Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
htb-writeups — 500개 이상의 Hack The Box 머신 라이트업, 400개 이상의 챌린지 솔루션, 그리고 침투 테스트 및 인증 시험 준비를 위한 지식 그래프, 공격 경로 다이어그램, 스킬 트리를 포함한 대화형 학습 도구의 체계적인 모음입니다. | Kitploit
도구/GitHubGitHub/momenbasel/htb-writeups
OSINT (Open Source Intelligence)Privilege EscalationExploitationForensicsWeb SecurityCTFPenetration TestingLearning & EducationCurated ResourcesLabs & Practice
GitHubmomenbasel/htb-writeups

htb-writeups

201411개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

500개 이상의 Hack The Box 머신 라이트업, 400개 이상의 챌린지 솔루션, 그리고 침투 테스트 및 인증 시험 준비를 위한 지식 그래프, 공격 경로 다이어그램, 스킬 트리를 포함한 대화형 학습 도구의 체계적인 모음입니다.

저장소 보기웹사이트

Hack The Box Writeups - 최고의 HTB 리소스

GitHub에서 가장 포괄적인 Hack The Box writeups, walkthroughs, cheatsheets 컬렉션입니다. 500개 이상의 머신, 400개 이상의 챌린지, ProLabs, Sherlocks (DFIR), CTF 이벤트, 침투 테스팅 방법론, 그리고 OSCP/CPTS 인증 준비 - 모든 것이 한 곳에 있습니다.``` ___ ___ ___________ __ __ .__ __
/ | \ __ / / \ / ___||/ | ____ __ ________ ______
/ ~ \ | | \ // /_ __ | \ / __ | | _
/ /
\ Y / | | \ / | | /| || | \ /| | / |> >
\
_
|_ / || _/\ / || |||| ___ >_/| / >
/ / / |__| /

root@kitploit:~
[![멋짐](https://awesome.re/badge-flat2.svg)](https://awesome.re)
[![별](https://img.shields.io/github/stars/momenbasel/htb-writeups?style=for-the-badge&color=yellow)](https://github.com/momenbasel/htb-writeups/stargazers)
[![포크](https://img.shields.io/github/forks/momenbasel/htb-writeups?style=for-the-badge&color=blue)](https://github.com/momenbasel/htb-writeups/network/members)
[![기여자](https://img.shields.io/github/contributors/momenbasel/htb-writeups?style=for-the-badge&color=green)](https://github.com/momenbasel/htb-writeups/graphs/contributors)
[![라이선스](https://img.shields.io/github/license/momenbasel/htb-writeups?style=for-the-badge)](LICENSE)
[![마지막 커밋](https://img.shields.io/github/last-commit/momenbasel/htb-writeups?style=for-the-badge&color=red)](https://github.com/momenbasel/htb-writeups/commits/main)

**이 저장소가 필요한 이유?** 흩어져 있는 블로그 게시물이나 단일 작성자 모음과 달리, 이곳은 **구조화되고 검색 가능한 인덱스**로 HTB 생태계 전체(2017~2026년의 머신, 모든 CTF 이벤트, 모든 챌린지 카테고리, 모든 ProLab)를 기술, 난이도, OS, 인증 관련성으로 상호 참조합니다. **OSCP**, **CPTS**, **CRTO**를 준비 중이거나 단순히 실력을 연마하는 중이라면 여기에서 시작하세요.

> **[사이트 방문하기](https://momenbasel.github.io/htb-writeups/)** - 대화형 도구, 검색, 다크 테마를 지원하는 최상의 경험을 누려보세요.

---

## 대화형 도구

|  | 도구 | 설명 |
|--|------|-------------|
| **[머신 파인더](https://momenbasel.github.io/htb-writeups/finder/)** | 검색 및 필터 | 난이도, OS, 기술, CVE 또는 인증별로 머신을 검색합니다. 실시간 필터링이 있는 테이블 및 카드 보기. |
| **[지식 그래프](https://momenbasel.github.io/htb-writeups/graph/)** | 시각적 탐색기 | 70개 이상의 머신과 40개 이상의 기술, 5개의 인증을 매핑하는 대화형 D3.js 힘-방향 그래프. |
| **[공격 경로](https://momenbasel.github.io/htb-writeups/attack-paths/)** | 순서도 | 정찰부터 루트까지의 완전한 공격 체인을 보여주는 Mermaid 다이어그램 (25개 이상의 머신). |
| **[스킬 트리](https://momenbasel.github.io/htb-writeups/skill-trees/)** | 진행 맵 | AD 공격, 웹 익스플로잇, Linux/Windows 권한 상승, 인증 준비를 위한 시각적 학습 경로. |

---

## 내부 구성

| 섹션 | 설명 | 개수 |
|---------|-------------|-------|
| [머신들](#machines) | Boot2root 워크스루 (쉬움 ~ 매우 어려움) | 300+ |
| [챌린지](#challenges) | 12개 카테고리의 CTF 스타일 챌린지 | 400+ |
| [ProLab](#prolabs) | 네트워크 토폴로지 다이어그램이 포함된 엔터프라이즈급 랩 워크스루 | 6 |
| [셜록](#sherlocks) | DFIR 및 블루 팀 조사 | 70+ |
| [CTF 이벤트](#ctf-events) | 공식 HTB CTF 대회 워크스루 | 14개 이벤트 |
| [엔드게임](#endgames) | 다중 머신 시나리오 워크스루 | 5 |
| [포트리스](#fortresses) | 다중 플래그 단일 호스트 챌린지 | 6 |
| [리소스](#resources) | 도구, 치트시트, 인증 준비, 방법론 | 10개 가이드 |

---

## 머신들

난이도별로 정리된 은퇴한 HTB 머신의 워크스루입니다. 각 워크스루는 열거, 익스플로잇, 권한 상승 단계를 전체 명령 출력과 함께 포함합니다.

