Machine-to-Technique Index
#Active Directory Machines
| Machine | Difficulty | Key Techniques |
|---|---|---|
| Active | Easy | SMB Enumeration, GPP (Group Policy Preferences) Exploitation, Kerberoasting |
| Blackfield | Hard | Anonymous SMB Enumeration, AS-REP Roasting, LSASS Credential Dumping, Backup Operators Group Abuse |
| Cascade | Medium | LDAP Anonymous Enumeration, TightVNC Password Decryption, .NET Decompilation, AD Recycle Bin |
| Cicada | Easy | Active Directory Enumeration, Password Spraying, SeBackupPrivilege Abuse, Pass-the-Hash |
| Escape | Medium | SMB Guest Access, MSSQL Authentication Relay, Hash Cracking, ESC1 Attack (ADCS) |
| Flight | Hard | LFI, NTLM Hash Capture, Password Spraying, NTLM Theft via File Shares, DCSync Attack |
| Fluffy | Easy | BloodHound Enumeration, Certipy Enumeration, ACL/DACL Abuse, ESC16 (CVE-2025-24071) |
| Forest | Easy | AS-REP Roasting, BloodHound Enumeration, Account Operators Group Abuse, DCSync |
| Monteverde | Medium | Password Spraying, Azure AD Connect Password Extraction, sqlcmd Usage |
| Return | Easy | Network Printer Abuse (LDAP Credential Capture), Server Operators Group Abuse |
| Sauna | Easy | AS-REP Roasting, Auto-Logon Credential Discovery, DCSync Attack |
| TheFrizz | Medium | CVE-2023-45878 (Arbitrary File Write), Password Cracking, GPO Exploitation, Kerberos SSH Authentication |
| Timelapse | Easy | Public SMB Share, PFX Certificate Extraction & Cracking, LAPS Privilege Escalation |
#Linux Machines
| Machine | Difficulty | Key Techniques |
|---|---|---|
| BoardLight | Easy | Web Enumeration, Dolibarr Exploitation (CVE-2023-30253), SUID Exploitation (CVE-2022-37706) |
| Broker | Easy | Apache ActiveMQ Unauthenticated RCE, Nginx Sudo Configuration Exploitation |
| Builder | Medium | CVE-2024-23897 (Jenkins Arbitrary File Read), Jenkins Cryptography, SSH Key Decryption |
| Busqueda | Easy | Command Injection, Git Configuration Enumeration, Docker Enumeration, Relative Path RCE |
| Cerberus | Hard | Icinga Web Pre-Auth RCE, Firejail SUID Breakout (CVE-2022-31214), sssd Cached Credential Cracking, ADSelfService Plus (CVE-2022-47966), Network Pivoting |
| Cereal | Hard | .NET Deserialization, XSS Exploitation, SSRF, SeImpersonatePrivilege Abuse |
| Clicker | Medium | NFS Share Enumeration, SQL Injection, SUID Binary Path Traversal, XXE via Intercepted cURL, Sudo Environment Variable Abuse |
| CozyHosting | Easy | Spring Boot Actuator Enumeration, Command Injection, SSH Abuse via Misconfiguration |
| Dog | Easy | Exposed .git Repository, BackdropCMS RCE via File Upload, Sudo Binary Exploitation |
| Editorial | Easy | Server-Side Request Forgery (SSRF), Git Repository Enumeration, CVE-2022-24439 Sudo Exploitation |
| Help | Easy | GraphQL Enumeration, Blind SQL Injection, Unauthenticated Arbitrary File Upload, Kernel Exploitation |
| Intentions | Hard | Second-Order SQL Injection, Hash-Based Authentication Bypass, Imagick Arbitrary Object Instantiation, CAP_DAC_READ_SEARCH Capability Abuse |
| Keeper | Easy | Default Credentials, KeePass Database Exploitation, SSH Key Retrieval |
| LinkVortex | Easy | Exposed .git Directory, CVE-2023-40028 (Ghost CMS Arbitrary File Read via Symlinks), TOCTOU Race Condition (Symlink) |
| Magic | Easy | SQL Injection Login Bypass, PHP File Upload Whitelist Bypass, Path Hijacking, SUID Abuse |
| Markup | Easy | XML External Entity (XXE) Injection, Weak Credentials on Web Login |
| Mentor | Medium | SNMP Community String Enumeration, Blind Remote Code Execution, PostgreSQL RCE via Default Credentials, Docker Pivoting & Tunneling, Sudo Exploitation |
