Knowledge Hub
Active Directory Labs
Available entries
-
Persisting Active Directory
TryHackMe room
-
Attacking Kerberos
--- Learn how to abuse the Kerberos Ticket Granting Service inside of a Windows Domain Controller --- This room will cover all of the...
-
CVE-2022-26923
---- Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services. ---...
-
RazorBlack
``` RazorBlack These guys call themselves hackers. Can you show them who's the boss ?? Throw something like a rock on the big green...
-
Active Directory Basics
--- Learn the basics of Active Directory and how it is used in the real world today --- ### Introduction Active Directory is the...
-
AD Certificate Templates
---- Walkthrough on the exploitation of misconfigured AD certificate templates ---...
-
Corp
--- Bypass Windows Applocker and escalate your privileges. You will learn about kerberoasting, evading AV, bypassing applocker and...
-
Crocc Crew
---- Crocc Crew has created a backdoor on a Cooctus Corp Domain Controller. We're calling in the experts to find the real back door!...
-
Enterprise
``` Enterprise es una máquina Windows Server 2019 configurada como Domain Controller. Para el acceso inicial tendremos que enumerar...
-
Enumerating Active Directory
TryHackMe room
-
Exploiting Active Directory
TryHackMe room
-
Fusion Corp
---- Fusion Corp said they got everything patched... did they? ---- ...
-
Ra 2
--- Just when they thought their hashes were safe... Ra 2 - The sequel! --- **Story** WindCorp recently had a security-breach. Since...
-
Recovering Active Directory
TryHackMe room
-
VulnNet: Roasted
--- VulnNet Entertainment quickly deployed another management instance on their very broad network... --- ### VulnNet: Roasted Start...
-
Active Directory Basics(1)
### Introduction Microsoft's Active Directory is the backbone of the corporate world. It simplifies the management of devices and users...
-
Advent of Cyber 2024
TryHackMe room
-
Attacktive Directory
TryHackMe room
-
Gatekeeper
--- Can you get past the gate and through the fire? ---  and (CVE-2021-34527). ---...
-
The Lay of the Land
--- Learn about and get hands-on with common technologies and security products used in corporate environments; both host and...
-
Active Directory Hardening
TryHackMe room
-
Advent of Cyber 2023
TryHackMe room
-
Breaching Active Directory
TryHackMe room
-
Conti
---- An Exchange server was compromised with ransomware. Use Splunk to investigate how the attackers compromised the server. ----...
-
Credentials Harvesting
--- Apply current authentication models employed in modern environments to a red team approach. ---...
-
DFIR: An Introduction
--- Introductory room for the DFIR module --- ### Introduction ##  and Web-App attack lab that aims to teach core web attack vectors and more advanced AD attack...
-
Intermediate Nmap
--- Can you combine your great nmap skills with other tools to log in to this machine? ---...
-
Jacob the Boss
---- Find a way in and learn a little more. ----  ### Task 1 Challenge Start...
-
Red Team Capstone Challenge
TryHackMe room
-
Sandbox Evasion
--- Learn about active defense mechanisms Blue Teamers can deploy to identify adversaries in their environment. ---...
-
Tech_Supp0rt: 1
--- Hack into the scammer's under-development website to foil their plans. --- -[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
Templated
``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
The Server From Hell
---- Face a server that feels as if it was configured and deployed by Satan himself. Can you escalate to root? ----...
-
Tony the Tiger
--- Learn how to use a Java Serialisation attack in this boot-to-root --- ### Deploy! Start Machine Firstly, ensure you are connected to...
-
Web Enumeration
--- Learn the methodology of enumerating websites by using tools such as Gobuster, Nikto and WPScan ---...
-
Wireshark: Traffic Analysis
--- Learn the basics of traffic analysis with Wireshark and how to find anomalies on your network! ---...
-
ZeroLogon
--- Learn about and exploit the ZeroLogon vulnerability that allows an attacker to go from Zero to Domain Admin without any valid...
-
25 Days of Cyber Security
TryHackMe room
-
AD Tier Model
TryHackMe room
-
AD: Authenticated Enumeration
TryHackMe room
-
AD: Basic Enumeration
TryHackMe room
-
Advent of Cyber 2 [2020]
TryHackMe room
-
Advent of Cyber 2022
--- Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading...
-
Advent of Cyber 3 (2021)
TryHackMe room
-
Analysing Volatile Memory
TryHackMe room
-
Android Malware Analysis
---- Android malware analysis with Pithus (static and hunting) --- ...
-
Anthem
TryHackMe room
-
Appointment
``` blob:https://app.hackthebox.com/5be081bc-9048-421a-a11f-090c3e6d5944 ┌──(kali㉿kali)-[~] └─$ ping 10.129.221.123 PING 10.129.221.123...
-
Appointment
``` blob:https://app.hackthebox.com/5be081bc-9048-421a-a11f-090c3e6d5944 ┌──(kali㉿kali)-[~] └─$ ping 10.129.221.123 PING 10.129.221.123...
-
Aratus
---- Do you like reading? Do you like to go through tons of text? Aratus has what you need! ----...
