← BACK HOME
//FLAGS CAPTURED, LESSONS LEARNED

CTF Writeups.

Solutions and methodology notes from TryHackMe, HackTheBox and CTF competitions. Spoiler policy: full flags redacted, techniques explained.

02
// FEATURED CASE · TRYHACKME · ACTIVE DIRECTORY

Ra
OSINT to Domain Admin

An original field guide through a recovery-flow clue, SMB artefacts, a Spark client exposure, overbroad AD delegation, and a SYSTEM task that trusts writable data.

OPEN THE CASE FILE →

All writeups

//2 ENTRIES · REVIEWED

Ra: OSINT to Domain Admin

Original Active Directory field notes covering portal metadata, SMB evidence, forced NTLM authentication in the authorised lab, Account Operators, and a scheduled-task trust failure.

Active DirectorySMBPowerShell
READ WRITEUP →

Pickle Rick: Source Code to Root

Detailed commands, original attack-path diagrams, spoiler-controlled answers, findings, remediation, and the methodology that transfers beyond the room.

Web ReconCommand ExecutionLinux PrivEsc
READ WRITEUP →