
500+ Hack The Box मशीन लेखों, 400+ चुनौती समाधानों और इंटरैक्टिव शिक्षण उपकरणों का संरचित संग्रह, जिसमें ज्ञान ग्राफ, आक्रमण पथ आरेख और पेनिट्रेशन परीक्षण एवं प्रमाणन तैयारी के लिए कौशल वृक्ष शामिल हैं।
Hack The Box writeups, walkthroughs, और cheatsheets का GitHub पर सबसे व्यापक संग्रह। 500+ मशीनें, 400+ चुनौतियाँ, ProLabs, Sherlocks (DFIR), CTF इवेंट, पेनिट्रेशन टेस्टिंग पद्धति, और OSCP/CPTS प्रमाणन तैयारी - सब एक ही स्थान पर।``` ___ ___ ___________ __ __ .__ __
/ | \ __ / / \ / ___||/ | ____ __ ________ ______
/ ~ \ | | \ // /_ __ | \ / __ | | _ / /
\ Y / | | \ / | | /| || | \ /| | / |> > \
_|_ / || _/\ / || |||| ___ >_/| / >
/ / / |__| /
[](https://awesome.re)
[](https://github.com/momenbasel/htb-writeups/stargazers)
[](https://github.com/momenbasel/htb-writeups/network/members)
[](https://github.com/momenbasel/htb-writeups/graphs/contributors)
[](LICENSE)
[](https://github.com/momenbasel/htb-writeups/commits/main)
**यह रिपॉजिटरी क्यों?** बिखरे हुए ब्लॉग पोस्ट और एकल-लेखक संग्रहों के विपरीत, यह संपूर्ण HTB पारिस्थितिकी तंत्र का एक **संरचित, खोजने योग्य सूचकांक** है - 2017 से 2026 तक की मशीनें, प्रत्येक CTF इवेंट, प्रत्येक चैलेंज श्रेणी, प्रत्येक ProLab - तकनीक, कठिनाई, OS और प्रमाणन प्रासंगिकता द्वारा क्रॉस-रेफ़रेंस किया गया है। चाहे आप **OSCP**, **CPTS**, **CRTO** की तैयारी कर रहे हों, या बस अपने कौशल को निखार रहे हों, यहीं से शुरू करें।
> **[साइट ब्राउज़ करें](https://momenbasel.github.io/htb-writeups/)** - इंटरैक्टिव टूल, खोज और डार्क थीम के साथ सबसे अच्छे अनुभव के लिए।
---
## इंटरैक्टिव टूल
| | टूल | विवरण |
|--|------|-------------|
| **[Machine Finder](https://momenbasel.github.io/htb-writeups/finder/)** | खोज और फ़िल्टर | कठिनाई, OS, तकनीक, CVE या प्रमाणन के अनुसार मशीनें खोजें। वास्तविक समय फ़िल्टरिंग के साथ तालिका और कार्ड दृश्य। |
| **[Knowledge Graph](https://momenbasel.github.io/htb-writeups/graph/)** | विज़ुअल एक्सप्लोरर | इंटरैक्टिव D3.js फोर्स-डायरेक्टेड ग्राफ जो 70+ मशीनों को 40+ तकनीकों और 5 प्रमाणपत्रों से मैप करता है। |
| **[Attack Paths](https://momenbasel.github.io/htb-writeups/attack-paths/)** | फ़्लोचार्ट | मर्मेड आरेख जो 25+ मशीनों के लिए पूर्ण हमले की श्रृंखला दिखाते हैं - recon से root तक। |
| **[Skill Trees](https://momenbasel.github.io/htb-writeups/skill-trees/)** | प्रगति मानचित्र | AD हमलों, वेब शोषण, Linux/Windows privesc और प्रमाणन तैयारी के लिए दृश्य सीखने के पथ। |
---
## अंदर क्या है
| अनुभाग | विवरण | गिनती |
|---------|-------------|-------|
| [Machines](#machines) | Boot2root वॉकथ्रू (Easy से Insane) | 300+ |
| [Challenges](#challenges) | 12 श्रेणियों में CTF-शैली के चैलेंज | 400+ |
| [ProLabs](#prolabs) | नेटवर्क टोपोलॉजी आरेखों के साथ एंटरप्राइज़-ग्रेड लैब वॉकथ्रू | 6 |
| [Sherlocks](#sherlocks) | DFIR और ब्लू टीम जाँच | 70+ |
| [CTF Events](#ctf-events) | आधिकारिक HTB CTF प्रतियोगिता राइटअप | 14 इवेंट |
| [Endgames](#endgames) | बहु-मशीन परिदृश्य वॉकथ्रू | 5 |
| [Fortresses](#fortresses) | बहु-फ़्लैग एकल-होस्ट चैलेंज | 6 |
| [Resources](#resources) | टूल, चीटशीट, प्रमाणन तैयारी, पद्धति | 10 गाइड |
---
## Machines
HTB के सेवानिवृत्त मशीनों के राइटअप, कठिनाई के अनुसार व्यवस्थित। प्रत्येक राइटअप में पूर्ण कमांड आउटपुट के साथ एन्युमरेशन, एक्सप्लॉइटेशन और प्रिविलेज एस्केलेशन चरण शामिल हैं।
### कठिनाई के अनुसार
| कठिनाई | पथ | मशीनें |
|------------|------|----------|
| Easy | [`machines/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/) | 132+ |
| Medium | [`machines/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/) | 136+ |
| Hard | [`machines/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | 70+ |
| Insane | [`machines/insane/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | 50+ |
### हाल ही में सेवानिवृत्त (2025-2026)
| मशीन | OS | कठिनाई | प्रमुख तकनीकें | तारीख |
|---------|----|------------|----------------|------|
| [MonitorsFour](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/MonitorsFour/) | Windows | Insane | PHP Type Juggling, Cacti CVE, Docker API Escape | May 2026 |
