
500以上のHack The Boxマシンのwriteups、400以上のチャレンジソリューション、そして知識グラフ、攻撃経路図、スキルツリーなどのインタラクティブな学習ツールを含む、ペネトレーションテストと資格試験対策のための体系化されたコレクション。
GitHub上で最も包括的なHack The Boxのライトアップ、ウォークスルー、およびチートシートのコレクション。500以上のマシン、400以上のチャレンジ、ProLabs、Sherlocks(DFIR)、CTFイベント、ペネトレーションテスト手法、そしてOSCP/CPTS認定対策 - すべて1か所に。``` ___ ___ ___________ __ __ .__ __
/ | \ __ / / \ / ___||/ | ____ __ ________ ______
/ ~ \ | | \ // /_ __ | \ / __ | | _ / /
\ Y / | | \ / | | /| || | \ /| | / |> > \
_|_ / || _/\ / || |||| ___ >_/| / >
/ / / |__| /
[](https://awesome.re)
[](https://github.com/momenbasel/htb-writeups/stargazers)
[](https://github.com/momenbasel/htb-writeups/network/members)
[](https://github.com/momenbasel/htb-writeups/graphs/contributors)
[](LICENSE)
[](https://github.com/momenbasel/htb-writeups/commits/main)
**このリポジトリの目的は?** 散在するブログ記事や単一著者のコレクションとは異なり、これは**構造化された検索可能なインデックス**です。2017年から2026年までのマシン、すべてのCTFイベント、すべてのチャレンジカテゴリ、すべてのProLabを、テクニック、難易度、OS、認定資格の関連性で相互参照します。**OSCP**、**CPTS**、**CRTO**の準備をしている方、または単にスキルを磨きたい方、ここから始めてください。
> **[サイトを閲覧](https://momenbasel.github.io/htb-writeups/)** すると、最高の体験が得られます。インタラクティブツール、検索、ダークテーマ。
---
## インタラクティブツール
| | ツール | 説明 |
|--|------|-------------|
| **[Machine Finder](https://momenbasel.github.io/htb-writeups/finder/)** | 検索&フィルター | 難易度、OS、テクニック、CVE、または認定資格でマシンを検索。テーブルビューとカードビュー、リアルタイムフィルタリング。 |
| **[Knowledge Graph](https://momenbasel.github.io/htb-writeups/graph/)** | ビジュアルエクスプローラー | インタラクティブなD3.jsフォース指向グラフ。70以上のマシンと40以上のテクニック、5つの認定資格をマッピング。 |
| **[Attack Paths](https://momenbasel.github.io/htb-writeups/attack-paths/)** | フローチャート | Mermaid図を使用した25以上のマシンの完全な攻撃チェーンを表示。偵察からルート取得まで。 |
| **[Skill Trees](https://momenbasel.github.io/htb-writeups/skill-trees/)** | 進行マップ | AD攻撃、Webエクスプロイト、Linux/Windows権限昇格、認定準備のためのビジュアル学習パス。 |
---
## 内部構成
| セクション | 説明 | 数 |
|---------|-------------|-------|
| [Machines](#machines) | Boot2rootウォークスルー(Easy~Insane) | 300+ |
| [Challenges](#challenges) | 12カテゴリにわたるCTFスタイルのチャレンジ | 400+ |
| [ProLabs](#prolabs) | ネットワークトポロジ図付きのエンタープライズグレードのラボウォークスルー | 6 |
| [Sherlocks](#sherlocks) | DFIR & ブルーチーム調査 | 70+ |
| [CTF Events](#ctf-events) | 公式HTB CTF競技のライトアップ | 14イベント |
| [Endgames](#endgames) | マルチマシンシナリオのウォークスルー | 5 |
| [Fortresses](#fortresses) | マルチフラグ単一ホストチャレンジ | 6 |
| [Resources](#resources) | ツール、チートシート、認定準備、方法論 | 10ガイド |
---
## Machines
退役したHTBマシンのウォークスルーを難易度別に整理。各ウォークスルーには、完全なコマンド出力付きの列挙、エクスプロイト、特権昇格の手順が含まれています。
### 難易度別
| 難易度 | パス | マシン数 |
|------------|------|----------|
| Easy | [`machines/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/) | 132+ |
| Medium | [`machines/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/) | 136+ |
| Hard | [`machines/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | 70+ |
| Insane | [`machines/insane/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | 50+ |
### 最近退役したマシン(2025-2026)
| マシン | OS | 難易度 | 主要テクニック | 日付 |
|---------|----|------------|----------------|------|
| [MonitorsFour](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/MonitorsFour/) | Windows | Insane | PHP型ジャグリング、Cacti CVE、Docker APIエスケープ | 2026年5月 |
| [Pterodactyl](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Pterodactyl/) | openSUSE | Insane | Pterodactyl Panel CVE-2025-49132、PEAR pearcmd LFI、Polkit | 2026年5月 |
| [Helix](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Helix/) | Linux | Medium | Apache NiFi ExecuteSQL + H2 Java Alias RCE | 2026年5月 |
