这是GitHub上最全面的 Hack The Box 解题报告、演练指南 和 速查表 集合。500+ 台机器、400+ 个挑战、ProLabs、Sherlocks (DFIR)、CTF赛事、渗透测试方法以及OSCP/CPTS认证备考——全部集中在一个地方。``` ___ ___ ___________ __ __ .__ __
/ | \ __ / / \ / ___||/ | ____ __ ________ ______
/ ~ \ | | \ // /_ __ | \ / __ | | _ / /
\ Y / | | \ / | | /| || | \ /| | / |> > \
_|_ / || _/\ / || |||| ___ >_/| / >
/ / / |__| /
[](https://awesome.re)
[](https://github.com/momenbasel/htb-writeups/stargazers)
[](https://github.com/momenbasel/htb-writeups/network/members)
[](https://github.com/momenbasel/htb-writeups/graphs/contributors)
[](LICENSE)
[](https://github.com/momenbasel/htb-writeups/commits/main)
**为什么选择这个仓库?** 不同于零散的博客文章和单一作者的收藏,这是一个**结构化、可搜索的索引**,涵盖整个 HTB 生态系统——从 2017 年到 2026 年的机器、每一次 CTF 赛事、每一个挑战类别、每一个 ProLab——并按照技术、难度、操作系统和认证相关性进行交叉引用。无论你是在准备 **OSCP**、**CPTS**、**CRTO**,还是仅仅想磨炼技能,都可以从这里开始。
> **[浏览网站](https://momenbasel.github.io/htb-writeups/)** 获得最佳体验——交互式工具、搜索和深色主题。
---
## 交互式工具
| | 工具 | 描述 |
|--|------|-------------|
| **[机器查找器](https://momenbasel.github.io/htb-writeups/finder/)** | 搜索与筛选 | 按难度、操作系统、技术、CVE 或认证查找机器。支持表格和卡片视图,实时筛选。 |
| **[知识图谱](https://momenbasel.github.io/htb-writeups/graph/)** | 可视化探索器 | 交互式 D3.js 力导向图,映射 70+ 台机器到 40+ 种技术和 5 种认证。 |
| **[攻击路径](https://momenbasel.github.io/htb-writeups/attack-paths/)** | 流程图 | 展示 25+ 台机器完整攻击链的 Mermaid 图表——从信息收集到获取 root。 |
| **[技能树](https://momenbasel.github.io/htb-writeups/skill-trees/)** | 进阶地图 | AD 攻击、Web 利用、Linux/Windows 提权和认证准备的视觉学习路径。 |
---
## 仓库内容
| 章节 | 描述 | 数量 |
|---------|-------------|-------|
| [机器](#machines) | Boot2root 演练 (简单到疯狂) | 300+ |
| [挑战](#challenges) | 跨 12 个类别的 CTF 风格挑战 | 400+ |
| [ProLabs](#prolabs) | 企业级实验室演练,包含网络拓扑图 | 6 |
| [侦探任务](#sherlocks) | DFIR 与蓝队调查 | 70+ |
| [CTF 赛事](#ctf-events) | 官方 HTB CTF 竞赛的 Writeup | 14 场 |
| [终局](#endgames) | 多机器场景演练 | 5 |
| [堡垒](#fortresses) | 单主机多旗帜挑战 | 6 |
| [资源](#resources) | 工具、速查表、认证准备、方法论 | 10 份指南 |
---
## 机器
已退役 HTB 机器的 Writeup,按难度组织。每份 Writeup 包含枚举、利用和权限提升步骤,以及完整的命令输出。
### 按难度
| 难度 | 路径 | 机器数量 |
|------------|------|----------|
| 简单 | [`machines/easy/`](https://github.com/momenbasel/htb-writeups/blob/main/machines/easy) | 132+ |
| 中等 | [`machines/medium/`](https://github.com/momenbasel/htb-writeups/blob/main/machines/medium) | 136+ |
| 困难 | [`machines/hard/`](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard) | 70+ |
| 疯狂 | [`machines/insane/`](https://github.com/momenbasel/htb-writeups/blob/main/machines/insane) | 50+ |
### 近期退役 (2025-2026)
| 机器 | 操作系统 | 难度 | 关键技术 | 日期 |
|---------|----|------------|----------------|------|
| [MonitorsFour](https://github.com/momenbasel/htb-writeups/blob/main/machines/insane/MonitorsFour) | Windows | 疯狂 | PHP 类型混淆、Cacti CVE、Docker API 逃逸 | 2026年5月 |
| [Pterodactyl](https://github.com/momenbasel/htb-writeups/blob/main/machines/insane/Pterodactyl) | openSUSE | 疯狂 | Pterodactyl Panel CVE-2025-49132、PEAR pearcmd LFI、Polkit | 2026年5月 |
| [Helix](https://github.com/momenbasel/htb-writeups/blob/main/machines/medium/Helix) | Linux | 中等 | Apache NiFi ExecuteSQL + H2 Java Alias RCE | 2026年5月 |
| [Overwatch](https://0xdf.gitlab.io/2026/05/09/htb-overwatch.html) | Windows | 疯狂 | .NET 逆向、WCF 服务注入、DNS | 2026年5月 |
| [Sorcery](https://github.com/momenbasel/htb-writeups/blob/main/machines/insane/Sorcery) | Linux | 疯狂 | Cypher 注入、WebAuthn XSS、Kafka、FreeIPA | 2026年4月 |
| [PingPong](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard/PingPong) | Windows | 困难 | 多林 AD、MSSQL 委派、ADCS | 2026年4月 |