| Monitored | Medium | SNMP Enumeration, Nagios API Exploitation, SQL Injection (CVE-2023-40931), Sudo Bash Script Abuse |
| Networked | Easy | File Upload Bypass, Command Injection, Crontab Exploitation, Sudo Exploitation via Network Script |
| Pandora | Easy | SNMP Enumeration, Port Forwarding, SQL Injection, SUID Binary PATH Variable Injection |
| Quick | Hard | HTTP/3 Protocol, ESI (Edge Side Includes) Injection, Symlink Exploitation, Plaintext Credential Reuse |
| Sau | Easy | SSRF via CVE-2023-27163 (Request Baskets), Command Injection, Sudo Exploitation |
| Soccer | Easy | Default Credentials, Tiny File Manager RCE (CVE-2021-45010), Blind SQL Injection via WebSockets, doas SUID Exploitation |
| Titanic | Easy | Virtual Host Fuzzing, Gitea Repository Enumeration, Arbitrary File Read, CVE-2024-41817 (ImageMagick RCE) |
| UpDown | Medium | Exposed .git Directory, HTTP Header Modification, PHP LFI with phar:// Wrapper, SUID Python Script Injection, easy_install Sudo Exploitation |
| Usage | Easy | SQL Injection, Laravel Admin Panel Exploitation, File Upload Filter Bypass, Binary Analysis, 7zip Symlink Abuse |
#Windows Machines
| Machine | Difficulty | Key Techniques |
|---|---|---|
| Absolute | Insane | AS-REP Roasting, LDAP Enumeration, Shadow Credential Attack, KrbRelay, ACL Abuse |
| Access | Easy | Access Database (.mdb) Enumeration, Outlook PST File Extraction, DPAPI Credential Extraction |
| Administrator | Medium | BloodHound Enumeration, ACL/DACL Abuse (GenericAll, GenericWrite), Targeted Kerberoasting, DCSync Attack |
| Aero | Medium | CVE-2023-38146 (ThemeBleed / Windows Themes), CVE-2023-28252 (CLFS Driver Exploitation), PoC Modification |
| APT | Insane | RPC Interface Enumeration, IPv6 Firewall Bypass, Remote Registry Access, NTLMv1 Exploitation |
| Atom | Medium | Electron Builder Signature Validation Exploit, Redis Credential Extraction, PortableKanban Password Decryption |
| Authority | Medium | Ansible Vault Cracking, AD CS Enumeration & Exploitation, Pass-the-Cert Attack |
| Certified | Medium | BloodHound Enumeration, Certipy Enumeration, ACL/DACL Abuse (WriteOwner, GenericWrite), Shadow Credential Attack, ESC9 |
| EscapeTwo | Easy | BloodHound Enumeration, File Header Magic Bytes Manipulation, Password Spraying, MSSQL Access, ADCS Misconfiguration Abuse |
| Intelligence | Medium | PDF Metadata Enumeration, Password Spraying, ADIDNS Abuse, ReadGMSAPassword Abuse, Constrained Delegation Abuse |
| Jeeves | Medium | Jenkins Groovy Script Exploitation, Windows Defender Bypass, Pass-the-Hash, Alternate Data Streams (ADS) Enumeration |
| Mailing | Easy | Path Traversal, hMailServer Password Hash Cracking, CVE-2024-21413 (MonikerLink NTLM Capture), CVE-2023-2255 (LibreOffice Macro Execution) |
| Manager | Medium | RID Cycling, Password Spraying, MSSQL xp_dirtree File Enumeration, ESC7 Exploitation (ADCS) |
| Multimaster | Insane | SQL Injection, VS Code Debug Functionality Exploitation, DLL Reverse Engineering, GenericWrite Abuse, Server Operators Group Abuse |
| Outdated | Medium | CVE-2022-30190 (Follina), Shadow Credential Attack, Golden Ticket Attack, WSUS Exploitation |
| Rebound | Insane | RID Cycling, AS-REP Roasting, Pre-Authentication Kerberoasting, ACL Abuse, Descendant Object Takeover (DOT), Shadow Credential Attack, Cross-Session NTLM Relay, gMSA Password Read, Resource-Based Constrained Delegation (RBCD), DCSync |
| ServMon | Easy | NVMS-1000 LFI, SSH Password Spraying, NSClient++ Exploitation, SSH Tunneling |
| StreamIO | Medium | Subdomain Enumeration, SQL Injection, LFI via PHP Wrappers, Remote File Inclusion (RFI), Browser Saved Credential Retrieval, LAPS Password Retrieval via LDAP |