| [Overwatch](https://0xdf.gitlab.io/2026/05/09/htb-overwatch.html) | Windows | Insane | .NETリバースエンジニアリング、WCFサービスインジェクション、DNS | 2026年5月 |
| [Sorcery](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Sorcery/) | Linux | Insane | Cypherインジェクション、WebAuthn XSS、Kafka、FreeIPA | 2026年4月 |
| [PingPong](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/PingPong/) | Windows | Hard | マルチフォレストAD、MSSQL委任、ADCS | 2026年4月 |
| [AirTouch](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/AirTouch/) | Linux | Hard | 802.11 WPA2クラック、Evil Twin、PEAP-MSCHAPv2 | 2026年4月 |
| [Eighteen](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Eighteen/) | Windows | Hard | Win Server 2025、MSSQL権限借用、Bad Successor dMSA | 2026年4月 |
| [DarkZero](https://0xdf.gitlab.io/2026/04/04/htb-darkzero.html) | Windows | Hard | クロスフォレストトラスト、AD悪用 | 2026年4月 |
| [Pirate](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Pirate/) | Windows | Hard | Pre2k、gMSA、PetitPotam、RBCD、S4U SPN Jack | 2026年2月 |
| [VariaType](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/VariaType/) | Linux | Medium | fontTools CVE-2025-66034、FontForge CVE-2024-25082 | 2026年3月 |
| [Interpreter](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Interpreter/) | Linux | Medium | Mirth Connect CVE-2023-43208、Python eval() | 2026年2月 |
| [Kobold](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Kobold/) | Linux | Easy | MCPJam CVE-2026-23744、Dockerグループ | 2026年3月 |
| [Facts](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Facts/) | Linux | Easy | Camaleon CMS IDOR + パストラバーサル + Facter Sudo | 2026年1月 |
| [Code](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Code/) | Linux | Easy | Pythonサンドボックスバイパス、Backy Sudo | 2025年8月 |
| [Cobblestone](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Cobblestone/) | Linux | Insane | 二次SQLi、Twig SSTI、Cobbler XMLRPC | 2025年 |
| [Snapped](https://0xdf.gitlab.io/2026/04/01/htb-snapped.html) | Linux | Hard | Nginx UI RCE、静的サイトエクスプロイト | 2026年3月 |
| [Browsed](https://0xdf.gitlab.io/2026/03/28/htb-browsed.html) | Linux | Medium | ブラウザ拡張機能エクスプロイト、ヘッドレスChrome | 2026年3月 |
| [Previous](https://0xdf.gitlab.io/2026/01/10/htb-previous.html) | Linux | Medium | NextJSエクスプロイト、フレームワーク悪用 | 2026年1月 |
| [Retire](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Windows | Hard | Active Directory、Kerberos悪用 | 2026年1月 |
| [Fries](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | Hard | Webエクスプロイト、カスタムエクスプロイト | 2025年11月 |
| [NanoCorp](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | Hard | カスタムプロトコル、バイナリ解析 | 2025年11月 |
| [Hercules](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | Linux | Insane | マルチステージエクスプロイト | 2025年10月 |
| [Signed](https://0xdf.gitlab.io/2026/02/07/htb-signed.html) | Windows | Medium | コード署名バイパス、証明書悪用 | 2025年10月 |
| [University](https://0xdf.gitlab.io/2025/08/09/htb-university.html) | Windows | Insane | マルチベクター攻撃、複雑なチェーン | 2025年8月 |
| [Dog](https://0xdf.gitlab.io/2025/07/12/htb-dog.html) | Linux | Easy | Backdrop CMS、Webエクスプロイト | 2025年7月 |
| [Mirage](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) | Windows | Hard | Active Directory、ADCS | 2025年7月 |
| [Voleur](https://0xdf.gitlab.io/2025/11/01/htb-voleur.html) | Windows | Medium | データ流出、カスタムエクスプロイト | 2025年7月 |