| [Pterodactyl](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Pterodactyl/) | openSUSE | Insane | Pterodactyl Panel CVE-2025-49132, PEAR pearcmd LFI, Polkit | May 2026 |
| [Helix](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Helix/) | Linux | Medium | Apache NiFi ExecuteSQL + H2 Java Alias RCE | May 2026 |
| [Overwatch](https://0xdf.gitlab.io/2026/05/09/htb-overwatch.html) | Windows | Insane | .NET Reversing, WCF Service Injection, DNS | May 2026 |
| [Sorcery](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Sorcery/) | Linux | Insane | Cypher Injection, WebAuthn XSS, Kafka, FreeIPA | Apr 2026 |
| [PingPong](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/PingPong/) | Windows | Hard | Multi-Forest AD, MSSQL Delegation, ADCS | Apr 2026 |
| [AirTouch](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/AirTouch/) | Linux | Hard | 802.11 WPA2 Crack, Evil Twin, PEAP-MSCHAPv2 | Apr 2026 |
| [Eighteen](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Eighteen/) | Windows | Hard | Win Server 2025, MSSQL Impersonation, Bad Successor dMSA | Apr 2026 |
| [DarkZero](https://0xdf.gitlab.io/2026/04/04/htb-darkzero.html) | Windows | Hard | Cross-Forest Trust, AD Abuse | Apr 2026 |
| [Pirate](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Pirate/) | Windows | Hard | Pre2k, gMSA, PetitPotam, RBCD, S4U SPN Jack | Feb 2026 |
| [VariaType](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/VariaType/) | Linux | Medium | fontTools CVE-2025-66034, FontForge CVE-2024-25082 | Mar 2026 |
| [Interpreter](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Interpreter/) | Linux | Medium | Mirth Connect CVE-2023-43208, Python eval() | Feb 2026 |
| [Kobold](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Kobold/) | Linux | Easy | MCPJam CVE-2026-23744, Docker Group | Mar 2026 |
| [Facts](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Facts/) | Linux | Easy | Camaleon CMS IDOR + Path Traversal + Facter Sudo | Jan 2026 |
| [Code](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Code/) | Linux | Easy | Python Sandbox Bypass, Backy Sudo | Aug 2025 |
| [Cobblestone](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Cobblestone/) | Linux | Insane | Second-Order SQLi, Twig SSTI, Cobbler XMLRPC | 2025 |
| [Snapped](https://0xdf.gitlab.io/2026/04/01/htb-snapped.html) | Linux | Hard | Nginx UI RCE, Static Site Exploitation | Mar 2026 |
| [Browsed](https://0xdf.gitlab.io/2026/03/28/htb-browsed.html) | Linux | Medium | Browser Extension Exploitation, Headless Chrome | Mar 2026 |
| [Previous](https://0xdf.gitlab.io/2026/01/10/htb-previous.html) | Linux | Medium | NextJS Exploitation, Framework Abuse | Jan 2026 |
| [Retire](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Windows | Hard | Active Directory, Kerberos Abuse | Jan 2026 |
| [Fries](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | Hard | Web Exploitation, Custom Exploitation | Nov 2025 |
| [NanoCorp](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | Hard | Custom Protocol, Binary Analysis | Nov 2025 |
| [Hercules](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | Linux | Insane | Multi-Stage Exploitation | Oct 2025 |
| [Signed](https://0xdf.gitlab.io/2026/02/07/htb-signed.html) | Windows | Medium | Code Signing Bypass, Certificate Abuse | Oct 2025 |
| [University](https://0xdf.gitlab.io/2025/08/09/htb-university.html) | Windows | Insane | Multi-Vector Attack, Complex Chain | Aug 2025 |
| [Dog](https://0xdf.gitlab.io/2025/07/12/htb-dog.html) | Linux | Easy | Backdrop CMS, Web Exploitation | Jul 2025 |
| [Mirage](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) | Windows | Hard | Active Directory, ADCS | Jul 2025 |
| [Voleur](https://0xdf.gitlab.io/2025/11/01/htb-voleur.html) | Windows | Medium | Data Exfiltration, Custom Exploitation | Jul 2025 |
