Knowledge Hub
OSINT and Recon Labs
Available entries
-
Cyber Kill Chain
--- The Cyber Kill Chain framework is designed for identification and prevention of the network intrusions. You will learn what the...
-
Deja Vu
--- Exploit a recent code injection vulnerability to take over a website full of cute dog pictures! ---...
-
HipFlask
``` Hip Flask is a beginner to intermediate level walkthrough. It aims to provide an in-depth analysis of the thought-processes involved...
-
Passive Reconnaissance
TryHackMe room
-
Python for Pentesters
--- Python is probably the most widely used and most convenient scripting language in cybersecurity. This room covers real examples of...
-
Subdomain Enumeration
--- Learn the various ways of discovering subdomains to expand your attack surface of a target. --- Subdomain enumeration is the process...
-
The Hacker Methodology
TryHackMe room
-
Advent of Cyber 2022
--- Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading...
-
Badbyte
--- Infiltrate BadByte and help us to take over root. --- ### Reconnaissance  Nmap is a free open...
-
Gobuster: The Basics
TryHackMe room
-
Grep
---- A challenge that tests your reconnaissance and OSINT skills. ---- -[~/Downloads/PHishing] └─$ wget http://0.0.0.0:8000/Email1.eml --2022-08-02 17:10:23-- http://0.0.0.0:8000/Email1.eml...
-
Sea Surfer
---- Ride the Wave! ----  -[~] └─$ ping 10.129.221.123 PING 10.129.221.123...
-
Appointment
``` blob:https://app.hackthebox.com/5be081bc-9048-421a-a11f-090c3e6d5944 ┌──(kali㉿kali)-[~] └─$ ping 10.129.221.123 PING 10.129.221.123...
-
Aurora EDR
TryHackMe room
-
Avengers Blog
--- Learn to hack into Tony Stark's machine! You will enumerate the machine, bypass a login portal via SQL injection and gain root...
-
AWS S3 - Attack and Defense
TryHackMe room
-
Brim
--- Learn and practice log investigation, pcap analysis and threat hunting with Brim. ---...
-
CyberCrafted
---- Pwn this pay-to-win Minecraft server! --- ...
-
Diamond Model
--- Learn about the four core features of the Diamond Model of Intrusion Analysis: adversary, infrastructure, capability, and victim....
-
Empline
---- Are you good enough to apply for this job? ---- -[~] └─$ sudo nmap -sC -sV...
-
Gatekeeper
--- Can you get past the gate and through the fire? ---  ###...
-
Holo
--- Holo is an Active Directory (AD) and Web-App attack lab that aims to teach core web attack vectors and more advanced AD attack...
-
Hunt Me I: Payment Collectors
TryHackMe room
-
Intro to Threat Emulation
---- A look into threat emulation practices as a means of cyber security assessment. ----...
-
Iron Corp
---- Can you get access to Iron Corp's system? ---- ...
-
Lumberjack Turtle
---- No logs, no crime... so says the lumberjack. ---- ...
-
Metasploit
--- Learn to use Metasploit, a tool to probe and exploit vulnerabilities on networks and servers. ---...
-
Network Security
--- Learn about network security, understand attack methodology, and practice hacking into a target server. --- ### Introduction A...
-
Nmap Post Port Scans
--- Learn how to leverage Nmap for service and OS detection, use Nmap Scripting Engine (NSE), and save the results. ---...
-
OWASP API Security Top 10 - 2
--- Learn the basic concepts for secure API development (Part 2). --- ...
-
RazorBlack
``` RazorBlack These guys call themselves hackers. Can you show them who's the boss ?? Throw something like a rock on the big green...
-
Red Team Recon
TryHackMe room
-
Red Team Threat Intel
--- Apply threat intelligence to red team engagements and adversary emulation. ---...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
SSRF
--- Learn how to exploit Server-Side Request Forgery (SSRF) vulnerabilities, allowing you to access internal server resources. --- ###...
-
TakeOver
--- This challenge revolves around subdomain enumeration. --- 
TryHackMe room
-
Alfred
--- Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens. ---...
-
All in One
--- This is a fun box where you will get to exploit the system in several ways. Few intended and unintended paths to getting user and...
-
AllSignsPoint2Pwnage
--- A room that contains a rushed Windows based Digital Sign system. Can you breach it? ---...
-
Amazon EC2 - Attack & Defense
TryHackMe room
-
Annie
---- Remote access comes in different flavors. ---- ### Task 1 Recon - Research - Exploit...
