROE) Task Your task is to …","date":"2025-04-17","permalink":"/posts/vl-shiva/","section":"posts","summary":"Shiva is an insane-difficulty Red Team lab on Vulnlab that simulates a hardened hybrid Active Directory environment (on-premises and Azure) with 10+ machines and active users. All protected by Endpoint Detection and Response (EDR), SIEM solutions, Windows Defender Application Control (WDAC), and common enterprise software.","title":"VULNLAB: Shiva","type":"page"},{"content":"Achievement Updated: 2025 MAR 9 Machine Name Operating System Difficulty Completion Type Manage Linux Easy O Machine Build Linux Easy O Machine Retro2 Windows Easy O Machine Baby Windows Easy O Machine Cicada Windows Medium O Machine Redelegate Windows Hard O Machine Retro Windows Easy O Machine Rainbow Windows Medium O Machine Rainbow2 Windows Hard O Machine Barrier Linux Medium O Machine Data …","date":"2025-03-09","permalink":"/posts/vl-machines/","section":"posts","summary":"43 vulnerable standalone machines with various difficulties from easy to insane.","title":"VULNLAB: Machine Master","type":"page"},{"content":"Overview Type Red Team Labs OS Mixed Severity Hard Creator xct Release date 2022 Dec 29 Showcased proficiency Hybrid-AD Environment Azure cloud services Phishing Bypassing AV \u0026amp;amp; EDR tools Bypassing Applocker \u0026amp;amp; WDAC Reverse Engineering Multiple Active Directory Certificate Service Attacks Kerberos Delegation and Relay Attacks Exploiting linked MSSQL servers Supply Chain Attacks Rule of …","date":"2025-03-09","permalink":"/posts/vl-shinra/","section":"posts","summary":"Shinra is a Hard-rated Red Team lab designed for those with foundational AD and pentesting knowledge to refine covert red teaming skills. Players focus on AD enumeration, exploitation, certificate services, lateral movement, phishing, CI/CD attacks, EDR bypass, backdooring apps, and relay attacks while evading real-time detections.","title":"VULNLAB: Shinra","type":"page"},{"content":"Achievement Updated: 2025 FEB 27 Chain Name Operating System Difficulty Completion Type Tengu Hybrid (Windows/Linux) Medium O Chain Unintended Linux Medium O Chain Vigilant Hybrid (Windows/Linux) Hard O Chain Heron Hybrid (Windows/Linux) Medium O Chain Hybrid Hybrid (Windows/Linux) Easy O Chain Trusted Windows Easy O Chain Puppet Windows Medium O Chain Mythical Hybrid (Windows/Linux) Medium O …","date":"2025-02-27","permalink":"/posts/vl-chains/","section":"posts","summary":"17 Chains which consist of 2-3 machines that are meant to be exploited together.","title":"VULNLAB: Chain Master","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator ar0x4 Release date 2024 Jul 12 (JST) Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.125.229 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.125.229 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-25 16:37 JST Nmap scan report for 10.10.125.229 Host is …","date":"2025-02-26","permalink":"/posts/vl-phantom/","section":"posts","summary":"Phantom is a medium-difficulty Windows AD exploitation machine. The foothold involves discovering a publicly accessible SMB share, cracking a VeraCrypt container, and abusing Resource-Based Constrained Delegation (RBCD) to escalate privileges.","title":"VULNLAB: Phantom","type":"page"},{"content":"Overview Atlas Type Machines OS Windows Severity Hard Creator sec77 Release date 2023 Aug 4 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.84.121 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.84.121 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-18 16:58 JST Nmap scan report for 10.10.84.121 Host is up (0.26s latency). Not shown: 65531 filtered tcp ports …","date":"2025-01-19","permalink":"/posts/vl-atlas/","section":"posts","summary":"Atlas is a Hard-difficulty machine focusing on Java deserialization and .NET cryptographic analysis. The foothold involves exploiting a vulnerable Castor XML library in a Spring Boot app and reverse-engineering a .NET application to recover credentials.","title":"VULNLAB: Atlas","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct \u0026amp;amp; r0BIT Release date 2023 Sep 8 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.84.121 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.64.103 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-19 14:10 JST Nmap scan report for 10.10.64.103 Host is up (0.27s latency). Not shown: 65521 filtered tcp ports …","date":"2025-01-19","permalink":"/posts/vl-baby2/","section":"posts","summary":"Baby2 is a medium-rated Active Directory machine on Vulnlab. The attack path involves initial SMB enumeration, password spraying to gain low-privileged domain user access, replacing a login VBS script in SYSVOL for a reverse shell, and escalating privileges by abusing GPO (Group Policy Object) DACL misconfigurations.","title":"VULNLAB: Baby2","type":"page"},{"content":"Overview Type Machines OS Linux Severity Medium Creator xct Release date 2025 Jan 17 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.91.209 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.91.209 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-26 17:24 JST Nmap scan report for 10.10.91.209 Host is up (0.26s latency). Not shown: 65532 closed tcp ports (reset) PORT …","date":"2025-01-17","permalink":"/posts/vl-odori/","section":"posts","summary":"Odori is a medium-difficulty machine on Vulnlab that involves gaining access to a Bitlocker encrypted disk image, in order to retrieve DPAPI protected credentials. Furthermore we will use SFTP to bypass login restrictions and manipulate a python cache file to gain root privileges.","title":"VULNLAB: Odori","type":"page"},{"content":"Overview Type Crypto Severity Medium Creator macz Release date 2021 Nov 21 Foothold Start the instance via Discord and let\u0026amp;rsquo;s go: We download the challenge file and open it $ cat flagsalad.sage: from random import randint from sage.all import Graph, matrix, ZZ, vector from secret import flag # evil me strips VL{} from flag :-) flag = flag[3:-1] def get_pubkey(): return …","date":"2025-01-08","permalink":"/posts/vl-flagsalad/","section":"posts","summary":"Flagsalad is a medium-severity crypto challenge where the flag is encoded as a vector, multiplied by a random matrix, and obscured with noise.","title":"VULNLAB: Flagsalad","type":"page"},{"content":"Overview Type Crypto Severity Easy Creator xct Release date 2021 Nov 21 Foothold Start the instance via Discord and let\u0026amp;rsquo;s go: We download the challenge file and open it $ cat share.txt: We have found one of these on each suspect. What secret could they share? (1,1236845980038787500330644426344609296563053316284551) (2,7455293105561248663255667475692465968758017231599185) …","date":"2025-01-08","permalink":"/posts/vl-share/","section":"posts","summary":"Share is an easy crypto challenge where the flag is encoded in a polynomial function f(x) = flag + a₁x + a₂x² + a₃x³, with 10 known points (x, f(x)) provided.","title":"VULNLAB: Share","type":"page"},{"content":"Overview Type Misc Severity Easy Creator xct Release date 2021 Nov 21 Foothold Start the instance via Discord and let\u0026amp;rsquo;s go: We download the challenge file and open it: After checked the / bot commands available in the Vulnlab\u0026amp;rsquo;s discord, we found a way to get the flag following the hint: /warmup VL{c22d28f165894460683efca37829d9ce} Got the flag VL{c22d28f165894460683efca37829d9ce} ","date":"2025-01-08","permalink":"/posts/vl-warmup1/","section":"posts","summary":"Warmup 1 is a easy misc challenge focus on Discord bot commands.","title":"VULNLAB: Warmup 1","type":"page"},{"content":"Overview Type Misc Severity Easy Creator xct Release date 2021 Nov 21 Foothold Start the instance via Discord and let\u0026amp;rsquo;s go: We download the challenge file and open it: Found the flag VL{e0fd4f05fe6bee3642faeb9dd2c38aaf}, so solved it. This challenge is a gift as easy to win. ","date":"2025-01-08","permalink":"/posts/vl-warmup2/","section":"posts","summary":"Warmup 2 is a easy misc challenge where the flag is hidden in a provided file.","title":"VULNLAB: Warmup 2","type":"page"},{"content":"Overview Type Misc Severity Easy Creator xct Release date 2021 Nov 21 Foothold Start the instance via Discord and let\u0026amp;rsquo;s go: We download the challenge file and open it: We open the link https://twitter.com/vulnlab_eu/status/1631384045601824800 in a browser: We follow it and open the Vulnlab website: We review the