| [RustyKey](https://0xdf.gitlab.io/2025/11/08/htb-rustykey.html) | Windows | Hard | Rust Binary Exploitation | Jun 2025 |
| [TombWatcher](https://0xdf.gitlab.io/2025/10/11/htb-tombwatcher.html) | Windows | Medium | Custom Service Exploitation | Jun 2025 |
| [Haze](https://0xdf.gitlab.io/2025/06/28/htb-haze.html) | Windows | Hard | Splunk Enterprise Exploitation | Jun 2025 |
| [Certificate](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html) | Windows | Hard | ADCS, Certificate Template Abuse | May 2025 |
| [Vintage](https://0xdf.gitlab.io/2025/04/26/htb-vintage.html) | Windows | Hard | Pure Active Directory, Kerberoasting | Apr 2025 |
### ऑपरेटिंग सिस्टम के अनुसार
- **Linux** - [`machines/` by OS फ़िल्टर किया गया](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Ubuntu, Debian, CentOS, कस्टम डिस्ट्रोस
- **Windows** - [`machines/` by OS फ़िल्टर किया गया](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Windows Server, Active Directory वातावरण
- **FreeBSD/OpenBSD** - दुर्लभ लेकिन कठिन स्तरों में मौजूद हैं
### तकनीक के अनुसार
<details>
<summary><b>Active Directory</b> - Kerberoasting, AS-REP Roasting, ADCS, DCSync, Pass-the-Hash, BloodHound</summary>
| मशीन | कठिनाई | विशिष्ट AD तकनीक |
|---------|------------|-----------------------|
| DarkZero | Hard | Cross-Forest Trust Abuse |
| Vintage | Hard | Kerberoasting, Pure AD |
| Certificate | Hard | ADCS Certificate Template Abuse |
| Mirage | Hard | ADCS, Shadow Credentials |
| Haze | Hard | Splunk + AD Integration |
| Retire | Hard | Kerberos Delegation Abuse |
</details>
<details>
<summary><b>Web Exploitation</b> - SQLi, XSS, SSRF, SSTI, LFI/RFI, Deserialization</summary>
| मशीन | कठिनाई | विशिष्ट वेब तकनीक |
|---------|------------|-----------------------|
| Dog | Easy | Backdrop CMS RCE |
| Browsed | Medium | Browser Extension RCE |
| Previous | Medium | NextJS Framework Exploitation |
| Snapped | Hard | Nginx UI Admin Panel RCE |
| Fries | Hard | Custom Web App Exploitation |
</details>
<details>
<summary><b>Binary Exploitation</b> - Buffer Overflow, ROP, Heap Exploitation, Format Strings</summary>
| मशीन | कठिनाई | विशिष्ट तकनीक |
|---------|------------|-----------------------|
| RustyKey | Hard | Rust Binary Exploitation |
| NanoCorp | Hard | Custom Protocol Exploitation |
</details>
<details>
<summary><b>Cloud & Infrastructure</b> - AWS, Azure, GCP, Docker, Kubernetes</summary>
| मशीन | कठिनाई | विशिष्ट तकनीक |
|---------|------------|-----------------------|
| Hercules | Insane | Container Escape, Cloud Metadata |
</details>
---
## Challenges
श्रेणी के अनुसार आयोजित CTF-शैली के चैलेंज। प्रत्येक राइटअप में चैलेंज विवरण, दृष्टिकोण, समाधान और सीखे गए सबक शामिल हैं।
| श्रेणी | पथ | गिनती | मुख्य कौशल |
|----------|------|-------|------------|
| Web | [`challenges/web/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/web/) | 75+ | XSS, SQLi, SSTI, SSRF, Deserialization, JWT, GraphQL |
| Crypto | [`challenges/crypto/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/crypto/) | 93+ | RSA, AES, ECC, Padding Oracle, PRNG, Lattice Attacks |
| Forensics | [`challenges/forensics/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/forensics/) | 33+ | Memory Analysis, Disk Forensics, Network PCAP, Malware |
| Reversing | [`challenges/reversing/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/reversing/) | 44+ | x86/x64, .NET, Python, Angr, Anti-Debug, VM |
| Pwn | [`challenges/pwn/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/pwn/) | 61+ | Stack/Heap Overflow, ROP, SROP, Kernel, tcache |
| Mobile | [`challenges/mobile/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/mobile/) | 10+ | Android APK, Frida, Smali, Certificate Pinning |
| Hardware | [`challenges/hardware/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/hardware/) | 11+ | UART, SPI, Firmware, VHDL, RF Analysis |
