#hackthebox
Here are some FREE platforms to get hands-on cybersecurity experience:

1. Cybrary
2.TryHackMe
3. OverTheWire
4. HackTheBox
5. LetsDefend
6. PicoCTF
November 11, 2025 at 7:08 AM
started this year learning pentesting on hackthebox, hit a wall and went to soc, backtracked to 100% the junior path, then studied for sec+ to pass the hr filter then last week i saw i could do isc2's cc for free

so now i end the year ready for cc & sec+ & w/ htb cjca @ 100%, cdsa @ 56%, cpts @ 26%
November 11, 2025 at 1:52 AM
I just completed module Introduction to Web Applications in HTB Academy! academy.hackthebox.com/achievement/... #hackthebox
Completed Introduction to Web Applications
In the Introduction to Web Applications module, you will learn all of the basics of how web applications work and begin to look at them from an information security perspective.
academy.hackthebox.com
November 10, 2025 at 6:17 PM
HTB Starting Point: Mongod Getting Familiar with MongoDB Moving onto our next Starting Point machine we have this bad boy. A quick look at the tasks associated with guy shows that we’re going to...

#programming #hackthebox #information-technology #hacking #cybersecurity

Origin | Interest | Match
November 12, 2025 at 3:08 AM
🚀 Just wrapped up HackTheBox Season 9 – Windows Machine: NanoCorp (Hard) 💻

This one was really enjoyable — the user part caught me off guard with how quick and unexpected it was 👀, but the root part totally made up for it — solid challenge, clever logic, and super satisfying to solve
November 8, 2025 at 11:18 PM
🚀 Just wrapped up HackTheBox Season 9 – Windows Machine: NanoCorp (Hard) 💻

This one was really enjoyable — the user part caught me off guard with how quick and unexpected it was 👀, but the root part totally made up for it — solid challenge, clever logic, and super satisfying to solve.
Owned NanoCorp from Hack The Box!
I have just owned machine NanoCorp from Hack The Box
labs.hackthebox.com
November 8, 2025 at 11:12 PM
RustyKey from HackTheBox is an assume breach AD box. I'll Timeroast to get a better foothold, and after some AD privilege chaining with BloodHound, perform a CLSID hijack, and then abuse AddAllowedToAct to RBCD to escalate to administrator.
HTB: RustyKey
RustyKey HTB walkthrough: Timeroasting to crack computer passwords, ForceChangePassword abuse, CLSID hijacking via registry, and RBCD for domain compromise.
0xdf.gitlab.io
November 8, 2025 at 3:00 PM
Unlock the Hacker’s Mindset: How Earning 1000 Reputation on HackTheBox Forged My Cybersecurity Career

Introduction: In the competitive world of cybersecurity, theoretical knowledge is insufficient; practical, hands-on experience is the true differentiator. Platforms like HackTheBox (HTB) provide a…
Unlock the Hacker’s Mindset: How Earning 1000 Reputation on HackTheBox Forged My Cybersecurity Career
Introduction: In the competitive world of cybersecurity, theoretical knowledge is insufficient; practical, hands-on experience is the true differentiator. Platforms like HackTheBox (HTB) provide a controlled, gamified environment where aspiring security professionals can legally test their skills against real-world vulnerabilities. Achieving a 1000-reputation milestone, as highlighted in a recent social media post, signifies a critical transition from novice to a competent practitioner capable of identifying and exploiting security flaws.
undercodetesting.com
November 8, 2025 at 1:11 AM
Two weeks away - have you registered yet? ⚡ DC207’s custom #HackTheBox CTF kicks off Nov 20 with pizza, #TheMatrix, and chaos. New to #hacking? We’ll get you started. Register today to save your spot! zurl.co/8s7bB #DC207 #DCGroups #DEFCON #MaineSec
November 6, 2025 at 1:02 PM
HTB Starting Point: Mongod Getting Familiar with MongoDB Moving onto our next Starting Point machine we have this bad boy. A quick look at the tasks associated with guy shows that we’re going to...

#programming #hackthebox #information-technology #hacking #cybersecurity

Origin | Interest | Match
HTB Starting Point: Mongod
Getting Familiar with MongoDB
infosecwriteups.com
November 9, 2025 at 9:19 AM
HTB Starting Point: Synced Rsync is a Pretty Important Tool Hey there and welcome to the final box under HTB’s Starting Point Tier 01 Yayyyy (this took me way too long). Anyhow, todays box is goi...