| [RustyKey](https://0xdf.gitlab.io/2025/11/08/htb-rustykey.html) | Windows | Hard | Rustバイナリエクスプロイト | 2025年6月 |
| [TombWatcher](https://0xdf.gitlab.io/2025/10/11/htb-tombwatcher.html) | Windows | Medium | カスタムサービスエクスプロイト | 2025年6月 |
| [Haze](https://0xdf.gitlab.io/2025/06/28/htb-haze.html) | Windows | Hard | Splunk Enterpriseエクスプロイト | 2025年6月 |
| [Certificate](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html) | Windows | Hard | ADCS、証明書テンプレート悪用 | 2025年5月 |
| [Vintage](https://0xdf.gitlab.io/2025/04/26/htb-vintage.html) | Windows | Hard | 純粋Active Directory、Kerberoasting | 2025年4月 |
### オペレーティングシステム別
- **Linux** - [`machines/` OSでフィルター](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Ubuntu、Debian、CentOS、カスタムディストリビューション
- **Windows** - [`machines/` OSでフィルター](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Windows Server、Active Directory環境
- **FreeBSD/OpenBSD** - まれですが、より難しい階層に存在します
### テクニック別
<details>
<summary><b>Active Directory</b> - Kerberoasting、AS-REP Roasting、ADCS、DCSync、Pass-the-Hash、BloodHound</summary>
| マシン | 難易度 | 具体的なADテクニック |
|---------|------------|-----------------------|
| DarkZero | Hard | クロスフォレストトラスト悪用 |
| Vintage | Hard | Kerberoasting、純粋AD |
| Certificate | Hard | ADCS証明書テンプレート悪用 |
| Mirage | Hard | ADCS、シャドウ資格情報 |
| Haze | Hard | Splunk + AD統合 |
| Retire | Hard | Kerberos委任悪用 |
</details>
<details>
<summary><b>Webエクスプロイト</b> - SQLi、XSS、SSRF、SSTI、LFI/RFI、デシリアライゼーション</summary>
| マシン | 難易度 | 具体的なWebテクニック |
|---------|------------|-----------------------|
| Dog | Easy | Backdrop CMS RCE |
| Browsed | Medium | ブラウザ拡張機能RCE |
| Previous | Medium | NextJSフレームワークエクスプロイト |
| Snapped | Hard | Nginx UI管理パネルRCE |
| Fries | Hard | カスタムWebアプリエクスプロイト |
</details>
<details>
<summary><b>バイナリエクスプロイト</b> - バッファオーバーフロー、ROP、ヒープエクスプロイト、フォーマットストリング</summary>
| マシン | 難易度 | 具体的なテクニック |
|---------|------------|-----------------------|
| RustyKey | Hard | Rustバイナリエクスプロイト |
| NanoCorp | Hard | カスタムプロトコルエクスプロイト |
</details>
<details>
<summary><b>クラウド&インフラストラクチャ</b> - AWS、Azure、GCP、Docker、Kubernetes</summary>
| マシン | 難易度 | 具体的なテクニック |
|---------|------------|-----------------------|
| Hercules | Insane | コンテナエスケープ、クラウドメタデータ |
</details>
---
## Challenges
カテゴリ別に整理されたCTFスタイルのチャレンジ。各ウォークスルーには、チャレンジの説明、アプローチ、解決策、学んだ教訓が含まれています。
| カテゴリ | パス | 数 | 主要スキル |
|----------|------|-------|------------|
| Web | [`challenges/web/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/web/) | 75+ | XSS、SQLi、SSTI、SSRF、デシリアライゼーション、JWT、GraphQL |
| Crypto | [`challenges/crypto/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/crypto/) | 93+ | RSA、AES、ECC、Padding Oracle、PRNG、Lattice Attacks |
| Forensics | [`challenges/forensics/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/forensics/) | 33+ | メモリ解析、ディスクフォレンジック、ネットワークPCAP、マルウェア |
| Reversing | [`challenges/reversing/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/reversing/) | 44+ | x86/x64、.NET、Python、Angr、アンチデバッグ、VM |
| Pwn | [`challenges/pwn/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/pwn/) | 61+ | スタック/ヒープオーバーフロー、ROP、SROP、カーネル、tcache |
| Mobile | [`challenges/mobile/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/mobile/) | 10+ | Android APK、Frida、Smali、証明書ピンニング |
| Hardware | [`challenges/hardware/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/hardware/) | 11+ | UART、SPI、ファームウェア、VHDL、RF解析 |
