Skip to main content

Posts

2026

HackTheBox Fluffy walkthrough
·2900 words·14 mins· loading · loading
A Windows Active Directory machine involving SMB share exposure, NTLM credential coercion, BloodHound-guided privilege escalation, shadow credentials abuse, and ADCS certificate exploitation leading to full domain compromise.
HackTheBox EscapeTwo walkthrough
·3793 words·18 mins· loading · loading
A Windows Active Directory machine involving SMB share exposure, NTLM credential coercion, BloodHound-guided privilege escalation, shadow credentials abuse, and ADCS certificate exploitation leading to full domain compromise.
HackTheBox Driver walkthrough
·1757 words·9 mins· loading · loading
A HackTheBox Windows machine involving NTLM hash capture through a firmware review workflow and privilege escalation via a vulnerable Ricoh printer driver.
HTB Active Writeup
·2115 words·10 mins· loading · loading
An Active Directory machine involving GPP password leakage, Kerberoasting, and domain admin compromise.
HackTheBox Cicada Writeup
·2907 words·14 mins· loading · loading
A Medium difficulty Active Directory machine involving SMB enumeration, credential exposure, and privilege abuse leading to full domain compromise.
HackTheBox Principal walkthrough
·2188 words·11 mins· loading · loading
A Linux machine involving JWT authentication bypass, credential reuse, and SSH CA key abuse to gain root access.
HTB Support Writeup
·1629 words·8 mins· loading · loading
An Active Directory machine involving SMB enumeration, credential extraction, and RBCD-based domain privilege escalation.
HTB Overwatch Writeup
·2124 words·10 mins· loading · loading
An Active Directory machine involving .NET WCF exploitation, SQL credential discovery, and ADIDNS hijacking leading to SYSTEM access.

2025

Dream Job-2
·1109 words·6 mins· loading · loading
An in-depth Threat Intelligence investigation of the Hack The Box Sherlocks challenge Dream Job-2, focused on malware used by the Lazarus Group during Operation Dream Job. This analysis covers malware lineage, macro-based initial access, payload staging, and defensive detection opportunities
HookFlare
·1040 words·5 mins· loading · loading
An Android DFIR investigation of the HTB Sherlocks challenge HookFlare, reconstructing an SMS-based phishing attack, malicious app behavior, permission abuse, and encrypted data exfiltration.