Knowledge Hub

Privilege Escalation Labs

Available entries

  • Wonderland
    ``` gobuster dir --url http://10.10.122.82/ --wordlist /usr/share/wordlists/dirb/common.txt -t 30 found /r then /a so /r/a/b/b/i/t...
  • Enumeration
    --- This room is an introduction to enumeration when approaching an unknown corporate environment. ---...
  • Common Linux Privesc
    --- A room explaining common Linux privilege escalation --- ### Understanding Privesc What does "privilege escalation" mean? At it's...
  • Holo
    --- Holo is an Active Directory (AD) and Web-App attack lab that aims to teach core web attack vectors and more advanced AD attack...
  • Wreath
    ---- Learn how to pivot through a network by compromising a public facing web machine and tunnelling your traffic to access other...
  • Alfred
    --- Exploit Jenkins to gain an initial shell, then escalate your privileges by exploiting Windows authentication tokens. ---...
  • APIWizards Breach
    TryHackMe room
  • Blog
    --- Billy Joel made a Wordpress blog! --- ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/618f1cc93596ff4082250bce9d869767.p...
  • Flatline
    --- How low are your morals? --- ![](https://cdn.pixabay.com/photo/2020/04/25/11/12/electrocardiogram-5090337_960_720.jpg) What are the...
  • GLITCH
    --- Challenge showcasing a web app and simple privilege escalation. Can you find the glitch? ---...
  • Hacked
    ``` It seems like our machine got hacked by an anonymous threat actor. However, we are lucky to have a .pcap file from the attack. Can...
  • Intrusion Detection
    ---- Learn cyber evasion techniques and put them to the test against two IDS --- ![](https://ctfresources.s3.eu-west-2.amazonaws.com/bann...
  • Linux PrivEsc Arena
    TryHackMe room
  • Linux Privilege Escalation
    TryHackMe room
  • Linux: Local Enumeration
    --- Learn to efficiently enumerate a linux machine and identify possible weaknesses ---...
  • Looking_Glass
    ``` Enumerating SSH When connecting to one of the ports (in this case trying one of the higher ones), the SSH server responds with...
  • Overpass
    ``` ***gobuster*** gobuster dir --url http://10.10.101.139 --wordlist /usr/share/wordlists/dirb/common.txt (found path /admin)...
  • Pwnkit
    --- CVE-2021-4034 (colloquially dubbed "Pwnkit") is a terrifying Local Privilege Escalation (LPE) vulnerability, located in the "Polkit"...
  • RazorBlack
    ``` RazorBlack These guys call themselves hackers. Can you show them who's the boss ?? Throw something like a rock on the big green...
  • Windows PrivEsc
    TryHackMe room
  • 25 Days of Cyber Security
    TryHackMe room
  • Advent of Cyber 2 [2020]
    TryHackMe room
  • Amazon EC2 - Attack & Defense
    TryHackMe room
  • Annie
    ---- Remote access comes in different flavors. ---- ### Task 1 Recon - Research - Exploit...
  • APT28 Inception Theory
    TryHackMe room
  • Archangel
    --- Boot2root, Web exploitation, Privilege escalation, LFI --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/915282ea9193c331e...
  • Atlas
    --- Hack the Atlas server in this beginner room covering Windows attack methodology! ---...
  • BlockChain
    ``` https://tryhackme.com/room/blockchainvkkgjrph7y ┌──(kali㉿kali)-[~/Downloads/Blockchain] └─$ ftp 10.10.131.24 Connected to...
  • Bypassing UAC
    TryHackMe room
  • CMSpit
    ---- This is a machine that allows you to practise web app hacking and privilege escalation using recent vulnerabilities. ----...
  • CVE-2019-18634
    ``` The stack is a very regimented section of memory which stores various important aspects of a program. The heap, on the other hand,...
  • Erit Securus I
    --- Learn to exploit the BoltCMS software by researching exploit-db. --- ### Reconnaissance ``` ┌──(kali㉿kali)-[~] └─$ sudo nmap -sC -sV...