| [AirTouch](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard/AirTouch) | Linux | 困难 | 802.11 WPA2 破解、邪恶双子、PEAP-MSCHAPv2 | 2026年4月 |
| [Eighteen](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard/Eighteen) | Windows | 困难 | Win Server 2025、MSSQL 模拟、Bad Successor dMSA | 2026年4月 |
| [DarkZero](https://0xdf.gitlab.io/2026/04/04/htb-darkzero.html) | Windows | 困难 | 跨林信任、AD 滥用 | 2026年4月 |
| [Pirate](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard/Pirate) | Windows | 困难 | Pre2k、gMSA、PetitPotam、RBCD、S4U SPN Jack | 2026年2月 |
| [VariaType](https://github.com/momenbasel/htb-writeups/blob/main/machines/medium/VariaType) | Linux | 中等 | fontTools CVE-2025-66034、FontForge CVE-2024-25082 | 2026年3月 |
| [Interpreter](https://github.com/momenbasel/htb-writeups/blob/main/machines/medium/Interpreter) | Linux | 中等 | Mirth Connect CVE-2023-43208、Python eval() | 2026年2月 |
| [Kobold](https://github.com/momenbasel/htb-writeups/blob/main/machines/easy/Kobold) | Linux | 简单 | MCPJam CVE-2026-23744、Docker 组 | 2026年3月 |
| [Facts](https://github.com/momenbasel/htb-writeups/blob/main/machines/easy/Facts) | Linux | 简单 | Camaleon CMS IDOR + 路径遍历 + Facter Sudo | 2026年1月 |
| [Code](https://github.com/momenbasel/htb-writeups/blob/main/machines/easy/Code) | Linux | 简单 | Python 沙箱绕过、Backy Sudo | 2025年8月 |
| [Cobblestone](https://github.com/momenbasel/htb-writeups/blob/main/machines/insane/Cobblestone) | Linux | 疯狂 | 二阶 SQLi、Twig SSTI、Cobbler XMLRPC | 2025年 |
| [Snapped](https://0xdf.gitlab.io/2026/04/01/htb-snapped.html) | Linux | 困难 | Nginx UI RCE、静态站点利用 | 2026年3月 |
| [Browsed](https://0xdf.gitlab.io/2026/03/28/htb-browsed.html) | Linux | 中等 | 浏览器扩展利用、Headless Chrome | 2026年3月 |
| [Previous](https://0xdf.gitlab.io/2026/01/10/htb-previous.html) | Linux | 中等 | NextJS 利用、框架滥用 | 2026年1月 |
| [Retire](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard) | Windows | 困难 | Active Directory、Kerberos 滥用 | 2026年1月 |
| [Fries](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard) | Linux | 困难 | Web 利用、自定义利用 | 2025年11月 |
| [NanoCorp](https://github.com/momenbasel/htb-writeups/blob/main/machines/hard) | Linux | 困难 | 自定义协议、二进制分析 | 2025年11月 |
| [Hercules](https://github.com/momenbasel/htb-writeups/blob/main/machines/insane) | Linux | 疯狂 | 多阶段利用 | 2025年10月 |
| [Signed](https://0xdf.gitlab.io/2026/02/07/htb-signed.html) | Windows | 中等 | 代码签名绕过、证书滥用 | 2025年10月 |
| [University](https://0xdf.gitlab.io/2025/08/09/htb-university.html) | Windows | 疯狂 | 多向量攻击、复杂链 | 2025年8月 |
| [Dog](https://0xdf.gitlab.io/2025/07/12/htb-dog.html) | Linux | 简单 | Backdrop CMS、Web 利用 | 2025年7月 |
| [Mirage](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) | Windows | 困难 | Active Directory、ADCS | 2025年7月 |
| [Voleur](https://0xdf.gitlab.io/2025/11/01/htb-voleur.html) | Windows | 中等 | 数据外泄、自定义利用 | 2025年7月 |
| [RustyKey](https://0xdf.gitlab.io/2025/11/08/htb-rustykey.html) | Windows | 困难 | Rust 二进制利用 | 2025年6月 |
| [TombWatcher](https://0xdf.gitlab.io/2025/10/11/htb-tombwatcher.html) | Windows | 中等 | 自定义服务利用 | 2025年6月 |
| [Haze](https://0xdf.gitlab.io/2025/06/28/htb-haze.html) | Windows | 困难 | Splunk Enterprise 利用 | 2025年6月 |
| [Certificate](https://0xdf.gitlab.io/2025/10/04/htb-certificate.html) | Windows | 困难 | ADCS、证书模板滥用 | 2025年5月 |
| [Vintage](https://0xdf.gitlab.io/2025/04/26/htb-vintage.html) | Windows | 困难 | 纯 Active Directory、Kerberoasting | 2025年4月 |
### 按操作系统