
Raccolta strutturata di oltre 500 writeup di macchine Hack The Box, oltre 400 soluzioni di sfide, e strumenti di apprendimento interattivi inclusi grafi di conoscenza, diagrammi dei percorsi di attacco e alberi delle competenze per test di penetrazione e preparazione alle certificazioni.
La più completa raccolta di writeup di Hack The Box, walkthrough e cheatsheets su GitHub. Oltre 500 macchine, 400+ sfide, ProLabs, Sherlocks (DFIR), eventi CTF, metodologia di penetration testing e preparazione alle certificazioni OSCP/CPTS - tutto in un unico posto.``` ___ ___ ___________ __ __ .__ __
/ | \ __ / / \ / ___||/ | ____ __ ________ ______
/ ~ \ | | \ // /_ __ | \ / __ | | _ / /
\ Y / | | \ / | | /| || | \ /| | / |> > \
_|_ / || _/\ / || |||| ___ >_/| / >
/ / / |__| /
[](https://awesome.re)
[](https://github.com/momenbasel/htb-writeups/stargazers)
[](https://github.com/momenbasel/htb-writeups/network/members)
[](https://github.com/momenbasel/htb-writeups/graphs/contributors)
[](LICENSE)
[](https://github.com/momenbasel/htb-writeups/commits/main)
**Perché questa repository?** A differenza di post di blog sparsi e raccolte di singoli autori, questa è una **strutturata** e **ricercabile** raccolta dell'intero ecosistema HTB - macchine dal 2017 al 2026, ogni evento CTF, ogni categoria di challenge, ogni ProLab - incrociato per tecnica, difficoltà, sistema operativo e rilevanza per le certificazioni. Che tu ti stia preparando per **OSCP**, **CPTS**, **CRTO** o semplicemente affinando le tue competenze, inizia qui.
> **[Esplora il sito](https://momenbasel.github.io/htb-writeups/)** per la migliore esperienza - strumenti interattivi, ricerca e tema scuro.
---
## Strumenti Interattivi
| | Strumento | Descrizione |
|--|------|-------------|
| **[Machine Finder](https://momenbasel.github.io/htb-writeups/finder/)** | Ricerca e Filtri | Trova macchine per difficoltà, OS, tecnica, CVE o certificazione. Viste tabella e schede con filtraggio in tempo reale. |
| **[Knowledge Graph](https://momenbasel.github.io/htb-writeups/graph/)** | Esploratore Visivo | Grafico interattivo D3.js a forza diretta che mappa 70+ macchine a 40+ tecniche e 5 certificazioni. |
| **[Attack Paths](https://momenbasel.github.io/htb-writeups/attack-paths/)** | Diagrammi di flusso | Diagrammi Mermaid che mostrano catene di attacco complete per 25+ macchine - dalla ricognizione al root. |
| **[Skill Trees](https://momenbasel.github.io/htb-writeups/skill-trees/)** | Mappe di progressione | Percorsi di apprendimento visivi per attacchi AD, exploit web, privesc Linux/Windows e preparazione alle certificazioni. |
---
## Cosa Contiene
| Sezione | Descrizione | Conteggio |
|---------|-------------|-------|
| [Macchine](#machines) | Procedure dettagliate Boot2root (Facile a Insane) | 300+ |
| [Challenge](#challenges) | Challenge in stile CTF in 12 categorie | 400+ |
| [ProLabs](#prolabs) | Procedure dettagliate di lab enterprise con diagrammi di topologia di rete | 6 |
| [Sherlocks](#sherlocks) | Indagini DFIR e Blue Team | 70+ |
| [Eventi CTF](#ctf-events) | Writeup ufficiali delle competizioni CTF HTB | 14 eventi |
| [Endgames](#endgames) | Procedure dettagliate di scenari multi-macchina | 5 |
| [Fortresses](#fortresses) | Challenge multi-flag su singolo host | 6 |
| [Risorse](#resources) | Strumenti, cheat sheet, preparazione certificazioni, metodologia | 10 guide |
---
## Macchine
Writeup per macchine HTB ritirate organizzati per difficoltà. Ogni writeup include fasi di enumerazione, sfruttamento e escalation dei privilegi con output completo dei comandi.