| OSINT | [`challenges/osint/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/osint/) | 12+ | 位置情報、ソーシャルメディア、DNS、メタデータ |
| Misc | [`challenges/misc/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/misc/) | 35+ | スクリプティング、論理、エンコーディング、Pickle、Pyjail |
| Stego | [`challenges/stego/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/stego/) | 12+ | 画像、音声、LSB、Steghide、ImageMagick |
| Blockchain | [`challenges/blockchain/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/blockchain/) | 10+ | Solidity、スマートコントラクト、ERC-721、ECDSA |
| AI/ML | [`challenges/ai-ml/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/ai-ml/) | 5+ | 敵対的ML、プロンプトインジェクション、LLMバイパス |
---
## ProLabs
実際の企業ネットワークを模したエンタープライズグレードのラボ環境。これらのウォークスルーは、マルチマシン攻撃パス、横方向の移動、ドメイン支配をカバーしています。
| ラボ | 難易度 | マシン数 | 焦点 |
|-----|-----------|----------|-------|
| [Dante](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 初心者 | 14 | ネットワークペネトレーションテストの基礎 |
| [Offshore](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 中級 | 21 | Active Directory、マルチドメイン |
| [RastaLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 中級 | 15 | レッドチームシミュレーション、フィッシング |
| [Zephyr](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 中級 | 17 | ADCS、DPAPI、制約付き委任 |
| [Cybernetics](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 上級 | 20+ | 高度なAD、クロスフォレスト攻撃 |
| [APTLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 上級 | 20+ | APTシミュレーション、マルチベクター |
---
## Sherlocks
DFIR(デジタルフォレンジック&インシデントレスポンス)調査ラボ。セキュリティインシデントを調査し、フォレンジックな質問に答えるブルーチームシナリオ。
| カテゴリ | パス | 焦点 |
|----------|------|-------|
| Easy | [`sherlocks/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | ログ分析、基本的なDFIR |
| Medium | [`sherlocks/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | メモリフォレンジック、マルウェアトリアージ |
| Hard | [`sherlocks/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | APT調査、複雑なIR |
### 注目のSherlocks
| 名前 | 難易度 | 焦点領域 | ウォークスルー |
|------|-----------|------------|---------|
| Meerkat | Easy | Suricata IDS、クレデンシャルスタッフィング、CVE-2022-25237 | [0xdf](https://0xdf.gitlab.io/2024/04/23/htb-sherlock-meerkat.html) |
| Brutus | Easy | SSHブルートフォース、auth.log分析 | [0xdf](https://0xdf.gitlab.io/2024/04/09/htb-sherlock-brutus.html) |
| Noted | Easy | Notepad++アーティファクト、データ恐喝 | [0xdf](https://0xdf.gitlab.io/2024/06/13/htb-sherlock-noted.html) |
| Knock Knock | Easy | PCAP、FTP、ポートノッキング、GonnaCryランサムウェア | [0xdf](https://0xdf.gitlab.io/2023/12/04/htb-sherlock-knock-knock.html) |
| Bumblebee | Easy | phpBB SQLite、アクセスログ分析 | [0xdf](https://0xdf.gitlab.io/2024/05/22/htb-sherlock-bumblebee.html) |
| Crown Jewel-1 | Medium | NTDS.ditダンプ、ボリュームシャドウコピーサービス | [CyberWired](https://www.cyberwiredtraining.net/writeups/htb-sherlock-crownjewel-1-jezdr) |
| Noxious | Medium | LLMNRポイズニング、不正デバイス検出 | [0xdf](https://0xdf.gitlab.io/2024/09/04/htb-sherlock-noxious.html) |
| Subatomic | Medium | Electronマルウェア、Discordハイジャック | [0xdf](https://0xdf.gitlab.io/2024/04/18/htb-sherlock-subatomic.html) |
| Nubilum-1 | Medium | AWS CloudTrail、PoshC2、クラウドフォレンジック | [0xdf](https://0xdf.gitlab.io/2024/05/30/htb-sherlock-nubilum-1.html) |
| MisCloud | Medium | GCP侵害、Gitea脆弱性 | [CyberEthical](https://blog.cyberethical.me/htb-sherlock-miscloud) |
| OpTinselTrace (1-5) | Hard | 完全なAPTキャンペーン調査(2023年クリスマス) | [GitHub](https://github.com/dbissell6/DFIR/blob/main/WalkThroughs/OpTinselTrace-1-5.md) |
