0xbbuddha

0xbbuddha

Base de connaissances

Par ici

README00
Recherche

Writeups

HackTheBox
CTF
ProLab

Red Team Notes

Red Team Notes

Pentest Web Notes

Pentest Web Notes

Arch Linux Notes

Arch Linux Notes

Cheatsheets

Cheatsheets

Blog

Blog05

Misc

Music
Chess
GitHubLinkedIn
0xbbuddha0xbbuddha

Writeups ProLab

HackTheBox ProLabs

Scénarios red team multi-machines, triés par tier (Operator, Adversary...).

3 entrées·HackTheBox ProLabs

Red Team Operator I

Red Team Operator I·C2 / ADCS / Cross-forest·2026-06-16

Mythical

Opération red team à travers un C2 Mythic déjà en place : flag Backup via un partage rsync, ESC4→ESC1 avec bypass du Full Enforcement Mode (extension SID) pour le flag Certified, pivot cross-forest et abus MSSQL TRUSTWORTHY jusqu'au flag Mythical Master sur le second domaine.

Red Team Operator I·Gitea / Pivoting / Docker / Samba AD forensics / Duplicati·2026-07-18

Unintended

Secrets oubliés dans l'historique Gitea, pivot SOCKS via SFTP jusqu'à MySQL et PostgreSQL/Mattermost, credentials réutilisés entre Gitea/Mattermost/domaine, privesc Docker triviale sur BACKUP, forensic d'un backup Samba AD hors-ligne jusqu'au Domain Admin, et abus d'une instance Duplicati live pour lire un fichier root sans jamais shell root.

Red Team Operator I·Node-RED RCE / ligolo-ng / gMSA / Delegation contrainte / DPAPI·2026-07-18

Tengu

RCE Node-RED non authentifiée en réécrivant un flow, secret de chiffrement en clair pour des creds MSSQL, pivot ligolo-ng vers un AD interne, hash MSSQL cracké via CrackStation, abus d'un gMSA par délégation contrainte, GodPotato pour SYSTEM sur SQL, puis LaZagne/DPAPI et Kerberos jusqu'à un compte Tier-0 protégé pour prendre le Domain Controller.

Sur cette page

Labs

Liens liés

HackTheBoxMachines par difficultéRed Team NotesMéthodologie