### Per Difficoltà
| Difficoltà | Percorso | Macchine |
|------------|------|----------|
| Facile | [`machines/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/) | 132+ |
| Media | [`machines/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/) | 136+ |
| Difficile | [`machines/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | 70+ |
| Insane | [`machines/insane/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | 50+ |
### Ritirate Recentemente (2025-2026)
| Macchina | OS | Difficoltà | Tecniche Chiave | Data |
|---------|----|------------|----------------|------|
| [MonitorsFour](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/MonitorsFour/) | Windows | Insane | PHP Type Juggling, Cacti CVE, Docker API Escape | Maggio 2026 |
| [Pterodactyl](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Pterodactyl/) | openSUSE | Insane | Pterodactyl Panel CVE-2025-49132, PEAR pearcmd LFI, Polkit | Maggio 2026 |
| [Helix](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Helix/) | Linux | Media | Apache NiFi ExecuteSQL + H2 Java Alias RCE | Maggio 2026 |
| [Overwatch](https://0xdf.gitlab.io/2026/05/09/htb-overwatch.html) | Windows | Insane | .NET Reversing, WCF Service Injection, DNS | Maggio 2026 |
| [Sorcery](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Sorcery/) | Linux | Insane | Cypher Injection, WebAuthn XSS, Kafka, FreeIPA | Aprile 2026 |
| [PingPong](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/PingPong/) | Windows | Difficile | Multi-Forest AD, MSSQL Delegation, ADCS | Aprile 2026 |
| [AirTouch](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/AirTouch/) | Linux | Difficile | 802.11 WPA2 Crack, Evil Twin, PEAP-MSCHAPv2 | Aprile 2026 |
| [Eighteen](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Eighteen/) | Windows | Difficile | Win Server 2025, MSSQL Impersonation, Bad Successor dMSA | Aprile 2026 |
| [DarkZero](https://0xdf.gitlab.io/2026/04/04/htb-darkzero.html) | Windows | Difficile | Cross-Forest Trust, AD Abuse | Aprile 2026 |
| [Pirate](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Pirate/) | Windows | Difficile | Pre2k, gMSA, PetitPotam, RBCD, S4U SPN Jack | Febbraio 2026 |
| [VariaType](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/VariaType/) | Linux | Media | fontTools CVE-2025-66034, FontForge CVE-2024-25082 | Marzo 2026 |
| [Interpreter](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Interpreter/) | Linux | Media | Mirth Connect CVE-2023-43208, Python eval() | Febbraio 2026 |
| [Kobold](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Kobold/) | Linux | Facile | MCPJam CVE-2026-23744, Docker Group | Marzo 2026 |
| [Facts](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Facts/) | Linux | Facile | Camaleon CMS IDOR + Path Traversal + Facter Sudo | Gennaio 2026 |
| [Code](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Code/) | Linux | Facile | Python Sandbox Bypass, Backy Sudo | Agosto 2025 |
| [Cobblestone](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Cobblestone/) | Linux | Insane | Second-Order SQLi, Twig SSTI, Cobbler XMLRPC | 2025 |
| [Snapped](https://0xdf.gitlab.io/2026/04/01/htb-snapped.html) | Linux | Difficile | Nginx UI RCE, Static Site Exploitation | Marzo 2026 |
| [Browsed](https://0xdf.gitlab.io/2026/03/28/htb-browsed.html) | Linux | Media | Browser Extension Exploitation, Headless Chrome | Marzo 2026 |
| [Previous](https://0xdf.gitlab.io/2026/01/10/htb-previous.html) | Linux | Media | NextJS Exploitation, Framework Abuse | Gennaio 2026 |
| [Retire](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Windows | Difficile | Active Directory, Kerberos Abuse | Gennaio 2026 |
| [Fries](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | Difficile | Web Exploitation, Custom Exploitation | Novembre 2025 |