| APTNightmare | Hard | 高度な持続的脅威調査 | [GitHub](https://github.com/jon-brandy/hackthebox/blob/main/Categories/Sherlocks/APTNightmare/README.md) |
完全なSherlocksインデックスは[こちら](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/README.md)(70以上のSherlocksとウォークスルーリンク)。
---
## CTF Events
公式Hack The Box競技CTFイベントのウォークスルー。
| イベント | 年 | パス | ハイライト |
|-------|------|------|------------|
| Cyber Apocalypse | 2025 | [`ctf-events/cyber-apocalypse-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Web、Crypto、Pwn、Forensics |
| Business CTF | 2025 | [`ctf-events/business-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | エンタープライズセキュリティフォーカス |
| University CTF | 2025 | [`ctf-events/university-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 学術チーム競技 |
| Cyber Apocalypse | 2024 | [`ctf-events/cyber-apocalypse-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Hacker Royaleテーマ |
| Business CTF | 2024 | [`ctf-events/business-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 企業シナリオ |
| University CTF | 2024 | [`ctf-events/university-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Binary Badlandsテーマ |
---
## Endgames
実際のペネトレーションテストエンゲージメントを模したマルチマシン、マルチステージのシナリオ。詳細なウォークスルーは[`endgames/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/README.md)を参照。
| エンドゲーム | パス | フラグ数 | 焦点 |
|---------|------|-------|-------|
| P.O.O. | [`endgames/poo/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5 | MSSQLリンクサーバー、IIS列挙 |
| Xen | [`endgames/xen/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | Citrixブレイクアウト、AD、フィッシング |
| Hades | [`endgames/hades/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | AS-REP Roast、DPAPI、RBCD、DNSスプーフィング |
| RPG | [`endgames/rpg/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 6 | Linuxエクスプロイト、マルチホストピボット |
| Ascension | [`endgames/ascension/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 7 | ブラインドSQLi、MSSQLプロキシ、RBCD |
---
## Fortresses
パートナー企業が作成したマルチフラグ単一ホストチャレンジ。マシンを強化したようなものです。詳細なウォークスルーは[`fortresses/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/README.md)を参照。
| フォートレス | 作成者 | フラグ数 | 焦点 |
|----------|---------|-------|-------|
| [Jet](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Jet | 11 | マルチサービスエクスプロイト |
| [Akerva](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Akerva | 8 | WordPress、SNMP、Webチェーン |
| [Context](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Context/Accenture | 7 | Web + インフラストラクチャ |
| [Synacktiv](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Synacktiv | 複数 | Symfony、AppSec、インフラストラクチャ |
| [AWS](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Amazon Web Services | 複数 | クラウドセキュリティ、IAM、Lambda、S3 |
| [Faraday](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Faraday | 7 | 一般的な攻撃的セキュリティ |
---
## Resources
### カテゴリ別ツール
<details>
<summary><b>列挙と偵察</b></summary>
| ツール | 目的 | リンク |
|------|---------|------|
| Nmap | ポートスキャンとサービス検出 | [nmap.org](https://nmap.org) |
| RustScan | 高速ポートスキャナー | [GitHub](https://github.com/RustScan/RustScan) |
| Gobuster | ディレクトリ/DNS/vhostブルートフォース | [GitHub](https://github.com/OJ/gobuster) |
| Feroxbuster | 再帰的コンテンツ発見 | [GitHub](https://github.com/epi052/feroxbuster) |
| ffuf | 高速Webファザー | [GitHub](https://github.com/ffuf/ffuf) |
| enum4linux-ng | SMB/Samba列挙 | [GitHub](https://github.com/cddmp/enum4linux-ng) |
</details>
<details>
<summary><b>Webエクスプロイト</b></summary>
| ツール | 目的 | リンク |
