Full write-ups for Hack The Box machines — enumeration, exploitation, and privilege escalation.
Hack The Box write-up for the Sense machine. Credential discovery via exposed text files leads to authenticated command injection on pfSense 2.1.3, resulting in root shell access.
Hack The Box write-up for the Return machine. LDAP credential capture via printer admin panel, WinRM access, and privilege escalation abusing the Server Operators group.
Hack The Box write-up for the Sauna machine. Employee names from a website feed Kerberos user enumeration, AS-REP roasting yields credentials, autologon secrets pivot to a service account with DCSync rights, and pass-the-hash completes the domain compromise.
Active Directory chain — CVE-2025-24071 hash leak, Shadow Credentials via GenericWrite, and ADCS ESC16 UPN hijack to Domain Admin.