| [NanoCorp](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | Difficile | Custom Protocol, Binary Analysis | Novembre 2025 |
| [Hercules](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | Linux | Insane | Multi-Stage Exploitation | Ottobre 2025 |
| [Signed](https://0xdf.gitlab.io/2026/02/07/htb-signed.html) | Windows | Media | Code Signing Bypass, Certificate Abuse | Ottobre 2025 |
| [University](https://0xdf.gitlab.io/2025/08/09/htb-university.html) | Windows | Insane | Multi-Vector Attack, Complex Chain | Agosto 2025 |
| [Dog](https://0xdf.gitlab.io/2025/07/12/htb-dog.html) | Linux | Facile | Backdrop CMS, Web Exploitation | Luglio 2025 |
| [Mirage](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) | Windows | Difficile | Active Directory, ADCS | Luglio 2025 |
| [Voleur](https://0xdf.gitlab.io/2025/11/01/htb-voleur.html) | Windows | Media | Data Exfiltration, Custom Exploitation | Luglio 2025 |
| [RustyKey](https://0xdf.gitlab.io/2025/11/08/htb-rustykey.html) | Windows | Difficile | Rust Binary Exploitation | Giugno 2025 |
| [TombWatcher](https://0xdf.gitlab.io/2025/10/11/htb-tombwatcher.html) | Windows | Media | Custom Service Exploitation | Giugno 2025 |
| [Haze](https://0xdf.gitlab.io/2025/06/28/htb-haze.html) | Windows | Difficile | Splunk Enterprise Exploitation | Giugno 2025 |
| [Certificate](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html) | Windows | Difficile | ADCS, Certificate Template Abuse | Maggio 2025 |
| [Vintage](https://0xdf.gitlab.io/2025/04/26/htb-vintage.html) | Windows | Difficile | Pure Active Directory, Kerberoasting | Aprile 2025 |
### Per Sistema Operativo
- **Linux** - [`machines/` filtrato per OS](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Ubuntu, Debian, CentOS, distribuzioni personalizzate
- **Windows** - [`machines/` filtrato per OS](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Windows Server, ambienti Active Directory
- **FreeBSD/OpenBSD** - Rari ma presenti nei livelli più difficili
### Per Tecnica
<details>
<summary><b>Active Directory</b> - Kerberoasting, AS-REP Roasting, ADCS, DCSync, Pass-the-Hash, BloodHound</summary>
| Macchina | Difficoltà | Tecnica AD Specifica |
|---------|------------|-----------------------|
| DarkZero | Difficile | Cross-Forest Trust Abuse |
| Vintage | Difficile | Kerberoasting, Pure AD |
| Certificate | Difficile | ADCS Certificate Template Abuse |
| Mirage | Difficile | ADCS, Shadow Credentials |
| Haze | Difficile | Splunk + AD Integration |
| Retire | Difficile | Kerberos Delegation Abuse |
</details>
<details>
<summary><b>Web Exploitation</b> - SQLi, XSS, SSRF, SSTI, LFI/RFI, Deserialization</summary>
| Macchina | Difficoltà | Tecnica Web Specifica |
|---------|------------|-----------------------|
| Dog | Facile | Backdrop CMS RCE |
| Browsed | Media | Browser Extension RCE |
| Previous | Media | NextJS Framework Exploitation |
| Snapped | Difficile | Nginx UI Admin Panel RCE |
| Fries | Difficile | Custom Web App Exploitation |
</details>
<details>
<summary><b>Binary Exploitation</b> - Buffer Overflow, ROP, Heap Exploitation, Format Strings</summary>
| Macchina | Difficoltà | Tecnica Specifica |
|---------|------------|-----------------------|
| RustyKey | Difficile | Rust Binary Exploitation |
| NanoCorp | Difficile | Custom Protocol Exploitation |
</details>
<details>
<summary><b>Cloud & Infrastructure</b> - AWS, Azure, GCP, Docker, Kubernetes</summary>
| Macchina | Difficoltà | Tecnica Specifica |
|---------|------------|-----------------------|
| Hercules | Insane | Container Escape, Cloud Metadata |
</details>
---
## Challenge
Challenge in stile CTF organizzate per categoria. Ogni writeup include la descrizione della challenge, l'approccio, la soluzione e le lezioni apprese.