|------|---------|------|
| Burp Suite | Webプロキシ&スキャナー | [portswigger.net](https://portswigger.net/burp) |
| SQLMap | SQLインジェクション自動化 | [GitHub](https://github.com/sqlmapproject/sqlmap) |
| Nuclei | テンプレートベースの脆弱性スキャナー | [GitHub](https://github.com/projectdiscovery/nuclei) |
| Caido | モダンWebプロキシ | [caido.io](https://caido.io) |
| PayloadsAllTheThings | ペイロードリポジトリ | [GitHub](https://github.com/swisskyrepo/PayloadsAllTheThings) |
</details>
<details>
<summary><b>Active Directory</b></summary>
| ツール | 目的 | リンク |
|------|---------|------|
| BloodHound | AD関係マッピング | [GitHub](https://github.com/SpecterOps/BloodHound) |
| Impacket | ネットワークプロトコルツールキット | [GitHub](https://github.com/fortra/impacket) |
| Rubeus | Kerberos悪用 | [GitHub](https://github.com/GhostPack/Rubeus) |
| Certipy | ADCSエクスプロイト | [GitHub](https://github.com/ly4k/Certipy) |
| NetExec (nxc) | ネットワーク実行ツールキット | [GitHub](https://github.com/Pennyw0rth/NetExec) |
| Ligolo-ng | トンネリング/ピボット | [GitHub](https://github.com/nicocha30/ligolo-ng) |
</details>
<details>
<summary><b>権限昇格</b></summary>
| ツール | 目的 | リンク |
|------|---------|------|
| LinPEAS | Linux権限昇格列挙 | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| WinPEAS | Windows権限昇格列挙 | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| pspy | プロセス監視(root不要) | [GitHub](https://github.com/DominicBreuker/pspy) |
| PowerUp | Windows権限昇格PowerShell | [GitHub](https://github.com/PowerShellMafia/PowerSploit) |
| GTFOBins | Unixバイナリエクスプロイト | [gtfobins.github.io](https://gtfobins.github.io) |
| LOLBAS | Windowsのland上での生活 | [lolbas-project.github.io](https://lolbas-project.github.io) |
</details>
<details>
<summary><b>フォレンジック&DFIR</b></summary>
| ツール | 目的 | リンク |
|------|---------|------|
| Volatility 3 | メモリフォレンジック | [GitHub](https://github.com/volatilityfoundation/volatility3) |
| Autopsy | ディスクフォレンジック | [autopsy.com](https://www.autopsy.com) |
| Wireshark | ネットワークキャプチャ分析 | [wireshark.org](https://www.wireshark.org) |
| CyberChef | データ変換 | [GitHub](https://github.com/gchq/CyberChef) |
| Chainsaw | Windowsイベントログ分析 | [GitHub](https://github.com/WithSecureLabs/chainsaw) |
</details>
<details>
<summary><b>リバースエンジニアリング</b></summary>
| ツール | 目的 | リンク |
|------|---------|------|
| Ghidra | バイナリ分析 | [ghidra-sre.org](https://ghidra-sre.org) |
| IDA Free | 逆アセンブラ | [hex-rays.com](https://hex-rays.com/ida-free) |
| radare2 | CLIリバースエンジニアリング | [GitHub](https://github.com/radareorg/radare2) |
| Binary Ninja | バイナリ分析プラットフォーム | [binary.ninja](https://binary.ninja) |
| dnSpy | .NET逆コンパイラ | [GitHub](https://github.com/dnSpy/dnSpy) |
</details>
<details>
<summary><b>バイナリエクスプロイト</b></summary>| ツール | 目的 | リンク |
|------|---------|------|
| pwntools | CTF エクスプロイトフレームワーク | [GitHub](https://github.com/Gallopsled/pwntools) |
| ROPgadget | ROP チェーンビルダー | [GitHub](https://github.com/JonathanSalwan/ROPgadget) |
| GEF | GDB 強化機能 | [GitHub](https://github.com/hugsy/gef) |
| one_gadget | libc ワンショットガジェット | [GitHub](https://github.com/david942j/one_gadget) |
| checksec | バイナリセキュリティチェック | [GitHub](https://github.com/slimm609/checksec.sh) |
</details>
### 認定資格対策
HTB で学んだ内容をプロフェッショナル認定資格に活かしましょう。
<details>
<summary><b>OSCP(Offensive Security Certified Professional)</b></summary>
**OSCP 対策におすすめの HTB マシン:**
| マシン | 難易度 | 主要スキル |
|---------|-----------|------------|
| Lame | Easy | Samba RCE、基本エクスプロイト |
