CTF write-ups
Hack The Box, Proving Grounds, TryHackMe, and other CTF-style walkthroughs.

PG • CTF • Hutch • Write-Up
Published: at 12:38 PMProving Grounds Hutch write-up: from LDAP user discovery to abusing WebDAV uploads for ASPX RCE, and finally using LAPS to read back the local Administrator password.

PG • CTF • Heist • Write-Up
Published: at 12:37 PMProving Grounds Heist write-up: turn a URL feature into SSRF, capture an NTLMv2 hash with Responder, abuse a gMSA password reader and finish with SeRestorePrivilege.

PG • CTF • Access • Write-Up
Published: at 12:36 PMProving Grounds CTF - Access. File upload vulnerability, Kerberoasting, and SeManageVolumePrivilege abuse.

HTB • CTF • Administrator • Write-Up
Updated: at 10:46 AMHack The Box Administrator: chain BloodHound-discovered ACL abuses (GenericAll → ForceChangePassword → GenericWrite) into DCSync, then crack the recovered Password Safe vault.