| Categoria | Percorso | Conteggio | Competenze Chiave |
|----------|------|-------|------------|
| Web | [`challenges/web/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/web/) | 75+ | XSS, SQLi, SSTI, SSRF, Deserialization, JWT, GraphQL |
| Crypto | [`challenges/crypto/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/crypto/) | 93+ | RSA, AES, ECC, Padding Oracle, PRNG, Lattice Attacks |
| Forensics | [`challenges/forensics/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/forensics/) | 33+ | Memory Analysis, Disk Forensics, Network PCAP, Malware |
| Reversing | [`challenges/reversing/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/reversing/) | 44+ | x86/x64, .NET, Python, Angr, Anti-Debug, VM |
| Pwn | [`challenges/pwn/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/pwn/) | 61+ | Stack/Heap Overflow, ROP, SROP, Kernel, tcache |
| Mobile | [`challenges/mobile/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/mobile/) | 10+ | Android APK, Frida, Smali, Certificate Pinning |
| Hardware | [`challenges/hardware/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/hardware/) | 11+ | UART, SPI, Firmware, VHDL, RF Analysis |
| OSINT | [`challenges/osint/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/osint/) | 12+ | Geolocation, Social Media, DNS, Metadata |
| Misc | [`challenges/misc/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/misc/) | 35+ | Scripting, Logic, Encoding, Pickle, Pyjail |
| Stego | [`challenges/stego/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/stego/) | 12+ | Image, Audio, LSB, Steghide, ImageMagick |
| Blockchain | [`challenges/blockchain/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/blockchain/) | 10+ | Solidity, Smart Contracts, ERC-721, ECDSA |
| AI/ML | [`challenges/ai-ml/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/ai-ml/) | 5+ | Adversarial ML, Prompt Injection, LLM Bypass |
---
## ProLabs
Ambienti di laboratorio di livello enterprise che simulano reti aziendali reali. Questi writeup coprono percorsi di attacco multi-macchina, movimento laterale e dominio del dominio.
| Lab | Difficoltà | Macchine | Focus |
|-----|-----------|----------|-------|
| [Dante](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Principiante | 14 | Fondamenti di Penetration Testing di Rete |
| [Offshore](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Intermedio | 21 | Active Directory, Multi-Dominio |
| [RastaLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Intermedio | 15 | Simulazione Red Team, Phishing |
| [Zephyr](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Intermedio | 17 | ADCS, DPAPI, Delega Vincolata |
| [Cybernetics](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Avanzato | 20+ | AD Avanzato, Attacchi Cross-Forest |
| [APTLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | Avanzato | 20+ | Simulazione APT, Multi-Vettore |
---
## Sherlocks
Laboratori di indagine DFIR (Digital Forensics & Incident Response). Scenari Blue Team in cui si investigano incidenti di sicurezza e si rispondono a domande forensi.
| Categoria | Percorso | Focus |
|----------|------|-------|
| Facile | [`sherlocks/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | Analisi dei Log, DFIR Base |
| Media | [`sherlocks/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | Forensica della Memoria, Triage Malware |
| Difficile | [`sherlocks/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | Indagine APT, IR Complessa |
### Sherlocks in Evidenza
| Nome | Difficoltà | Area di Focus | Writeup |
|------|-----------|------------|---------|
| Meerkat | Facile | Suricata IDS, Credential Stuffing, CVE-2022-25237 | [0xdf](https://0xdf.gitlab.io/2024/04/23/htb-sherlock-meerkat.html) |
| Brutus | Facile | Forza Bruta SSH, Analisi auth.log | [0xdf](https://0xdf.gitlab.io/2024/04/09/htb-sherlock-brutus.html) |
| Noted | Facile | Manufatti Notepad++, Estorsione Dati | [0xdf](https://0xdf.gitlab.io/2024/06/13/htb-sherlock-noted.html) |
| Knock Knock | Facile | PCAP, FTP, Port Knocking, Ransomware GonnaCry | [0xdf](https://0xdf.gitlab.io/2023/12/04/htb-sherlock-knock-knock.html) |
| Bumblebee | Facile | phpBB SQLite, Analisi Log di Accesso | [0xdf](https://0xdf.gitlab.io/2024/05/22/htb-sherlock-bumblebee.html) |
| Crown Jewel-1 | Media | Dump NTDS.dit, Volume Shadow Copy Service | [CyberWired](https://www.cyberwiredtraining.net/writeups/htb-sherlock-crownjewel-1-jezdr) |
| Noxious | Media | Avvelenamento LLMNR, Rilevamento Dispositivi Rogue | [0xdf](https://0xdf.gitlab.io/2024/09/04/htb-sherlock-noxious.html) |
| Subatomic | Media | Malware Electron, Hijacking Discord | [0xdf](https://0xdf.gitlab.io/2024/04/18/htb-sherlock-subatomic.html) |
| Nubilum-1 | Media | AWS CloudTrail, PoshC2, Forensica Cloud | [0xdf](https://0xdf.gitlab.io/2024/05/30/htb-sherlock-nubilum-1.html) |
| MisCloud | Media | Violazione GCP, Vulnerabilità Gitea | [CyberEthical](https://blog.cyberethical.me/htb-sherlock-miscloud) |
| OpTinselTrace (1-5) | Difficile | Indagine Completa Campagna APT (Natale 2023) | [GitHub](https://github.com/dbissell6/DFIR/blob/main/WalkThroughs/OpTinselTrace-1-5.md) |
| APTNightmare | Difficile | Indagine su Minaccia Persistente Avanzata | [GitHub](https://github.com/jon-brandy/hackthebox/blob/main/Categories/Sherlocks/APTNightmare/README.md) |
Vedi l'[indice completo degli Sherlocks](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/README.md) per 70+ Sherlocks con link ai writeup.