| Support | Easy | SMB Anonymous Access, .NET Decompilation, LDAP Querying, Resource-Based Constrained Delegation (RBCD) |
| Vintage | Hard | Pre-Created Computer Account Exploitation, NTLM-Disabled Enumeration, gMSA Password Retrieval, Kerberoasting, Credential Manager Extraction, RBCD |
#Technique Cross-Reference
#Active Directory Attacks
| Technique | Machines |
|---|---|
| AS-REP Roasting | Forest, Sauna, Blackfield, Rebound, Absolute |
| Kerberoasting | Active, Rebound, Administrator, Vintage, TombWatcher |
| Targeted Kerberoasting | Administrator, Rebound, Vintage, TombWatcher |
| DCSync Attack | Forest, Sauna, Flight, Administrator, Rebound |
| Password Spraying | Cicada, Monteverde, Flight, Intelligence, Manager, EscapeTwo, Administrator, ServMon |
| Pass-the-Hash | Cicada, Jeeves |
| Pass-the-Cert | Authority |
| Golden Ticket | Outdated |
| Kerberos Delegation (Constrained) | Intelligence |
| Kerberos Delegation (RBCD) | Rebound, Support, Vintage, Outdated |
| S4U2Self / S4U2Proxy | Rebound |
| ACL/DACL Abuse | Fluffy, Absolute, Administrator, Certified, Rebound, Multimaster, EscapeTwo |
| GenericAll / GenericWrite Abuse | Administrator, Certified, Multimaster |
| ForceChangePassword | Administrator, TombWatcher |
| WriteOwner Abuse | Certified, EscapeTwo |
| Shadow Credential Attack | Absolute, Rebound, Outdated, TombWatcher, Certified |
| Descendant Object Takeover (DOT) | Rebound |
| Account Operators Group Abuse | Forest |
| Backup Operators Group Abuse | Blackfield |
| Server Operators Group Abuse | Return, Multimaster |
| SeBackupPrivilege Abuse | Cicada |
| LAPS Password Retrieval | Timelapse, StreamIO |
| ReadGMSAPassword / gMSA Abuse | Intelligence, Rebound, Vintage, TombWatcher |
| GPO Exploitation | TheFrizz |
| AD Recycle Bin | Cascade, TombWatcher |
| ADIDNS Abuse | Intelligence |
| Pre-Created Computer Account | Vintage |
| KrbRelay | Absolute |
#Active Directory Certificate Services (ADCS) Attacks
| Technique | Machines |
|---|---|
| ESC1 (Enrollee Supplies Subject) | Escape |
| ESC7 (CA Manager) | Manager |
| ESC9 (No Security Extension) | Certified |
| ESC15 (Application Policy Mismatch) | TombWatcher |
| ESC16 | Fluffy |
| AD CS Enumeration (Certipy) | Fluffy, Certified, Manager, Authority |
| AD CS Misconfiguration Exploitation | EscapeTwo, Authority |
#Enumeration & Discovery
| Technique | Machines |
|---|---|
| SMB Anonymous/Guest Access | Blackfield, Support, Timelapse, Escape, Active |
| LDAP Anonymous Enumeration | Cascade, Forest, Absolute |
| LDAP Querying | Support |
| SNMP Enumeration | Mentor, Monitored, Pandora |
| RID Cycling / User Enumeration | Manager, Rebound |
| RPC Enumeration | APT |
| Web Enumeration | BoardLight, Editorial, Help, Keeper, Quick, CozyHosting, Sau, Soccer, Magic |
| BloodHound Enumeration | Forest, Fluffy, Administrator, Certified, EscapeTwo, TombWatcher |
| Subdomain Enumeration | StreamIO, Titanic |
| Virtual Host Fuzzing | Titanic, Flight |
| Exposed .git Directory | Dog, LinkVortex, UpDown, Editorial, Busqueda |
| DNS Enumeration | Intelligence |
| Port Forwarding / Tunneling | Pandora, ServMon, Cerberus, Mentor |
| Network Pivoting | Cerberus, Mentor |
| HTTP/3 Protocol | Quick |
| GraphQL Enumeration | Help |
#Credential Attacks
| Technique | Machines |
|---|---|
| Hash Cracking (general) | Escape, TheFrizz, Mailing, Atom, StreamIO |
| AS-REP Hash Cracking | Forest, Sauna, Blackfield, Rebound, Absolute |
| Kerberoast Hash Cracking | Active, Rebound, Administrator, Vintage, TombWatcher |
| LSASS Credential Dumping | Blackfield |
