Archive
Browse case studies
Reviewed, evidence-based case studies from Hack The Box machines and Sherlocks, covering Windows, Linux, DFIR and SOC work where available. Search or filter by category and topic.
Reviewed, evidence-based case studies from Hack The Box machines and Sherlocks, covering Windows, Linux, DFIR and SOC work where available. Search or filter by category and topic.
72 published case studies. Narrow by focus or keyword.
Showing 12 of 72Showing all 72 case studies
A Medium Linux Hack The Box machine where a pac4j-jwt JWE authentication bypass opens the dashboard, the exposed encryption key doubles as an SSH password, and a leaked SSH CA private key yields root.
DFIR notes from a medium-difficulty Sherlock where a decommissioned host was used to prompt-inject an MSP helpdesk AI, then remotely access a workstation to dump credentials, add persistence, and exfiltrate files.
A share readable by a low-privileged domain account exposes a live MSSQL sa credential, enabling command execution and configuration-file password reuse before AD CS ESC4 template abuse issues a certificate for the administrative identity.
Web enumeration exposes an interactive phpbash shell for www-data command execution, then a passwordless sudo transition and a writable root-scheduled script yield root.
Web enumeration exposes a custom Java plugin; decompilation reveals hardcoded database credentials later reused for SSH, and an unrestricted sudo policy yields root.
Virtual host enumeration reveals a Dolibarr CRM instance with default credentials; authenticated RCE, credential reuse, and an Enlightenment SUID flaw chain to root.
An Apache ActiveMQ deployment with a vulnerable OpenWire service and default console credentials yields a service-account shell; unrestricted nginx sudo enables a root file-write path.
Unauthenticated Jenkins CLI file read (CVE-2024-23897) exposes a bcrypt password hash whose offline recovery unlocks the Script Console, and the credential store then reveals a path to root.
Unsafe evaluation in a Searchor search request yields command execution; exposed Git credentials, container environment inspection through sudo, and relative-path execution in a root script extend access.
A blind SQL injection in ZoneMinder recovers credential hashes for SSH access, then filename command injection in a root-run motionEye service leads to root.
A Spring Boot Actuator session leak grants admin access, and command injection in the SSH feature provides a foothold; credentials from the application JAR and an SSH ProxyCommand sudo rule lead to root.
Leaked Gogs source exposes hardcoded API credentials and a Flask eval() call for container root; database credential reuse, a Gogs SSH key, and HashiCorp Vault SSH OTP then provide host root.
Grafana path traversal (CVE-2021-43798) extracts the application database for offline credential cracking, and a permissive docker exec sudo rule mounts the host filesystem to reach root.
XWiki SolrSearch unauthenticated Groovy code execution (CVE-2025-24893) provides a foothold; reused database credentials enable SSH, and a SUID Netdata ndsudo helper is hijacked through PATH to reach root.
SSRF in a book-cover upload exposes an internal API and development credentials; Git history reveals production credentials, and a sudo-permitted GitPython script vulnerable to CVE-2022-24439 yields root.
IKE Aggressive Mode with PSK authentication exposes a crackable hash for SSH access, and a non-standard sudo binary is abused through a hostname-based policy bypass (CVE-2025-32462) to reach root.
Unauthenticated Apache NiFi command execution through CVE-2023-34468 and an H2 database driver, a recovered operator SSH key, and a cracked operations guide open an OPC UA maintenance window that grants root.
A GraphQL endpoint leaks HelpDeskZ credentials and an attachment-upload weakness stores rejected PHP files under predictable names for web-service code execution; a kernel eBPF flaw (CVE-2017-16995) escalates to root.
Mirth Connect XStream deserialization (CVE-2023-43208) provides an unauthenticated shell; database credentials and a PBKDF2 hash give SSH access, then a double eval() in a root-owned Flask service yields root.
Default Request Tracker credentials and a password stored in a comment field provide user access; KeePass master-password recovery from a crash dump (CVE-2023-32784) unlocks an unencrypted root SSH key.