### 난이도별

| 난이도 | 경로 | 머신 수 |
|------------|------|----------|
| 쉬움 | [`machines/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/) | 132+ |
| 중간 | [`machines/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/) | 136+ |
| 어려움 | [`machines/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | 70+ |
| 매우 어려움 | [`machines/insane/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | 50+ |

### 최근 은퇴한 머신 (2025–2026)

| 머신 | OS | 난이도 | 주요 기술 | 날짜 |
|---------|----|------------|----------------|------|
| [MonitorsFour](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/MonitorsFour/) | Windows | 매우 어려움 | PHP 타입 저글링, Cacti CVE, Docker API 탈출 | May 2026 |
| [Pterodactyl](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Pterodactyl/) | openSUSE | 매우 어려움 | Pterodactyl Panel CVE-2025-49132, PEAR pearcmd LFI, Polkit | May 2026 |
| [Helix](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Helix/) | Linux | 중간 | Apache NiFi ExecuteSQL + H2 Java Alias RCE | May 2026 |
| [Overwatch](https://0xdf.gitlab.io/2026/05/09/htb-overwatch.html) | Windows | 매우 어려움 | .NET 리버싱, WCF 서비스 인젝션, DNS | May 2026 |
| [Sorcery](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Sorcery/) | Linux | 매우 어려움 | Cypher Injection, WebAuthn XSS, Kafka, FreeIPA | Apr 2026 |
| [PingPong](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/PingPong/) | Windows | 어려움 | 다중 포리스트 AD, MSSQL 위임, ADCS | Apr 2026 |
| [AirTouch](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/AirTouch/) | Linux | 어려움 | 802.11 WPA2 크랙, Evil Twin, PEAP-MSCHAPv2 | Apr 2026 |
| [Eighteen](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Eighteen/) | Windows | 어려움 | Win Server 2025, MSSQL Impersonation, Bad Successor dMSA | Apr 2026 |
| [DarkZero](https://0xdf.gitlab.io/2026/04/04/htb-darkzero.html) | Windows | 어려움 | 교차 포리스트 트러스트, AD 남용 | Apr 2026 |
| [Pirate](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/Pirate/) | Windows | 어려움 | Pre2k, gMSA, PetitPotam, RBCD, S4U SPN Jack | Feb 2026 |
| [VariaType](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/VariaType/) | Linux | 중간 | fontTools CVE-2025-66034, FontForge CVE-2024-25082 | Mar 2026 |
| [Interpreter](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/medium/Interpreter/) | Linux | 중간 | Mirth Connect CVE-2023-43208, Python eval() | Feb 2026 |
| [Kobold](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Kobold/) | Linux | 쉬움 | MCPJam CVE-2026-23744, Docker 그룹 | Mar 2026 |
| [Facts](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Facts/) | Linux | 쉬움 | Camaleon CMS IDOR + 경로 탐색 + Facter Sudo | Jan 2026 |
| [Code](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/easy/Code/) | Linux | 쉬움 | Python 샌드박스 우회, Backy Sudo | Aug 2025 |
| [Cobblestone](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/Cobblestone/) | Linux | 매우 어려움 | 2차 SQLi, Twig SSTI, Cobbler XMLRPC | 2025 |
| [Snapped](https://0xdf.gitlab.io/2026/04/01/htb-snapped.html) | Linux | 어려움 | Nginx UI RCE, 정적 사이트 익스플로잇 | Mar 2026 |
| [Browsed](https://0xdf.gitlab.io/2026/03/28/htb-browsed.html) | Linux | 중간 | 브라우저 확장 익스플로잇, Headless Chrome | Mar 2026 |
| [Previous](https://0xdf.gitlab.io/2026/01/10/htb-previous.html) | Linux | 중간 | NextJS 익스플로잇, 프레임워크 남용 | Jan 2026 |
| [Retire](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Windows | 어려움 | Active Directory, Kerberos 남용 | Jan 2026 |
| [Fries](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | 어려움 | 웹 익스플로잇, 사용자 정의 익스플로잇 | Nov 2025 |
| [NanoCorp](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/hard/) | Linux | 어려움 | 사용자 정의 프로토콜, 이진 분석 | Nov 2025 |
| [Hercules](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/insane/) | Linux | 매우 어려움 | 다단계 익스플로잇 | Oct 2025 |
| [Signed](https://0xdf.gitlab.io/2026/02/07/htb-signed.html) | Windows | 중간 | 코드 서명 우회, 인증서 남용 | Oct 2025 |
| [University](https://0xdf.gitlab.io/2025/08/09/htb-university.html) | Windows | 매우 어려움 | 다중 벡터 공격, 복잡한 체인 | Aug 2025 |
| [Dog](https://0xdf.gitlab.io/2025/07/12/htb-dog.html) | Linux | 쉬움 | Backdrop CMS, 웹 익스플로잇 | Jul 2025 |
| [Mirage](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) | Windows | 어려움 | Active Directory, ADCS | Jul 2025 |
| [Voleur](https://0xdf.gitlab.io/2025/11/01/htb-voleur.html) | Windows | 중간 | 데이터 유출, 사용자 정의 익스플로잇 | Jul 2025 |
| [RustyKey](https://0xdf.gitlab.io/2025/11/08/htb-rustykey.html) | Windows | 어려움 | Rust 이진 익스플로잇 | Jun 2025 |
| [TombWatcher](https://0xdf.gitlab.io/2025/10/11/htb-tombwatcher.html) | Windows | 중간 | 사용자 정의 서비스 익스플로잇 | Jun 2025 |
| [Haze](https://0xdf.gitlab.io/2025/06/28/htb-haze.html) | Windows | 어려움 | Splunk Enterprise 익스플로잇 | Jun 2025 |
| [Certificate](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html) | Windows | 어려움 | ADCS, 인증서 템플릿 남용 | May 2025 |
| [Vintage](https://0xdf.gitlab.io/2025/04/26/htb-vintage.html) | Windows | 어려움 | 순수 Active Directory, Kerberoasting | Apr 2025 |