source code and found an interesting stuff: view-source:https://www.vulnlab.com/ …","date":"2025-01-08","permalink":"/posts/vl-warmup3/","section":"posts","summary":"Warmup 3 is a easy misc challenge where the flag is hidden on a webpage.","title":"VULNLAB: Warmup 3","type":"page"},{"content":"Overview Type Machines OS Linux Severity Medium Creator xct Release date 2025 Jan 2 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go (waiting 5 min to be sure the instance is fully deployed): 10.10.67.143 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.67.143 Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-03 19:46 JST Nmap scan report for 10.10.67.143 Host is up (0.26s …","date":"2025-01-02","permalink":"/posts/vl-barrier/","section":"posts","summary":"Barrier is a medium-rated machine that features exposed credentials and exploiting SSO authentication, privileged API access and CI/CD runners. Initial access is gained by discovering credentials in a public repository and then exploiting a SAML authentication bypass in GitLab to obtain administrative access. From there, a CI/CD runner is abused to execute code and extract sensitive information from environment variables. With the authorization token, the Authentik API can be exploited to obtain administrative control of the identity platform. Access to the Authentik admin panel allows user impersonation and access to Apache Guacamole. Then an existing connection within Guacamole provides remote access to the host. Finally, a private SSH key is recovered from MySQL and privilege escalation is achieved through credential disclosure in shell history.","title":"VULNLAB: Barrier","type":"page"},{"content":"Overview Type Machines OS Windows Severity Hard Creator Geiseric Release date 2024 Nov 22 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.86.64 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.86.64 PORT STATE SERVICE VERSION 21/tcp open ftp Microsoft ftpd | ftp-syst: |_ SYST: Windows_NT | ftp-anon: Anonymous FTP login allowed (FTP code 230) | 10-20-24 12:11AM 434 …","date":"2024-11-22","permalink":"/posts/vl-redelegate/","section":"posts","summary":"Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.","title":"VULNLAB: Redelegate","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2024 Nov 21 (JST) Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.84.140 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.84.140 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-22 08:29 JST Nmap scan report for 10.10.84.140 Host is up …","date":"2024-11-21","permalink":"/posts/vl-shibuya/","section":"posts","summary":"Shibuya is a Medium Windows machine that starts of with the SMB port exposed. Enumerating possible usernames through Kerberos an attacker is able to find the valid machine account red:red. With these credentials, he can further enumerate the remote users and discover that the user svc_autojoin has a password in its description. With this account in hand, he is able to discover some Windows Imaging Format (.wmi) files that contain hashes for the user simon.watson. Now, the attacker has command execution through SSH on the remote machine and is able to enumerate that another user has an active interactive session. By performing a cross-session relay attack he is able to steal the hash and crack the password for the user nigel.mills. The new user is member of the t1_admin groups which has enrolment rights on a certificate template that's vulnerable to ESC1 and by exploiting it we are able to gain SYSTEM privileges on the machine.","title":"VULNLAB: Shibuya","type":"page"},{"content":"Overview Type Chains OS Windows/Linux (Hybrid) Severity Medium Creator xct Release date 2024 Nov 06 IP 10.10.175.197, 10.10.175.198, 10.10.175.199 Rule of Engagement (ROE) Important Give this chain at least 5 minutes to fully startup. Note Mythical got ransomwared last year - now they are more careful on where to store their backups and have also \u0026amp;ldquo;fixed\u0026amp;rdquo; the vulnerabilities that the …","date":"2024-11-06","permalink":"/posts/vl-mythical/","section":"posts","summary":"Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging windows environment.","title":"VULNLAB: Mythical","type":"page"},{"content":"Overview Type Chains OS Windows Severity Medium Creator xct Release date 2024 Oct 22 IP 10.10.213.5, 10.10.213.6, 10.10.213.7 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.213.5 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-30 19:00 JST Nmap scan report for 10.10.213.5 Host is up (0.25s latency). Not shown: 65534 …","date":"2024-10-22","permalink":"/posts/vl-puppet/","section":"posts","summary":"Puppet is a Medium-rated small active directory chain in which you start with an already running Sliver C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging hybrid environment.","title":"VULNLAB: Puppet","type":"page"},{"content":"Overview Type Machines OS Linux Severity Hard Creator jkr Release date 2024 Oct 11 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.64.124 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.64.124 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-12 18:17 JST Nmap scan report for 10.10.64.124 Host is up (0.24s latency). Not shown: 65532 closed tcp ports (reset) PORT …","date":"2024-10-11","permalink":"/posts/vl-ten/","section":"posts","summary":"Ten is a Hard difficulty Linux machine that simulates a misconfigured shared-hosting environment. Players enumerate a public sign-up portal that provisions FTP accounts, abuse weak MySQL/FTP integration to pivot into a real local user, and finally achieve root by poisoning an etcd-driven Apache configuration reload.","title":"VULNLAB: Ten","type":"page"},{"content":"Overview Type Machines OS Windows Severity Easy Creator xct Release date 2021 Nov 21 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.110.189 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.110.189 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-28 18:19 JST Nmap scan report for 10.10.110.189 Host is up (0.24s latency). Not shown: 65514 filtered tcp ports …","date":"2024-09-28","permalink":"/posts/vl-baby/","section":"posts","summary":"Baby is an easy difficulty Windows machine that features LDAP enumeration, password spraying and exposed credentials. For privilege escalation, the SeBackupPrivilege is exploited to extract registry hives and the NTDS.dit file. A Pass-the-Hash attack can be performed using the uncovered domain hashes ultimately achieving Administrator access.","title":"VULNLAB: Baby","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2024 Sep 26 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.70.81 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.70.81 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-05 18:29 JST PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 …","date":"2024-09-26","permalink":"/posts/vl-cicada/","section":"posts","summary":"Cicada is a Medium-rated Windows Active Directory machine hosted on the VulnLab platform, that involves discovering a password inside an image on a public share. With that password an attacker is able to discover that the machine is vulnerable to ESC8 and can use Kerberos relaying to bypass self-relay restrictions in order to get a certificate as the machine account itself. With this new certificate, we are able to dump the hashes of the Administrator user and thus compromise the whole domain.","title":"VULNLAB: Cicada","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator jkr Release date 2024 Sep 20 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go (waiting 5 min to be sure the instance is fully deployed): 10.10.91.60 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.91.60 Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-08 20:06 JST Nmap scan report for 10.10.91.60 Host is up (0.26s …","date":"2024-09-20","permalink":"/posts/vl-down/","section":"posts","summary":"Down is an easy-rated Linux machine that involves exploiting an arbitrary file read by bypassing a protocol-based filter to discover the source code of the running PHP web app, eventually, a remote code execution to gain an initial foothold. The attacker finds a readable pswm encrypted file in the user's home directory. The pwsm uses Python's cryptocode module and a master password to encrypt and decrypt the data. The attacker is supposed to write a small script to decrypt the blob and compromise the user. The compromised user is a