| DPAPI Credential Extraction | Access |
| Browser Saved Credential Retrieval | StreamIO |
| Credential Manager Extraction | Vintage |
| Auto-Logon Credential Discovery | Sauna |
| KeePass Database Exploitation | Keeper |
| Ansible Vault Cracking | Authority |
| Azure AD Connect Password Extraction | Monteverde |
| Default Credentials | Keeper, Quick, Soccer |
| Plaintext Credential Reuse / Storage | Magic, Quick, Cicada, Usage, Busqueda |
| Password Cracking (ZIP/PFX) | Timelapse |
| GPP (Group Policy Preferences) Exploitation | Active |
| NTLM Hash Capture / Theft | Flight, Mailing |
| NTLMv1 Exploitation | APT |
| Cross-Session NTLM Relay | Rebound |
#Web Application Attacks
| Technique | Machines |
|---|---|
| SQL Injection (Basic / Login Bypass) | Magic, Help, Clicker, Networked, Usage |
| SQL Injection (Blind) | Soccer, Help |
| SQL Injection (Second-Order) | Intentions |
| SQL Injection (with xp_dirtree) | Manager |
| Command Injection | Busqueda, CozyHosting, Sau, Networked |
| Server-Side Request Forgery (SSRF) | Cereal, Editorial, Sau |
| XML External Entity (XXE) Injection | Markup, Clicker |
| XSS Exploitation | Cereal |
| .NET Deserialization | Cereal |
| ESI (Edge Side Includes) Injection | Quick |
| Local File Inclusion (LFI) | Flight, ServMon, StreamIO |
| PHP Wrapper Exploitation (phar://) | UpDown |
| Remote File Inclusion (RFI) | StreamIO |
| File Upload Bypass | Networked, Magic, Help, Usage |
| Path Traversal | Mailing |
| Arbitrary File Read | Titanic, LinkVortex, Builder |
| HTTP Header Modification | UpDown |
| WebSocket SQL Injection | Soccer |
| SSRF via CVE-2023-27163 (Request Baskets) | Sau |
#CVE / Known Vulnerability Exploitation
| Technique | Machines |
|---|---|
| CVE-2023-30253 (Dolibarr) | BoardLight |
| CVE-2022-37706 (Enlightenment SUID) | BoardLight |
| CVE-2024-23897 (Jenkins Arbitrary File Read) | Builder |
| CVE-2022-31214 (Firejail Breakout) | Cerberus |
| CVE-2022-47966 (ADSelfService Plus) | Cerberus |
| CVE-2023-45878 (Gibbon CMS File Write) | TheFrizz |
| CVE-2023-40028 (Ghost CMS Arbitrary File Read) | LinkVortex |
| CVE-2023-40931 (Nagios SQL Injection) | Monitored |
| CVE-2023-27163 (Request Baskets SSRF) | Sau |
| CVE-2021-45010 (Tiny File Manager RCE) | Soccer |
| CVE-2022-24439 (GitPython Sudo) | Editorial |
| CVE-2024-41817 (ImageMagick RCE) | Titanic |
| CVE-2023-38146 (ThemeBleed / Windows Themes) | Aero |
| CVE-2023-28252 (CLFS Driver) | Aero |
| CVE-2022-30190 (Follina) | Outdated |
| CVE-2024-21413 (MonikerLink) | Mailing |
| CVE-2023-2255 (LibreOffice Macro) | Mailing |
| CVE-2025-24071 | Fluffy |
#Linux Privilege Escalation
| Technique | Machines |
|---|---|
| SUID Binary Exploitation | BoardLight, Cerberus, Clicker, Magic, Pandora, UpDown, Usage, Soccer |
| Sudo Exploitation / Misconfiguration | Broker, CozyHosting, Mentor, Monitored, Sau, UpDown, Dog, Clicker, Networked, Editorial |
| Sudo Environment Variable Abuse | Clicker |
| Sudo Binary Path Hijacking | Magic |
| PATH Variable Injection | Pandora |
| Cron / Scheduled Task Abuse | Networked, Titanic |
| Kernel Exploitation | Help |
| CAP_DAC_READ_SEARCH Capability Abuse | Intentions |
| Docker Container Escape / Enumeration | Cerberus, Mentor, Titanic, Busqueda |
| SSH Key Theft / Misconfiguration | CozyHosting, Keeper, Builder, Monitored, Clicker |
| Symlink / Race Condition (TOCTOU) | LinkVortex, Quick, Usage |
| 7zip Symlink Abuse | Usage |
| doas Exploitation | Soccer |
| easy_install Sudo Exploitation | UpDown |
| Imagick Object Instantiation | Intentions |
| Git Repository Analysis | Dog, Editorial, UpDown, Busqueda |
#Windows Privilege Escalation