  • Fowsniff CTF
    --- Hack this machine and get the flag. There are lots of hints along the way and is perfect for beginners! ---...
  • hackerNote
    ---- A custom webapp, introducing username enumeration, custom wordlists and a basic privilege escalation exploit. ---...
  • Hacking Hadoop
    TryHackMe room
  • HackPark
    --- Bruteforce a websites login with Hydra, identify and use a public exploit then escalate your privileges on this Windows machine! ---...
  • Introductory Researching
    TryHackMe room
  • Jack
    --- Compromise a web server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module....
  • Linux PrivEsc
    TryHackMe room
  • Living Off the Land
    --- Learn the essential concept of "Living Off the Land" in Red Team engagements. ---...
  • Lumberjack Turtle
    ---- No logs, no crime... so says the lumberjack. ---- ![](https://www.honeytokens.io/img/LumberjackTurtle.png)...
  • Microsoft Windows Hardening
    --- To learn key attack vectors used by hackers and how to protect yourself using different hardening techniques. ---...
  • Network Services 2
    --- Enumerating and Exploiting More Common Network Services & Misconfigurations --- ### Understanding NFS What is NFS? NFS stands for...
  • NIS - Linux Part I
    --- Enhance your Linux knowledge with this beginner friendly room! --- ![|222](https://tryhackme-images.s3.amazonaws.com/room-icons/a6046...
  • Osquery: The Basics
    --- Let's cover the basics of Osquery. --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5e8dd9a4a45e18443162feab/room-conte...
  • OWASP Broken Access Control
    ---- Exploit Broken Access Control: Number 1 of the Top 10 web security risks. ----...
  • Polkit_CVE
    ``` What is the URL of the website you should submit dynamic flags to? https://flag.muir.land/ Overview In early 2021 a researcher named...
  • Res
    --- Hack into a vulnerable database server with an in-memory data-structure in this semi-guided challenge! ---...
  • Sau
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ nmap 10.10.11.224 Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-21 12:53 EDT Nmap scan report...
  • Sau
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ nmap 10.10.11.224 Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-21 12:53 EDT Nmap scan report...
  • Sea Surfer
    ---- Ride the Wave! ---- ![](https://i.imgur.com/yvuFbNQ.jpeg) ![](https://tryhackme-images.s3.amazonaws.com/room-icons/137a8e8a8cdc4ba57...
  • Skynet
    --- A vulnerable Terminator themed Linux machine. --- ![|333](https://i.imgur.com/SNHDHoh.png) Hasta la vista, baby. Are you able to...
  • Snort
    --- Learn how to use Snort to detect real-time threats, analyse recorded traffic files and identify anomalies. ---...
  • Tempest
    ---- You are tasked to conduct an investigation from a workstation affected by a full attack chain. ---...
  • The Docker Rodeo
    --- Learn a wide variety of Docker vulnerabilities in this guided showcase. --- ![777](https://assets.tryhackme.com/room-banners/DockerPr...
  • Thompson
    --- boot2root machine for FIT and bsides guatemala CTF --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/f5e35bf1d933a9b45077e...
  • toc2
    ---- It's a setup... Can you get the flags in time? ---- ![222](https://tryhackme-images.s3.amazonaws.com/room-icons/aab108830eaf8908ce3d...
  • Wazuh
    --- Wazuh is a free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring. ---...
  • Weaponization
    --- Understand and explore common red teaming weaponization techniques. You will learn to build custom payloads using common methods...
  • Wgel CTF
    --- Can you exfiltrate the root flag? --- ![|313](https://tryhackme-images.s3.amazonaws.com/room-icons/8116d1d52d3a63dd1e7c2e7ddce8a0d5.p...
  • Windows Local Persistence
    --- Learn the most common persistence techniques used on Windows machines. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/1...
  • Windows Privilege Escalation
    --- Learn the fundamentals of Windows privilege escalation techniques. --- ![](https://assets.tryhackme.com/room-banners/privesc.png)...
  • Zeek
    --- Introduction to hands-on network monitoring and threat detection with Zeek (formerly Bro). ---...