member of the sudo group, allowing the user to escalate and obtain root access.","title":"VULNLAB: Down","type":"page"},{"content":"Overview Type Red Team Labs OS Mixed Severity Easy (Hard if we want to remain stealthy) Creator xct Release date 2024 Aug 8 Showcased proficiency Common Active Directory Attacks Basic Reverse Engineering Abusing Active Directory Certificate Services Lateral Movements across multiple Domains \u0026amp;amp; Forests Bypassing modern AV Rule of Engagement (ROE) In this Assumed-Breach Scenario, your main …","date":"2024-09-15","permalink":"/posts/vl-ifrit/","section":"posts","summary":"Ifrit is an Assumed-Breach scenario with the main objective is getting domain administrator privileges in the ifrit.vl Domain. It designed for those with foundational AD and pentesting knowledge to hone covert red teaming skills. Players aim for Domain Admin while evading real-time detections, practicing AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, and relay attacks across multiple forests.","title":"VULNLAB: Ifrit","type":"page"},{"content":"Overview Type Machines OS Windows Severity Hard Creator xct Release date 2024 Sep 11 Enumeration Start the instance via Discord, wait around 10 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.64.29 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.64.29 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-30 10:42 JST Nmap scan report for lus2dc.lustrous2.vl (10.10.64.29) …","date":"2024-09-11","permalink":"/posts/vl-lustrous2/","section":"posts","summary":"LustrousTwo is a hard-rated Windows machine that deals with LDAP signing, channel binding, and disabled NTLM authentication. The machine has a web server vulnerable to arbitrary file read, which helps attackers capture a Net-NTLMv2 hash for the service account, using it to request Service Tickets via s4u2self, a stealthier alternative to Silver Ticket, to bypass protective measures like Account is sensitive and cannot be delegated. After reversing and auditing the source code, the attacker achieves Remote Code Execution. For privilege escalation, the attacker exploits a misconfigured, insecure Velociraptor installation.","title":"VULNLAB: Lustrous2","type":"page"},{"content":"Overview Type Machines OS Windows Severity Easy Creator xct Release date 2024 Aug 22 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.127.72 Nmap $ nmap -sT -v -T4 -p 22,53,80,88,443,8080,3128,135,139,445,389,636,5985,3389 --open -Pn 10.10.127.72 PORT STATE SERVICE 53/tcp open domain 88/tcp open kerberos-sec 135/tcp open msrpc 139/tcp open netbios-ssn 389/tcp open ldap 445/tcp …","date":"2024-08-22","permalink":"/posts/vl-retro2/","section":"posts","summary":"Retro2 is an easy difficulty Windows machine, which highlights AD exploitation. Initial external enumeration reveals a publicly accessible SMB Share containing a Microsoft Access Database file, which is password protected. After cracking the password, the contents of the accdb file are accessible, enabling the retrieval of the VBA script inside, where AD credentials can be retrieved. Then, by abusing pre-created computer accounts , we gain access to a computer account with the GenericWrite privilege over another account, which, when leveraged, provides access to the system via RDP . Finally, exploiting the RpcEptMapper registry key results in privilege escalation to a system account.","title":"VULNLAB: Retro2","type":"page"},{"content":"Overview Type Red Team Labs OS Mixed Severity Medium Creator xct Release date 2023 Apr 9 Showcased proficiency Credential Phishing \u0026amp;amp; Credential Spraying Active Directory Attacks with 4 Domains \u0026amp;amp; Forests Reverse Engineering Custom Backdoors Lateral Movements across multiple Domains \u0026amp;amp; Forests PKI Attacks Bypassing modern AV Rule of Engagement (ROE) The Wutai Group has tasked you with …","date":"2024-08-20","permalink":"/posts/vl-wutai/","section":"posts","summary":"Wutai is a Medium-difficulty Red Team lab featuring 15+ machines across multiple networks, domains, and forests, challenging players to achieve Enterprise Admin status. Players refine AD enumeration, exploitation, certificate services, lateral movement, EDR bypass, reverse engineering, and covert operations while abusing trust relationships.","title":"VULNLAB: Wutai","type":"page"},{"content":"Overview Type Machines OS Linux Severity Medium Creator DarkCat \u0026amp;amp; whatev3n Release date 2024 Jul 26 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.93.110 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.93.110 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-29 08:43 JST Nmap scan report for 10.10.93.110 Host is up (0.24s latency). Not shown: 65530 closed tcp ports …","date":"2024-07-24","permalink":"/posts/vl-watcher/","section":"posts","summary":"Watcher is a medium difficulty Linux box that involves Zabbix and is vulnerable to CVE-2024-22120, which allows an attacker to gain Remote Code Execution. After getting RCE, the attacker discovers that a web app can be backdoored, allowing them to gain credentials for a user account. The user is allowed to access TeamCity, which is running as root, and an agent terminal is active, allowing an attacker to gain a reverse shell as the root user.","title":"VULNLAB: Watcher","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator fume \u0026amp;amp; xct Release date 2024 Jun 28 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.98.73 Nmap $ nmap -sC -sV -T4 -p- 10.10.98.73 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-07-06 12:39 JST Nmap scan report for 10.10.98.73 Host is up (0.24s latency). Not shown: 65521 closed tcp ports (conn-refused) PORT STATE …","date":"2024-06-28","permalink":"/posts/vl-manage/","section":"posts","summary":"Manage is an easy Linux machine that features an exposed Java RMI service. Exploiting the underlying vulnerable JMX service leads to remote code execution and gaining a remote shell as the tomcat user. Lateral movement to the useradmin account can be achieved by discovering a misconfigured backup archive which leaks sensitive files, including SSH keys and OTP codes. Finally, a sudo misconfiguration allows for creating a privileged user and achieving full privilege escalation.","title":"VULNLAB: Manage","type":"page"},{"content":"Overview Type Chains OS Windows/Linux (Hybrid) Severity Medium Creator xct Release date 2024 Jun 13 IP 10.10.181.245, 10.10.181.246, 10.10.181.247 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -T4 -Pn 10.10.237.213 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-06-18 18:11 JST Nmap scan report for 10.10.237.213 Host is up. All 1000 scanned ports on …","date":"2024-06-13","permalink":"/posts/vl-heron/","section":"posts","summary":"Heron is a medium-difficulty chain hosted on Vulnlab, featuring an assumed breach from a domain-joined linux jump server access to domain controller. Starting with an enumeration of the internal website for domain users and performing AS-REP roasting, decrypting GPP password from the sysvol share, leading to smb share having write access to web.config, gaining a shell by using AspNetCoreModule for executing powershell commands which lead to finding linux admin’s credentials, reusing the same password that will lead to another user which has WriteAccountRestrictions on dc that leads to resource based delegation","title":"VULNLAB: Heron","type":"page"},{"content":"Overview Type Chains OS Hybrid (Windows/Linux) Severity Insane Creator snowscan Release date 2024 May 24 IP 10.10.157.85, 10.10.157.86, 10.10.157.87 Enumeration Start the instance via Discord, wait around 5/8 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.157.85 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-27 10:46 JST …","date":"2024-05-24","permalink":"/posts/vl-klendathu/","section":"posts","summary":"Klendathu is an Insane difficulty chain hosted on Vulnlab, involved coercion with an undocumented function/procedure on MSSQL, forging a silver ticket, spoofing domain users on linux with GSSAPI authentication, and decrypting RDCMan credentials with domain backup keys.","title":"VULNLAB: Klendathu","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator xct Release date 2024 May 10 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.92.227 Nmap $ nmap -sV -T4 -p- -Pn 10.10.92.227 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-07-06 19:56 JST Nmap scan report for 10.10.92.227 Host is up (0.24s latency). Not shown: 