A walkthrough of Management Wants a Word, a TryHackMe Windows forensics room involving a KAPE dump, cracked local credentials, DPAPI master keys, Chrome secrets, and a VeraCrypt container hiding the flag.
A walkthrough of Infinity Pool, a TryHackMe Boot2Root room involving command injection, exposed internal configuration, FreePBX, and a root-owned automation API.
A beginner-friendly walkthrough of The Hollow Shell, a TryHackMe web challenge that combines a login leak, archive upload abuse, LFI, and server-side hook execution.
A beginner-friendly walkthrough of CryptoCabana, a TryHackMe Azure challenge involving a leaked SAS token, exposed service-principal credentials, and Key Vault secret versions.
A walkthrough of Do Not Disturb, a TryHackMe Boot2Root room involving NoSQL injection, EJS template injection, an exposed Node.js inspector, and disk-group privilege escalation.
A beginner-friendly walkthrough of Beach Bar, a TryHackMe Linux challenge involving exposed credentials, unsafe YAML deserialization, and a password leaked through a root process.