root@z2r:~/blog/category#cd writeups && ls -la

<CTF Writeups />

Walkthroughs of CTF challenges from HackTheBox, TryHackMe, and more

> grep -i
CTF WRITEUPSFORENSICS

THM - After Hours

TryHackMeMedium

A hunt through a resort's offline WMI repository that traces a fileless backdoor from a "clean" event-log binding down through Base64-and-UTF16-encoded PowerShell, a reflectively-loaded .NET payload hidden in a custom Win32_HardwareTelemetry class, and a quietly planted net user backdoor account.

August 8, 202613 min read
CTF WRITEUPSACTIVE DIRECTORY

HackSmarter - MartiniAD

HackSmarterEasy

MartiniAD is an Easy-difficulty Active Directory lab hosted by HackSmarter. The domain `DRY.MARTINI.BARS` is fronted by a single Domain Controller (`DC01`) that permits unauthenticated SMB null/guest sessions. This allows enumeration of a non-default share containing plaintext credentials for a low-privileged domain user. Those credentials are used to Kerberoast a service account, whose cracked password grants a foothold via WinRM. Password reuse between the service account and a linked human Tier-0 admin account (which sits in Domain Admins) then provides full domain compromise, culminating in a DCSync attack to extract the KRBTGT hash.

August 6, 202610 min read
CTF WRITEUPSACTIVE DIRECTORY

HackSmarter - ShadowGate

HackSmarterEasy

Compromising the ShadowGate Active Directory lab through a chained attack path — from AS-REP roasting and ACL abuse via Shadow Credentials, to coercing the Domain Controller with PetitPotam and relaying its authentication into a certificate-based DCSync — culminating in full domain compromise via the krbtgt hash.

August 6, 20268 min read
CTF WRITEUPSBOOT2ROOT

HackSmarter - SysAdmins

HackSmarterMedium

In this HackSmarter SysAdmins lab, I chained anonymous FTP disclosure, OSINT, SNMPv3 username and credential reuse, and a critical sudo privilege escalation (CVE-2025-32463) to move from initial access to full root compromise.

August 6, 202611 min read
CTF WRITEUPSCLOUD

HackSmarter - Rotation

HackSmarterMedium

This is a Medium AWS Challenge Lab, it is an IAM privilege escalation via access key rotation abuse.

August 6, 20268 min read
CTF WRITEUPSCRYPTO

HTB - The Ashen Field

HackTheBoxEasy

Exploit a standard implementation of the Hidden Field Equations protocol via Groebner Basis

August 5, 20266 min read
[< Prev][Next >]