-
Archangel
--- Boot2root, Web exploitation, Privilege escalation, LFI --- ...
-
Blizzard
TryHackMe room
-
Blog
--- Billy Joel made a Wordpress blog! ---  ### Deploy...
-
Brim
--- Learn and practice log investigation, pcap analysis and threat hunting with Brim. ---...
-
Brute Force Heroes
--- Walkthrough room to look at the different tools that can be used when brute forcing, as well as the different situations that might...
-
Bugged
---- John likes to live in a very Internet connected world. Maybe too connected... ---...
-
Carnage
TryHackMe room
-
CMesS
---- Can you root this Gila CMS box? ---  ### Flags Start Machine Please add `MACHINE_IP cmess.thm`...
-
Content Security Policy
--- In this room you'll learn what CSP is, what it's used for and how to recognize vulnerabilities in a CSP header. --- ### Introduction...
-
CORS & SOP
TryHackMe room
-
CVE-2019-18634
``` The stack is a very regimented section of memory which stores various important aspects of a program. The heap, on the other hand,...
-
Cyber Kill Chain
--- The Cyber Kill Chain framework is designed for identification and prevention of the network intrusions. You will learn what the...
-
CyberChef: The Basics
TryHackMe room
-
CyberCrafted
---- Pwn this pay-to-win Minecraft server! --- ...
-
Data Exfiltration
--- An introduction to Data Exfiltration and Tunneling techniques over various protocols. ---...
-
Diamond Model
--- Learn about the four core features of the Diamond Model of Intrusion Analysis: adversary, infrastructure, capability, and victim....
-
Different CTF
---- interesting room, you can shoot the sun ---- ...
-
Dig Dug
--- Turns out this machine is a DNS server - it's time to get your shovels out! ---...
-
Disk Analysis & Autopsy
TryHackMe room
-
DNS
``` If you were on Windows, what command could you use to query a txt record for 'youtube.com'? nslookup -type=txt youtube.com If you...
-
DNS in detail
TryHackMe room
-
DNS Manipulation
TryHackMe room
-
Dunkle Materie
TryHackMe room
-
DX1: Liberty Island
--- Can you help the NSF get a foothold in UNATCO's system? --- ...
-
Empire
``` Installing the current project: empire-bc-security-fork (4.6.1) [+] Install Complete! [+] Run the following commands in separate...
-
Empline
---- Are you good enough to apply for this job? ----  What are the...
-
Ghizer
---- lucrecia has installed multiple web applications on the server. ---- ...
-
Hip Flask
TryHackMe room
-
Hunt Me I: Payment Collectors
TryHackMe room
-
Hunt Me II: Typo Squatters
TryHackMe room
-
Ice
TryHackMe room
-
Identification & Scoping
TryHackMe room
-
Incident handling with Splunk
--- Learn to use Splunk for incident handling through interactive scenarios. --- ### Introduction: Incident Handling This room covers an...
-
Intro to Detection Engineering
---- Introduce the concept of detection engineering and the frameworks used towards crafting effective threat detection strategies. ----...
-
Intro to ISAC
--- Learn how to utilize Information Sharing and Analysis Centers to gather threat intelligence and collect IOCs. ---...
-
Intro to Offensive Security
---- Hack your first website (legally in a safe environment) and experience an ethical hacker's job. ---...
-
Introduction to CryptOps
TryHackMe room
-
Introduction to SIEM
--- An introduction to Security Information and Event Management. --- ...
-
Keldagrim
--- The dwarves are hiding their gold! --- . ---...
-
Lumberjack Turtle
---- No logs, no crime... so says the lumberjack. ---- ...
-
macOS Forensics: The Basics
TryHackMe room
-
Madeye's Castle
---- A boot2root box that is modified from a box used in CuCTF by the team at Runcode.ninja ----...
-
magician
``` ┌──(kali㉿kali)-[~] └─$ sudo su [sudo] password for kali: ┌──(root㉿kali)-[/home/kali] └─# nano /etc/hosts ┌──(root㉿kali)-[/home/kali]...
-
MAL: Strings
--- Investigating "strings" within an application and why these values are important! ---...
-
Masterminds
---- Practice analyzing malicious traffic using Brim. ----  scans, spoofing, in addition to FW and IDS evasion. ---...
-
Nmap Basic Port Scans
--- Learn in-depth how nmap TCP connect scan, TCP SYN port scan, and UDP port scan work. ---...
-
Opacity
---- Opacity is a Boot2Root made for pentesters and cybersecurity enthusiasts. ----...
-
OpenCTI
--- Provide an understanding of the OpenCTI Project ---  ### Osiris...
-
Osquery: The Basics
--- Let's cover the basics of Osquery. --- -[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Phishing
--- Learn what phishing is and why it's important to a red team engagement. You will set up phishing infrastructure, write a convincing...
-
Phishing Analysis Tools
TryHackMe room
-
Phishing Emails 3
--- Learn the tools used to aid an analyst to investigate suspicious emails. --- -[~/Downloads/PHishing] └─$ wget http://0.0.0.0:8000/Email1.eml --2022-08-02 17:10:23-- http://0.0.0.0:8000/Email1.eml...