-
Anonymous
--- Not the hacking group --- ...
-
Archetype
``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
-
Archetype
``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
-
Atlas
--- Hack the Atlas server in this beginner room covering Windows attack methodology! ---...
-
Attacking Kerberos
--- Learn how to abuse the Kerberos Ticket Granting Service inside of a Windows Domain Controller --- This room will cover all of the...
-
Authentication Bypass
--- Learn how to defeat logins and other authentication mechanisms to allow you access to unpermitted areas. --- In this room, we will...
-
Autopsy
--- Learn how to use Autopsy to investigate artifacts from a disk image. Use your knowledge to investigate an employee who is being...
-
AV Evasion: Shellcode
--- Learn shellcode encoding, packing, binders, and crypters. --- ### Introduction In this room, we'll explore how to build and deliver...
-
AWS IAM Enumeration
TryHackMe room
-
AWS IAM Initial Access
TryHackMe room
-
Basic Dynamic Analysis
TryHackMe room
-
Binex
--- Escalate your privileges by exploiting vulnerable binaries. --- ...
-
Blog
--- Billy Joel made a Wordpress blog! ---  ###...
-
Boogeyman 1
---- A new threat actor emerges from the wild using the name Boogeyman. Are you afraid of the Boogeyman? ---- ### [Introduction] New...
-
Bookstore
---- A Beginner level box with basic web enumeration and REST API Fuzzing. ----  ### Deploy...
-
CALDERA
TryHackMe room
-
CMesS
---- Can you root this Gila CMS box? ---  ### Flags Start Machine Please add `MACHINE_IP cmess.thm`...
-
CMSpit
---- This is a machine that allows you to practise web app hacking and privilege escalation using recent vulnerabilities. ----...
-
Common Linux Privesc
--- A room explaining common Linux privilege escalation --- ### Understanding Privesc What does "privilege escalation" mean? At it's...
-
Content Discovery
TryHackMe room
-
Content Security Policy
--- In this room you'll learn what CSP is, what it's used for and how to recognize vulnerabilities in a CSP header. --- ### Introduction...
-
Cooctus Stories
---- This room is about the Cooctus Clan ---- ...
-
Credentials Harvesting
--- Apply current authentication models employed in modern environments to a red team approach. ---...
-
Crocodile
``` blob:https://app.hackthebox.com/51f9dfe3-9c91-469a-8453-feab80baf3c3 ┌──(kali㉿kali)-[~] └─$ ping 10.129.165.101 PING 10.129.165.101...
-
Crocodile
``` blob:https://app.hackthebox.com/51f9dfe3-9c91-469a-8453-feab80baf3c3 ┌──(kali㉿kali)-[~] └─$ ping 10.129.165.101 PING 10.129.165.101...
-
Crylo
---- Learn about the CryptoJS library and JavaScript-based client-side encryption and decryption. ----...
-
Data Exfiltration
--- An introduction to Data Exfiltration and Tunneling techniques over various protocols. ---...
-
Debug
---- Linux Machine CTF! You'll learn about enumeration, finding hidden password files and how to exploit php deserialization! ----...
-
Different CTF
---- interesting room, you can shoot the sun ---- ...
-
Digital Forensics Case B4DM755
---- Acquire the critical skills of evidence preservation, disk imaging, and artefact analysis for use in court. ----...
-
DNS
``` If you were on Windows, what command could you use to query a txt record for 'youtube.com'? nslookup -type=txt youtube.com If you...
-
DNS in detail
TryHackMe room
-
DX1: Liberty Island
--- Can you help the NSF get a foothold in UNATCO's system? --- ...
-
En-pass
---- Get what you can't. ----  ###...
-
Enumeration
--- This room is an introduction to enumeration when approaching an unknown corporate environment. ---...
-
Enumeration & Brute Force
TryHackMe room
-
Eviction
TryHackMe room
-
EXT Analysis
TryHackMe room
-
Flatline
--- How low are your morals? ---  What are the...
-
GoldenEye
--- Bond, James Bond. A guided CTF. --- ...
-
Hacker vs. Hacker
--- Someone has compromised this server already! Can you get in and evade their countermeasures? ---...
-
Hacking with PowerShell
--- Learn the basics of PowerShell and PowerShell Scripting ---  ### Objectives...
-
harder
---- Real pentest findings combined ---- ...
-
Hip Flask
TryHackMe room
-
IDE
--- An easy box to polish your enumeration skills! ---  and is perfect for newbies starting out in penetration...
