Pwned Machines
Full attack chains on retired Hack The Box machines — enumeration to root, every step documented.
Disclaimer
Writeups are only published for retired machines in accordance with Hack The Box's rules. No active machine solutions are shared here.
🖥️ Windows
🔥 Medium
HTB Querier Walkthrough
Step-by-step Hack The Box Querier walkthrough. Exploit hardcoded Excel macro credentials, capture MSSQL NTLMv2 hashes, and escalate via Cached GPP files.
🖥️ Linux
🔥 Easy
HTB Sau Walkthrough
Sau is an Easy Difficulty Linux machine that features a Request Baskets instance that is vulnerable to Server-Side Request Forgery (SSRF) via [CVE-2023-27163](https://nvd.nist.gov/vuln/detail/CVE-2...
🖥️ Linux
🔥 Easy
HTB Cap Walkthrough
A comprehensive penetration testing walkthrough for Hack The Box: Cap. Covers service enumeration, exploiting Insecure Direct Object Reference (IDOR) to leak sensitive PCAP data, and escalating privileges via abused Linux Capabilities and CVE-2021-4034 (PwnKit).
🖥️ Linux
🔥 Easy
HTB Soccer Walkthrough
A highly detailed, professional walkthrough for the Hack The Box machine Soccer. Explores Tiny File Manager exploitation, WebSocket Blind SQL Injection, and privilege escalation via doas and dstat plugins.
🖥️ Linux
🔥 Hard
HTB Nimbus Walkthrough
Step-by-step Hack The Box Nimbus walkthrough. Exploit SSRF filter bypass, extract AWS IAM credentials, and abuse SQS queue for remote code execution.
🖥️ Windows
🔥 Medium
HTB Checkpoint Walkthrough — BadSuccessor (CVE-2025-53779) Active Directory Exploit
Step-by-step Hack The Box Checkpoint walkthrough. Exploit the BadSuccessor dMSA vulnerability (CVE-2025-53779) on Windows Server 2025 for full domain compromise via AD object restoration, malicious VS Code extension, and Volatility memory forensics.
🖥️ Windows
🔥 Easy
HTB EscapeTwo Walkthrough — ADCS ESC1 & ESC4 Exploitation
Step-by-step HTB EscapeTwo walkthrough. Abuse MSSQL database privileges, exploit ADCS certificate template vulnerabilities (ESC1 & ESC4) with Certipy, and compromise the Domain Controller.
🖥️ Windows
🔥 Medium
HTB Escape Walkthrough — MSSQL & ADCS ESC1 Exploitation
Step-by-step HTB Escape walkthrough. Extract MSSQL credentials from a public PDF, capture NetNTLM hashes, exploit log files, and abuse ADCS ESC1 for full domain administrator takeover.
🖥️ Windows
🔥 Easy
HTB Sauna Walkthrough — Autologon & DCSync Exploitation
Step-by-step HTB Sauna walkthrough. Enumerate Active Directory via AS-REP Roasting, crack registry autologon credentials, and perform a DCSync attack for Domain Administrator access.
🖥️ Windows
🔥 Insane
HTB Rebound Walkthrough
Step-by-step HTB Rebound walkthrough. Execute AS-REP Roasting, exploit Constrained Delegation and Shadow Credentials, chain with RemotePotato0, and dump NTDS.dit secrets.
🖥️ Windows
🔥 Insane
HTB Sizzle Walkthrough — ADCS, Kerberoasting, & DCSync Privilege Escalation
Step-by-step HTB Sizzle walkthrough. Abuse SMB write permissions, exploit Active Directory Certificate Services (ADCS) web enrollment, execute Kerberoasting, and perform DCSync.
🖥️ Windows
🔥 Hard
HTB Mantis Walkthrough — SQL Server & OrchardCMS Exploitation
Step-by-step HTB Mantis walkthrough. Perform SQL Server database enumeration, crack binary and base64 encoded OrchardCMS credentials, and elevate privileges on the domain controller.
🖥️ Windows
🔥 Hard
HTB Vintage Walkthrough — gMSA, DPAPI, & RBCD Exploitation
Step-by-step HTB Vintage walkthrough. Exploit service account password reuse, gMSA misconfigurations, computer object delegation, and extract credentials from DPAPI for domain compromise.
🖥️ Windows
🔥 Easy
HTB Access Walkthrough — Saved Credentials & FTP Exploitation
Step-by-step HTB Access walkthrough. Exploit weak physical security configurations, extract saved credentials from FTP and database backups, and elevate privileges to SYSTEM.
🖥️ Windows
🔥 Easy
HTB Forest Walkthrough — Exchange & Account Operators AD Exploitation
Step-by-step HTB Forest walkthrough. Enumerate domain objects via LDAP anonymous binds, exploit pre-authentication, abuse Account Operators privileges, and perform a DCSync attack.
🖥️ Windows
🔥 Medium
HTB Administrator — Targeted Kerberoasting & DCSync Privilege Escalation
Complete walkthrough of HTB Administrator machine featuring targeted Kerberoasting, ACL abuse, Password Safe cracking, and DCSync attack for full domain compromise.
🖥️ Windows
🔥 Medium
HTB Certified Walkthrough — Active Directory Certificate Services (ADCS) ESC9 Exploitation
Step-by-step HTB Certified walkthrough. Exploit Active Directory Certificate Services (ADCS) ESC9 vulnerability for full domain compromise using PowerView, Certipy, and PKINIT.
🔥 Unknown
_Template
============================================================================= HTB WALKTHROUGH TEMPLATE ============================================================================= INSTRUCTIONS: 1....
[root@purplesec ~]# ls -l /var/log/pwned/archive/
drwxr-xr-x 2026 [-]
drwxr-xr-x 2025 [+]
drwxr-xr-x 2024 [+]
[Dec 30]
HTB Sauna Walkthrough — Autologon & DCSync Exploitation
[Dec 18]
HTB Rebound Walkthrough
[Dec 08]
HTB Sizzle Walkthrough — ADCS, Kerberoasting, & DCSync Privilege Escalation
[Dec 06]
HTB Mantis Walkthrough — SQL Server & OrchardCMS Exploitation
[Dec 04]
HTB Vintage Walkthrough — gMSA, DPAPI, & RBCD Exploitation
[Dec 04]
HTB Access Walkthrough — Saved Credentials & FTP Exploitation
[Nov 19]
HTB Forest Walkthrough — Exchange & Account Operators AD Exploitation
[Nov 11]
HTB Administrator — Targeted Kerberoasting & DCSync Privilege Escalation
[Nov 06]
HTB Certified Walkthrough — Active Directory Certificate Services (ADCS) ESC9 Exploitation
drwxr-xr-x 1970 [+]
_