Knowledge Hub
Privilege Escalation Labs
Available entries
-
Wonderland
``` gobuster dir --url http://10.10.122.82/ --wordlist /usr/share/wordlists/dirb/common.txt -t 30 found /r then /a so /r/a/b/b/i/t...
-
Enumeration
--- This room is an introduction to enumeration when approaching an unknown corporate environment. ---...
-
Common Linux Privesc
--- A room explaining common Linux privilege escalation --- ### Understanding Privesc What does "privilege escalation" mean? At it's...
-
Holo
--- Holo is an Active Directory (AD) and Web-App attack lab that aims to teach core web attack vectors and more advanced AD attack...
-
Wreath
---- Learn how to pivot through a network by compromising a public facing web machine and tunnelling your traffic to access other...
-
Alfred
--- Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens. ---...
-
APIWizards Breach
TryHackMe room
-
Blog
--- Billy Joel made a Wordpress blog! ---  What are the...
-
GLITCH
--- Challenge showcasing a web app and simple privilege escalation. Can you find the glitch? ---...
-
Hacked
``` It seems like our machine got hacked by an anonymous threat actor. However, we are lucky to have a .pcap file from the attack. Can...
-
Intrusion Detection
---- Learn cyber evasion techniques and put them to the test against two IDS --- , the SSH server responds with...
-
Overpass
``` ***gobuster*** gobuster dir --url http://10.10.101.139 --wordlist /usr/share/wordlists/dirb/common.txt (found path /admin)...
-
Pwnkit
--- CVE-2021-4034 (colloquially dubbed "Pwnkit") is a terrifying Local Privilege Escalation (LPE) vulnerability, located in the "Polkit"...
-
RazorBlack
``` RazorBlack These guys call themselves hackers. Can you show them who's the boss ?? Throw something like a rock on the big green...
-
Windows PrivEsc
TryHackMe room
-
25 Days of Cyber Security
TryHackMe room
-
Advent of Cyber 2 [2020]
TryHackMe room
-
Amazon EC2 - Attack & Defense
TryHackMe room
-
Annie
---- Remote access comes in different flavors. ---- ### Task 1 Recon - Research - Exploit...
-
APT28 Inception Theory
TryHackMe room
-
Archangel
--- Boot2root, Web exploitation, Privilege escalation, LFI --- -[~/Downloads/Blockchain] └─$ ftp 10.10.131.24 Connected to...
-
Bypassing UAC
TryHackMe room
-
CMSpit
---- This is a machine that allows you to practise web app hacking and privilege escalation using recent vulnerabilities. ----...
-
CVE-2019-18634
``` The stack is a very regimented section of memory which stores various important aspects of a program. The heap, on the other hand,...
-
Erit Securus I
--- Learn to exploit the BoltCMS software by researching exploit-db. --- ### Reconnaissance ``` ┌──(kali㉿kali)-[~] └─$ sudo nmap -sC -sV...
-
Fowsniff CTF
--- Hack this machine and get the flag. There are lots of hints along the way and is perfect for beginners! ---...
-
hackerNote
---- A custom webapp, introducing username enumeration, custom wordlists and a basic privilege escalation exploit. ---...
-
Hacking Hadoop
TryHackMe room
-
HackPark
--- Bruteforce a websites login with Hydra, identify and use a public exploit then escalate your privileges on this Windows machine! ---...
-
Introductory Researching
TryHackMe room
-
Jack
--- Compromise a web server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module....
-
Linux PrivEsc
TryHackMe room
-
Living Off the Land
--- Learn the essential concept of "Living Off the Land" in Red Team engagements. ---...
-
Lumberjack Turtle
---- No logs, no crime... so says the lumberjack. ---- ...
-
Microsoft Windows Hardening
--- To learn key attack vectors used by hackers and how to protect yourself using different hardening techniques. ---...
-
Network Services 2
--- Enumerating and Exploiting More Common Network Services & Misconfigurations --- ### Understanding NFS What is NFS? NFS stands for...
-
NIS - Linux Part I
--- Enhance your Linux knowledge with this beginner friendly room! --- -[~/Downloads] └─$ nmap 10.10.11.224 Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-21 12:53 EDT Nmap scan report...
-
Sau
``` ┌──(witty㉿kali)-[~/Downloads] └─$ nmap 10.10.11.224 Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-21 12:53 EDT Nmap scan report...
-
Sea Surfer
---- Ride the Wave! ----   Hasta la vista, baby. Are you able to...
-
Snort
--- Learn how to use Snort to detect real-time threats, analyse recorded traffic files and identify anomalies. ---...