| OSINT | [`challenges/osint/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/osint/) | 12+ | Geolocation, Social Media, DNS, Metadata |
| Misc | [`challenges/misc/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/misc/) | 35+ | Scripting, Logic, Encoding, Pickle, Pyjail |
| Stego | [`challenges/stego/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/stego/) | 12+ | Image, Audio, LSB, Steghide, ImageMagick |
| Blockchain | [`challenges/blockchain/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/blockchain/) | 10+ | Solidity, Smart Contracts, ERC-721, ECDSA |
| AI/ML | [`challenges/ai-ml/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/ai-ml/) | 5+ | Adversarial ML, Prompt Injection, LLM Bypass |
---
## ProLabs
वास्तविक कॉर्पोरेट नेटवर्क का अनुकरण करने वाले एंटरप्राइज़-ग्रेड लैब वातावरण। ये राइटअप बहु-मशीन हमले के पथ, पार्श्व गति और डोमेन प्रभुत्व को कवर करते हैं।
| लैब | कठिनाई | मशीनें | फोकस |
|-----|-----------|----------|-------|
| [Dante](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Beginner | 14 | Network Pentesting Fundamentals |
| [Offshore](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Intermediate | 21 | Active Directory, Multi-Domain |
| [RastaLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Intermediate | 15 | Red Team Simulation, Phishing |
| [Zephyr](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Intermediate | 17 | ADCS, DPAPI, Constrained Delegation |
| [Cybernetics](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Advanced | 20+ | Advanced AD, Cross-Forest Attacks |
| [APTLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Advanced | 20+ | APT Simulation, Multi-Vector |
---
## Sherlocks
DFIR (Digital Forensics & Incident Response) जाँच लैब। ब्लू टीम परिदृश्य जहाँ आप सुरक्षा घटनाओं की जाँच करते हैं और फोरेंसिक प्रश्नों के उत्तर देते हैं।
| श्रेणी | पथ | फोकस |
|----------|------|-------|
| Easy | [`sherlocks/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | Log Analysis, Basic DFIR |
| Medium | [`sherlocks/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | Memory Forensics, Malware Triage |
| Hard | [`sherlocks/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | APT Investigation, Complex IR |
### विशेष शेरलॉक
| नाम | कठिनाई | फोकस क्षेत्र | राइटअप |
|------|-----------|------------|---------|
| Meerkat | Easy | Suricata IDS, Credential Stuffing, CVE-2022-25237 | [0xdf](https://0xdf.gitlab.io/2024/04/23/htb-sherlock-meerkat.html) |
| Brutus | Easy | SSH Brute Force, auth.log Analysis | [0xdf](https://0xdf.gitlab.io/2024/04/09/htb-sherlock-brutus.html) |
| Noted | Easy | Notepad++ Artifacts, Data Extortion | [0xdf](https://0xdf.gitlab.io/2024/06/13/htb-sherlock-noted.html) |
| Knock Knock | Easy | PCAP, FTP, Port Knocking, GonnaCry Ransomware | [0xdf](https://0xdf.gitlab.io/2023/12/04/htb-sherlock-knock-knock.html) |
| Bumblebee | Easy | phpBB SQLite, Access Log Analysis | [0xdf](https://0xdf.gitlab.io/2024/05/22/htb-sherlock-bumblebee.html) |
| Crown Jewel-1 | Medium | NTDS.dit Dump, Volume Shadow Copy Service | [CyberWired](https://www.cyberwiredtraining.net/writeups/htb-sherlock-crownjewel-1-jezdr) |
| Noxious | Medium | LLMNR Poisoning, Rogue Device Detection | [0xdf](https://0xdf.gitlab.io/2024/09/04/htb-sherlock-noxious.html) |
| Subatomic | Medium | Electron Malware, Discord Hijacking | [0xdf](https://0xdf.gitlab.io/2024/04/18/htb-sherlock-subatomic.html) |
| Nubilum-1 | Medium | AWS CloudTrail, PoshC2, Cloud Forensics | [0xdf](https://0xdf.gitlab.io/2024/05/30/htb-sherlock-nubilum-1.html) |
| MisCloud | Medium | GCP Breach, Gitea Vulnerability | [CyberEthical](https://blog.cyberethical.me/htb-sherlock-miscloud) |
| OpTinselTrace (1-5) | Hard | Full APT Campaign Investigation (Christmas 2023) | [GitHub](https://github.com/dbissell6/DFIR/blob/main/WalkThroughs/OpTinselTrace-1-5.md) |