  • Abusing Windows Internals
    --- Leverage windows internals components to evade common detection solutions, using modern tool-agnostic approaches. ---...
  • AD Certificate Templates
    ---- Walkthrough on the exploitation of misconfigured AD certificate templates ---...
  • Advent of Cyber 1 [2019]
    TryHackMe room
  • Advent of Cyber 2022
    --- Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading...
  • Advent of Cyber 3 (2021)
    TryHackMe room
  • Agent Sudo
    TryHackMe room
  • Anonymous
    --- Not the hacking group --- ![222](https://tryhackme-images.s3.amazonaws.com/room-icons/876a5185c429c9703e625cb48c39637b.png)...
  • Archetype
    ``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
  • Archetype
    ``` blob:https://app.hackthebox.com/4f38037f-6ebb-44b8-9c8c-992a446560fa ┌──(kali㉿kali)-[~] └─$ rustscan -a 10.129.232.196 --ulimit 5500...
  • Atlassian, CVE-2022-26134
    --- An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability. ---...
  • Avengers Blog
    --- Learn to hack into Tony Stark's machine! You will enumerate the machine, bypass a login portal via SQL injection and gain root...
  • AWS Basic Concepts
    TryHackMe room
  • Badbyte
    --- Infiltrate BadByte and help us to take over root. --- ### Reconnaissance ![](https://i.imgur.com/gZqOO8D.png) Nmap is a free open...
  • Baron Samedit
    TryHackMe room
  • Bebop
    --- Who thought making a flying shell was a good idea? --- ![](https://qlaims.com/wp-content/uploads/2017/10/drone-header.jpg) ###...
  • Binex
    --- Escalate your privileges by exploiting vulnerable binaries. --- ![](https://i.imgur.com/aohxmGa.jpg)...
  • biteme
    ---- Stay out of my server! ---- ![](https://images.unsplash.com/photo-1550751827-4bd374c3f58b?ixlib=rb-1.2.1&ixid=MnwxMjA3fDB8MHxwaG90by...
  • BlueTeam
    --- For those who want to improve themselves in the Cyber Security Defense Field ---...
  • Boogeyman 1
    ---- A new threat actor emerges from the wild using the name Boogeyman. Are you afraid of the Boogeyman? ---- ### [Introduction] New...
  • Boogeyman 3
    TryHackMe room
  • BountyHacker
    ``` Find open ports on the machine. First of all we’ll need to find open ports on our target machine, but if you are beginner you’ll...
  • Brainstorm
    --- Reverse engineer a chat program and write a script to exploit a Windows machine. --- ![](https://i.imgur.com/rqwhSuo.png) ### Deploy...
  • Break Out The Cage
    --- Help Cage bring back his acting career and investigate the nefarious goings on of his agent! --- ```anonymous (no pass) ftp...
  • Brooklyn Nine Nine
    --- This room is aimed for beginner level hackers but anyone can try to hack this box. There are two main intended ways to root the box....
  • Brute
    --- You as well, Brutus? --- ![](https://i.postimg.cc/5NFMNX0n/Webp-net-resizeimage-1.png)...
  • Brute Force Heroes
    --- Walkthrough room to look at the different tools that can be used when brute forcing, as well as the different situations that might...
  • Bulletproof Penguin
    TryHackMe room
  • Burp Suite: Other Modules
    --- Take a dive into some of Burp Suite's lesser known modules --- ### Outline Alongside the well-known Repeater and Intruder rooms,...
  • CAPA: The Basics
    TryHackMe room
  • Careers in Cyber
    --- Learn about the different careers in cyber security. --- ![|100](https://tryhackme-images.s3.amazonaws.com/room-icons/7934742b978f977...
  • Carpe Diem 1
    ---- Recover your clients encrypted files before the ransomware timer runs out! ----...
  • Chocolate Factory
    --- A Charlie And The Chocolate Factory themed room, revisit Willy Wonka's chocolate factory! --- ### rustscan > found port 21 ftp, port...
