Lab write-ups
Command-by-command walkthroughs of retired and publicly published labs, teaching the method exams reward — enumeration first, version to vulnerability, then exploitation.Every box here is retired or public by design, so nothing is exam material; each walkthrough shows the actual commands and links the technique back to the methodology references.

A command-by-command walkthrough of retired Hack The Box machine Bashed — a left-behind web shell to www-data, then a writable root cron job to root.
Read the walkthrough →HTB retired · CronosHTB retired: Cronos — a full chain, start to rootA command-by-command walkthrough of retired HTB machine Cronos — DNS zone transfer, SQL injection, command injection, then a cron privilege escalation to root.
Read the walkthrough →HTB retired · JerryHTB retired: Jerry — the whole box is a default passwordA command-by-command walkthrough of retired Hack The Box machine Jerry — Tomcat Manager default credentials and a WAR payload straight to SYSTEM.
Read the walkthrough →HTB retired · LameHTB retired: Lame — Samba usermap to rootA command-by-command walkthrough of retired Hack The Box machine Lame — full port scan to root through the Samba 3.0.20 username-map flaw (CVE-2007-2447).
Read the walkthrough →TryHackMe · BlueTryHackMe: Blue — exploiting EternalBlue (MS17-010)A command-by-command walkthrough of the TryHackMe room Blue — enumerating and exploiting the MS17-010 EternalBlue SMB vulnerability to SYSTEM on Windows.
Read the walkthrough →