-
Tempest
---- You are tasked to conduct an investigation from a workstation affected by a full attack chain. ---...
-
The Docker Rodeo
--- Learn a wide variety of Docker vulnerabilities in this guided showcase. --- ...
-
Zeek
--- Introduction to hands-on network monitoring and threat detection with Zeek (formerly Bro). ---...
-
Abusing Windows Internals
--- Leverage windows internals components to evade common detection solutions, using modern tool-agnostic approaches. ---...
-
AD Certificate Templates
---- Walkthrough on the exploitation of misconfigured AD certificate templates ---...
-
Advent of Cyber 1 [2019]
TryHackMe room
-
Advent of Cyber 2022
--- Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading...
-
Advent of Cyber 3 (2021)
TryHackMe room
-
Agent Sudo
TryHackMe room
-
Anonymous
--- Not the hacking group --- ...
-
Archetype
``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
-
Archetype
``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
-
Atlassian, CVE-2022-26134
--- An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability. ---...
-
Avengers Blog
--- Learn to hack into Tony Stark's machine! You will enumerate the machine, bypass a login portal via SQL injection and gain root...
-
AWS Basic Concepts
TryHackMe room
-
Badbyte
--- Infiltrate BadByte and help us to take over root. --- ### Reconnaissance  Nmap is a free open...
-
Baron Samedit
TryHackMe room
-
Bebop
--- Who thought making a flying shell was a good idea? ---  ###...
-
Binex
--- Escalate your privileges by exploiting vulnerable binaries. --- ...
-
biteme
---- Stay out of my server! ----  ### Deploy...
-
Break Out The Cage
--- Help Cage bring back his acting career and investigate the nefarious goings on of his agent! --- ```anonymous (no pass) ftp...
-
Brooklyn Nine Nine
--- This room is aimed for beginner level hackers but anyone can try to hack this box. There are two main intended ways to root the box....
-
Brute
--- You as well, Brutus? --- ...
-
Brute Force Heroes
--- Walkthrough room to look at the different tools that can be used when brute forcing, as well as the different situations that might...
-
Bulletproof Penguin
TryHackMe room
-
Burp Suite: Other Modules
--- Take a dive into some of Burp Suite's lesser known modules --- ### Outline Alongside the well-known Repeater and Intruder rooms,...
-
CAPA: The Basics
TryHackMe room
-
Careers in Cyber
--- Learn about the different careers in cyber security. --- ...
-
Corp
--- Bypass Windows Applocker and escalate your privileges. You will learn about kerberoasting, evading AV, bypassing applocker and...
-
Crocc Crew
---- Crocc Crew has created a backdoor on a Cooctus Corp Domain Controller. We're calling in the experts to find the real back door!...
-
Cross-site Scripting
--- Learn how to detect and exploit XSS vulnerabilities, giving you control of other visitor's browsers. --- ### Room Brief...
-
Cross-site Scripting-1
--- Understand how cross-site scripting occurs and how to exploit it. --- . ----...
-
CyberHeroes
--- Want to be a part of the elite club of CyberHeroes? Prove your merit by finding a way to log in! ---...
-
Cyborg
--- A box involving encrypted archives, source code analysis and more --- ## vpn ``` tryhackme-vpn sudo openvpn WittyAle.ovpn ``` ###...
-
Daily Bugle
--- Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum. ---...
-
Dav
--- boot2root machine for FIT and bsides guatemala CTF --- -[~/Downloads/DDOS] └─$ ftp 10.10.161.202 Connected to 10.10.161.202....
-
Deja Vu
--- Exploit a recent code injection vulnerability to take over a website full of cute dog pictures! ---...
-
DFIR: An Introduction
--- Introductory room for the DFIR module --- ### Introduction ##  ###...
-
GitLab CVE-2023-7028
TryHackMe room
-
GoldenEye
--- Bond, James Bond. A guided CTF. --- ...
-
Grep
---- A challenge that tests your reconnaissance and OSINT skills. ----  ### HA...
-
Hacker vs. Hacker
--- Someone has compromised this server already! Can you get in and evade their countermeasures? ---...
-
Hacking with PowerShell
--- Learn the basics of PowerShell and PowerShell Scripting ---  ### Objectives...
-
Hardening Basics Part 1
--- Learn how to harden an Ubuntu Server! Covers a wide range of topics (Part 1) ---...
-
HaskHell
---- Teach your CS professor that his PhD isn't in security. ---- ...
-
HipFlask
``` Hip Flask is a beginner to intermediate level walkthrough. It aims to provide an in-depth analysis of the thought-processes involved...