| APTNightmare | Hard | Advanced Persistent Threat Investigation | [GitHub](https://github.com/jon-brandy/hackthebox/blob/main/Categories/Sherlocks/APTNightmare/README.md) |
पूर्ण [शेरलॉक इंडेक्स](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/README.md) देखें 70+ शेरलॉक के साथ राइटअप लिंक।
---
## CTF Events
आधिकारिक Hack The Box प्रतिस्पर्धी CTF इवेंट्स के राइटअप।
| इवेंट | वर्ष | पथ | हाइलाइट्स |
|-------|------|------|------------|
| Cyber Apocalypse | 2025 | [`ctf-events/cyber-apocalypse-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Web, Crypto, Pwn, Forensics |
| Business CTF | 2025 | [`ctf-events/business-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Enterprise Security Focus |
| University CTF | 2025 | [`ctf-events/university-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Academic Team Competition |
| Cyber Apocalypse | 2024 | [`ctf-events/cyber-apocalypse-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Hacker Royale Theme |
| Business CTF | 2024 | [`ctf-events/business-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Corporate Scenario |
| University CTF | 2024 | [`ctf-events/university-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Binary Badlands Theme |
---
## Endgames
बहु-मशीन, बहु-चरणीय परिदृश्य जो वास्तविक पेनिट्रेशन टेस्टिंग एंगेजमेंट का अनुकरण करते हैं। विस्तृत वॉकथ्रू के लिए [`endgames/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/README.md) देखें।
| एंडगेम | पथ | फ़्लैग | फोकस |
|---------|------|-------|-------|
| P.O.O. | [`endgames/poo/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5 | MSSQL Linked Servers, IIS Enumeration |
| Xen | [`endgames/xen/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | Citrix Breakout, AD, Phishing |
| Hades | [`endgames/hades/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | AS-REP Roast, DPAPI, RBCD, DNS Spoofing |
| RPG | [`endgames/rpg/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 6 | Linux Exploitation, Multi-Host Pivoting |
| Ascension | [`endgames/ascension/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 7 | Blind SQLi, MSSQL Proxy, RBCD |
---
## Fortresses
साझेदार कंपनियों द्वारा बनाए गए बहु-फ़्लैग एकल-होस्ट चैलेंज। स्टेरॉयड पर मशीनों की तरह। विस्तृत वॉकथ्रू के लिए [`fortresses/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/README.md) देखें।
| फोर्ट्रेस | निर्माता | फ़्लैग | फोकस |
|----------|---------|-------|-------|
| [Jet](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Jet | 11 | Multi-service exploitation |
| [Akerva](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Akerva | 8 | WordPress, SNMP, web chains |
| [Context](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Context/Accenture | 7 | Web + infrastructure |
| [Synacktiv](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Synacktiv | Multiple | Symfony, AppSec, infrastructure |
| [AWS](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Amazon Web Services | Multiple | Cloud security, IAM, Lambda, S3 |
| [Faraday](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Faraday | 7 | General offensive security |
---
## Resources
### श्रेणी के अनुसार टूल
<details>
<summary><b>Enumeration & Reconnaissance</b></summary>
| टूल | उद्देश्य | लिंक |
|------|---------|------|
| Nmap | पोर्ट स्कैनिंग और सेवा पहचान | [nmap.org](https://nmap.org) |
| RustScan | तेज़ पोर्ट स्कैनर | [GitHub](https://github.com/RustScan/RustScan) |
| Gobuster | Directory/DNS/vhost ब्रूट-फोर्सिंग | [GitHub](https://github.com/OJ/gobuster) |
| Feroxbuster | पुनरावर्ती कंटेंट डिस्कवरी | [GitHub](https://github.com/epi052/feroxbuster) |
| ffuf | तेज़ वेब फ़ज़र | [GitHub](https://github.com/ffuf/ffuf) |
| enum4linux-ng | SMB/Samba एन्युमरेशन | [GitHub](https://github.com/cddmp/enum4linux-ng) |
</details>
<details>
<summary><b>Web Exploitation</b></summary>