-
Post-Exploitation Basics
TryHackMe room
-
PowerShell for Pentesters
--- This room covers the principle uses of PowerShell in Penetration Tests. Interacting with files, scanning the network and system...
-
PrintNightmare, thrice!
--- The nightmare continues.. Search the artifacts on the endpoint, again, to determine if the employee used any of the Windows Printer...
-
Putting it all together
--- Learn how all the individual components of the web work together to bring you access to your favourite web sites. --- **Putting It...
-
Pyramid Of Pain
--- Learn what is the Pyramid of Pain and how to utilize this model to determine the level of difficulty it will cause for an adversary...
-
Python for Pentesters
--- Python is probably the most widely used and most convenient scripting language in cybersecurity. This room covers real examples of...
-
Red Team OPSEC
--- Learn how to apply Operations Security (OPSEC) process for Red Teams. --- ...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Retro
--- New high score! ---   : its responsibilities, services, and data sources. --- ### Introduction to Security...
-
Security Principles
--- Learn about the security triad and common security models and principles. ---...
-
Servidae: Log Analysis in ELK
TryHackMe room
-
Set
--- Once again you find yourself on the internal network of the Windcorp Corporation. --- ### Set ...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Skynet
--- A vulnerable Terminator themed Linux machine. ---  Hasta la vista, baby. Are you able to...
-
Snapped Phish-ing Line
TryHackMe room
-
Snapped Phishing Line
---- Apply learned skills to probe malicious emails and URLs, exposing a vast phishing campaign. ----...
-
Splunk 2
--- Part of the Blue Primer series. This room is based on version 2 of the Boss of the SOC (BOTS) competition by Splunk. ---...
-
SQHell
---- Try and find all the flags in the SQL Injections ----  ###...
-
Squid Game
TryHackMe room
-
SSRF
--- Learn how to exploit Server-Side Request Forgery (SSRF) vulnerabilities, allowing you to access internal server resources. --- ###...
-
Steel Mountain
--- Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilise powershell for Windows privilege escalation...
-
Subdomain Enumeration
--- Learn the various ways of discovering subdomains to expand your attack surface of a target. --- Subdomain enumeration is the process...
-
Sustah
---- Play a game to gain access to a vulnerable CMS. Can you beat the odds? ---- ...
-
That's The Ticket
---- IT Support are going to have a bad day, can you get into the admin account? ----...
-
The Docker Rodeo
--- Learn a wide variety of Docker vulnerabilities in this guided showcase. --- -[~/hackthebox] └─$ rustscan -a 10.129.72.184...
-
Upload Vulnerabilities
--- Tutorial room exploring some basic file-upload vulnerabilities in websites --- ### Getting Started First up, let's deploy the...
-
Vaccine
``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
-
Vaccine
``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
-
Volatility
--- Learn how to perform memory forensics with Volatility! ---  ###...
-
VulnNet: Endgame
---- Hack your way into this simulated vulnerable infrastructure. No puzzles. Enumeration is the key. ----...
-
VulnNet: Internal
--- VulnNet Entertainment learns from its mistakes, and now they have something new for you... ---...
-
Warzone 1
---- You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
-
Warzone 2
---- You received another IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
-
Wazuh
--- Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring. ---...
-
Weasel
---- I think the data science team has been a bit fast and loose with their project resources. ---- ### Task 1 Start the VM Start...
-
Web Application Basics
TryHackMe room
-
WebOSINT
TryHackMe room
-
Wekor
---- CTF challenge involving Sqli , WordPress , vhost enumeration and recognizing internal services ;) ---...
-
Windows Applications Forensics
TryHackMe room
-
Windows Network Analysis
TryHackMe room
-
Windows Privilege Escalation
--- Learn the fundamentals of Windows privilege escalation techniques. --- ...
-
Windows User Account Forensics
TryHackMe room
-
Wireshark 101
--- Learn the basics of Wireshark and how to analyze various protocols and PCAPs --- ### Introduction Wireshark, a tool used for...
-
Wireshark: Packet Operations
--- Learn the fundamentals of packet analysis with Wireshark and how to find the needle in the haystack! ---...
-
Wonderland
``` gobuster dir --url http://10.10.122.82/ --wordlist /usr/share/wordlists/dirb/common.txt -t 30 found /r then /a so /r/a/b/b/i/t...
-
Wreath
---- Learn how to pivot through a network by compromising a public facing web machine and tunnelling your traffic to access other...
-
Year of the Fox
---- Don't underestimate the sly old fox... ---  ### Hack the machine and obtain the flags Start...
-
Year of the Owl
---- The foolish owl sits on his throne... ---- ...
-
You're in a cave
---- A room with some ctf elements inspired in text based RPGs ---- ...
-
Zeek
--- Introduction to hands-on network monitoring and threat detection with Zeek (formerly Bro). ---...
-
Zeek Exercises
--- Put your Zeek skills into practice and analyse network traffic. --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/613113...
-
Zero Logon
TryHackMe room