| Legacy | Easy | MS08-067、Windows エクスプロイト |
| Blue | Easy | EternalBlue(MS17-010) |
| Optimum | Easy | HFS RCE、Windows 権限昇格 |
| Shocker | Easy | Shellshock、Linux 基礎 |
| Nibbles | Easy | CMS エクスプロイト、ファイルアップロード |
| Bashed | Easy | PHP ウェブシェル、Cron 悪用 |
| Arctic | Easy | ColdFusion、Windows エクスプロイト |
| Grandpa | Easy | IIS WebDAV、トークン偽装 |
| Bastard | Medium | Drupal RCE、Windows 権限昇格 |
| Cronos | Medium | DNS ゾーン転送、SQL インジェクション |
| SolidState | Medium | Apache James RCE、Cron 権限昇格 |
| Node | Medium | API エクスプロイト、カーネルエクスプロイト |
| Valentine | Easy | Heartbleed、tmux ハイジャック |
| Poison | Medium | LFI、VNC トンネリング |
| Sunday | Easy | Finger 列挙、シャドウファイル |
| DevOops | Medium | XXE、Git 秘密情報 |
| Jeeves | Medium | Jenkins RCE、KeePass クラッキング |
| Conceal | Hard | IPSec VPN、SNMP、JuicyPotato |
</details>
<details>
<summary><b>CPTS(Certified Penetration Testing Specialist)</b></summary>
**CPTS 対策におすすめの HTB マシン:**
| マシン | 難易度 | 主要スキル |
|---------|-----------|------------|
| Active | Easy | AD 基礎、GPP 悪用、Kerberoasting |
| Forest | Easy | AS-REP Roasting、DCSync |
| Sauna | Easy | AS-REP Roasting、WinRM |
| Monteverde | Medium | Azure AD、パスワードスプレー攻撃 |
| Resolute | Medium | DNS 管理者 DLL インジェクション |
| Cascade | Medium | LDAP 列挙、.NET リバースエンジニアリング |
| Blackfield | Hard | AS-REP、Backup Operators 権限昇格 |
| Vintage | Hard | 純正 AD エクスプロイト |
| Certificate | Hard | ADCS エクスプロイト |
| Support | Easy | LDAP、.NET バイナリ解析 |
</details>
<details>
<summary><b>CRTO(Certified Red Team Operator)</b></summary>
ProLabs に重点を置く:**RastaLabs** と **Zephyr** は CRTO の内容に直接対応しています。
| マシン/ラボ | 種類 | 主要スキル |
|-------------|------|------------|
| RastaLabs | ProLab | フィッシング、C2、横展開 |
| Zephyr | ProLab | ADCS、DPAPI、制約付き委任 |
| Offshore | ProLab | マルチドメイン AD |
| Reel | Hard | フィッシング、AppLocker 回避 |
| Mantis | Hard | AD、Kerberos、MS14-068 |
</details>
### チートシート
| チートシート | 説明 |
|------------|-------------|
| [Linux 列挙](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/linux-enumeration.md) | Linux 事後調査の列挙コマンド |
| [Windows 列挙](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/windows-enumeration.md) | Windows 事後調査の列挙コマンド |
| [Active Directory](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/active-directory.md) | AD 攻撃手法とコマンド |
| [Web アプリケーション](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/web-application.md) | Web エクスプロイト技術とペイロード |
| [権限昇格 - Linux](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-linux.md) | Linux 権限昇格ベクトル |
| [権限昇格 - Windows](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-windows.md) | Windows 権限昇格ベクトル |
| [ファイル転送](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/file-transfers.md) | マシン間でファイルを転送する方法 |
| [リバースシェル](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/reverse-shells.md) | 全言語のリバースシェルワンライナー |
| [ピボット&トンネリング](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/pivoting.md) | SSH トンネリング、Chisel、Ligolo、SOCKS |
| [パスワード攻撃](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/password-attacks.md) | クラッキング、スプレー攻撃、ブルートフォース |
### 方法論
| ガイド | 説明 |
|-------|-------------|
| [HTB マシンのアプローチ](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/machine-approach.md) | HTB マシンに体系的にアプローチする方法 |
| [ノート作成テンプレート](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/note-taking.md) | ライトアップ用の構造化されたノート作成 |
| [レポート作成](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/report-writing.md) | プロフェッショナルなペンテストレポートテンプレート |