| टूल | उद्देश्य | लिंक |
|------|---------|------|
| Burp Suite | वेब प्रॉक्सी और स्कैनर | [portswigger.net](https://portswigger.net/burp) |
| SQLMap | SQL इंजेक्शन ऑटोमेशन | [GitHub](https://github.com/sqlmapproject/sqlmap) |
| Nuclei | टेम्पलेट-आधारित वल्न स्कैनर | [GitHub](https://github.com/projectdiscovery/nuclei) |
| Caido | आधुनिक वेब प्रॉक्सी | [caido.io](https://caido.io) |
| PayloadsAllTheThings | पेलोड रिपॉजिटरी | [GitHub](https://github.com/swisskyrepo/PayloadsAllTheThings) |
</details>
<details>
<summary><b>Active Directory</b></summary>
| टूल | उद्देश्य | लिंक |
|------|---------|------|
| BloodHound | AD संबंध मैपिंग | [GitHub](https://github.com/SpecterOps/BloodHound) |
| Impacket | नेटवर्क प्रोटोकॉल टूलकिट | [GitHub](https://github.com/fortra/impacket) |
| Rubeus | Kerberos शोषण | [GitHub](https://github.com/GhostPack/Rubeus) |
| Certipy | ADCS शोषण | [GitHub](https://github.com/ly4k/Certipy) |
| NetExec (nxc) | नेटवर्क एक्ज़ीक्यूशन टूलकिट | [GitHub](https://github.com/Pennyw0rth/NetExec) |
| Ligolo-ng | टनलिंग/पिवोटिंग | [GitHub](https://github.com/nicocha30/ligolo-ng) |
</details>
<details>
<summary><b>Privilege Escalation</b></summary>
| टूल | उद्देश्य | लिंक |
|------|---------|------|
| LinPEAS | Linux privesc एन्युमरेशन | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| WinPEAS | Windows privesc एन्युमरेशन | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| pspy | प्रक्रिया मॉनिटरिंग (रूट के बिना) | [GitHub](https://github.com/DominicBreuker/pspy) |
| PowerUp | Windows privesc PowerShell | [GitHub](https://github.com/PowerShellMafia/PowerSploit) |
| GTFOBins | Unix बाइनरी शोषण | [gtfobins.github.io](https://gtfobins.github.io) |
| LOLBAS | Windows living-off-the-land | [lolbas-project.github.io](https://lolbas-project.github.io) |
</details>
<details>
<summary><b>Forensics & DFIR</b></summary>
| टूल | उद्देश्य | लिंक |
|------|---------|------|
| Volatility 3 | मेमोरी फोरेंसिक्स | [GitHub](https://github.com/volatilityfoundation/volatility3) |
| Autopsy | डिस्क फोरेंसिक्स | [autopsy.com](https://www.autopsy.com) |
| Wireshark | नेटवर्क कैप्चर विश्लेषण | [wireshark.org](https://www.wireshark.org) |
| CyberChef | डेटा रूपांतरण | [GitHub](https://github.com/gchq/CyberChef) |
| Chainsaw | Windows इवेंट लॉग विश्लेषण | [GitHub](https://github.com/WithSecureLabs/chainsaw) |
</details>
<details>
<summary><b>Reverse Engineering</b></summary>
| टूल | उद्देश्य | लिंक |
|------|---------|------|
| Ghidra | बाइनरी विश्लेषण | [ghidra-sre.org](https://ghidra-sre.org) |
| IDA Free | डिसेम्बलर | [hex-rays.com](https://hex-rays.com/ida-free) |
| radare2 | CLI रिवर्स इंजीनियरिंग | [GitHub](https://github.com/radareorg/radare2) |
| Binary Ninja | बाइनरी विश्लेषण प्लेटफ़ॉर्म | [binary.ninja](https://binary.ninja) |
| dnSpy | .NET डीकंपाइलर | [GitHub](https://github.com/dnSpy/dnSpy) |
</details>
<details>
<summary><b>Binary Exploitation</b></summary>| उपकरण | उद्देश्य | लिंक |
|------|---------|------|
| pwntools | CTF शोषण ढांचा | [GitHub](https://github.com/Gallopsled/pwntools) |
| ROPgadget | ROP श्रृंखला निर्माता | [GitHub](https://github.com/JonathanSalwan/ROPgadget) |
| GEF | GDB उन्नत सुविधाएँ | [GitHub](https://github.com/hugsy/gef) |
| one_gadget | libc वन-शॉट गैजेट | [GitHub](https://github.com/david942j/one_gadget) |
| checksec | बाइनरी सुरक्षा जांच | [GitHub](https://github.com/slimm609/checksec.sh) |
</details>
### प्रमाणन तैयारी
अपनी HTB यात्रा को पेशेवर प्रमाणपत्रों से मैप करें।
<details>
<summary><b>OSCP (Offensive Security Certified Professional)</b></summary>
**OSCP तैयारी के लिए अनुशंसित HTB मशीनें:**
| मशीन | कठिनाई | मुख्य कौशल |
|---------|-----------|------------|
| Lame | आसान | Samba RCE, बुनियादी शोषण |
| Legacy | आसान | MS08-067, Windows शोषण |
| Blue | आसान | EternalBlue (MS17-010) |
| Optimum | आसान | HFS RCE, Windows विशेषाधिकार वृद्धि |