---
## Eventi CTF
Writeup degli eventi CTF competitivi ufficiali di Hack The Box.
| Evento | Anno | Percorso | Punti Salienti |
|-------|------|------|------------|
| Cyber Apocalypse | 2025 | [`ctf-events/cyber-apocalypse-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Web, Crypto, Pwn, Forensics |
| Business CTF | 2025 | [`ctf-events/business-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Enterprise Security Focus |
| University CTF | 2025 | [`ctf-events/university-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Academic Team Competition |
| Cyber Apocalypse | 2024 | [`ctf-events/cyber-apocalypse-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Hacker Royale Theme |
| Business CTF | 2024 | [`ctf-events/business-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Corporate Scenario |
| University CTF | 2024 | [`ctf-events/university-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Binary Badlands Theme |
---
## Endgames
Scenari multi-macchina e multi-fase che simulano reali impegni di penetration testing. Vedi [`endgames/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/README.md) per procedure dettagliate.
| Endgame | Percorso | Flag | Focus |
|---------|------|-------|-------|
| P.O.O. | [`endgames/poo/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5 | Server Collegati MSSQL, Enumerazione IIS |
| Xen | [`endgames/xen/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | Citrix Breakout, AD, Phishing |
| Hades | [`endgames/hades/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | AS-REP Roast, DPAPI, RBCD, Spoofing DNS |
| RPG | [`endgames/rpg/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 6 | Sfruttamento Linux, Pivoting Multi-Host |
| Ascension | [`endgames/ascension/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 7 | Blind SQLi, Proxy MSSQL, RBCD |
---
## Fortresses
Challenge multi-flag su singolo host create da aziende partner. Come macchine potenziate. Vedi [`fortresses/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/README.md) per procedure dettagliate.
| Fortezza | Creatore | Flag | Focus |
|----------|---------|-------|-------|
| [Jet](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Jet | 11 | Sfruttamento multi-servizio |
| [Akerva](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Akerva | 8 | WordPress, SNMP, catene web |
| [Context](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Context/Accenture | 7 | Web + infrastruttura |
| [Synacktiv](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Synacktiv | Multiple | Symfony, AppSec, infrastruttura |
| [AWS](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Amazon Web Services | Multiple | Sicurezza cloud, IAM, Lambda, S3 |
| [Faraday](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Faraday | 7 | Sicurezza offensiva generale |
---
## Risorse
### Strumenti per Categoria
<details>
<summary><b>Enumerazione e Ricognizione</b></summary>
| Strumento | Scopo | Link |
|------|---------|------|
| Nmap | Scansione porte e rilevamento servizi | [nmap.org](https://nmap.org) |
| RustScan | Scanner porte veloce | [GitHub](https://github.com/RustScan/RustScan) |
| Gobuster | Forzatura brute di directory/DNS/vhost | [GitHub](https://github.com/OJ/gobuster) |
| Feroxbuster | Scoperta ricorsiva di contenuti | [GitHub](https://github.com/epi052/feroxbuster) |
| ffuf | Fuzzer web veloce | [GitHub](https://github.com/ffuf/ffuf) |
| enum4linux-ng | Enumerazione SMB/Samba | [GitHub](https://github.com/cddmp/enum4linux-ng) |
</details>
<details>
<summary><b>Sfruttamento Web</b></summary>
| Strumento | Scopo | Link |
|------|---------|------|
