Skip to content
taktak.hu
Search
Ctrl
K
Cancel
Select theme
Dark
Light
Auto
Menu
All Work
Training & Profiles
Offensive Security
Windows
Access — Credential Sprawl Across Legacy Services
Administrator — ACL Abuse, Kerberoasting, and DCSync to Domain Compromise
Aero — ThemeBleed and CLFS Privilege Escalation
Authority — AD CS ESC1 via Ansible Vault Credential Exposure
Breach — Kerberoasting and Unconstrained Delegation to Domain Administrator
Cascade — Anonymous LDAP Disclosure and AD Recycle Bin Credential Recovery
Certified — Active Directory ACL Delegation and AD CS ESC9 Escalation
Cicada — Credential Chaining to Backup Operators Hive Extraction
Delegate — Active Directory Unconstrained Delegation via NETLOGON Script Credentials
Eighteen — MSSQL Impersonation to badsuccessor Delegation and DCSync
Escape — AD CS ESC1 from Anonymous SMB and MSSQL Coercion
EscapeTwo — AD CS ESC4 Template Abuse via WriteOwner and Shadow Credentials
Fries — From a Gitea Credential Leak to ESC7 Domain Compromise
Heist — Cisco Config Leak to Firefox Credential Extraction
Intelligence — PDF Metadata to GMSA Silver Ticket via DNS Injection
Jerry — Tomcat Manager Default Credentials to SYSTEM Shell
Logging — Log Leak, Shadow Credentials, and Rogue WSUS to SYSTEM
Mailing — Path Traversal, Outlook NTLM Coercion, and LibreOffice Privilege Escalation
Manager — AD CS ESC7 via Certificate Authority Abuse
MonitorsFour — Cacti API Token Bypass to Privileged Docker Escape
Monteverde — Azure AD Sync Credential Extraction
NanoCorp — NTLMv2 Capture, AD Delegation Abuse, and CheckMK MSI Repair Escalation
Overwatch — ADIDNS Poisoning and WCF SOAP Command Injection
Pirate — gMSA Disclosure, NTLM-Relay RBCD, and SPN Abuse to Domain Controller
Resolute — LDAP Credential Exposure and DNSAdmins DLL Injection to SYSTEM
Retro — AD CS ESC1 Impersonation via Guest SMB Disclosure and a Pre-created Computer Account
Return — LDAP Credential Capture via Printer Admin Panel
Scrambled — Weak Password Reset and Kerberos Ticket Forgery in Active Directory
Support — Embedded Credentials and RBCD Domain Compromise
TheFrizz — Gibbon LMS RCE and a Group Policy Creator Owners Escalation Path
Timelapse — Certificate-Based WinRM Access and LAPS Password Disclosure
Voleur — Credential Chain to Offline Directory-Backup Abuse
Linux
Bashed — Exposed Web Shell and Root-Scheduled Script Abuse
Blocky — Exposed Plugin Credentials and Unrestricted Sudo
BoardLight — Dolibarr RCE and Enlightenment SUID Privilege Escalation
Broker — ActiveMQ OpenWire RCE and Unsafe Daemon Sudo
Builder — Unauthenticated Jenkins CLI File Read to Root Credential Recovery
Busqueda — Searchor Expression Injection and Relative-Path Sudo Escalation
CCTV — ZoneMinder Blind SQL Injection to Root via motionEye Filename Command Injection
CozyHosting — Actuator Session Leak and sudo ssh ProxyCommand Escalation
Craft — eval() Injection, Credential Reuse, and Vault SSH OTP
Data — Grafana Path Traversal to Docker Container Escape
Editor — XWiki CVE-2025-24893 RCE to Netdata ndsudo PATH Hijack
Editorial — SSRF and Git History Credential Leak to GitPython Command Injection
Expressway — IKE Aggressive Mode to Sudo Hostname Bypass
Helix — Unauthenticated NiFi RCE, a Recovered Operator Key, and OPC UA Maintenance-Window Root
Help — GraphQL Credential Leak to HelpDeskZ Upload RCE
Interpreter — Mirth Connect Unauthenticated RCE and Flask eval() Privilege Escalation
Keeper — Default Credentials to KeePass Memory Disclosure
Knife — PHP 8.1.0-dev Backdoor RCE and NOPASSWD knife Escalation
LinkVortex — Exposed Git History to Ghost CMS RCE and a Symlink-Protection Bypass
Magic — SQL Injection and Magic-Byte Upload Bypass to SUID PATH Hijack
Networked — Web Shell Upload, Filename Command Injection, and sudo Network-Script Abuse
Orion — Craft CMS Pre-Auth RCE and Loopback Telnet Authentication Bypass to Root
Outbound — Roundcube RCE, DES Session Decryption, and below Symlink Privilege Escalation
Pandora — SNMP Credential Leak to Pandora FMS Session Hijacking and SUID PATH Hijacking
Ransom — PHP Type Juggling and ZipCrypto Known-Plaintext
Sau — SSRF Chain to Maltrail Command Injection and Pager Escape
Silentium — Flowise Token Disclosure and CustomMCP Code Injection to Root
Snapped — Pre-Authentication Backup Disclosure and Encryption-Key Leak
Soccer — Tiny File Manager Upload and dstat Plugin Privilege Escalation
Strutted — Apache Struts Upload Path Traversal and tcpdump Sudo Hook
Titanic — Path Traversal to ImageMagick Shared-Library Hijacking
UpDown — Exposed Git Metadata, Upload Race, and Privileged Interpreter Abuse
Usage — SQL Injection to Root via Laravel-admin Upload Bypass and 7-Zip Wildcard Abuse
Wifinetic — Backup-Exposed Wi-Fi Key Reuse and a Default-PIN WPS Attack
WifineticTwo — OpenPLC RCE and WPS PixieDust Pivot
Investigations
DFIR
Brutus — SSH Brute-Force, Interactive Root Access, and a Persistent Sudo Account
LogJammer — Windows Event-Log Reconstruction of Interactive Access, Scheduled-Task Persistence, and Firewall Log Clearing
Reaper — NTLM Relay Correlated from Packet Capture and Security Logs
Select theme
Dark
Light
Auto
DFIR
Investigation case studies and evidence analysis from HTB Sherlocks.
Edit page
Last updated:
Sep 15, 2026