Security Writeups
CTF writeups, machine walkthroughs, and security challenge solutions. Active machines show approach only — full writeups available after retirement.
Active Machines
approach onlyScaffold - HackTheBox
XXE exploitation
Password spray
TrustFall - HackTheBox
CVE-2026-22200
CVE-2026-24061
Management - HackTheBox
CVE-2026-33439
Glpi password decrypt
BlockSynergy - HackTheBox
Blockchain exploit.
SSRF -> RCE.
SmartHire
Enumerated hiring platform
Found authentication flaw
Reactor
In-depth enumeration
Identified reactor vulnerability
PingPong
Scanned target with nmap
Enumerated ping-pong service
PaperWork
Nmap scan revealed services
Enumerated paperwork application
Nimbus
Comprehensive enumeration
Identified cloud misconfiguration
MakeSense
Enumerated target system
Found sense-making vulnerability
Garfield
Nmap scan revealed services
Enumerated web server
Enigma
Comprehensive enumeration
Decrypted enigma configuration
DevHub
Enumerated development hub
Found exposed development endpoints
DarkZeroReturns
In-depth enumeration
Identified return vulnerability
DanglingTree
Nmap scan revealed services
Enumerated web application
Connected
Enumerated connected services
Found service vulnerability
Cohort
AD enumeration with BloodHound
Identified cohort group misconfiguration
Checkpoint
Comprehensive enumeration
Found checkpoint system vulnerability
BedSide
Enumerated target with nmap
Discovered web application vulnerability
Retired Writeups
36 availableSilentium
VHost fuzzing
CVE-2025-58434 for account takeover
WingData
Scanned target with nmap
Enumerated data application
VariaType
Nmap scan revealed services
Enumerated typing application
Soulmate
Scanned target with nmap
Enumerated web server
Sorcery
Nmap scan revealed services
Enumerated web application
Snapped
Initial enumeration
Discovered snapshot application
Signed
Scanned target with nmap
Enumerated services
Rebound
AD enumeration
Identified complex misconfiguration
Pterodactyl
Nmap scan revealed services
Enumerated game server panel
Principal
AD enumeration
Identified vulnerable service
Pirate
Pre-Windows 2000 Compatible Access group membership
LSA Secrets storing cleartext domain credentials
Overwatch
Comprehensive enumeration
Identified monitoring system vulnerability
NanoCorp
Nmap scan revealed services
Enumerated corporation website
Logging
Initial enumeration
Discovered logging application
Kobold
Scanned target with nmap
Enumerated web application
Interpreter
Nmap scan revealed services
Enumerated interpreter application
Intelligence
AD enumeration
Identified GPO vulnerability
Hercules
Scanned target with nmap
Enumerated services
Helix
Comprehensive enumeration
Identified multiple attack vectors
Guardian
Initial enumeration
Discovered security application
Giveback
Nmap scan revealed services
Enumerated web application
Gavel
In-depth enumeration
Identified complex vulnerability chain
Fries
Scanned target with nmap
Enumerated web application
FireFlow
Comprehensive enumeration
Identified workflow engine vulnerability
Facts
Nmap scan revealed services
Enumerated web server
Expressway
Scanned target with nmap
Enumerated services
Eloquia
Initial enumeration
Discovered web application
Eighteen
Nmap scan revealed services
Enumerated web application
DevArea
Scanned target with nmap
Enumerated development environment
DarkZero
Comprehensive enumeration
Identified complex attack chain
Conversor
Nmap scan revealed services
Enumerated conversion service
Cobblestone
Initial enumeration
Discovered web application
CCTV
Scanned target with nmap
Enumerated camera management system
Browsed
Nmap scan revealed services
Enumerated web server
Breach
Comprehensive enumeration
Identified vulnerable web application
AirTouch
Nmap scan revealed open services
Enumerated web application