Walkthroughs
Step-by-step HackTheBox machine writeups, Pro Labs, Fortresses and exam-lab walkthroughs — full recon, exploitation and privilege …
Email Verification Issue Resolved We would like to inform you that there was a temporary technical glitch affecting the email verification process. The issue has now been resolved, and email verification is working properly. If your account is still inactive, please complete your email verification now to activate your account. Thank you for your patience and understanding.
Everything you need to pass the OSCP+ exam in one place. This guide covers all PEN-200 topics with working commands and real methodology - written like short handwritten notes with zero fluff.
Read article →
Full security assessment walkthrough for Manager on HackTheBox. Includes reconnaissance, enumeration, exploitation steps, and a professional penetration testing report with CVSS v3.1 scores and remediation guidance.
Read article →Step-by-step HackTheBox machine writeups, Pro Labs, Fortresses and exam-lab walkthroughs — full recon, exploitation and privilege …
Hands-on web exploitation — SQLi, XSS, SSRF, XXE, SSTI, request smuggling and the full OWASP Top 10.
LLM and ML security — prompt injection, jailbreaks, RAG attacks, adversarial ML and AI red teaming.
Attacking and defending Active Directory — Kerberoasting, ADCS, delegation, ACL abuse, BloodHound, trusts and persistence.
Adversary simulation — C2, phishing, initial access, AV/EDR evasion, lateral movement and persistence.
Android and iOS pentesting — Frida, APK/IPA reverse engineering, SSL pinning bypass and insecure storage.
Binary analysis and exploit dev — Ghidra/IDA, x86 assembly, ROP, fuzzing and packed-binary unpacking.
Network attack and defence — ARP/DHCP/VLAN abuse, MITM, pivoting, Wi-Fi, BLE, SNMP and SMB.
API pentesting — REST, GraphQL and gRPC, the OWASP API Top 10, BOLA/BFLA, webhooks and gateways.
Field-ready pentest checklists turned into step-by-step "how to test" guides — for every item: the scenario, the real co…
Multi-host HackTheBox Pro Lab walkthroughs — full enterprise-network compromise across forests and flags.
Cloud attack paths — AWS, Azure and GCP IAM, Kubernetes, container escapes and CI/CD pipeline abuse.
Security tooling and automation — custom scripts and exploits for recon, exploitation and post-exploitation.
Linux and Windows privilege escalation — misconfigs, SUID, kernel exploits, token abuse and weak services.
HackTheBox Fortress walkthroughs — multi-flag vendor challenge labs spanning web, binary, crypto and more.
Open-source intelligence — target profiling, breach data, dark-web monitoring and OSINT tooling.
Exam reviews and prep guides — OSCP, CPTS, CWEE and more, with strategy, lab notes and real exam experience.
Static and dynamic malware analysis — unpacking, behavioural sandboxing, RE and indicators of compromise.
Ciphers, hashing and crypto attacks — padding oracles, hash cracking, RSA flaws and TLS weaknesses.