Offensive security walkthroughs across the full attack chain, from OSINT and enumeration to exploitation and post-exploitation.
Latest Posts
View all →
Sysco 馃摗 | Hack Smarter Labs
A medium-difficulty Active Directory lab where usernames built from a company team page lead to an AS-REP Roast, a Cisco enable secret in webmail and a password saved in a PuTTY shortcut both open domain accounts, and GenericAll over Default Domain Policy lets us push a scheduled task that makes a user an administrator on the domain controller.

Anomaly 馃浉 | Hack Smarter Labs
A medium-difficulty Active Directory lab where a Jenkins script console and a sudo binary injection give root on a domain-joined Ubuntu server, a readable Kerberos keytab and a password in an AD description field pivot into the domain, and an ESC1 template abused through a created machine account resets a Domain Admin鈥檚 password over Schannel when PKINIT is unavailable.

ShareThePain 馃 | Hack Smarter Labs
A medium-difficulty Active Directory lab where a null SMB session with write access to a share captures a user hash through ntlm_theft, GenericAll over a second account resets its password to a WinRM shell, and a loopback-bound SQL Server instance reached through a Ligolo-ng tunnel gives up xp_cmdshell execution whose SeImpersonatePrivilege escalates to SYSTEM on the domain controller.