| Burp Suite | Proxy web e scanner | [portswigger.net](https://portswigger.net/burp) |
| SQLMap | Automazione SQL injection | [GitHub](https://github.com/sqlmapproject/sqlmap) |
| Nuclei | Scanner di vulnerabilità basato su template | [GitHub](https://github.com/projectdiscovery/nuclei) |
| Caido | Proxy web moderno | [caido.io](https://caido.io) |
| PayloadsAllTheThings | Repository di payload | [GitHub](https://github.com/swisskyrepo/PayloadsAllTheThings) |
</details>
<details>
<summary><b>Active Directory</b></summary>
| Strumento | Scopo | Link |
|------|---------|------|
| BloodHound | Mappatura relazioni AD | [GitHub](https://github.com/SpecterOps/BloodHound) |
| Impacket | Toolkit di protocolli di rete | [GitHub](https://github.com/fortra/impacket) |
| Rubeus | Abuso Kerberos | [GitHub](https://github.com/GhostPack/Rubeus) |
| Certipy | Sfruttamento ADCS | [GitHub](https://github.com/ly4k/Certipy) |
| NetExec (nxc) | Toolkit di esecuzione di rete | [GitHub](https://github.com/Pennyw0rth/NetExec) |
| Ligolo-ng | Tunneling/pivoting | [GitHub](https://github.com/nicocha30/ligolo-ng) |
</details>
<details>
<summary><b>Escalation dei Privilegi</b></summary>
| Strumento | Scopo | Link |
|------|---------|------|
| LinPEAS | Enumerazione di escalation privilegi Linux | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| WinPEAS | Enumerazione di escalation privilegi Windows | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| pspy | Monitoraggio processi (senza root) | [GitHub](https://github.com/DominicBreuker/pspy) |
| PowerUp | PowerShell per escalation privilegi Windows | [GitHub](https://github.com/PowerShellMafia/PowerSploit) |
| GTFOBins | Sfruttamento binari Unix | [gtfobins.github.io](https://gtfobins.github.io) |
| LOLBAS | Living-off-the-land Windows | [lolbas-project.github.io](https://lolbas-project.github.io) |
</details>
<details>
<summary><b>Forensica e DFIR</b></summary>
| Strumento | Scopo | Link |
|------|---------|------|
| Volatility 3 | Forensica della memoria | [GitHub](https://github.com/volatilityfoundation/volatility3) |
| Autopsy | Forensica dei dischi | [autopsy.com](https://www.autopsy.com) |
| Wireshark | Analisi di catture di rete | [wireshark.org](https://www.wireshark.org) |
| CyberChef | Trasformazione dati | [GitHub](https://github.com/gchq/CyberChef) |
| Chainsaw | Analisi log eventi Windows | [GitHub](https://github.com/WithSecureLabs/chainsaw) |
</details>
<details>
<summary><b>Reverse Engineering</b></summary>
| Strumento | Scopo | Link |
|------|---------|------|
| Ghidra | Analisi binaria | [ghidra-sre.org](https://ghidra-sre.org) |
| IDA Free | Disassemblatore | [hex-rays.com](https://hex-rays.com/ida-free) |
| radare2 | Reverse engineering da riga di comando | [GitHub](https://github.com/radareorg/radare2) |
| Binary Ninja | Piattaforma di analisi binaria | [binary.ninja](https://binary.ninja) |
| dnSpy | Decompilatore .NET | [GitHub](https://github.com/dnSpy/dnSpy) |
</details>
<details>
<summary><b>Sfruttamento Binario</b></summary>
| Strumento | Scopo | Link || Strumento | Scopo | Link |
|-----------|-------|------|
| pwntools | Framework per exploit CTF | [GitHub](https://github.com/Gallopsled/pwntools) |
| ROPgadget | Costruttore di catene ROP | [GitHub](https://github.com/JonathanSalwan/ROPgadget) |
| GEF | Funzionalità avanzate per GDB | [GitHub](https://github.com/hugsy/gef) |
| one_gadget | Gadget one-shot di libc | [GitHub](https://github.com/david942j/one_gadget) |
| checksec | Controlli di sicurezza binari | [GitHub](https://github.com/slimm609/checksec.sh) |
</details>
### Preparazione Certificazioni
Mappa il tuo percorso su HTB verso le certificazioni professionali.