65526 closed tcp ports (conn-refused) PORT STATE SERVICE …","date":"2024-05-10","permalink":"/posts/vl-build/","section":"posts","summary":"Build is an easy-level Linux machine hosted on the VulnLab platform. Its attack path relies primarily on exploiting a PowerDNSAdmin database, a configuration leak, and DNS poisoning to fully compromise the system.","title":"VULNLAB: Build","type":"page"},{"content":"Overview Type Machines OS Windows Severity Insane Creator xct Release date 2024 May 10 Enumeration Start the instance via Discord, wait around 5 minutes and let\u0026amp;rsquo;s go: 10.10.95.132 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.95.132 Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-04 09:44 JST Nmap scan report for 10.10.95.132 Host is up (0.26s latency). Not shown: 65530 filtered tcp …","date":"2024-05-10","permalink":"/posts/vl-reaper2/","section":"posts","summary":"ReaperTwo is an Insane Windows machine that involves both browser and kernel exploitation. The attack chain begins with enumeration of exposed services and access to an SMB share containing development artifacts. A vulnerable web application leveraging the V8 JavaScript engine allows for arbitrary JavaScript execution, which is escalated to remote code execution through a type confusion vulnerability in Harmony Set methods, combined with WebAssembly-based shellcode execution. After gaining an initial foothold as a low-privileged user, privilege escalation is achieved by exploiting a vulnerable kernel driver that exposes a function pointer execution primitive. The exploit bypasses modern protections such as kASLR, DEP, and SMEP by leaking kernel addresses via MSRs, performing a stack pivot, and constructing a ROP chain to modify Page Table Entries (PTEs). Finally, custom kernel shellcode is executed to steal a SYSTEM token, resulting in full system compromise.","title":"VULNLAB: Reaper2","type":"page"},{"content":"Overview Type Chains OS Linux Severity Medium Creator kavigihan Release date 2024 Apr 25 IP 10.10.161.21, 10.10.161.22, 10.10.161.23 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.161.21 10.10.161.22 10.10.161.23 Nmap $ nmap -sC -sV -Pn --min-rate=1000 -T4 10.10.161.21 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-01 14:51 JST Nmap scan report for 10.10.161.21 Host is …","date":"2024-04-25","permalink":"/posts/vl-unintended/","section":"posts","summary":"Unintended is an Medium chain that provides a hands-on experience with common missteps in Active Directory deployments, demonstrating how attackers can pivot between services to escalate privileges. It blends Linux privilege escalation techniques with Active Directory attack paths, making it a valuable practice ground for both offensive and defensive security practitioners.","title":"VULNLAB: Unintended","type":"page"},{"content":"Overview Type Chains OS Windows/Linux (Hybrid) Severity Hard Creator ar0x4 \u0026amp;amp; xct Release date 2024 Apr 15 IP 10.10.219.245, 10.10.219.246 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.219.245 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-03 15:33 JST Nmap scan report for 10.10.219.245 Host is up (0.25s latency). Not …","date":"2024-04-15","permalink":"/posts/vl-vigilant/","section":"posts","summary":"Vigilant is a Hard hybrid Active Directory chain. The environment consists of a domain-joined Linux system and a Windows Domain Controller, presenting a realistic enterprise attack surface. It designed to evaluate penetration testing capabilities in hybrid Windows-Linux environments. Participants begin with zero initial access and must systematically escalate privileges to achieve Domain Administrator-level compromise.","title":"VULNLAB: Vigilant","type":"page"},{"content":"Overview Type Chains OS Windows/Linux (Hybrid) Severity Medium Creator r0BIT Release date 2024 Mar 28 IP 10.10.181.245, 10.10.181.246, 10.10.181.247 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -Pn 10.10.181.245 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-04-27 14:00 JST Nmap scan report for 10.10.181.245 Host is up (0.25s latency). Not shown: 999 …","date":"2024-03-28","permalink":"/posts/vl-tengu/","section":"posts","summary":"Tengu is a medium-rated chained machine on VulnLab, features a mixed environment with two Windows hosts and one Linux host. Exploiting Node-RED on Linux (with MSSQL) grants command execution, decrypts service passwords, and pivots to dump NTLM hash. Constrained delegation allows impersonating MSSQL admin for local admin access then recover Domain Admin credentials via DPAPI and Kerberos to compromise the Domain Controller (DC).","title":"VULNLAB: Tengu","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2024 Mar 15 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.64.89 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.64.89 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-23 18:36 JST Nmap scan report for 10.10.64.89 Host is up (0.24s latency). Not shown: 65521 filtered tcp ports (no-response) …","date":"2024-03-15","permalink":"/posts/vl-sendai/","section":"posts","summary":"Sendai is a medium-difficulty Windows Active Directory machine focused on weak account hygiene, GMSA abuse, and ADCS misconfigurations. Initial access is gained through anonymous SMB enumeration, revealing files that hint at expired accounts with weak passwords. RID brute-forcing identifies users, and login attempts highlight accounts in a forced password reset state. By resetting thomas.powell’s password, the attacker obtains a domain foothold. BloodHound analysis shows that Powell’s group membership can be leveraged to compromise the MGTSVC$ GMSA account, enabling remote code execution on the domain controller. Further local enumeration uncovers inline credentials for clifford.davey, whose CA-OPERATORS group membership grants GenericAll rights over a certificate template. Abusing ESC4/ESC1 conditions with Certipy, the attacker forges a certificate for the administrator account, retrieves its NT hash, and authenticates via WinRM, achieving full domain compromise.","title":"VULNLAB: Sendai","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator Yeeb Release date 2024 Mar 1 Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.115.23 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.115.23 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-25 15:05 JST Nmap scan report for 10.10.115.23 Host is up (0.24s …","date":"2024-03-01","permalink":"/posts/vl-sweep/","section":"posts","summary":"Sweep is a medium difficulty Windows box that involves Active Directory and Lansweeper, a technology asset intelligence tool. The attacker abuses an enabled guest account to gain access to Lansweeper, which has Map Credentials configured, which are login/password combinations for accessing and scanning network assets remotely. The attacker deploys a honeypot SSH server to read the configured credentials. The compromised account is a member of the Lansweeper Discovery group, which has GenericAll ACL over the Lansweeper Admins group. Any account member of the Lansweeper Admins group has administrator privileges on the Lansweeper dashboard. The attacker creates and deploys a package on the Domain Controller to gain complete control.","title":"VULNLAB: Sweep","type":"page"},{"content":"Overview Type Machines OS Windows Severity Easy Creator xct and kozie Release date 2024 Feb 16 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.127.30 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.127.30 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-15 09:34 JST Nmap scan report for 10.10.127.30 Host is up (0.26s latency). Not shown: 65534 filtered tcp ports …","date":"2024-02-16","permalink":"/posts/vl-escape/","section":"posts","summary":"Escape is an Easy Windows machine where users can log in restricted Kiosk mode via RDP without a password. By exploiting the file:// scheme in Microsoft Edge, attackers can browse the file system, bypass restrictions, and open PowerShell. Further enumeration reveals a Remote Desktop Plus profile, whose password can be extracted using BulletsPassView, allowing admin access and UAC bypass to read the root flag.","title":"VULNLAB: Escape","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator xct Release date 2024 Feb 7 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.123.134 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.123.134 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-08 08:40 