---
## リポジトリ構造```
htb-writeups/
|-- machines/
| |-- easy/ # Easy difficulty machines
| |-- medium/ # Medium difficulty machines
| |-- hard/ # Hard difficulty machines
| |-- insane/ # Insane difficulty machines
|-- challenges/
| |-- web/ # Web exploitation challenges
| |-- crypto/ # Cryptography challenges
| |-- forensics/ # Digital forensics challenges
| |-- reversing/ # Reverse engineering challenges
| |-- pwn/ # Binary exploitation challenges
| |-- mobile/ # Mobile security challenges
| |-- hardware/ # Hardware hacking challenges
| |-- osint/ # OSINT challenges
| |-- misc/ # Miscellaneous challenges
| |-- stego/ # Steganography challenges
| |-- blockchain/ # Blockchain/smart contract challenges
| |-- ai-ml/ # AI/ML security challenges
|-- prolabs/
| |-- dante/ # Dante ProLab walkthrough
| |-- offshore/ # Offshore ProLab walkthrough
| |-- rastalabs/ # RastaLabs ProLab walkthrough
| |-- zephyr/ # Zephyr ProLab walkthrough
| |-- cybernetics/ # Cybernetics ProLab walkthrough
| |-- aptlabs/ # APTLabs ProLab walkthrough
|-- sherlocks/
| |-- easy/ # Easy DFIR investigations
| |-- medium/ # Medium DFIR investigations
| |-- hard/ # Hard DFIR investigations
|-- ctf-events/ # Official HTB CTF writeups
|-- endgames/ # Multi-machine scenarios
|-- fortresses/ # Fortress challenges
|-- resources/
| |-- cheatsheets/ # Quick reference guides
| |-- tools/ # Tool guides and configs
| |-- methodology/ # Approach guides and templates
| |-- cert-prep/ # Certification preparation guides
|-- templates/ # Writeup templates
コントリビューションを歓迎します! 詳細なガイドラインは CONTRIBUTING.md をご覧ください。
クイックスタート:
Writeupの要件:
これらのWriteupは教育目的のみのものです。すべてのコンテンツは、Hack The Boxプラットフォーム上で既に退役したマシンとチャレンジを扱っています。アクティブなマシンの解法を共有することは、HTBの利用規約に違反します。
常に倫理的なハッキングを実践し、明示的にテスト許可を得たシステムのみをテストしてください。
このリポジトリのマシンWriteupは、多様な視点を得るために複数の独立した著者にリンクしています。主な出典は以下の通りです。
このコレクションは、米国法人の攻撃的セキュリティ企業 GreyCore Labs によって構築・保守されています。あなたのプロダクトにも同じ目線を適用しませんか?
このプロジェクトはMITライセンスの下でライセンスされています。詳細は LICENSE をご覧ください。
このリポジトリがボックス攻略や資格取得に役立ったなら、スターを付けてください。他の人も見つけやすくなります。
キーワード: hack the box writeups, HTB walkthrough, hackthebox machines, HTB challenges, OSCP prep machines, CPTS certification, penetration testing writeups, CTF writeups, active directory hacking, privilege escalation, web exploitation, binary exploitation, digital forensics, incident response, red team, blue team, cybersecurity training, ethical hacking, infosec resources, security cheatsheets
| 著者 / 出典 | URL | カバレッジ |
|---|
| 0xdf | 0xdf.gitlab.io | 500以上のマシン – 黄金基準、徹底した詳細 |
| IppSec | youtube.com/ippsec | 430以上の動画ウォークスルー(ライブデバッグ付き) |
| HackingArticles | hackingarticles.in | 40以上のマシン – Raj Chandel、クラシック時代(2017-2022) |
| Rana Khalil | rana-khalil.gitbook.io | 26以上のマシン – OSCP重視、Metasploit不使用 |
| snowscan | snowscan.io | 20以上のマシン – 詳細で一貫した品質 |
| 0xRick | 0xrick.github.io | 10以上のマシン – クリーンなブログ形式のWriteup |
| Medium / InfoSecWriteups | medium.com | 45以上のマシン – 多様なコミュニティ著者 |
| リソース | 説明 |
|---|
| HackTricks | 包括的なペネトレーションテストリファレンス |
| PayloadsAllTheThings | ペイロードとバイパス手法のコレクション |
| The Hacker Recipes | 構造化された攻撃レシピ |
| GTFOBins | Unixバイナリ悪用リファレンス |
| LOLBAS | WindowsのLOL(Living-off-the-land)バイナリ |
| WADComs | Windows/ADコマンドリファレンス |
| RevShells | リバースシェルジェネレーター |
| CyberChef | データ変換ツールキット |
| SecLists | セキュリティテスト用ワードリスト |
| IppSec.rocks | IppSecのHTB動画の検索可能インデックス |