  • CI/CD and Build Security
    TryHackMe room
  • Cluster Hardening
    TryHackMe room
  • ColddBox: Easy
    --- An easy level machine with multiple ways to escalate privileges. --- ### boot2Root Can you get access and get both **flags**? Good...
  • Command Injection
    --- Learn about a vulnerability allowing you to execute commands through a vulnerable app, and its remediations. --- ### Introduction...
  • Confidential
    --- We got our hands on a confidential case file from some self-declared "black hat hackers"... it looks like they have a secret invite...
  • Container Hardening
    TryHackMe room
  • Cooctus Stories
    ---- This room is about the Cooctus Clan ---- ![](https://pbs.twimg.com/profile_banners/1696074763/1605441583/1500x500)...
  • Corp
    --- Bypass Windows Applocker and escalate your privileges. You will learn about kerberoasting, evading AV, bypassing applocker and...
  • Crocc Crew
    ---- Crocc Crew has created a backdoor on a Cooctus Corp Domain Controller. We're calling in the experts to find the real back door!...
  • Cross-site Scripting
    --- Learn how to detect and exploit XSS vulnerabilities, giving you control of other visitor's browsers. --- ### Room Brief...
  • Cross-site Scripting-1
    --- Understand how cross-site scripting occurs and how to exploit it. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/9c4baf...
  • Crylo
    ---- Learn about the CryptoJS library and JavaScript-based client-side encryption and decryption. ----...
  • CSRF
    TryHackMe room
  • CVE-2022-26923
    ---- Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services. ---...
  • CVE-2023-38408
    ---- Learn how to move laterally abusing libraries' side effects in Ubuntu (CVE-2023-38408). ----...
  • CyberHeroes
    --- Want to be a part of the elite club of CyberHeroes? Prove your merit by finding a way to log in! ---...
  • Cyborg
    --- A box involving encrypted archives, source code analysis and more --- ## vpn ``` tryhackme-vpn sudo openvpn WittyAle.ovpn ``` ###...
  • Daily Bugle
    --- Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum. ---...
  • Dav
    --- boot2root machine for FIT and bsides guatemala CTF --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/cb525f3e7944eb5eec637...
  • DDOS
    ``` https://tryhackme.com/room/blockchainvkkgjrphsh ┌──(kali㉿kali)-[~/Downloads/DDOS] └─$ ftp 10.10.161.202 Connected to 10.10.161.202....
  • Deja Vu
    --- Exploit a recent code injection vulnerability to take over a website full of cute dog pictures! ---...
  • DFIR: An Introduction
    --- Introductory room for the DFIR module --- ### Introduction ## ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/61306d87a330...
  • Diamond Model
    --- Learn about the four core features of the Diamond Model of Intrusion Analysis: adversary, infrastructure, capability, and victim....
  • Dirty Pipe
    --- This room will provide an overview of the vulnerability, as well as give you an opportunity to exploit it for yourself in the...
  • Disgruntled
    TryHackMe room
  • Eavesdropper
    --- Listen closely, you might hear a password! --- ![111](https://tryhackme-images.s3.amazonaws.com/room-icons/de6446e44292ce978b994c0992...
  • Empline
    ---- Are you good enough to apply for this job? ---- ![111](https://tryhackme-images.s3.amazonaws.com/room-icons/189112ffef41c0fa813d7d5b...
  • Firewall Fundamentals
    TryHackMe room
  • Firewalls
    --- Learn about and experiment with various firewall evasion techniques, such as port hopping and port tunneling. ---...
  • Forgotten Implant
    ---- With almost no attack surface, you must use a forgotten C2 implant to get initial access. ----...
  • Game Zone
    --- Learn to hack into this machine. Understand how to use SQLMap, crack some passwords, reveal services using a reverse SSH tunnel and...
  • Gatekeeper
    --- Can you get past the gate and through the fire? --- ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/8979e58d84147f072077...
  • Generic University
    ---- API and Web testing room --- ![222](https://tryhackme-images.s3.amazonaws.com/room-icons/6a9730b73744a7e6af162994e74b2191.jpeg) ###...