-
Ice
TryHackMe room
-
Insecure Randomness
TryHackMe room
-
Internal
--- Penetration Testing Challenge --- ...
-
Intro to Cross-site Scripting
TryHackMe room
-
Intro to Cyber Threat Intel
--- Introducing cyber threat intelligence and related topics, such as relevant standards and frameworks. ---...
-
Intro to Detection Engineering
---- Introduce the concept of detection engineering and the frameworks used towards crafting effective threat detection strategies. ----...
-
Intro to Docker
---- Learn to create, build and deploy Docker containers! ---- ...
-
John The Ripper
--- Learn how to use John the Ripper - An extremely powerful and adaptable hash cracking tool ---...
-
JPGChat
``` ┌──(kali㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.248.160 --ulimit 5000 -b 65535 -- -A .----. .-. .-. .----..---. .----. .---. .--....
-
K8s Best Security Practices
TryHackMe room
-
kiba
TryHackMe room
-
L2 MAC Flooding & ARP Spoofing
--- Learn how to use MAC Flooding to sniff traffic and ARP Cache Poisoning to manipulate network traffic as a MITM. ---...
-
Lessons Learned
TryHackMe room
-
Linux File System Analysis
TryHackMe room
-
Linux Forensics
--- Learn about the common forensic artifacts found in the file system of Linux Operating System ---...
-
Linux Logs Investigations
TryHackMe room
-
Linux System Hardening
TryHackMe room
-
LocalPotato
---- Learn how to elevate your privileges on Windows using LocalPotato (CVE-2023-21746). ---...
-
Lunizz CTF
...
-
macOS Forensics: The Basics
TryHackMe room
-
magician
``` ┌──(kali㉿kali)-[~] └─$ sudo su [sudo] password for kali: ┌──(root㉿kali)-[/home/kali] └─# nano /etc/hosts ┌──(root㉿kali)-[/home/kali]...
-
Memory Acquisition
TryHackMe room
-
Meow
Download vpn from lab Let the configuration script run until you see the Initialization Sequence Completed message at the very end of...
-
Meow
Download vpn from lab What does the acronym VM stand for? *Virtual Machine * What tool do we use to interact with the operating system...
-
Metasploit
--- Learn to use Metasploit, a tool to probe and exploit vulnerabilities on networks and servers. ---...
-
Metasploit: Exploitation
--- Using Metasploit for scanning, vulnerability assessment and exploitation. ---...
-
Microservices Architectures
TryHackMe room
-
MISP
--- Walkthrough on the use of MISP as a Threat Sharing Platform ---  scans, spoofing, in addition to FW and IDS evasion. ---...
-
Nmap Basic Port Scans
--- Learn in-depth how nmap TCP connect scan, TCP SYN port scan, and UDP port scan work. ---...
-
Nmap Post Port Scans
--- Learn how to leverage Nmap for service and OS detection, use Nmap Scripting Engine (NSE), and save the results. ---...
-
OAuth Vulnerabilities
TryHackMe room
-
Obfuscation Principles
--- Leverage tool-agnostic software obfuscation practices to hide malicious functions and create unique code. ---...
-
Oh My WebServer
--- Can you root me? ---  ###...
-
Oopsie
``` blob:https://app.hackthebox.com/40488db7-9438-4437-8c1a-5e50b5bc5bc3 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.95.191...
-
Oopsie
``` blob:https://app.hackthebox.com/40488db7-9438-4437-8c1a-5e50b5bc5bc3 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.95.191...
-
Osiris
--- Can you Quack it? ---  ### Osiris...
-
Overpass3
``` Initial foothold ***enumerating ports with rustscan*** port 80 open Enumerating with gobuster allows to discover a hidden /backups...
-
OWASP API Security Top 10 - 1
--- Learn the basic concepts for secure API development (Part 1). --- ...
-
OWASP API Security Top 10 - 2
--- Learn the basic concepts for secure API development (Part 2). --- ...
-
OWASP Top 10 - 2021
---- Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks. ---...
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Phishing Emails 3
--- Learn the tools used to aid an analyst to investigate suspicious emails. --- ...
-
Poster
--- The sys admin set up a rdbms in a safe way. ---  and (CVE-2021-34527). ---...
-
Protocols and Servers 2
--- Learn about attacks against passwords and cleartext traffic; explore options for mitigation via SSH and SSL/TLS. ---...
-
Ra
You have found WindCorp's internal network and their Domain Controller. Can you pwn their network? ...