A backdoored PHP 8.1.0-dev build executes code through the User-Agentt header, and an unrestricted sudo rule for the Chef knife tool is abused via knife exec to reach root.
An exposed .git directory on a development virtual host reveals a CMS password for authenticated RCE; a sudo cleanup script with a user-controlled glob and a two-hop symlink chain reads a protected file.
SQL injection in a login page and PNG magic-byte upload evasion provide a foothold; MySQL credentials tunneled through Chisel and reused admin credentials enable lateral movement, and a SUID sysinfo binary is hijacked through PATH to reach root.
An API access-control flaw exposes password hashes, and an unauthenticated Docker daemon allows a privileged container escape to host root.
A leaked backup exposes upload source with weak MIME and extension checks, enabling a double-extension PHP web shell; command injection through filenames in a cron script and input validation gaps in a sudo network script lead to privileged access.
Craft CMS pre-authentication RCE (CVE-2025-32432) and plaintext database credentials lead to an administrator hash and SSH access; a GNU inetutils telnet authentication bypass (CVE-2026-24061) on loopback yields root.
Authenticated Roundcube RCE (CVE-2025-49113) and session-table password decryption with the application DES key lead to SSH access; a symlink attack on the below utility's error log (CVE-2025-27591) yields root.
SNMP enumeration leaks credentials for SSH access; an internal Pandora FMS instance reached through SSH dynamic forwarding is SQL-injected for session hijacking, and a SUID backup binary calling tar by relative name enables PATH hijacking to root.
A PHP loose-comparison flaw bypasses authentication; a ZIP archive's ZipCrypto encryption is broken via known-plaintext to recover an SSH key, and a hardcoded credential in Laravel source provides root.
SSRF in request-baskets (CVE-2023-27163) reaches an internal Maltrail service vulnerable to command injection, and a NOPASSWD systemctl status rule is escalated through a less-pager escape (CVE-2023-26604) to root.
A password-reset token returned in an API response, unsafe dynamic configuration evaluation in an AI-agent platform, and container secret exposure chain through an internal service to privileged access.
Virtual host enumeration exposes an administrative interface and a pre-authentication backup disclosure that leaks AES key material; decrypting the application database recovers an SSH credential, and local enumeration identifies a privilege-escalation path.
Default credentials on exposed file-management software and an executable upload provide a web-service shell; WebSocket SQL injection recovers an SSH credential, and a doas rule for dstat is abused through plugin loading to reach root.
An exposed application archive identifies legacy Apache Struts upload handling, and CVE-2024-53677 path traversal yields a service-account shell; a stored credential enables SSH, and a sudo tcpdump post-rotate hook reaches root.
A download endpoint's path traversal exposes Gitea configuration and database data for password recovery and SSH access; an ImageMagick shared-library hijack (CVE-2024-41817) in a scheduled process provides elevated access.
Exposed version-control metadata and a custom-header development virtual host lead to an upload blocklist bypass and a race condition for a web-service shell; a SUID Python 2 input() helper and a package-installer sudo rule reach root.
SQL injection in a password-reset workflow and a Laravel-admin upload-validation bypass provide a foothold; reused Monit credentials enable SSH, and wildcard and @listfile handling in a sudo 7-Zip backup reach a protected root key.
Anonymous FTP exposes an OpenWrt backup containing a wireless key reused for SSH access; a raw-packet-capable reaver and a default WPS PIN recover a WPA key that grants root SSH.
Default OpenPLC credentials and a Structured Text C extension provide container root; wireless scanning and a WPS PixieDust attack recover a WPA passphrase, and association leads to passwordless root SSH on a router.
Anonymous FTP and archive recovery expose credentials that grant Telnet access, then escalate through cached credential abuse.
Misconfigured object permissions drive a multi-hop chain through Kerberoasting, credential capture, and DCSync to domain compromise.