### 운영 체제별

- **Linux** - [`machines/` OS 필터링](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Ubuntu, Debian, CentOS, 사용자 정의 배포판
- **Windows** - [`machines/` OS 필터링](https://github.com/momenbasel/htb-writeups/blob/HEAD/machines/) - Windows Server, Active Directory 환경
- **FreeBSD/OpenBSD** - 드물지만 더 높은 난이도에 존재함

### 기술별

<details>
<summary><b>Active Directory</b> - Kerberoasting, AS-REP Roasting, ADCS, DCSync, Pass-the-Hash, BloodHound</summary>

| 머신 | 난이도 | 특정 AD 기술 |
|---------|------------|-----------------------|
| DarkZero | 어려움 | 교차 포리스트 트러스트 남용 |
| Vintage | 어려움 | Kerberoasting, 순수 AD |
| Certificate | 어려움 | ADCS 인증서 템플릿 남용 |
| Mirage | 어려움 | ADCS, Shadow Credentials |
| Haze | 어려움 | Splunk + AD 통합 |
| Retire | 어려움 | Kerberos 위임 남용 |

</details>

<details>
<summary><b>웹 익스플로잇</b> - SQLi, XSS, SSRF, SSTI, LFI/RFI, 역직렬화</summary>

| 머신 | 난이도 | 특정 웹 기술 |
|---------|------------|-----------------------|
| Dog | 쉬움 | Backdrop CMS RCE |
| Browsed | 중간 | 브라우저 확장 RCE |
| Previous | 중간 | NextJS 프레임워크 익스플로잇 |
| Snapped | 어려움 | Nginx UI 관리자 패널 RCE |
| Fries | 어려움 | 사용자 정의 웹 앱 익스플로잇 |

</details>

<details>
<summary><b>이진 익스플로잇</b> - 버퍼 오버플로우, ROP, 힙 익스플로잇, 포맷 문자열</summary>

| 머신 | 난이도 | 특정 기술 |
|---------|------------|-----------------------|
| RustyKey | 어려움 | Rust 이진 익스플로잇 |
| NanoCorp | 어려움 | 사용자 정의 프로토콜 익스플로잇 |

</details>

<details>
<summary><b>클라우드 및 인프라</b> - AWS, Azure, GCP, Docker, Kubernetes</summary>

| 머신 | 난이도 | 특정 기술 |
|---------|------------|-----------------------|
| Hercules | 매우 어려움 | 컨테이너 탈출, 클라우드 메타데이터 |

</details>

---

## 챌린지

카테고리별로 정리된 CTF 스타일 챌린지. 각 워크스루는 챌린지 설명, 접근 방식, 해결 방법, 배운 점을 포함합니다.

| 카테고리 | 경로 | 개수 | 주요 기술 |
|----------|------|-------|------------|
| 웹 | [`challenges/web/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/web/) | 75+ | XSS, SQLi, SSTI, SSRF, 역직렬화, JWT, GraphQL |
| 암호 | [`challenges/crypto/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/crypto/) | 93+ | RSA, AES, ECC, Padding Oracle, PRNG, Lattice Attack |
| 포렌식 | [`challenges/forensics/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/forensics/) | 33+ | 메모리 분석, 디스크 포렌식, 네트워크 PCAP, 악성코드 |
| 리버싱 | [`challenges/reversing/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/reversing/) | 44+ | x86/x64, .NET, Python, Angr, Anti-Debug, VM |
| Pwn | [`challenges/pwn/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/pwn/) | 61+ | 스택/힙 오버플로우, ROP, SROP, 커널, tcache |
| 모바일 | [`challenges/mobile/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/mobile/) | 10+ | Android APK, Frida, Smali, 인증서 고정 |
| 하드웨어 | [`challenges/hardware/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/hardware/) | 11+ | UART, SPI, 펌웨어, VHDL, RF 분석 |
| OSINT | [`challenges/osint/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/osint/) | 12+ | 지리적 위치, 소셜 미디어, DNS, 메타데이터 |
| 기타 | [`challenges/misc/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/misc/) | 35+ | 스크립팅, 로직, 인코딩, Pickle, Pyjail |
| 스테가노그래피 | [`challenges/stego/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/stego/) | 12+ | 이미지, 오디오, LSB, Steghide, ImageMagick |
| 블록체인 | [`challenges/blockchain/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/blockchain/) | 10+ | Solidity, 스마트 계약, ERC-721, ECDSA |
| AI/ML | [`challenges/ai-ml/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/challenges/ai-ml/) | 5+ | 적대적 ML, 프롬프트 인젝션, LLM 우회 |