  • GitLab CVE-2023-7028
    TryHackMe room
  • GoldenEye
    --- Bond, James Bond. A guided CTF. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/77b55a2ac1ac79ca534d6fc003c042b3.png)...
  • Grep
    ---- A challenge that tests your reconnaissance and OSINT skills. ---- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/645b19f...
  • h4cked
    TryHackMe room
  • HA Joker CTF
    ---- Batman hits Joker. --- ![222](https://tryhackme-images.s3.amazonaws.com/room-icons/ed910d9d7c419b8266128e044a40c7e2.jpeg) ### HA...
  • Hacker vs. Hacker
    --- Someone has compromised this server already! Can you get in and evade their countermeasures? ---...
  • Hacking with PowerShell
    --- Learn the basics of PowerShell and PowerShell Scripting --- ![](https://i.imgur.com/xFIv4Ve.png) ### Objectives...
  • Hardening Basics Part 1
    --- Learn how to harden an Ubuntu Server! Covers a wide range of topics (Part 1) ---...
  • HaskHell
    ---- Teach your CS professor that his PhD isn't in security. ---- ![](https://i.imgur.com/4AocURG.jpg)...
  • HipFlask
    ``` Hip Flask is a beginner to intermediate level walkthrough. It aims to provide an in-depth analysis of the thought-processes involved...
  • Ice
    TryHackMe room
  • Insecure Randomness
    TryHackMe room
  • Internal
    --- Penetration Testing Challenge --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/222b3e855f88a482c1267748f76f90e0.jpeg)...
  • Intro to Cross-site Scripting
    TryHackMe room
  • Intro to Cyber Threat Intel
    --- Introducing cyber threat intelligence and related topics, such as relevant standards and frameworks. ---...
  • Intro to Detection Engineering
    ---- Introduce the concept of detection engineering and the frameworks used towards crafting effective threat detection strategies. ----...
  • Intro to Docker
    ---- Learn to create, build and deploy Docker containers! ---- ![](https://assets.tryhackme.com/additional/containerisation-module/Contai...
  • Intro to Endpoint Security
    --- Learn about fundamentals, methodology, and tooling for endpoint security monitoring. ---...
  • Intro to ISAC
    --- Learn how to utilize Information Sharing and Analysis Centers to gather threat intelligence and collect IOCs. ---...
  • Intro to Pipeline Automation
    --- This room provides an introduction to DevOps pipeline automation and the potential security concerns. ---...
  • Intro To Pwntools
    ---- An introductory room for the binary exploit toolkit Pwntools. --- ![](https://raw.githubusercontent.com/Gallopsled/pwntools/stable/d...
  • Intro to Threat Emulation
    ---- A look into threat emulation practices as a means of cyber security assessment. ----...
  • Introduction to CryptOps
    TryHackMe room
  • Introduction to SIEM
    --- An introduction to Security Information and Event Management. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/c5eca9a893...
  • Investigating Windows 3.x
    TryHackMe room
  • Jack-of-All-Trades
    --- Boot-to-root originally designed for Securi-Tay 2020 --- ![](https://i.imgur.com/w0iocsP.png)...
  • John The Ripper
    --- Learn how to use John the Ripper - An extremely powerful and adaptable hash cracking tool ---...
  • JPGChat
    ``` ┌──(kali㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.248.160 --ulimit 5000 -b 65535 -- -A .----. .-. .-. .----..---. .----. .---. .--....
  • K8s Best Security Practices
    TryHackMe room
  • kiba
    TryHackMe room
  • L2 MAC Flooding & ARP Spoofing
    --- Learn how to use MAC Flooding to sniff traffic and ARP Cache Poisoning to manipulate network traffic as a MITM. ---...
  • Lessons Learned
    TryHackMe room
  • Linux File System Analysis
    TryHackMe room
  • Linux Forensics
    --- Learn about the common forensic artifacts found in the file system of Linux Operating System ---...
  • Linux Logs Investigations
    TryHackMe room
  • Linux System Hardening
    TryHackMe room
  • LocalPotato
    ---- Learn how to elevate your privileges on Windows using LocalPotato (CVE-2023-21746). ---...