-
Insekube
--- Exploiting Kubernetes by leveraging a Grafana LFI vulnerability ---  ### Introduction Start...
-
Internal
--- Penetration Testing Challenge --- ...
-
Intro to ISAC
--- Learn how to utilize Information Sharing and Analysis Centers to gather threat intelligence and collect IOCs. ---...
-
Introductory Networking
TryHackMe room
-
Intrusion Detection
---- Learn cyber evasion techniques and put them to the test against two IDS --- ...
-
JPGChat
``` ┌──(kali㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.248.160 --ulimit 5000 -b 65535 -- -A .----. .-. .-. .----..---. .----. .---. .--....
-
K8s Runtime Security
TryHackMe room
-
KAPE
--- An introduction to Kroll Artifact Parser and Extractor (KAPE) for collecting and processing forensic artifacts ---...
-
Kubernetes for Everyone
--- A Kubernetes hacking challenge for DevOps/SRE enthusiasts. --- ...
-
Looking_Glass
``` Enumerating SSH When connecting to one of the ports (in this case trying one of the higher ones), the SSH server responds with...
-
Lunizz CTF
...
-
Madeye's Castle
---- A boot2root box that is modified from a box used in CuCTF by the team at Runcode.ninja ----...
-
Masterminds
---- Practice analyzing malicious traffic using Brim. ----  ### Task 1 Challenge Start...
-
MISP
--- Walkthrough on the use of MISP as a Threat Sharing Platform ---  ### Task 1...
-
Napping
--- Even Admins can fall asleep on the job --- ...
-
Network Services
--- Learn about, then enumerate and exploit a variety of network services and misconfigurations. --- ### Understanding SMB **What is...
-
Network Services 2
--- Enumerating and Exploiting More Common Network Services & Misconfigurations --- ### Understanding NFS What is NFS? NFS stands for...
-
Opacity
---- Opacity is a Boot2Root made for pentesters and cybersecurity enthusiasts. ----...
-
Osquery: The Basics
--- Let's cover the basics of Osquery. --- -[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Phishing
--- Learn what phishing is and why it's important to a red team engagement. You will set up phishing infrastructure, write a convincing...
-
Phishing Analysis Fundamentals
TryHackMe room
-
Phishing Emails 3
--- Learn the tools used to aid an analyst to investigate suspicious emails. --- ...
-
PowerShell for Pentesters
--- This room covers the principle uses of PowerShell in Penetration Tests. Interacting with files, scanning the network and system...
-
pyLon
---- Can you penetrate the defenses and become root? ---- ...
-
Redline
--- Learn how to use Redline to perform memory analysis and to scan for IOCs on an endpoint. ---...
-
Relevant
--- Penetration Testing Challenge --- ...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Revenge
---- You've been hired by Billy Joel to get revenge on Ducky Inc...the company that fired him. Can you break into the server and...
-
Road
--- Inspired by a real-world pentesting engagement --- ...
-
Shodan.io
TryHackMe room
-
Skynet
--- A vulnerable Terminator themed Linux machine. ---  Hasta la vista, baby. Are you able to...
-
Slingshot
TryHackMe room
-
Snyk Open Source
TryHackMe room
-
Splunk 2
--- Part of the Blue Primer series. This room is based on version 2 of the Boss of the SOC (BOTS) competition by Splunk. ---...
-
SQLMAP
--- Learn about and use Sqlmap to exploit the web application ---  Introduction...
-
Steel Mountain
--- Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilise powershell for Windows privilege escalation...
-
Sustah
---- Play a game to gain access to a vulnerable CMS. Can you beat the odds? ---- ...
-
Tempus Fugit Durius
--- The latin word Durius means "harder" --- ...
-
That's The Ticket
---- IT Support are going to have a bad day, can you get into the admin account? ----...
-
The Cod Caper
--- A guided room taking you through infiltrating and exploiting a Linux system. --- ### Intro Hello there my name is Pingu. I've come...
-
The Docker Rodeo
--- Learn a wide variety of Docker vulnerabilities in this guided showcase. ---  ---...
-
Windows Forensics 1
--- Introduction to Windows Registry Forensics --- ...
-
Windows Forensics 2
--- Learn about common Windows file systems and forensic artifacts in the file systems. ---...
-
Windows Local Persistence
--- Learn the most common persistence techniques used on Windows machines. ---  ### Hack the machine and obtain the flags Start...
-
Year of the Pig
---- Some pigs do fly... ----  ...
-
Zeek Exercises
--- Put your Zeek skills into practice and analyse network traffic. --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/613113...