---

## ProLab

실제 기업 네트워크를 시뮬레이션하는 엔터프라이즈급 랩 환경. 이 워크스루는 다중 머신 공격 경로, 측면 이동, 도메인 장악을 다룹니다.

| 랩 | 난이도 | 머신 수 | 초점 |
|-----|-----------|----------|-------|
| [Dante](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 초급 | 14 | 네트워크 침투 테스트 기초 |
| [Offshore](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 중급 | 21 | Active Directory, 다중 도메인 |
| [RastaLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 중급 | 15 | 레드 팀 시뮬레이션, 피싱 |
| [Zephyr](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 중급 | 17 | ADCS, DPAPI, 제한된 위임 |
| [Cybernetics](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 고급 | 20+ | 고급 AD, 교차 포리스트 공격 |
| [APTLabs](https://github.com/momenbasel/htb-writeups/blob/HEAD/prolabs/#{0}) | 고급 | 20+ | APT 시뮬레이션, 다중 벡터 |

---

## 셜록

DFIR(디지털 포렌식 및 침해 대응) 조사 랩. 보안 사고를 조사하고 포렌식 질문에 답변하는 블루 팀 시나리오.

| 카테고리 | 경로 | 초점 |
|----------|------|-------|
| 쉬움 | [`sherlocks/easy/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | 로그 분석, 기본 DFIR |
| 중간 | [`sherlocks/medium/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | 메모리 포렌식, 악성코드 트라이지 |
| 어려움 | [`sherlocks/hard/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/) | APT 조사, 복합 IR |

### 주요 셜록

| 이름 | 난이도 | 초점 영역 | 워크스루 |
|------|-----------|------------|---------|
| Meerkat | 쉬움 | Suricata IDS, 자격 증명 스터핑, CVE-2022-25237 | [0xdf](https://0xdf.gitlab.io/2024/04/23/htb-sherlock-meerkat.html) |
| Brutus | 쉬움 | SSH 무차별 대입, auth.log 분석 | [0xdf](https://0xdf.gitlab.io/2024/04/09/htb-sherlock-brutus.html) |
| Noted | 쉬움 | Notepad++ 아티팩트, 데이터 갈취 | [0xdf](https://0xdf.gitlab.io/2024/06/13/htb-sherlock-noted.html) |
| Knock Knock | 쉬움 | PCAP, FTP, 포트 노킹, GonnaCry 랜섬웨어 | [0xdf](https://0xdf.gitlab.io/2023/12/04/htb-sherlock-knock-knock.html) |
| Bumblebee | 쉬움 | phpBB SQLite, 액세스 로그 분석 | [0xdf](https://0xdf.gitlab.io/2024/05/22/htb-sherlock-bumblebee.html) |
| Crown Jewel-1 | 중간 | NTDS.dit 덤프, 볼륨 섀도 복사본 서비스 | [CyberWired](https://www.cyberwiredtraining.net/writeups/htb-sherlock-crownjewel-1-jezdr) |
| Noxious | 중간 | LLMNR 포이즈닝, 불량 장치 탐지 | [0xdf](https://0xdf.gitlab.io/2024/09/04/htb-sherlock-noxious.html) |
| Subatomic | 중간 | Electron 악성코드, Discord 하이재킹 | [0xdf](https://0xdf.gitlab.io/2024/04/18/htb-sherlock-subatomic.html) |
| Nubilum-1 | 중간 | AWS CloudTrail, PoshC2, 클라우드 포렌식 | [0xdf](https://0xdf.gitlab.io/2024/05/30/htb-sherlock-nubilum-1.html) |
| MisCloud | 중간 | GCP 침해, Gitea 취약점 | [CyberEthical](https://blog.cyberethical.me/htb-sherlock-miscloud) |
| OpTinselTrace (1-5) | 어려움 | 전체 APT 캠페인 조사 (2023년 크리스마스) | [GitHub](https://github.com/dbissell6/DFIR/blob/main/WalkThroughs/OpTinselTrace-1-5.md) |
| APTNightmare | 어려움 | 고급 지속 위협 조사 | [GitHub](https://github.com/jon-brandy/hackthebox/blob/main/Categories/Sherlocks/APTNightmare/README.md) |

전체 셜록 인덱스는 [셜록 전체 목록](https://github.com/momenbasel/htb-writeups/blob/HEAD/sherlocks/README.md)에서 70개 이상의 셜록과 워크스루 링크를 확인하세요.