JST Nmap scan report for 10.10.123.134 Host is up (0.25s latency). Not shown: 65530 closed tcp ports (reset) PORT …","date":"2024-02-07","permalink":"/posts/vl-reset/","section":"posts","summary":"Reset is an Easy difficulty Linux machine which showcases abusing a password reset functionality in a web application following a log poisoning attack, to achieve Remote Code Execution. For privilege escalation, Rservices are abused, then a detached tmux session is used to abuse sudo privileges on nano text editor and execute commands as the root user.","title":"VULNLAB: Reset","type":"page"},{"content":"Overview Type Chains OS Windows Severity Hard Creator xct Release date 2024 Feb 2 IP 10.10.212.197, 10.10.212.198, 10.10.212.199 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.212.197 PORT STATE SERVICE VERSION 3389/tcp open ms-wbt-server Microsoft Terminal Services | ssl-cert: Subject: commonName=BERSRV100.kaiju.vl | Not valid …","date":"2024-02-02","permalink":"/posts/vl-kaiju/","section":"posts","summary":"Kaiju is a Hard-rated Active Directory chain, from initial reconnaissance to full domain compromise, covering FileZilla exploitation, KeePass database extraction, NTLM relay attacks, and ADCS abuse (ESC8).","title":"VULNLAB: Kaiju","type":"page"},{"content":"Overview Type Machines OS Windows Severity Easy Creator xct and kozie Release date 2024 Jan 19 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.117.66 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.117.66 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-14 12:49 JST Nmap scan report for 10.10.117.66 Host is up (0.26s latency). Not shown: 65531 filtered tcp ports …","date":"2024-01-19","permalink":"/posts/vl-lock/","section":"posts","summary":"Lock is an Easy-rated Windows machine that involves enumerating a Gitea repository to find a Personal Access Token. This token is then used to deploy an ASPX web shell on the server, which provides an initial foothold. A password is then decrypted from an mRemoteNG configuration file, providing access to a new user account. Finally, a local privilege escalation vulnerability in the PDF24 application is exploited to obtain a shell with SYSTEM privileges.","title":"VULNLAB: Lock","type":"page"},{"content":"Overview Type Chains OS Windows Severity Medium Creator kozie Release date 2024 Jan 5 IP 10.10.231.117, 10.10.231.118 Enumeration Start the instance via Discord, wait around 8 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.231.117 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-04 17:00 JST Nmap scan report for 10.10.231.117 …","date":"2024-01-05","permalink":"/posts/vl-tea/","section":"posts","summary":"Tea is a medium-rate small Active Directory chain that provides hands-on experience with common Active Directory and DevOps vulnerabilities and misconfigurations, demonstrating how attackers can pivot between services and retrieve sensitive data to move laterally and escalate privileges.","title":"VULNLAB: Tea","type":"page"},{"content":"Overview Type Machines OS Linux Severity Hard Creator jkr Release date 2023 Dec 22 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.112.131 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.112.131 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-24 09:29 JST Nmap scan report for 10.10.112.131 Host is up (0.25s latency). Not shown: 65533 closed tcp ports (reset) PORT …","date":"2023-12-22","permalink":"/posts/vl-race/","section":"posts","summary":"Race is a hard-difficulty Linux machine with a web application running Grav CMS and phpsysinfo. The phpsysinfo endpoint is protected with basic authentication, but its password is weak. The endpoint leaks credentials for the Grav CMS admin panel, which is accessible to a low-privilege user with permission to create web server backups. The attacker exploits the backup functionality to retrieve the rest token for a user with privileges to add a proxy and install themes. The attacker adds a proxy to intercept the response, uploads a custom theme, and gets a reverse shell. After gaining a reverse shell, the attacker is able to read sensitive files using a hardcoded password for the max user account. The max user account is a racers group member, which has write permission over a file vulnerable to a time-of-check / time-of-use vulnerability in a cron script. As an attacker, we will create named pipes to suspend execution and replace the file, thereby gaining command execution as root.","title":"VULNLAB: Race","type":"page"},{"content":"Overview Type Chains OS Windows Severity Hard Creator Geiseric Release date 2023 Dec 15 IP 10.10.152.213, 10.10.152.214 Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.152.213 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-08 18:50 JST Nmap scan report for …","date":"2023-12-15","permalink":"/posts/vl-sidecar/","section":"posts","summary":"Sidecar is a Hard-rated small Active Directory chain that contains 2 Windows machines, however, attacks are not for beginners on Active Directory Pentesting. From initial enumeration through to full domain compromise, including Shell via a .lnk file, NTLM relay, WebDAV coercion, Shadow Credentials, PKINIT abuse, and a Silver Ticket attack.","title":"VULNLAB: Sidecar","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator xct Release date 2023 Dec 8 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.68.89 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.68.89 Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-12 12:58 JST Nmap scan report for 10.10.68.89 Host is up (0.23s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE …","date":"2023-12-08","permalink":"/posts/vl-forgotten/","section":"posts","summary":"Forgotten is an Easy Linux machine on VulnLab that challenges players to exploit an unfinished LimeSurvey installation by deploying a controlled MariaDB instance to gain admin access. Players then upload a malicious plugin for remote code execution inside a Docker container, discover an environment variable for host access, and escalate privileges by chaining low host access with container root privileges via a setuid binary.","title":"VULNLAB: Forgotten","type":"page"},{"content":"Overview Type Machines OS Linux Severity Medium Creator xct Release date 2023 Oct 27 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.86.123 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.86.123 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-17 19:45 JST Nmap scan report for 10.10.86.123 Host is up (0.25s latency). Not shown: 65527 closed tcp ports (reset) PORT STATE …","date":"2023-10-27","permalink":"/posts/vl-slonik/","section":"posts","summary":"Slonik is a Medium-difficulty Linux machine that focuses on NFS, PostgreSQL abuse, and privilege escalation through insecure backup automation. Initial access is obtained by enumerating exposed NFS shares and leveraging UID/GID trust relationships to access a home directory. History files within the share reveal database credentials and reference a locally bound PostgreSQL socket. Although direct SSH access is restricted, the socket is tunneled over SSH to interact with the database, where built-in PostgreSQL functionality is leveraged to achieve remote code execution. Privilege escalation is accomplished by monitoring system processes and identifying a root-executed backup script, ultimately leveraging pg_basebackup behavior and SUID permissions to obtain a root shell.","title":"VULNLAB: Slonik","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator enox Release date 2023 Oct 13 Enumeration Start the instance via Discord, wait around 2 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.83.122 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.83.122 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-27 18:06 JST Nmap scan report for 10.10.83.122 Host is up …","date":"2023-10-13","permalink":"/posts/vl-media/","section":"posts","summary":"Media is a Medium-rated machine that features an Apache XAMPP stack on Windows hosting a custom PHP web application. The web application allows the upload of a Windows Media Player compatible file that can be leveraged to leak the NTLMv2 hash of the user account that opens it. This hash can be cracked to obtain user credentials that can be used to authenticate to the target via SSH. Upon gaining initial access the source code of the application can be analyzed to determine the generate storage path of uploaded files on the web application which