| Shocker | आसान | Shellshock, Linux मूल बातें |
| Nibbles | आसान | CMS शोषण, फ़ाइल अपलोड |
| Bashed | आसान | PHP वेबशेल, Cron दुरुपयोग |
| Arctic | आसान | ColdFusion, Windows शोषण |
| Grandpa | आसान | IIS WebDAV, टोकन प्रतिरूपण |
| Bastard | मध्यम | Drupal RCE, Windows विशेषाधिकार वृद्धि |
| Cronos | मध्यम | DNS ज़ोन ट्रांसफर, SQL इंजेक्शन |
| SolidState | मध्यम | Apache James RCE, Cron विशेषाधिकार वृद्धि |
| Node | मध्यम | API शोषण, कर्नेल शोषण |
| Valentine | आसान | Heartbleed, tmux अपहरण |
| Poison | मध्यम | LFI, VNC टनलिंग |
| Sunday | आसान | Finger गणना, Shadow फ़ाइल |
| DevOops | मध्यम | XXE, Git रहस्य |
| Jeeves | मध्यम | Jenkins RCE, KeePass क्रैकिंग |
| Conceal | कठिन | IPSec VPN, SNMP, JuicyPotato |
</details>
<details>
<summary><b>CPTS (Certified Penetration Testing Specialist)</b></summary>
**CPTS तैयारी के लिए अनुशंसित HTB मशीनें:**
| मशीन | कठिनाई | मुख्य कौशल |
|---------|-----------|------------|
| Active | आसान | AD मूल बातें, GPP दुरुपयोग, Kerberoasting |
| Forest | आसान | AS-REP Roasting, DCSync |
| Sauna | आसान | AS-REP Roasting, WinRM |
| Monteverde | मध्यम | Azure AD, पासवर्ड स्प्रेइंग |
| Resolute | मध्यम | DNS Admin DLL इंजेक्शन |
| Cascade | मध्यम | LDAP गणना, .NET रिवर्सिंग |
| Blackfield | कठिन | AS-REP, Backup Operators विशेषाधिकार वृद्धि |
| Vintage | कठिन | शुद्ध AD शोषण |
| Certificate | कठिन | ADCS शोषण |
| Support | आसान | LDAP, .NET बाइनरी विश्लेषण |
</details>
<details>
<summary><b>CRTO (Certified Red Team Operator)</b></summary>
ProLabs पर ध्यान केंद्रित करें: **RastaLabs** और **Zephyr** सीधे CRTO सामग्री से संरेखित हैं।
| मशीन/लैब | प्रकार | मुख्य कौशल |
|-------------|------|------------|
| RastaLabs | ProLab | फिशिंग, C2, पार्श्व गति |
| Zephyr | ProLab | ADCS, DPAPI, प्रतिबंधित प्रतिनिधिमंडल |
| Offshore | ProLab | मल्टी-डोमेन AD |
| Reel | कठिन | फिशिंग, AppLocker बाईपास |
| Mantis | कठिन | AD, Kerberos, MS14-068 |
</details>
### चीटशीट्स
| चीटशीट | विवरण |
|------------|-------------|
| [Linux गणना](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/linux-enumeration.md) | पोस्ट-एक्सप्लॉइटेशन Linux गणना कमांड |
| [Windows गणना](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/windows-enumeration.md) | पोस्ट-एक्सप्लॉइटेशन Windows गणना कमांड |
| [सक्रिय निर्देशिका](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/active-directory.md) | AD हमला पद्धति और कमांड |
| [वेब अनुप्रयोग](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/web-application.md) | वेब शोषण तकनीक और पेलोड |
| [विशेषाधिकार वृद्धि - Linux](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-linux.md) | Linux विशेषाधिकार वृद्धि वेक्टर्स |
| [विशेषाधिकार वृद्धि - Windows](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-windows.md) | Windows विशेषाधिकार वृद्धि वेक्टर्स |
| [फ़ाइल स्थानांतरण](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/file-transfers.md) | मशीनों के बीच फ़ाइलें स्थानांतरित करने के तरीके |
| [रिवर्स शेल](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/reverse-shells.md) | सभी भाषाओं के लिए रिवर्स शेल वन-लाइनर्स |
| [पिवटिंग और टनलिंग](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/pivoting.md) | SSH टनलिंग, Chisel, Ligolo, SOCKS |
| [पासवर्ड हमले](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/password-attacks.md) | क्रैकिंग, स्प्रेइंग, ब्रूट-फोर्सिंग |
### पद्धति
| गाइड | विवरण |
|-------|-------------|
| [HTB मशीन दृष्टिकोण](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/machine-approach.md) | किसी भी HTB मशीन को व्यवस्थित रूप से कैसे अपनाएं |
| [नोट-टेकिंग टेम्पलेट](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/note-taking.md) | राइटअप के लिए संरचित नोट-टेकिंग |
| [रिपोर्ट लेखन](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/report-writing.md) | पेशेवर पेंटेस्ट रिपोर्ट टेम्पलेट |
---
## रिपॉजिटरी संरचना```
htb-writeups/
|-- machines/
| |-- easy/ # Easy difficulty machines