---

## CTF 이벤트

공식 Hack The Box 경쟁 CTF 이벤트의 워크스루.

| 이벤트 | 연도 | 경로 | 하이라이트 |
|-------|------|------|------------|
| Cyber Apocalypse | 2025 | [`ctf-events/cyber-apocalypse-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 웹, 암호, Pwn, 포렌식 |
| Business CTF | 2025 | [`ctf-events/business-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 기업 보안 초점 |
| University CTF | 2025 | [`ctf-events/university-ctf-2025/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 학술 팀 대회 |
| Cyber Apocalypse | 2024 | [`ctf-events/cyber-apocalypse-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 해커 로얄 테마 |
| Business CTF | 2024 | [`ctf-events/business-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | 기업 시나리오 |
| University CTF | 2024 | [`ctf-events/university-ctf-2024/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/ctf-events/) | Binary Badlands 테마 |

---

## 엔드게임

실제 침투 테스트 업무를 시뮬레이션하는 다중 머신, 다단계 시나리오. 자세한 워크스루는 [`endgames/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/README.md)를 참조하세요.

| 엔드게임 | 경로 | 플래그 수 | 초점 |
|---------|------|-------|-------|
| P.O.O. | [`endgames/poo/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5 | MSSQL 연결 서버, IIS 열거 |
| Xen | [`endgames/xen/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | Citrix 탈출, AD, 피싱 |
| Hades | [`endgames/hades/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 5+ | AS-REP Roast, DPAPI, RBCD, DNS 스푸핑 |
| RPG | [`endgames/rpg/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 6 | Linux 익스플로잇, 다중 호스트 피보팅 |
| Ascension | [`endgames/ascension/`](https://github.com/momenbasel/htb-writeups/blob/HEAD/endgames/) | 7 | Blind SQLi, MSSQL 프록시, RBCD |

---

## 포트리스

파트너 회사가 만든 다중 플래그 단일 호스트 챌린지. 강화된 머신과 같습니다. 자세한 워크스루는 [`fortresses/README.md`](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/README.md)를 참조하세요.

| 포트리스 | 제작자 | 플래그 수 | 초점 |
|----------|---------|-------|-------|
| [Jet](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Jet | 11 | 다중 서비스 익스플로잇 |
| [Akerva](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Akerva | 8 | WordPress, SNMP, 웹 체인 |
| [Context](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Context/Accenture | 7 | 웹 + 인프라 |
| [Synacktiv](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Synacktiv | 여러 개 | Symfony, AppSec, 인프라 |
| [AWS](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Amazon Web Services | 여러 개 | 클라우드 보안, IAM, Lambda, S3 |
| [Faraday](https://github.com/momenbasel/htb-writeups/blob/HEAD/fortresses/) | Faraday | 7 | 일반 공격적 보안 |

---

## 리소스

### 카테고리별 도구

<details>
<summary><b>열거 및 정찰</b></summary>

| 도구 | 목적 | 링크 |
|------|---------|------|
| Nmap | 포트 스캐닝 및 서비스 탐지 | [nmap.org](https://nmap.org) |
| RustScan | 빠른 포트 스캐너 | [GitHub](https://github.com/RustScan/RustScan) |
| Gobuster | 디렉터리/DNS/vhost 무차별 대입 | [GitHub](https://github.com/OJ/gobuster) |
| Feroxbuster | 재귀적 콘텐츠 발견 | [GitHub](https://github.com/epi052/feroxbuster) |
| ffuf | 빠른 웹 퍼저 | [GitHub](https://github.com/ffuf/ffuf) |
| enum4linux-ng | SMB/Samba 열거 | [GitHub](https://github.com/cddmp/enum4linux-ng) |

</details>

<details>
<summary><b>웹 익스플로잇</b></summary>

| 도구 | 목적 | 링크 |
|------|---------|------|
| Burp Suite | 웹 프록시 및 스캐너 | [portswigger.net](https://portswigger.net/burp) |
| SQLMap | SQL 인젝션 자동화 | [GitHub](https://github.com/sqlmapproject/sqlmap) |
| Nuclei | 템플릿 기반 취약점 스캐너 | [GitHub](https://github.com/projectdiscovery/nuclei) |
| Caido | 현대식 웹 프록시 | [caido.io](https://caido.io) |
| PayloadsAllTheThings | 페이로드 저장소 | [GitHub](https://github.com/swisskyrepo/PayloadsAllTheThings) |

</details>

<details>
<summary><b>Active Directory</b></summary>

| 도구 | 목적 | 링크 |
|------|---------|------|
| BloodHound | AD 관계 매핑 | [GitHub](https://github.com/SpecterOps/BloodHound) |
| Impacket | 네트워크 프로토콜 툴킷 | [GitHub](https://github.com/fortra/impacket) |
| Rubeus | Kerberos 남용 | [GitHub](https://github.com/GhostPack/Rubeus) |
| Certipy | ADCS 익스플로잇 | [GitHub](https://github.com/ly4k/Certipy) |
| NetExec (nxc) | 네트워크 실행 툴킷 | [GitHub](https://github.com/Pennyw0rth/NetExec) |
| Ligolo-ng | 터널링/피보팅 | [GitHub](https://github.com/nicocha30/ligolo-ng) |