#cybersecurity #hackthebox #security #information-security #hacking

Origin | Interest | Match
HTB Starting Point: Synced
Rsync is a Pretty Important Tool
infosecwriteups.com
November 9, 2025 at 9:28 AM
Unlock Elite Hacking Skills: How AI is Revolutionizing Cybersecurity Training

Introduction: The traditional method of learning penetration testing through HackTheBox writeups is being transformed by artificial intelligence. Cybersecurity professionals are now using AI tutors to deeply understand…
Unlock Elite Hacking Skills: How AI is Revolutionizing Cybersecurity Training
Introduction: The traditional method of learning penetration testing through HackTheBox writeups is being transformed by artificial intelligence. Cybersecurity professionals are now using AI tutors to deeply understand exploitation techniques without being handed the solution, creating a more effective learning experience that builds genuine expertise rather than dependency on walkthroughs. Learning Objectives: Master prompt engineering techniques for creating effective AI hacking tutors…
undercodetesting.com
November 5, 2025 at 11:55 PM
If you're using writeups to learn how to hack on HackTheBox (or other CTFs), use AI as a tutor. In this video I'll show a free prompt to use, as well as a Claude Skill I developed.
Free AI HTB Tutor
Generative AI has many applications. An amazing one is to give it a writeup to a challenge you're trying to solve but stuck on and getting it to coach you th...
www.youtube.com
November 5, 2025 at 3:42 PM
Just cleaned out my /etc/hosts file today. It truly is a trip down memory lane.

A bit of context: For every #hackthebox lab, #ctf, or other competition that I do, it's often convenient to add entries to the hosts file.
November 5, 2025 at 12:24 PM
Free Learning
You have no excuse.

· TryHackMe / HackTheBox
· Professor Messer (YouTube)
· Microsoft Learn
The resources are free. The discipline to use them isn't.
November 4, 2025 at 5:29 PM
Dump from VulnLab released on HackTheBox last week. It has some very trick injections and a sudo rule puzzle to work out - I'll show two ways.
HTB: Dump
Dump has a website that collects packets on a specific port. It can also handle PCAP uploads and download all the current PCAP files in a zip archive. I’ll abuse wildcard injection in the zip command with some carefully crafted filenames to get RCE and a shell. I’ll pivot to the next user with a password from the database. I’ll then abuse how www-data can run sudo to run tcpdump to get root.
0xdf.gitlab.io
November 4, 2025 at 12:27 PM
The Voleur Hack: Unpacking the Advanced Active Directory Assumed-Breach Attack

Introduction: The HackTheBox machine "Voleur" represents a sophisticated assumed-breach Active Directory scenario that tests multiple advanced attack vectors. This complex engagement demonstrates how attackers can chain…
The Voleur Hack: Unpacking the Advanced Active Directory Assumed-Breach Attack
Introduction: The HackTheBox machine "Voleur" represents a sophisticated assumed-breach Active Directory scenario that tests multiple advanced attack vectors. This complex engagement demonstrates how attackers can chain together vulnerabilities in password management, DPAPI exploitation, and Kerberos attacks to compromise entire Windows domains. Learning Objectives: Master techniques for recovering deleted user accounts and associated credentials Understand DPAPI exploitation for credential extraction from registry hives…
undercodetesting.com
November 1, 2025 at 6:42 PM
The Voleur Active Directory Hack: A Step-by-Step Breakdown of a Modern Domain Compromise

Introduction: The compromise of an Active Directory domain remains a primary objective for cyber adversaries, and the HackTheBox "Voleur" machine provides a masterclass in chaining together common…
The Voleur Active Directory Hack: A Step-by-Step Breakdown of a Modern Domain Compromise
Introduction: The compromise of an Active Directory domain remains a primary objective for cyber adversaries, and the HackTheBox "Voleur" machine provides a masterclass in chaining together common misconfigurations to achieve full domain dominance. This attack path, from initial access to Domain Admin, leverages vulnerabilities in Kerberos, user permissions, and the Data Protection API (DPAPI) to demonstrate a realistic enterprise network intrusion.
undercodetesting.com
November 1, 2025 at 5:26 PM
Voleur is an assume breach active directory box from HackTheBox. It has lots of passwords, deleted user recovery, DPAPI, targeted kerberoasting, and hashes from registry hives.
HTB: Voleur
Voleur is an active directory box that starts with assume breach credentials. I’ll find an Excel notebook with credentials and get a shell. I’ll find a deleted user and switch to a service account to recover it. That user can access an SMB share with a user’s home directory backup, where I’ll find DPAPI encrypted credentials. I’ll recover those, getting access to an SSH key that provides access to a WSL instance. There I’ll find registry hive backups where I can dump the administrator hash.
0xdf.gitlab.io
November 1, 2025 at 3:40 PM
The big players in the cyber degrees space are also solving this in really clumsy ways like relying heavily on certs and HackTheBox, which I have huge ethical concerns with. We are starting to really learn which schools do what, though,
October 31, 2025 at 9:05 PM
Store from VulnLab released on HackTheBox yesterday. It's got a web decryption known plaintext attack, directory traversal, node inspect, and Chrome debug.
HTB: Store
HTB Store walkthrough: exploiting XOR encryption for arbitrary file read, SFTP tunneling to Node.js debugger, and Chrome webdriver RCE for root access.
0xdf.gitlab.io
October 30, 2025 at 10:00 AM