-
Red Team OPSEC
--- Learn how to apply Operations Security (OPSEC) process for Red Teams. --- ...
-
REMnux: Getting Started
TryHackMe room
-
REmux The Tmux
--- Tmux is known as a terminal multiplexer. That allows you to craft a single terminal however you need it. --- ### ssh ``` ssh...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
Responder
``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
-
ret2libc
---- This room teaches basic return-oriented programming (ROP), exploitation of binaries and an ASLR bypass. ---- ### Task 1...
-
Retro
--- New high score! ---  -[~] └─$ ping 10.129.71.100 PING 10.129.71.100...
-
Sequel
``` blob:https://app.hackthebox.com/75b7ab04-575b-4cf9-800c-bd03e22b0be6 ┌──(kali㉿kali)-[~] └─$ ping 10.129.71.100 PING 10.129.71.100...
-
Servidae: Log Analysis in ELK
TryHackMe room
-
Set
--- Once again you find yourself on the internal network of the Windcorp Corporation. --- ### Set ...
-
Shells Overview
TryHackMe room
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Shoppy
``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
-
Smag Grotto
--- Follow the yellow brick road. --- ...
-
Snort Challenge - Live Attacks
--- Put your snort skills into practice and defend against a live attack --- ### Scenario 1 | Brute-Force Use the attached VM to finish...
-
Snort Challenge - The Basics
--- Put your snort skills into practice and write snort rules to analyse live capture network traffic. --- ### Introduction...
-
Source
--- Exploit a recent vulnerability and hack Webmin, a web-based system configuration tool. --- ### rustscan > 10000/tcp open http...
-
Splunk 101
--- This room will cover the basics of Splunk. --- ...
-
SQLMAP
--- Learn about and use Sqlmap to exploit the web application ---  Introduction...
-
SSRF
--- Learn how to exploit Server-Side Request Forgery (SSRF) vulnerabilities, allowing you to access internal server resources. --- ###...
-
Startup
--- Abuse traditional vulnerabilities via untraditional means. --- -[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
Templated
``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
The Cod Caper
--- A guided room taking you through infiltrating and exploiting a Linux system. --- ### Intro Hello there my name is Pingu. I've come...
-
The Lay of the Land
--- Learn about and get hands-on with common technologies and security products used in corporate environments; both host and...
-
TheHive Project
--- Learn how to use TheHive, a Security Incident Response Platform, to report investigation findings ---...
-
Threat Hunting With YARA
TryHackMe room
-
Toolbox: Vim
TryHackMe room
-
ToolsRus
--- Practise using tools such as dirbuster, hydra, nmap, nikto and metasploit ---...
-
Topology
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.217 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Topology
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.217 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Tor
``` ***enumerating*** rustscan -a 10.10.9.58 --ulimit 5000 -b 65535 -- -A ***log ssh port 22*** via linux ssh thm@10.10.168.200 pass ->...
-
Trooper
TryHackMe room
-
TryHack3M: Subscribe
TryHackMe room
-
Undiscovered
---- Discovery consists not in seeking new landscapes, but in having new eyes.. ----...
-
Unified Kill Chain
--- The Unified Kill Chain is a framework which establishes the phases of an attack, and a means of identifying and mitigating risk to...
-
Upload Vulnerabilities
--- Tutorial room exploring some basic file-upload vulnerabilities in websites --- ### Getting Started First up, let's deploy the...
-
Vaccine
``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
-
Vaccine
``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
-
Vulnerability Management
TryHackMe room
-
VulnNet: Node
--- After the previous breach, VulnNet Entertainment states it won't happen again. Can you prove they're wrong? ---...
-
Vulnversity
TryHackMe room
-
Warzone 1
---- You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
-
Watcher
---- A boot2root Linux machine utilising web exploits along with some common privilege escalation techniques. ---...
-
Weaponizing Vulnerabilities
TryHackMe room
-
Weasel
---- I think the data science team has been a bit fast and loose with their project resources. ---- ### Task 1 Start the VM Start...
-
Web Enumeration
--- Learn the methodology of enumerating websites by using tools such as Gobuster, Nikto and WPScan ---...
-
Wekor
---- CTF challenge involving Sqli , WordPress , vhost enumeration and recognizing internal services ;) ---...
-
What the Shell?
TryHackMe room
-
Willow
---- What lies under the Willow Tree? ----   ### Hack the machine and obtain the flags Start...
-
Year of the Rabbit
--- Let's have a nice gentle start to the New Year! Can you hack into the Year of the Rabbit box without falling down a hole? --- ###...