can lead to an NTFS Junction (directory symbolic link) attack to upload a malicious PHP web shell for RCE. Once a shell under the context of the web server's service account, players can abuse the SeTcbPrivilege - Act as part of the operating system, a Windows privilege that lets code impersonate any user and achieve administrative privileges. Alternative methods for privilege escalation involve regaining the SeImpersonate privilege to elevate to NT Authority\\SYSTEM.","title":"VULNLAB: Media","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator Geiseric Release date 2023 Oct 6 Enumeration Start the instance via Discord, wait around 2 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.120.223 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.120.223 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-26 17:44 JST Nmap scan report for 10.10.120.223 Host is up …","date":"2023-10-06","permalink":"/posts/vl-delegate/","section":"posts","summary":"Delegate is a medium-rated Windows machine that involves Active Directory attacks. The machine has the guest account enabled, allowing the attacker to read files that contain hard-coded credentials. The credentials allow us to WriteProperty of a user account that is allowed to have WinRM sessions on the Domain Controller. The compromised user has the SeEnableDelegationPrivilege privilege assigned, which allows us to modify the TRUSTED_FOR_DELEGATION flag for AD objects, enabling us to perform Unconstrained Delegation.","title":"VULNLAB: Delegate","type":"page"},{"content":"Overview Type Chains OS Windows Severity Hard Creator kozie \u0026amp;amp; xct Release date 2023 Sep 22 IP 10.10.200.21, 10.10.200.22 Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.200.21 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-23 14:43 JST Nmap scan report for …","date":"2023-09-22","permalink":"/posts/vl-push/","section":"posts","summary":"Push is a Hard-rated small Windows Active Directory chain featuring a one domain controller and one member server. This chain focuses on advanced attack techniques including ClickOnce application exploitation, SCCM coercion, and ADCS exploitation via Golden Certificate attacks.","title":"VULNLAB: Push","type":"page"},{"content":"Overview Type Machines OS Windows Severity Insane Creator xct Release date 2023 Aug 18 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.125.10 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.125.10 Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-02 11:27 JST Nmap scan report for 10.10.121.253 Host is up (0.24s latency). Not shown: 65531 filtered tcp ports (no-response) …","date":"2023-08-18","permalink":"/posts/vl-reaper/","section":"posts","summary":"Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and buffer-overflow attacks. By exploiting these flaws, an attacker can leak sensitive memory regions, hijack the program’s execution flow, and ultimately obtain a reverse shell on the target as the user keysvc. After gaining initial access, the attacker discovers a file containing a DPAPI blob. Once decrypted, this blob provides valid credentials for RDP access as keysvc. Continued enumeration reveals a custom kernel driver present and actively running on the system. Through reverse-engineering the driver, the attacker determines that it permits arbitrary kernel-level writes. Leveraging this capability, the attacker is able to steal a privileged token and escalate to a full SYSTEM shell (NT AUTHORITY\\SYSTEM).","title":"VULNLAB: Reaper","type":"page"},{"content":"Overview Type Machines OS Windows Severity Easy Creator r0BIT Release date 2023 Aug 11 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.77.33 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.77.33 PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-12-17 10:43:01Z) 135/tcp open msrpc Microsoft …","date":"2023-08-11","permalink":"/posts/vl-retro/","section":"posts","summary":"Retro is an Easy Windows machine that showcases an Active Directory Domain Controller. Through SMB enumeration and pre-created machine account exploitation, we gain access to the system. Through the exploitation of the Active Directory Certificate Service and specifically by using the ESC1 attack, which involves exploiting certificate templates to impersonate the Administrative user, privilege escalation is achieved.","title":"VULNLAB: Retro","type":"page"},{"content":"Overview Type Chains OS Linux Severity Hard Creator jkr Release date 2023 Jul 21 IP 10.10.165.181, 10.10.165.182 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.165.181 10.10.165.182 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.165.181 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-13 09:57 JST Nmap scan report for 10.10.165.181 Host is up (0.26s latency). Not shown: …","date":"2023-07-21","permalink":"/posts/vl-control/","section":"posts","summary":"Control is a Hard-rated chains focus on a small multi-host Linux environment that simulates a realistic internal network and endpoint-management infrastructure. The lab contains two primary hosts (os.control.vl and intra.control.vl) and a variety of services (web apps, OSCTRL/osquery, SSH, nginx, Docker) that chain together to a full domain compromise. It focuses on exploiting web applications, abusing management tooling (OSCTRL / osquery), and leveraging operational misconfigurations to move from an initial foothold to full root on multiple hosts.","title":"VULNLAB: Control","type":"page"},{"content":"Overview Type Chains OS Windows/Linux (Hybrid) Severity Easy Creator xct Release date 2023 Jun 22 IP 10.10.192.5, 10.10.192.6 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.192.5 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-28 09:58 JST Nmap scan report for 10.10.192.5 Host is up (0.26s latency). Not shown: 65521 …","date":"2023-06-22","permalink":"/posts/vl-hybrid/","section":"posts","summary":"Hybrid is an Easy-rated, simplified Active Directory chain with 2 servers MAIL01 (Roundcube webmail) and DC01. Exploited a vulnerable Roundcube plugin via a crafted email, escalated privileges via NFS, and abused AD CS with certipy to achieve Domain Admin.","title":"VULNLAB: Hybrid","type":"page"},{"content":"Overview Type Machines OS Linux Severity Medium Creator xct Release date 2023 Jun 10 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.107.35 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.107.35 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-15 21:22 JST Nmap scan report for 10.10.92.62 Host is up (0.26s latency). Not shown: 65533 filtered tcp ports (no-response) …","date":"2023-06-10","permalink":"/posts/vl-bamboo/","section":"posts","summary":"Bamboo is an medium-rated Linux machine that begins with discovering a Squid proxy. The proxy is used to scan internal ports and reveals a PaperCut NG instance. A known PaperCut vulnerability CVE-2023-27350 is exploited to gain a foothold. Local enumeration reveals a writable directory containing a script that runs with root privileges. By modifying the script, we obtain a shell as root.","title":"VULNLAB: Bamboo","type":"page"},{"content":"Overview Type Chains OS Windows Severity Medium Creator xct \u0026amp;amp; r0BIT Release date 2023 Jun 10 IP 10.10.184.133, 10.10.184.134, 10.10.184.135 Enumeration Start the instance via Discord, wait around 10 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.184.133 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-02 15:52 JST Nmap …","date":"2023-06-10","permalink":"/posts/vl-reflection/","section":"posts","summary":"Reflection is a medium-difficulty Active Directory chain that simulates a vulnerable enterprise environment and challenges users to progress from limited access to Domain Administrator. Including 3 machines, with anonymous SMB bind abuse, MSSQL abuse, NTLM relay attacks, Windows Credential Vault harvesting, Resource-Based Constrained Delegation (RBCD), and finally credential reuse.","title":"VULNLAB: Reflection","type":"page"},{"content":"Overview Type Machines OS Windows Severity Hard Creator xct Release date 2023 May 10 (JST) Enumeration Start the instance via Discord, wait around 2 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.92.144 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.75.231 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-19 11:48 JST Nmap scan report for 10.10.75.231 Host is up …","date":"2023-05-10","permalink":"/posts/vl-job2/","section":"posts","summary":"Job2 is a hard-rated