</details>

<details>
<summary><b>권한 상승</b></summary>

| 도구 | 목적 | 링크 |
|------|---------|------|
| LinPEAS | Linux 권한 상승 열거 | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| WinPEAS | Windows 권한 상승 열거 | [GitHub](https://github.com/peass-ng/PEASS-ng) |
| pspy | 프로세스 모니터링 (루트 없음) | [GitHub](https://github.com/DominicBreuker/pspy) |
| PowerUp | Windows 권한 상승 PowerShell | [GitHub](https://github.com/PowerShellMafia/PowerSploit) |
| GTFOBins | Unix 이진 익스플로잇 | [gtfobins.github.io](https://gtfobins.github.io) |
| LOLBAS | Windows living-off-the-land | [lolbas-project.github.io](https://lolbas-project.github.io) |

</details>

<details>
<summary><b>포렌식 및 DFIR</b></summary>

| 도구 | 목적 | 링크 |
|------|---------|------|
| Volatility 3 | 메모리 포렌식 | [GitHub](https://github.com/volatilityfoundation/volatility3) |
| Autopsy | 디스크 포렌식 | [autopsy.com](https://www.autopsy.com) |
| Wireshark | 네트워크 캡처 분석 | [wireshark.org](https://www.wireshark.org) |
| CyberChef | 데이터 변환 | [GitHub](https://github.com/gchq/CyberChef) |
| Chainsaw | Windows 이벤트 로그 분석 | [GitHub](https://github.com/WithSecureLabs/chainsaw) |

</details>

<details>
<summary><b>리버스 엔지니어링</b></summary>

| 도구 | 목적 | 링크 |
|------|---------|------|
| Ghidra | 이진 분석 | [ghidra-sre.org](https://ghidra-sre.org) |
| IDA Free | 디스어셈블러 | [hex-rays.com](https://hex-rays.com/ida-free) |
| radare2 | CLI 리버스 엔지니어링 | [GitHub](https://github.com/radareorg/radare2) |
| Binary Ninja | 이진 분석 플랫폼 | [binary.ninja](https://binary.ninja) |
| dnSpy | .NET 디컴파일러 | [GitHub](https://github.com/dnSpy/dnSpy) |

</details>

<details>
<summary><b>이진 익스플로잇</b></summary>| 도구 | 용도 | 링크 |
|------|---------|------|
| pwntools | CTF 익스플로잇 프레임워크 | [GitHub](https://github.com/Gallopsled/pwntools) |
| ROPgadget | ROP 체인 빌더 | [GitHub](https://github.com/JonathanSalwan/ROPgadget) |
| GEF | GDB 향상 기능 | [GitHub](https://github.com/hugsy/gef) |
| one_gadget | libc 원샷 가젯 | [GitHub](https://github.com/david942j/one_gadget) |
| checksec | 바이너리 보안 검사 | [GitHub](https://github.com/slimm609/checksec.sh) |

</details>

### 인증 시험 대비

HTB 여정을 전문 자격증에 연결하세요.

<details>
<summary><b>OSCP (Offensive Security Certified Professional)</b></summary>

**OSCP 준비를 위한 추천 HTB 머신:**

| 머신 | 난이도 | 주요 기술 |
|---------|-----------|------------|
| Lame | 쉬움 | Samba RCE, 기본 익스플로잇 |
| Legacy | 쉬움 | MS08-067, Windows 익스플로잇 |
| Blue | 쉬움 | EternalBlue (MS17-010) |
| Optimum | 쉬움 | HFS RCE, Windows 권한 상승 |
| Shocker | 쉬움 | Shellshock, 리눅스 기초 |
| Nibbles | 쉬움 | CMS 익스플로잇, 파일 업로드 |
| Bashed | 쉬움 | PHP 웹쉘, Cron 남용 |
| Arctic | 쉬움 | ColdFusion, Windows 익스플로잇 |
| Grandpa | 쉬움 | IIS WebDAV, 토큰 가장 |
| Bastard | 중간 | Drupal RCE, Windows 권한 상승 |
| Cronos | 중간 | DNS 존 전송, SQL 인젝션 |
| SolidState | 중간 | Apache James RCE, Cron 권한 상승 |
| Node | 중간 | API 익스플로잇, 커널 익스플로잇 |
| Valentine | 쉬움 | Heartbleed, tmux 하이재킹 |
| Poison | 중간 | LFI, VNC 터널링 |
| Sunday | 쉬움 | Finger 열거, 섀도 파일 |
| DevOops | 중간 | XXE, Git 비밀 |
| Jeeves | 중간 | Jenkins RCE, KeePass 크래킹 |
| Conceal | 어려움 | IPSec VPN, SNMP, JuicyPotato |

</details>

<details>
<summary><b>CPTS (Certified Penetration Testing Specialist)</b></summary>

