Hacker Mystery Box #003: The Unlit City Hero Roll — A Night Seal Was Never a Pass (Custom Machine)
Hacker Blind Box #002: Night Letter from the Listening Rain Inn — The Rain Gate Believed the First Lie
Hacker Blind Box #001: Yunhai Sword Sect — Claiming the Grandmaster's Secret Teachings (Custom Vulnerable Machine)
TryHackMe Watcher Walkthrough: Variations on a Writable File
Generic University — OWASP API Security Top 10 Lab Writeup
MBPTL: Full Penetration Testing Lab Writeup (17 Flags)
ThreadHub Lab: Chaining Secondary-Context Path Traversal and DNS Rebinding into SSRF
PhantomShop (PhantomRange) Writeup Part 1 — Recon, Info Disclosure & Broken Auth
VulNyx Brain Walkthrough: LFI to Root via /proc/sched_debug
DockerLabs redirection Writeup: Open Redirect to Root
After the Legend: A Complete Map of Modern Pentest Lab Platforms Beyond VulnHub (2026)
Node: 1 Full Walkthrough — From AngularJS API Leak All the Way to PwnKit
Temple of Doom: 1 Full Walkthrough — From Environment Hell to PwnKit
GoldenEye: 1 — Full Walkthrough: Rooting a VulnHub Box from the Command Line When the Tools Won't Cooperate
Damn Vulnerable RESTaurant: The Full API Attack Chain from Anonymous Visitor to In-Container RCE
Beyond Juice Shop: Broken Crystals and the "Diamond Labs" I've Been Collecting
Hands-On with OAuth Labs (Part 1): Exploiting Unstable Claims in Lab 01
Broken Crystals Field Notes 4: MCP Attack — Full Kill Chain from Unauthenticated Guest to admin Privilege-Escalation RCE
Broken Crystals Field Notes 3: eval SSJI to root RCE, and an XXE That Reads Files but Can't Do SSRF
Broken Crystals Field Notes 2: From a Single Query Parameter to a Root Reverse Shell
Broken Crystals Field Notes 1: From Information Disclosure to Arbitrary File Read (LFI)
Chill Hack Walkthrough (TryHackMe): Command Injection to Root via Docker
TryHackMe Mr. Robot Writeup: WordPress RCE to Root
TryHackMe Network Services 2 (SMTP) Writeup
TryHackMe Network Services 2 (MySQL) Writeup
TryHackMe Network Services 1 (SMB) Writeup
TryHackMe Security Footage Writeup: Recovering MJPEG Camera Footage from a PCAP
TryHackMe - Intro to IoT Pentesting Writeup
TryHackMe Publisher Writeup: SPIP RCE & AppArmor Bypass
TryHackMe Lookup Writeup: Username Enumeration to Root
TryHackMe DNS Manipulation Walkthrough: DNS Data Exfiltration
VulnHub Investigator: 1 Writeup — ADB Root, SQLite SMS and Cracking the SSH Key
VulnHub The Planets: Earth Writeup