| |-- medium/ # Medium difficulty machines
| |-- hard/ # Hard difficulty machines
| |-- insane/ # Insane difficulty machines
|-- challenges/
| |-- web/ # Web exploitation challenges
| |-- crypto/ # Cryptography challenges
| |-- forensics/ # Digital forensics challenges
| |-- reversing/ # Reverse engineering challenges
| |-- pwn/ # Binary exploitation challenges
| |-- mobile/ # Mobile security challenges
| |-- hardware/ # Hardware hacking challenges
| |-- osint/ # OSINT challenges
| |-- misc/ # Miscellaneous challenges
| |-- stego/ # Steganography challenges
| |-- blockchain/ # Blockchain/smart contract challenges
| |-- ai-ml/ # AI/ML security challenges
|-- prolabs/
| |-- dante/ # Dante ProLab walkthrough
| |-- offshore/ # Offshore ProLab walkthrough
| |-- rastalabs/ # RastaLabs ProLab walkthrough
| |-- zephyr/ # Zephyr ProLab walkthrough
| |-- cybernetics/ # Cybernetics ProLab walkthrough
| |-- aptlabs/ # APTLabs ProLab walkthrough
|-- sherlocks/
| |-- easy/ # Easy DFIR investigations
| |-- medium/ # Medium DFIR investigations
| |-- hard/ # Hard DFIR investigations
|-- ctf-events/ # Official HTB CTF writeups
|-- endgames/ # Multi-machine scenarios
|-- fortresses/ # Fortress challenges
|-- resources/
| |-- cheatsheets/ # Quick reference guides
| |-- tools/ # Tool guides and configs
| |-- methodology/ # Approach guides and templates
| |-- cert-prep/ # Certification preparation guides
|-- templates/ # Writeup templates
हम योगदान का स्वागत करते हैं! विस्तृत दिशानिर्देशों के लिए CONTRIBUTING.md देखें।
त्वरित शुरुआत:
राइटअप आवश्यकताएं:
ये राइटअप केवल शैक्षिक उद्देश्यों के लिए हैं। सभी सामग्री उन मशीनों और चुनौतियों को कवर करती है जो Hack The Box प्लेटफॉर्म पर अब सक्रिय नहीं हैं (सेवानिवृत्त)। सक्रिय मशीनों के समाधान साझा करना HTB की सेवा की शर्तों का उल्लंघन करता है।
हमेशा एथिकल हैकिंग का अभ्यास करें। केवल उन प्रणालियों का परीक्षण करें जिनके परीक्षण के लिए आपके पास स्पष्ट प्राधिकरण है।
इस रिपॉजिटरी में मशीन राइटअप विविध दृष्टिकोणों के लिए कई स्वतंत्र लेखकों से लिंक हैं। यहां प्राथमिक स्रोत हैं:
यह संग्रह GreyCore Labs द्वारा निर्मित और रखरखाव किया गया है, जो एक अमेरिका में निगमित आक्रामक सुरक्षा फर्म है। क्या आप अपने उत्पाद पर भी वही नजर चाहते हैं?
This project is licensed under the MIT License - see LICENSE for details.
यदि इससे आपको कोई बॉक्स पॉप करने या प्रमाणपत्र पास करने में मदद मिली, तो एक स्टार दें - इससे दूसरों को भी इसे खोजने में मदद मिलती है।
कीवर्ड्स: hack the box writeups, HTB walkthrough, hackthebox machines, HTB challenges, OSCP prep machines, CPTS certification, penetration testing writeups, CTF writeups, active directory hacking, privilege escalation, web exploitation, binary exploitation, digital forensics, incident response, red team, blue team, cybersecurity training, ethical hacking, infosec resources, security cheatsheets
| लेखक / स्रोत | URL | कवरेज |
|---|
| 0xdf | 0xdf.gitlab.io | 500+ मशीनें - स्वर्ण मानक, विस्तृत विवरण |
| IppSec | youtube.com/ippsec | 430+ वीडियो वॉकथ्रू लाइव डिबगिंग के साथ |
| HackingArticles | hackingarticles.in | 40+ मशीनें - राज चंदेल, क्लासिक युग (2017-2022) |
| Rana Khalil | rana-khalil.gitbook.io | 26+ मशीनें - OSCP-केंद्रित, कोई Metasploit नहीं |
| snowscan | snowscan.io | 20+ मशीनें - विस्तृत, सुसंगत गुणवत्ता |
| 0xRick | 0xrick.github.io | 10+ मशीनें - साफ-सुथरे ब्लॉग राइटअप |
| Medium / InfosecWriteups | medium.com | 45+ मशीनें - विविध समुदाय लेखक |
| संसाधन | विवरण |
|---|
| HackTricks | व्यापक पेंटेस्टिंग संदर्भ |
| PayloadsAllTheThings | पेलोड और बायपास संग्रह |
| The Hacker Recipes | संरचित हमले की विधियाँ |
| GTFOBins | यूनिक्स बाइनरी शोषण संदर्भ |
| LOLBAS | विंडोज लिविंग-ऑफ-द-लैंड बाइनरीज |
| WADComs | विंडोज/एडी कमांड संदर्भ |
| RevShells | रिवर्स शेल जनरेटर |
| CyberChef | डेटा रूपांतरण टूलकिट |
| SecLists | सुरक्षा परीक्षण के लिए शब्द सूचियां |
| IppSec.rocks | IppSec के HTB वीडियो का खोज योग्य सूचकांक |