**CPTS 준비를 위한 추천 HTB 머신:**

| 머신 | 난이도 | 주요 기술 |
|---------|-----------|------------|
| Active | 쉬움 | AD 기초, GPP 남용, Kerberoasting |
| Forest | 쉬움 | AS-REP 로스팅, DCSync |
| Sauna | 쉬움 | AS-REP 로스팅, WinRM |
| Monteverde | 중간 | Azure AD, 비밀번호 스프레이 공격 |
| Resolute | 중간 | DNS 관리자 DLL 인젝션 |
| Cascade | 중간 | LDAP 열거, .NET 리버싱 |
| Blackfield | 어려움 | AS-REP, Backup Operators 권한 상승 |
| Vintage | 어려움 | 순수 AD 익스플로잇 |
| Certificate | 어려움 | ADCS 익스플로잇 |
| Support | 쉬움 | LDAP, .NET 바이너리 분석 |

</details>

<details>
<summary><b>CRTO (Certified Red Team Operator)</b></summary>

ProLabs에 집중: **RastaLabs** 및 **Zephyr**는 CRTO 자료와 직접적으로 연관됩니다.

| 머신/랩 | 유형 | 주요 기술 |
|-------------|------|------------|
| RastaLabs | ProLab | 피싱, C2, 측면 이동 |
| Zephyr | ProLab | ADCS, DPAPI, 제한된 위임 |
| Offshore | ProLab | 다중 도메인 AD |
| Reel | 어려움 | 피싱, AppLocker 우회 |
| Mantis | 어려움 | AD, Kerberos, MS14-068 |

</details>

### 치트시트

| 치트시트 | 설명 |
|------------|-------------|
| [Linux 열거](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/linux-enumeration.md) | 포스트 익스플로잇 리눅스 열거 명령어 |
| [Windows 열거](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/windows-enumeration.md) | 포스트 익스플로잇 Windows 열거 명령어 |
| [Active Directory](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/active-directory.md) | AD 공격 방법론 및 명령어 |
| [웹 애플리케이션](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/web-application.md) | 웹 익스플로잇 기술 및 페이로드 |
| [권한 상승 - 리눅스](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-linux.md) | 리눅스 권한 상승 벡터 |
| [권한 상승 - Windows](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/privesc-windows.md) | Windows 권한 상승 벡터 |
| [파일 전송](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/file-transfers.md) | 머신 간 파일 전송 방법 |
| [리버스 셸](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/reverse-shells.md) | 모든 언어용 리버스 셸 원라이너 |
| [피벗 및 터널링](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/pivoting.md) | SSH 터널링, Chisel, Ligolo, SOCKS |
| [비밀번호 공격](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/cheatsheets/password-attacks.md) | 크래킹, 스프레이 공격, 무차별 대입 |

### 방법론

| 가이드 | 설명 |
|-------|-------------|
| [HTB 머신 접근법](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/machine-approach.md) | 모든 HTB 머신에 체계적으로 접근하는 방법 |
| [노트 작성 템플릿](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/note-taking.md) | 라이트업을 위한 체계적인 노트 작성 |
| [보고서 작성](https://github.com/momenbasel/htb-writeups/blob/HEAD/resources/methodology/report-writing.md) | 전문적인 침투 테스트 보고서 템플릿 |

---

## 저장소 구조```
htb-writeups/
|-- machines/
|   |-- easy/                    # Easy difficulty machines
|   |-- medium/                  # Medium difficulty machines
|   |-- hard/                    # Hard difficulty machines
|   |-- insane/                  # Insane difficulty machines
|-- challenges/
|   |-- web/                     # Web exploitation challenges
|   |-- crypto/                  # Cryptography challenges
|   |-- forensics/               # Digital forensics challenges
|   |-- reversing/               # Reverse engineering challenges
|   |-- pwn/                     # Binary exploitation challenges
|   |-- mobile/                  # Mobile security challenges
|   |-- hardware/                # Hardware hacking challenges
|   |-- osint/                   # OSINT challenges
|   |-- misc/                    # Miscellaneous challenges
|   |-- stego/                   # Steganography challenges
|   |-- blockchain/              # Blockchain/smart contract challenges
|   |-- ai-ml/                   # AI/ML security challenges
|-- prolabs/
|   |-- dante/                   # Dante ProLab walkthrough
|   |-- offshore/                # Offshore ProLab walkthrough
|   |-- rastalabs/               # RastaLabs ProLab walkthrough
|   |-- zephyr/                  # Zephyr ProLab walkthrough
|   |-- cybernetics/             # Cybernetics ProLab walkthrough
|   |-- aptlabs/                 # APTLabs ProLab walkthrough
|-- sherlocks/
|   |-- easy/                    # Easy DFIR investigations
|   |-- medium/                  # Medium DFIR investigations
|   |-- hard/                    # Hard DFIR investigations
|-- ctf-events/                  # Official HTB CTF writeups
|-- endgames/                    # Multi-machine scenarios
|-- fortresses/                  # Fortress challenges
|-- resources/
|   |-- cheatsheets/             # Quick reference guides
|   |-- tools/                   # Tool guides and configs
|   |-- methodology/             # Approach guides and templates
|   |-- cert-prep/               # Certification preparation guides
|-- templates/                   # Writeup templates

