Offensive security walkthroughs across the full attack chain, from OSINT and enumeration to exploitation and post-exploitation.
Latest Posts
View all →
ShadowGate2 ⛩️ | Hack Smarter Labs
A medium-difficulty Active Directory lab chaining a SQL injection auth bypass, an NTLMv2 capture through a file-upload portal, a WriteOwner and GenericAll ACL chain, a deleted-account recovery, and ESC3 enrollment-agent abuse to enroll as Administrator.

MartiniAD 🍸 | Hack Smarter Labs
An easy-difficulty Active Directory lab chaining anonymous SMB access, plaintext credentials left on an open share, Kerberoasting, and password reuse on a tier 0 admin account to dump NTDS and recover the krbtgt hash.

Arasaka 🗼 | Hack Smarter Labs
An easy-difficulty Active Directory lab chaining Kerberoasting, a GenericAll and GenericWrite ACL chain, and ESC1 certificate abuse against an expired admin to reach a live Domain Administrator and dump NTDS.