A malicious Windows theme upload on the ThemeBleed path yields a shell, then CLFS abuse escalates to SYSTEM.
An exposed Ansible vault and rogue LDAP listener expose service credentials, enabling ESC1 certificate abuse for Domain Administrator.
A guest-readable logon script and excessive directory permissions lead through Kerberos delegation abuse to domain compromise.
Anonymous LDAP disclosure, SMB configuration artifacts, audit-app analysis, and AD Recycle Bin data combine into a credential-exposure chain.
Group and account-control permissions form an ACL chain ending in AD CS ESC9 certificate abuse.
Guest SMB, LDAP attributes, and embedded script credentials chain into Backup Operators hive extraction and domain compromise.
NETLOGON script credentials and GenericWrite over a delegation admin enable Kerberoasting, PetitPotam coercion, and DCSync.
A weakly secured MSSQL database yields cracked credentials, then badsuccessor OU delegation and DCSync complete domain compromise.
Anonymous SMB and MSSQL coercion recover credentials, then AD CS ESC1 certificate abuse yields the privileged account NT hash.
A provided Gitea login exposes database credentials that yield pgAdmin 4 remote code execution, Docker daemon control, captured domain credentials, and ESC7 certificate abuse on a dual-OS Active Directory lab.
A leaked Cisco configuration yields SMB and WinRM access, then Firefox process memory recovery exposes the Administrator password.
PDF metadata and a default onboarding password enable DNS record injection and NTLM capture, then GMSA silver-ticket abuse reaches Domain Administrator.
Default Tomcat Manager credentials allow WAR deployment, producing an immediate SYSTEM shell.
A log-file credential leak, Shadow Credentials abuse, and a rogue update server chain to SYSTEM code execution.
A mail server path traversal exposes a configuration hash, and a crafted document triggers privileged code execution on a client host.
RID brute forcing, password spraying, and a legacy backup expose ManageCA rights, enabling the AD CS ESC7 abuse chain to domain compromise.
Guest SMB null authentication and a stored CliXml credential lead to Azure AD Sync database decryption and a domain administrator password.
A zip-upload SSRF captures an NTLMv2 hash, and delegation abuse plus an MSI repair flaw create a domain administrator.
A monitoring binary leaks MSSQL credentials; ADIDNS poisoning captures more, and WCF command injection returns a SYSTEM shell.
Kerberos clock-skew alignment, gMSA enumeration, and an NTLM relay pivot lead through delegation abuse to domain controller compromise.
An LDAP description attribute and PowerShell transcripts expose administrative credentials, then DNSAdmins abuse loads a malicious DLL for SYSTEM.
Guest SMB notes and a pre-created computer account lead to an ESC1 certificate template and administrator impersonation.
A printer admin panel's LDAP configuration is redirected to capture service credentials, then Server Operators escalation reaches Administrator.
A weak password reset enables Kerberoasting and silver-ticket forgery, then SeImpersonate abuse escalates to SYSTEM via GodPotato.
Guest-accessible tooling, reversible credential obfuscation, and excessive computer-object permissions form a path to privileged access.
Gibbon LMS enumeration and database credential recovery lead to a Group Policy Creator Owners path toward Domain Administrator.
An SMB share exposes a protected certificate archive, and PowerShell history leaks a service account with LAPS read access.
Share-hosted documents, Kerberoasting, AD Recycle Bin recovery, and a WSL pivot lead into offline directory-backup analysis.
HTB Sherlock case study correlating authentication logs and session records to reconstruct an SSH brute-force, interactive root access, and a persistent sudo account.
HTB Sherlock case study reconstructing a single-host Windows event-log timeline with Chainsaw: interactive logon, discovery-tool detection, audit-policy tampering, scheduled-task persistence, and Firewall log clearing.
Correlating a packet capture with Windows Security event logs to investigate a suspected NTLM relay and authenticated SMB share activity.
No case studies match. Clear a filter or broaden the search.