<details>
<summary><b>OSCP (Offensive Security Certified Professional)</b></summary>
**Macchine HTB consigliate per la preparazione all'OSCP:**
| Macchina | Difficoltà | Competenze Chiave |
|----------|------------|-------------------|
| Lame | Facile | Samba RCE, Sfruttamento Base |
| Legacy | Facile | MS08-067, Sfruttamento Windows |
| Blue | Facile | EternalBlue (MS17-010) |
| Optimum | Facile | HFS RCE, Privesc Windows |
| Shocker | Facile | Shellshock, Basi Linux |
| Nibbles | Facile | Sfruttamento CMS, Caricamento File |
| Bashed | Facile | WebShell PHP, Abuso Cron |
| Arctic | Facile | ColdFusion, Sfruttamento Windows |
| Grandpa | Facile | IIS WebDAV, Impersonazione Token |
| Bastard | Media | Drupal RCE, Privesc Windows |
| Cronos | Media | Trasferimento di Zona DNS, SQL Injection |
| SolidState | Media | Apache James RCE, Privesc Cron |
| Node | Media | Sfruttamento API, Exploit Kernel |
| Valentine | Facile | Heartbleed, Hijack tmux |
| Poison | Media | LFI, Tunneling VNC |
| Sunday | Facile | Enumerazione Finger, File Shadow |
| DevOops | Media | XXE, Segreti Git |
| Jeeves | Media | Jenkins RCE, Cracking KeePass |
| Conceal | Difficile | VPN IPSec, SNMP, JuicyPotato |
</details>
<details>
<summary><b>CPTS (Certified Penetration Testing Specialist)</b></summary>
**Macchine HTB consigliate per la preparazione al CPTS:**
| Macchina | Difficoltà | Competenze Chiave |
|----------|------------|-------------------|
| Active | Facile | Basi AD, Abuso GPP, Kerberoasting |
| Forest | Facile | AS-REP Roasting, DCSync |
| Sauna | Facile | AS-REP Roasting, WinRM |
| Monteverde | Media | Azure AD, Password Spraying |
| Resolute | Media | DNS Admin DLL Injection |
| Cascade | Media | Enumerazione LDAP, Reverse Engineering .NET |
| Blackfield | Difficile | AS-REP, Privesc Operatori Backup |
| Vintage | Difficile | Sfruttamento AD Puro |
| Certificate | Difficile | Sfruttamento ADCS |
| Support | Facile | LDAP, Analisi Binari .NET |
</details>
<details>
<summary><b>CRTO (Certified Red Team Operator)</b></summary>
Concentrati su ProLabs: **RastaLabs** e **Zephyr** sono direttamente allineati con il materiale CRTO.
| Macchina/Lab | Tipo | Competenze Chiave |
|--------------|------|-------------------|
| RastaLabs | ProLab | Phishing, C2, Movimento Laterale |
| Zephyr | ProLab | ADCS, DPAPI, Delega Vincolata |
| Offshore | ProLab | AD Multi-Dominio |
| Reel | Difficile | Phishing, Bypass AppLocker |
| Mantis | Difficile | AD, Kerberos, MS14-068 |
</details>
### Cheat Sheet
| Cheat Sheet | Descrizione |
|-------------|-------------|
| [Enumerazione Linux](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/linux-enumeration.md) | Comandi di enumerazione Linux post-sfruttamento |
| [Enumerazione Windows](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/windows-enumeration.md) | Comandi di enumerazione Windows post-sfruttamento |
| [Active Directory](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/active-directory.md) | Metodologia e comandi per attacchi AD |
| [Applicazioni Web](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/web-application.md) | Tecniche di sfruttamento web e payload |
| [Escalation Privilegi - Linux](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-linux.md) | Vettori di escalation privilegi Linux |
| [Escalation Privilegi - Windows](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-windows.md) | Vettori di escalation privilegi Windows |
| [Trasferimento File](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/file-transfers.md) | Metodi per trasferire file tra macchine |
| [Reverse Shell](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/reverse-shells.md) | One-liner di reverse shell per tutti i linguaggi |
| [Pivoting & Tunneling](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/pivoting.md) | SSH tunneling, Chisel, Ligolo, SOCKS |
| [Attacchi Password](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/password-attacks.md) | Cracking, spraying, brute-forcing |
### Metodologia
| Guida | Descrizione |
|-------|-------------|
| [Approccio alle Macchine HTB](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/machine-approach.md) | Come affrontare sistematicamente qualsiasi macchina HTB |