이 저장소 사용 방법

초보자용

  1. Easy 난이도의 머신부터 시작하세요 - 기본기를 가르쳐줍니다
  2. 머신 접근 가이드 를 따라 체계적인 방법을 익히세요
  3. 자격증을 준비 중이라면 OSCP 준비 목록을 활용하세요
  4. 먼저 직접 머신을 시도해 본 후 라이트업을 확인하세요

중급자용

  1. Medium/Hard 난이도의 머신을 기술별(AD, 웹 등)로 집중 공략하세요
  2. ProLab 하나를 끝까지 진행하세요 (Dante부터 시작)
  3. 블루 팀 기술 향상을 위해 Sherlock 챌린지에 도전하세요
  4. 과거 라이트업을 훈련 자료로 활용하여 CTF 이벤트에 참여하세요

고급자용

  1. Insane 난이도 머신과 Hard 챌린지를 목표로 삼으세요
  2. Cybernetics 또는 APTLabs ProLab을 완료하세요
  3. 자신만의 라이트업을 작성하고 기여하세요
  4. 맞춤 도구와 방법론을 개발하세요

기여하기

기여를 환영합니다! 자세한 지침은 CONTRIBUTING.md를 참조하세요.

빠른 시작:

  1. 저장소를 포크하세요
  2. 라이트업에 적합한 템플릿을 사용하세요
  3. 올바른 카테고리 폴더에 배치하세요
  4. 풀 리퀘스트를 제출하세요

라이트업 요구사항:

  • 은퇴한(Retired) 머신/챌린지만 가능 (활성 콘텐츠 금지)
  • 모든 단계 포함: 정찰, 익스플로잇, 권한 상승
  • 주요 단계에 스크린샷 또는 명령 출력 추가
  • 일관성을 위해 제공된 템플릿 사용
  • 활성 콘텐츠에 대한 스포일러 금지

면책 조항

이 라이트업은 교육 목적으로만 제공됩니다. 모든 콘텐츠는 Hack The Box 플랫폼에서 더 이상 활성화되지 않은 은퇴한(Retired) 머신 및 챌린지를 다룹니다. 활성 머신에 대한 솔루션 공유는 HTB의 서비스 약관을 위반합니다.

항상 윤리적 해킹을 실천하세요. 명시적 승인을 받은 시스템만 테스트하세요.


라이트업 출처

이 저장소의 머신 라이트업은 다양한 관점을 제공하기 위해 여러 독립 저자의 글을 링크합니다. 주요 출처는 다음과 같습니다:


관련 자료


전문 서비스

이 컬렉션은 미국 기반의 오펜시브 보안 회사인 GreyCore Labs에서 구축 및 유지 관리합니다. 동일한 노하우를 귀하의 제품에 적용하고 싶으신가요?

  • 침투 테스트 - 웹, API, 모바일, 클라우드. 24시간 내 고정 견적 제공, 요청 시 익명 처리된 샘플 보고서 제공.
  • 무료 외부 공격 표면 스캔 - 48시간 내 1페이지 보고서 제공, 의무 사항 없음.

라이선스

이 프로젝트는 MIT 라이선스에 따라 라이선스가 부여됩니다. 자세한 내용은 LICENSE를 참조하세요.


이 자료가 머신을 뚫거나 자격증을 취득하는 데 도움이 되었다면, 별표를 눌러주세요 - 다른 사람들이 찾는 데도 도움이 됩니다.

이 저장소에 별표 표시


키워드: hack the box 라이트업, HTB 워크스루, hackthebox 머신, HTB 챌린지, OSCP 준비 머신, CPTS 자격증, 침투 테스트 라이트업, CTF 라이트업, 액티브 디렉토리 해킹, 권한 상승, 웹 익스플로잇, 바이너리 익스플로잇, 디지털 포렌식, 사고 대응, 레드 팀, 블루 팀, 사이버 보안 교육, 윤리적 해킹, 정보 보안 자료, 보안 치트시트

도구 다운로드
저자 / 출처URL범위
0xdf0xdf.gitlab.io500+ 머신 - 최고 수준, 철저한 세부 정보
IppSecyoutube.com/ippsec430+ 동영상 워크스루(실시간 디버깅 포함)
HackingArticleshackingarticles.in40+ 머신 - Raj Chandel, 클래식 시대 (2017-2022)
Rana Khalilrana-khalil.gitbook.io26+ 머신 - OSCP 중심, Metasploit 미사용
snowscansnowscan.io20+ 머신 - 상세하고 일관된 품질
0xRick0xrick.github.io10+ 머신 - 깔끔한 블로그 라이트업
Medium / InfoSecWriteupsmedium.com45+ 머신 - 다양한 커뮤니티 저자
자료설명
HackTricks포괄적인 침투 테스트 참고 자료
PayloadsAllTheThings페이로드 및 우회 기법 모음
The Hacker Recipes구조화된 공격 레시피
GTFOBinsUnix 바이너리 익스플로잇 참고 자료
LOLBASWindows 로컬 바이너리 (Living-off-the-land)
WADComsWindows/AD 명령 참고 자료
RevShells리버스 셸 생성기
CyberChef데이터 변환 도구 키트
SecLists보안 테스트용 워드리스트
IppSec.rocksIppSec의 HTB 동영상 검색 인덱스