  • Lunizz CTF
    ![](https://cdn.pixabay.com/photo/2016/11/08/05/20/adventure-1807524_960_720.jpg)...
  • macOS Forensics: The Basics
    TryHackMe room
  • magician
    ``` ┌──(kali㉿kali)-[~] └─$ sudo su [sudo] password for kali: ┌──(root㉿kali)-[/home/kali] └─# nano /etc/hosts ┌──(root㉿kali)-[/home/kali]...
  • Memory Acquisition
    TryHackMe room
  • Meow
    Download vpn from lab Let the configuration script run until you see the Initialization Sequence Completed message at the very end of...
  • Meow
    Download vpn from lab What does the acronym VM stand for? *Virtual Machine * What tool do we use to interact with the operating system...
  • Metasploit
    --- Learn to use Metasploit, a tool to probe and exploit vulnerabilities on networks and servers. ---...
  • Metasploit: Exploitation
    --- Using Metasploit for scanning, vulnerability assessment and exploitation. ---...
  • Microservices Architectures
    TryHackMe room
  • MISP
    --- Walkthrough on the use of MISP as a Threat Sharing Platform --- ![](https://assets.tryhackme.com/additional/jrsecanalyst/jrsec-room-b...
  • Mouse Trap
    TryHackMe room
  • MS Sentinel: Just Looking
    TryHackMe room
  • Network Security
    --- Learn about network security, understand attack methodology, and practice hacking into a target server. --- ### Introduction A...
  • Nmap
    TryHackMe room
  • Nmap Advanced Port Scans
    --- Learn advanced techniques such as null, FIN, Xmas, and idle (zombie) scans, spoofing, in addition to FW and IDS evasion. ---...
  • Nmap Basic Port Scans
    --- Learn in-depth how nmap TCP connect scan, TCP SYN port scan, and UDP port scan work. ---...
  • Nmap Post Port Scans
    --- Learn how to leverage Nmap for service and OS detection, use Nmap Scripting Engine (NSE), and save the results. ---...
  • OAuth Vulnerabilities
    TryHackMe room
  • Obfuscation Principles
    --- Leverage tool-agnostic software obfuscation practices to hide malicious functions and create unique code. ---...
  • Oh My WebServer
    --- Can you root me? --- ![222](https://tryhackme-images.s3.amazonaws.com/room-icons/c1833021c98fa6c74fc125f4b34741ca.png) ###...
  • Oopsie
    ``` blob:https://app.hackthebox.com/40488db7-9438-4437-8c1a-5e50b5bc5bc3 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.95.191...
  • Oopsie
    ``` blob:https://app.hackthebox.com/40488db7-9438-4437-8c1a-5e50b5bc5bc3 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.95.191...
  • Osiris
    --- Can you Quack it? --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/fe8053432e57f1958c78240c42e094a2.png) ### Osiris...
  • Overpass3
    ``` Initial foothold ***enumerating ports with rustscan*** port 80 open Enumerating with gobuster allows to discover a hidden /backups...
  • OWASP API Security Top 10 - 1
    --- Learn the basic concepts for secure API development (Part 1). --- ![](https://i.imgur.com/sP6d0iZ.png)...
  • OWASP API Security Top 10 - 2
    --- Learn the basic concepts for secure API development (Part 2). --- ![](https://i.imgur.com/sP6d0iZ.png)...
  • OWASP Top 10 - 2021
    ---- Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks. ---...
  • PC
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
  • PC
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
  • Phishing Emails 3
    --- Learn the tools used to aid an analyst to investigate suspicious emails. --- ![](https://assets.tryhackme.com/additional/phishing1/ph...
  • Plotted-TMS
    --- Everything here is plotted! --- ![](https://wiki.thehacker.nz/wp-content/uploads/2021/10/pe_banner.png)...
  • Poster
    --- The sys admin set up a rdbms in a safe way. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/37983213b742f063a0b1fbd37a32...
  • Preparation
    TryHackMe room
  • PrintNightmare
    --- Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527). ---...