| Technique | Machines |
|---|---|
| SeImpersonatePrivilege Abuse | Cereal |
| SeBackupPrivilege Abuse | Cicada |
| Server Operators Group Abuse | Return, Multimaster |
| Backup Operators Group Abuse | Blackfield |
| Account Operators Group Abuse | Forest |
| VS Code Exploitation / Debug Abuse | Multimaster |
| Jenkins Exploitation (Windows) | Jeeves |
| NSClient++ Exploitation | ServMon |
| NVMS-1000 LFI | ServMon |
| WSUS Exploitation | Outdated |
| GPO Creation / Exploitation | TheFrizz |
| LAPS Password Retrieval | Timelapse, StreamIO |
| Alternate Data Streams (ADS) | Jeeves |
| Windows Defender Bypass | Jeeves |
| Electron Builder Exploit | Atom |
| KrbRelay | Absolute |
| NTLMv1 Exploitation | APT |
| IPv6 Techniques | APT |
| Remote Registry | APT |
#Lateral Movement & Pivoting
| Technique | Machines |
|---|---|
| WinRM Lateral Movement | Timelapse, Sauna, Blackfield, Monteverde, Escape, EscapeTwo, Certified, Administrator |
| SSH Lateral Movement | ServMon, TheFrizz, Cerberus |
| RDP Lateral Movement | Absolute |
| Pass-the-Hash | Cicada, Jeeves |
| Pass-the-Cert | Authority |
| Credential Reuse / Password Spraying | Monteverde, Flight, Manager, EscapeTwo, Administrator, Intelligence |
| SQL Command Line (sqlcmd) Abuse | Monteverde, StreamIO |
| MSSQL xp_dirtree | Manager |
| Network Pivoting / Tunneling | Cerberus, Mentor |
| Cross-Session Relay | Rebound |
#Code Analysis & Reverse Engineering
| Technique | Machines |
|---|---|
| .NET Decompilation / Analysis | Cascade, Support, Cereal |
| DLL Reverse Engineering | Multimaster |
| Binary / Executable Analysis | Absolute, Support, Usage |
| Source Code Review | Busqueda, Clicker, StreamIO, UpDown |
| Git History Analysis | Dog, Editorial, UpDown, Busqueda |
| PowerShell History Analysis | Timelapse |
| PDF Metadata Analysis | Intelligence, Absolute |
| Browser Database Decoding | StreamIO |
| Magic Bytes / File Header Manipulation | EscapeTwo |
#Service-Specific Exploitation
| Technique | Machines |
|---|---|
| Apache ActiveMQ RCE | Broker |
| Jenkins Exploitation | Builder, Jeeves |
| Nagios Exploitation | Monitored |
| Dolibarr Exploitation | BoardLight |
| Spring Boot Actuator | CozyHosting |
| BackdropCMS Exploitation | Dog |
| Ghost CMS Exploitation | LinkVortex |
| Gibbon CMS Exploitation | TheFrizz |
| Icinga Web Exploitation | Cerberus |
| ADSelfService Plus | Cerberus |
| Laravel Module Abuse | Usage |
| Tiny File Manager Exploitation | Soccer |
| KeePass Exploitation | Keeper |
| NSClient++ Exploitation | ServMon |
| hMailServer Exploitation | Mailing |
| Redis | Atom |
| Gitea | Titanic, Busqueda |
| GraphQL | Help |
| Request Baskets | Sau |
| Maltrail | Sau |
| Pandora FMS | Pandora |
| PortableKanban | Atom |
| PostgreSQL RCE | Mentor |
| Network Printer Abuse | Return |
#Difficulty Summary
| Difficulty | AD Machines | Linux Machines | Windows Machines |
|---|---|---|---|
| Easy | Active, Cicada, Fluffy, Forest, Return, Sauna, Timelapse | BoardLight, Broker, CozyHosting, Dog, Editorial, Help, Keeper, LinkVortex, Magic, Markup, Networked, Pandora, Sau, Soccer, Titanic, Usage | Access, EscapeTwo, Jeeves, Mailing, ServMon, Support |
| Medium | Cascade, Escape, Monteverde, TheFrizz | Builder, Busqueda, Clicker, Mentor, Monitored, UpDown | Administrator, Aero, Atom, Authority, Certified, Intelligence, Manager, Outdated, StreamIO |
| Hard | Blackfield, Flight | Cerberus, Cereal, Intentions, Quick | Blackfield, Vintage |
| Insane | -- | -- | Absolute, APT, Multimaster, Rebound |
Auto-generated from HTB machine walkthroughs. Each entry extracted from the Synopsis and Skills Learned sections.