| [Template per Appunti](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/note-taking.md) | Appunti strutturati per writeup |
| [Scrittura Report](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/report-writing.md) | Template professionale per report di pentest |
---
## Struttura del Repository```
htb-writeups/
|-- machines/
| |-- easy/ # Easy difficulty machines
| |-- medium/ # Medium difficulty machines
| |-- hard/ # Hard difficulty machines
| |-- insane/ # Insane difficulty machines
|-- challenges/
| |-- web/ # Web exploitation challenges
| |-- crypto/ # Cryptography challenges
| |-- forensics/ # Digital forensics challenges
| |-- reversing/ # Reverse engineering challenges
| |-- pwn/ # Binary exploitation challenges
| |-- mobile/ # Mobile security challenges
| |-- hardware/ # Hardware hacking challenges
| |-- osint/ # OSINT challenges
| |-- misc/ # Miscellaneous challenges
| |-- stego/ # Steganography challenges
| |-- blockchain/ # Blockchain/smart contract challenges
| |-- ai-ml/ # AI/ML security challenges
|-- prolabs/
| |-- dante/ # Dante ProLab walkthrough
| |-- offshore/ # Offshore ProLab walkthrough
| |-- rastalabs/ # RastaLabs ProLab walkthrough
| |-- zephyr/ # Zephyr ProLab walkthrough
| |-- cybernetics/ # Cybernetics ProLab walkthrough
| |-- aptlabs/ # APTLabs ProLab walkthrough
|-- sherlocks/
| |-- easy/ # Easy DFIR investigations
| |-- medium/ # Medium DFIR investigations
| |-- hard/ # Hard DFIR investigations
|-- ctf-events/ # Official HTB CTF writeups
|-- endgames/ # Multi-machine scenarios
|-- fortresses/ # Fortress challenges
|-- resources/
| |-- cheatsheets/ # Quick reference guides
| |-- tools/ # Tool guides and configs
| |-- methodology/ # Approach guides and templates
| |-- cert-prep/ # Certification preparation guides
|-- templates/ # Writeup templates
We welcome contributions! See CONTRIBUTING.md for detailed guidelines.
Quick start:
Writeup Requirements:
These writeups are for educational purposes only. All content covers retired machines and challenges that are no longer active on the Hack The Box platform. Sharing solutions for active machines violates HTB's Terms of Service.
Always practice ethical hacking. Only test systems you have explicit authorization to test.
Machine writeups in this repo link to multiple independent authors for diverse perspectives. Here are the primary sources:
This collection is built and maintained by GreyCore Labs, a US-incorporated offensive security firm. Want the same eye on your own product?
This project is licensed under the MIT License - see LICENSE for details.
If this helped you pop a box or pass a cert, drop a star - it helps others find it too.
Keywords: hack the box writeups, HTB walkthrough, hackthebox machines, HTB challenges, OSCP prep machines, CPTS certification, penetration testing writeups, CTF writeups, active directory hacking, privilege escalation, web exploitation, binary exploitation, digital forensics, incident response, red team, blue team, cybersecurity training, ethical hacking, infosec resources, security cheatsheets
| Author / Source | URL | Coverage |
|---|
| 0xdf | 0xdf.gitlab.io | 500+ machines - gold standard, exhaustive detail |
| IppSec | youtube.com/ippsec | 430+ video walkthroughs with live debugging |
| HackingArticles | hackingarticles.in | 40+ machines - Raj Chandel, classic era (2017-2022) |
| Rana Khalil | rana-khalil.gitbook.io | 26+ machines - OSCP-focused, no Metasploit |
| snowscan | snowscan.io | 20+ machines - detailed, consistent quality |
| 0xRick | 0xrick.github.io | 10+ machines - clean blog writeups |
| Medium / InfosecWriteups | medium.com | 45+ machines - diverse community authors |
| Resource | Description |
|---|
| HackTricks | Comprehensive pentesting reference |
| PayloadsAllTheThings | Payload and bypass collection |
| The Hacker Recipes | Structured attack recipes |
| GTFOBins | Unix binary exploitation reference |
| LOLBAS | Windows living-off-the-land binaries |
| WADComs | Windows/AD command reference |
| RevShells | Reverse shell generator |
| CyberChef | Data transformation toolkit |
| SecLists | Wordlists for security testing |
| IppSec.rocks | Searchable index of IppSec's HTB videos |