  • Protocols and Servers 2
    --- Learn about attacks against passwords and cleartext traffic; explore options for mitigation via SSH and SSL/TLS. ---...
  • Ra
    You have found WindCorp's internal network and their Domain Controller. Can you pwn their network? ![](https://i.imgur.com/eyf66N3.png)...
  • Red Team OPSEC
    --- Learn how to apply Operations Security (OPSEC) process for Red Teams. --- ![|222](https://tryhackme-images.s3.amazonaws.com/room-icon...
  • Relevant
    --- Penetration Testing Challenge --- ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/10524728b2b462e8d164efe4e67ed087.jpeg)...
  • REMnux: Getting Started
    TryHackMe room
  • REmux The Tmux
    --- Tmux is known as a terminal multiplexer. That allows you to craft a single terminal however you need it. --- ### ssh ``` ssh...
  • Responder
    ``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
  • Responder
    ``` blob:https://app.hackthebox.com/207ef7e2-d519-4814-8616-c6679d11f80a ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.89.108 PING...
  • ret2libc
    ---- This room teaches basic return-oriented programming (ROP), exploitation of binaries and an ASLR bypass. ---- ### Task 1...
  • Retro
    --- New high score! --- ![](https://i.imgur.com/RDzWHJI.png) ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/a222ca9fb08b8bd...
  • Road
    --- Inspired by a real-world pentesting engagement --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/86d73ce54a3f392bd56336da0...
  • RootMe
    TryHackMe room
  • Runtime Detection Evasion
    --- Learn how to bypass common runtime detection measures, such as AMSI, using modern tool-agnostic approaches. ---...
  • Sequel
    ``` blob:https://app.hackthebox.com/75b7ab04-575b-4cf9-800c-bd03e22b0be6 ┌──(kali㉿kali)-[~] └─$ ping 10.129.71.100 PING 10.129.71.100...
  • Sequel
    ``` blob:https://app.hackthebox.com/75b7ab04-575b-4cf9-800c-bd03e22b0be6 ┌──(kali㉿kali)-[~] └─$ ping 10.129.71.100 PING 10.129.71.100...
  • Servidae: Log Analysis in ELK
    TryHackMe room
  • Set
    --- Once again you find yourself on the internal network of the Windcorp Corporation. --- ### Set ![](https://i.imgur.com/UySYgtM.png)...
  • Shells Overview
    TryHackMe room
  • Shoppy
    ``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
  • Shoppy
    ``` ┌──(kali㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.10.11.180 PING...
  • Smag Grotto
    --- Follow the yellow brick road. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/d4071f466e055d38d5a169cae9f12b33.png)...
  • Snort Challenge - Live Attacks
    --- Put your snort skills into practice and defend against a live attack --- ### Scenario 1 | Brute-Force Use the attached VM to finish...
  • Snort Challenge - The Basics
    --- Put your snort skills into practice and write snort rules to analyse live capture network traffic. --- ### Introduction...
  • Source
    --- Exploit a recent vulnerability and hack Webmin, a web-based system configuration tool. --- ### rustscan > 10000/tcp open http...
  • Splunk 101
    --- This room will cover the basics of Splunk. --- ![](https://assets.tryhackme.com/additional/splunk-overview/splunk-room-banner.png)...
  • SQLMAP
    --- Learn about and use Sqlmap to exploit the web application --- ![](https://i.imgur.com/2O70ow2.png) Introduction...
  • SSRF
    --- Learn how to exploit Server-Side Request Forgery (SSRF) vulnerabilities, allowing you to access internal server resources. --- ###...
  • Startup
    --- Abuse traditional vulnerabilities via untraditional means. --- ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/98d1e206f...
  • Steel Mountain
    --- Hack into a Mr. Robot themed Windows machine. Use metasploit for initial access, utilise powershell for Windows privilege escalation...
  • Sudo Buffer Overflow
    TryHackMe room
  • Sudo Security Bypass
    TryHackMe room
  • Sweettooth Inc.
    ---- Sweettooth Inc. needs your help to find out how secure their system is! ----...