Windows machine that involves a macro phishing attack for initial foothold. The machine has hMailServer installed, which includes a configuration file containing encrypted credentials for the database connection. After extracting the password database, we decrypt the SQL Server Compact database file (SDF), allowing a compromised user who can use WinRM to the machine. The machine has a vulnerable version of Veeam Backup \u0026 Replication; the attacker executes a malicious executable under sqlserver.exe, which is running as SYSTEM to gain full access.","title":"VULNLAB: Job2","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator xct Release date 2023 Apr 25 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.123.168 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.123.168 Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-11 12:47 JST Nmap scan report for 10.10.123.168 Host is up (0.24s latency). Not shown: 65531 closed tcp ports (reset) PORT …","date":"2023-04-25","permalink":"/posts/vl-sync/","section":"posts","summary":"Sync is an Easy-rated Linux machine on the Vulnlab platform that focuses on service enumeration and exploiting an insecure Rsync configuration, custom hash cracking, and privilege escalation.","title":"VULNLAB: Sync","type":"page"},{"content":"Overview Type Machines OS Linux Severity Hard Creator jkr Release date 2023 Mar 13 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.87.208 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.87.208 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-14 16:06 JST Nmap scan report for 10.10.87.208 Host is up (0.24s latency). Not shown: 65533 closed tcp ports (reset) PORT …","date":"2023-03-13","permalink":"/posts/vl-dump/","section":"posts","summary":"Dump is a Hard-rated Linux machine featuring a custom PHP web application that allows the creation of packet captures as well as upload and download functionality of pcap files. The machine demonstrates command argument injection through file naming to obtain initial remote code execution as www-data. Enumeration of the system reveals a sudo rule with tcpdump that can be abused for arbitrary file writes to the system and bypassing AppArmor security policy restrictions. With arbitrary file writes players can write malicious Message of The Day configurations that execute as root during system login.","title":"VULNLAB: Dump","type":"page"},{"content":"Overview Type Machines OS Linux Severity Hard Creator xct Release date 2023 Feb 17 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.126.244 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.126.244 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-15 11:30 JST Nmap scan report for 10.10.126.244 Host is up (0.26s latency). Not shown: 65531 closed tcp ports (reset) PORT …","date":"2023-02-17","permalink":"/posts/vl-store/","section":"posts","summary":"Store is a Hard difficulty box that hosts a Node.js web application, allowing file uploads and storage. The app is vulnerable to Arbitrary File Read, which lets us read configuration files and recover SFTP credentials. We can also dump the host’s environment variables and discover the app was started with --inspect, with the Node inspector listening on port 9229. By abusing SFTP for port forwarding, we can tunnel that internal inspector port to our machine, attach and run JavaScript to spawn a reverse shell as user dev. For privilege escalation, the ChromeDriver service on port 9515 can be abused via its WebDriver API to execute a malicious script and gain a root shell.","title":"VULNLAB: Store","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2023 Feb 14 Enumeration Start the instance via Discord, wait a minute for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.116.137 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.116.137 PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 | http-methods: …","date":"2023-02-14","permalink":"/posts/vl-breach/","section":"posts","summary":"Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the `Administrator` user and gain access to Microsoft SQL Server. Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.","title":"VULNLAB: Breach","type":"page"},{"content":"Overview Type Chains OS Windows Severity Easy Creator r0BIT Release date 2022 Sep 20 IP 10.10.140.69, 10.10.140.70 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.140.69 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-03 11:49 JST Nmap scan report for 10.10.140.69 Host is up (0.24s latency). Not shown: 65509 closed tcp …","date":"2022-09-20","permalink":"/posts/vl-trusted/","section":"posts","summary":"Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web vulnerabilities, local privilege escalation, and cross-domain trust abuse. An internal network access is provided with no credentials, and the goal is to assess the security posture of the AD environment.","title":"VULNLAB: Trusted","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2022 Jul 2 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.106.103 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.106.103 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-28 09:56 JST Nmap scan report for 10.10.106.103 Host is up (0.25s latency). Not shown: 65522 filtered tcp ports …","date":"2022-07-02","permalink":"/posts/vl-bruno/","section":"posts","summary":"Bruno is a medium-rated Windows domain box that chains insecure application configuration and weak Active Directory hygiene to go from no access to domain admin. The service-facing component is a custom .NET application that extracts ZIP entries unsafely using Path.Combine, allowing crafted archives to perform a zip-slip and place files under the app folder. That capability enables a DLL-search-path hijack - an attacker who can write to the queue share can drop a malicious dll and achieve code execution as the service user. On the network/AD side, an account svc_scan is discoverable and kerberoastable/AS-REP crackable; its recovered credentials grant write access to the queue share, which is used to trigger the DLL payload and get a low-privilege shell. From there the default machine account quota of authenticated users and RBCD are abused to perform a Kerberos relay/RBCD attack that resets the Administrator password and yields full domain compromise.","title":"VULNLAB: Bruno","type":"page"},{"content":"Overview Type Machines OS Windows Severity Hard Creator xct Release date 2022 Jun 6 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.89.134 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.89.134 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-31 17:41 JST Stats: 0:04:49 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan Service scan Timing: About 75.00% …","date":"2022-06-06","permalink":"/posts/vl-rainbow2/","section":"posts","summary":"Rainbow2 is a Hard Windows machine centered around exploit development for a custom network file-sharing service. Initial enumeration reveals anonymous FTP access and an unknown service listening on TCP port 2121. The FTP share exposes the vulnerable service binary, a developer README, and a copy of SysWOW64\\kernel32.dll. The README confirms that the service was rebuilt with ASLR, DEP, and GS enabled. Static and dynamic analysis then shows that the service is still vulnerable to a format string issue and a stack-based overflow that overwrites the SEH chain. The format string leak provides a reliable ASLR bypass by disclosing a pointer inside filesrv.exe; the SEH overwrite provides control of the exception handler; and a ROP chain calls VirtualAlloc to bypass DEP. Privilege escalation is achieved by abusing SeDebugPrivilege to migrate into a SYSTEM process.","title":"VULNLAB: Rainbow2","type":"page"},{"content":"Overview Type Machines OS Linux Severity Medium Creator xct Release date 2022 Mars 4 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.90.15 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.90.15 Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-21 08:25 JST Nmap scan report for 10.10.90.15 Host is up (0.23s latency). Not shown: 65532 filtered tcp ports (no-response) PORT …","date":"2022-03-04","permalink":"/posts/vl-unchained/","section":"posts","summary":"Unchained is a Medium-rated Linux machine available on Vulnlab platform. Starting with NFS share enumeration then a source code analysis allows a JSONPICKLE deserialization to obtain a reverse shell as user. For the privilege escalation, CVE-2021-44730 (Dirty snap-confine LPE) or CVE-2022-0847 (DirtyPipe) can be exploited.","title":"VULNLAB: Unchained","type":"page"},{"content":"Overview Type Machines OS Linux Severity Insane Creator jkr Release date 2022 Feb 25 (JST) Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.71.179 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.71.179 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-16 11:05 JST Nmap scan report for 10.10.71.179 Host is up (0.24s latency). Not shown: 65533 closed tcp ports (reset) PORT …","date":"2022-02-25","permalink":"/posts/vl-zero/","section":"posts","summary":"Zero is an Insane difficulty Linux machine that features a web application that allows for the creation of credentials to be used on an SFTP server where users can create their own HTML pages. This service is exploitable by uploading a malicious .htaccess file to gain arbitrary file read access to the web servers' asset files. By viewing the source code of these files players will find hard coded credentials that allow for access to the target over SSH. The Apache server configuration is periodically managed by a cronjob that checks the integrity of the Apache configurations and can be abused by satisfying the conditions of the cronjob task to include a malicious line into the restored configuration to leak the contents of files owned by root.","title":"VULNLAB: Zero","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator xct Release date 2022 Jan 23 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go (waiting 5 min to be sure the instance is fully deployed): 10.10.99.27 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.99.27 Nmap scan report for 10.10.85.164 Host is up (0.26s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE …","date":"2022-01-23","permalink":"/posts/vl-data/","section":"posts","summary":"Data is an Easy Linux machine that involves exploiting CVE-2021-43798, an arbitrary file read via path traversal in Grafana. By exploiting this vulnerability, the database file for Grafana is extracted, and the hashes in the database are converted to a format readable by Hashcat. The hash is then cracked and can be used for SSH access to the target as user boris. The compromised user has the privileges to execute docker exec as root on the system, allowing the user to escalate and obtain root access by adding the privileged flag to running containers and mounting the host filesystem.","title":"VULNLAB: Data","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2022 Jan 17 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go: 10.10.91.23 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.91.23 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-29 12:57 JST Stats: 0:04:18 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan Service scan Timing: About 88.89% …","date":"2022-01-17","permalink":"/posts/vl-rainbow/","section":"posts","summary":"Rainbow is a medium-difficulty Windows machine exposing FTP and HTTP services on ports 21 and 80 \u0026 8080 respectively. From the FTP server, we can retrieve the web server binary and a PowerShell restart script, which is used to relaunch the server in the event of a crash automatically. The HTTP service on port 8080 is vulnerable to an SEH-based buffer overflow and exploiting this yields code execution as the rainbow user. Because rainbow is a member of the Administrators group, we achieved full elevation by bypassing UAC via the FodHelper technique.","title":"VULNLAB: Rainbow","type":"page"},{"content":"Overview Type Chains OS Windows Severity Hard Creator xct Release date 2021 Dec 25 IP 10.10.233.245, 10.10.233.246 Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.233.245 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-06 10:24 JST Nmap scan report for 10.10.233.245 …","date":"2021-12-25","permalink":"/posts/vl-intercept/","section":"posts","summary":"Intercept is a small Active Directory scenario rated as Hard that provides hands-on experience with common Active Directory vulnerabilities and misconfigurations, demonstrating relay attacks and authentication coercion attacks can be used to get access to the domain.","title":"VULNLAB: Intercept","type":"page"},{"content":"Overview Type Chains OS Windows Severity Hard Creator xct Release date 2021 Dec 25 IP 10.10.236.229, 10.10.236.230 Enumeration Start the instance via Discord, wait around 5 minutes for the machine to start all services and let\u0026amp;rsquo;s go: Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.236.229 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-05 19:18 JST Nmap scan report for LUSDC.lustrous.vl …","date":"2021-12-25","permalink":"/posts/vl-lustrous/","section":"posts","summary":"Lustrous is a Hard-rated chain consisting of 2 machines on vulnlab. Cevering AS-REP roasts, Kerberoasts, the main lesson on this chain is to demonstrate how silver tickets can be used with service accounts in a Active Directory environment.","title":"VULNLAB: Lustrous","type":"page"},{"content":"Overview Type Machines OS Linux Severity Easy Creator xct Release date 2021 Dec 12 Enumeration Start the instance via Discord and let\u0026amp;rsquo;s go (waiting 5 min to be sure the instance is fully deployed): 10.10.116.125 Nmap $ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.116.125 Nmap scan report for 10.10.116.125 Host is up (0.24s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE …","date":"2021-12-12","permalink":"/posts/vl-feedback/","section":"posts","summary":"Feedback is an Easy-rated Linux machine centered around exploiting a vulnerable Log4j input field.","title":"VULNLAB: Feedback","type":"page"},{"content":"Overview Type Machines OS Windows Severity Medium Creator xct Release date 2021 Nov 27 (JST) Enumeration Start the instance via Discord, wait around 2 minutes for the machine to start all services and let\u0026amp;rsquo;s go: 10.10.97.227 Nmap $ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.97.227 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-16 18:52 JST Nmap scan report for 10.10.122.11 Host is up …","date":"2021-11-27","permalink":"/posts/vl-job/","section":"posts","summary":"Job is a Medium-rated Windows box. It runs an SMTP server and its website accepts LibreOffice-compatible documents, providing a vector to deliver a document with embedded macros that leads to remote code execution as user jack.black. jack.black is a member of the DEVELOPERS group, which has write access to the IIS web root, allowing files to be placed in the webroot and achieve code execution as the IIS AppPool service account. The IIS AppPool account has the SeImpersonate privilege, creating conditions that allow token-impersonation techniques to be used to escalate privileges to Administrator.","title":"VULNLAB: Job","type":"page"},{"content":"Proposed research paper Building an AI-Augmented SOC with Codex, Daybreak Blue and Microsoft Defender XDR From alert triage to controlled automated containment Research focus: Using GPT-5.6 Sol through Daybreak Blue and Microsoft XDR including Defender for Endpoint APIs to improve SOC alert triage accuracy, reduce analyst workload, and automate selected defensive response actions. Abstract Modern …","date":"2026-09-04","permalink":"/research/ai-soc-xdr/","section":"research","summary":"Reasoning without Authority: Designing a Governed GPT-5.6 Daybreak Blue Architecture for Microsoft Defender XDR","title":"AI-Augmented Security Operations","type":"page"},{"content":"METR Redwood Research ","date":"2026-08-26","permalink":"/research/openai-huggingface-metr/","section":"research","summary":"Two METR staff members (Hjalmar Wijk and Ajeya Cotra) and a Redwood Research staff member contracting with METR (Ryan Greenblatt) worked on premises at OpenAI over a total of six days to attempt to form an independent understanding of model behavior observed during the recent incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned message board.","title":"METR – the OpenAI / Hugging Face hacking incident investigation","type":"page"},{"content":"","date":"2026-08-26","permalink":"/research/openai-huggingface/","section":"research","summary":"In July 2026, during internal cybersecurity evaluations, OpenAI models in an internal evaluation environment circumvented controls intended to isolate them from the internet and performed computer network exploitation of OpenAI’s internal research infrastructure and Hugging Face systems.","title":"OpenAI – Hugging Face Incident","type":"page"}]