CTFs

Detailed walkthroughs for TryHackMe, HackTheBox, and VulnHub machines.

TryHackMe

TryHackMe room walkthroughs, from easy to hard.

189 entries Explore

HackTheBox

HackTheBox walkthroughs for retired machines.

73 entries Explore

Vulnhub

VulnHub boot-to-root walkthroughs and machine solutions.

53 entries Explore

Recent

Oh My Webserver Walkthrough

easy windows

Today we are solving another Linux-based TryHackMe machine called Oh My WebServer. This machine focuses on exploiting vulnerable web services, container breakout-style enumeration,

Carnage Walkthrough

easy linux

Today we are solving another Defensive Security challenge from TryHackMe called Carnage. In this challenge we are provided with a packet capture (PCAP) file from a real-world malwa

BreakOutTheCage Walkthrough

easy linux

Today we are solving another TryHackMe machine called Break Out The Cage, a Linux-based challenge inspired by Nicolas Cage. The machine contains multiple stages including anonymous

Super Spammr Walkthrough

easy windows

The infamous cosmic hacker Super-spam has returned. Originating from the planet Alpha Solaris IV, Super-spam's mission is to eliminate Linux systems across the galaxy and replace t

REvil Walkthrough

intermediate linux

One of the employees at Lockman Group reported that all of his files had suddenly been renamed with an unfamiliar extension. After a quick inspection, the IT department suspected r

Conti Walkthrough

easy linux

Today we are investigating a ransomware incident involving Conti Ransomware, one of the most notorious Ransomware-as-a-Service (RaaS) operations.

IronShade Walkthrough

easy linux

Based on threat intelligence reports, an APT group known as IronShade has been actively targeting Linux servers across the region.

Operation Coldstart Walkthrough

easy linux

Operation ColdStart is an easy Linux-based machine where our objective is to compromise the target, gain user access, and ultimately escalate privileges to root.

Itsybitsy Walkthrough

easy linux

During routine SOC monitoring, Analyst John observed an IDS alert indicating potential Command and Control (C2) communication originating from a user named Browne in the HR departm