WE ARE THE BUG
WE ARE THE BUG
ARCHIVES ABOUT RESEARCH TOOLS MISC GH
ARCHIVES ABOUT RESEARCH TOOLS MISC GH

    RDP

    HTB: Touch

    Touch is an Easy-rated Windows machine featuring a kiosk-mode device management application. Initial access stems from improperly secured credentials exposed …

    October 4, 2026 · 3644 words · 18 min
    Easy Windows Season 12 Special Season: Aero Exposed API RDP Kiosk Escape DLL Hijack MySQL UDF

    HTB: TrustFall

    TrustFall is an Insane-rated hybrid machine featuring a complex, multi-stage kill chain that bridges external web exploitation with deep Active Directory and …

    September 12, 2026 · 22337 words · 105 min
    Insane Windows Season 11 Season of the Punk CVE-2026-22200 CVE-2026-24061 ADCS ESC17 WinRM RDP DACL VBScript PRNG WSUS ESC7

    NetExec

    Swiss-army knife for Active Directory and network protocol enumeration/exploitation, successor to CrackMapExec.

    July 25, 2026 · 3151 words · 15 min
    Linux Active Directory Python SMB LDAP WinRM WMI RDP SSH

    VULNLAB: Shiva

    Shiva is an insane-difficulty Red Team lab on Vulnlab that simulates a hardened hybrid Active Directory environment (on-premises and Azure) with 10+ machines …

    April 17, 2025 · 33714 words · 159 min
    Insane Windows Azure Entra id O365 AWS S3 bucket PSINFO WDAC Command execution Refresh Token Git SMB share RDP AddSelf LSA MSSQL SeImpersonatePrivilege Pleasant Password Manager Veeam Backup Sharepoint

    VULNLAB: Escape

    Escape is an Easy Windows machine where users can log in restricted Kiosk mode via RDP without a password. By exploiting the file:// scheme in Microsoft Edge, …

    February 16, 2024 · 1593 words · 8 min
    Easy Windows RDP Kiosk escape BulletsPassView UAC Bypass

    VULNLAB: Reaper

    Reaper is an Insane Windows machine that begins with an exposed FTP service. Within the FTP share resides a Windows binary vulnerable to both format-string and …

    August 18, 2023 · 8779 words · 42 min
    Insane Windows Buffer overflow Format string RDP DPAPI Python C Kernel exploitation Reverse engineering

    VULNLAB: Trusted

    Trusted is an Easy small Active Directory chain involving two domain controllers (labdc.lab.trusted.vl and trusteddc.trusted.vl) that focuses on web …

    September 20, 2022 · 7056 words · 34 min
    Easy Windows Apache XAMPP LFI Fuzzing MariaDB ForceChangePassword ProcMon Reverse engineering DLL Hijack Domain trusts EFS bypassing WinRM RDP

    No posts match this tag.

      Copyright 2026. WE ARE THE BUG · authorized research & for education purpose only
      Built with Hugo & 💜+🧠