  • Tardigrade
    ---- Can you find all the basic persistence mechanisms in this Linux endpoint? ----...
  • Tech_Supp0rt: 1
    --- Hack into the scammer's under-development website to foil their plans. --- ![](https://lh3.googleusercontent.com/fife/AAWUweXoOnrHJUw...
  • Templated
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
  • Templated
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
  • The Cod Caper
    --- A guided room taking you through infiltrating and exploiting a Linux system. --- ### Intro Hello there my name is Pingu. I've come...
  • The Lay of the Land
    --- Learn about and get hands-on with common technologies and security products used in corporate environments; both host and...
  • TheHive Project
    --- Learn how to use TheHive, a Security Incident Response Platform, to report investigation findings ---...
  • Threat Hunting With YARA
    TryHackMe room
  • Toolbox: Vim
    TryHackMe room
  • ToolsRus
    --- Practise using tools such as dirbuster, hydra, nmap, nikto and metasploit ---...
  • Topology
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.217 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
  • Topology
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.217 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
  • Tor
    ``` ***enumerating*** rustscan -a 10.10.9.58 --ulimit 5000 -b 65535 -- -A ***log ssh port 22*** via linux ssh thm@10.10.168.200 pass ->...
  • Trooper
    TryHackMe room
  • TryHack3M: Subscribe
    TryHackMe room
  • Undiscovered
    ---- Discovery consists not in seeking new landscapes, but in having new eyes.. ----...
  • Unified Kill Chain
    --- The Unified Kill Chain is a framework which establishes the phases of an attack, and a means of identifying and mitigating risk to...
  • Upload Vulnerabilities
    --- Tutorial room exploring some basic file-upload vulnerabilities in websites --- ### Getting Started First up, let's deploy the...
  • Vaccine
    ``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
  • Vaccine
    ``` blob:https://app.hackthebox.com/992bb2da-a712-4692-91e4-86edbc11e2d7 ┌──(kali㉿kali)-[~/hackthebox] └─$ ping 10.129.247.247 PING...
  • Vulnerability Management
    TryHackMe room
  • VulnNet: Node
    --- After the previous breach, VulnNet Entertainment states it won't happen again. Can you prove they're wrong? ---...
  • Vulnversity
    TryHackMe room
  • Warzone 1
    ---- You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
  • Watcher
    ---- A boot2root Linux machine utilising web exploits along with some common privilege escalation techniques. ---...
  • Weaponizing Vulnerabilities
    TryHackMe room
  • Weasel
    ---- I think the data science team has been a bit fast and loose with their project resources. ---- ### Task 1 Start the VM Start...
  • Web Enumeration
    --- Learn the methodology of enumerating websites by using tools such as Gobuster, Nikto and WPScan ---...
  • Wekor
    ---- CTF challenge involving Sqli , WordPress , vhost enumeration and recognizing internal services ;) ---...
  • What the Shell?
    TryHackMe room
  • Willow
    ---- What lies under the Willow Tree? ---- ![](https://i.imgur.com/8C4TXFS.jpg) ![222](https://tryhackme-images.s3.amazonaws.com/room-ico...
  • Windows Event Logs
    --- Introduction to Windows Event Logs and the tools to query them. --- ![|222](https://tryhackme-images.s3.amazonaws.com/room-icons/09ca...
  • Windows Forensics 2
    --- Learn about common Windows file systems and forensic artifacts in the file systems. ---...
  • Windows Fundamentals 1
    TryHackMe room
  • Windows Internals
    --- Learn and understand the fundamentals of how Windows operates at its core. ---...
  • Windows PrivEsc Arena
    TryHackMe room
  • Yara
    --- Learn the applications and language that is Yara for everything threat intelligence, forensics, and threat hunting! ---...
  • Year of the Fox
    ---- Don't underestimate the sly old fox... --- ![](https://i.imgur.com/JOBQtGF.png) ### Hack the machine and obtain the flags Start...
  • Year of the Rabbit
    --- Let's have a nice gentle start to the New Year! Can you hack into the Year of the Rabbit box without falling down a hole? --- ###...