FO-Sec
HomeCheatsheetWriteupsArticles
Internal

Realistic CTF challenge that focuses on finding and exploiting software misconfigurations in a Wordpress environment.

TryHackMe
Hard
Cybercrafted

Fun and complete CTF involving SQLi, command injection, bruteforcing and dangerous binary permissions.

TryHackMe
Medium
Pandora

Interesting and complete machine that includes SNMP enumeration, SQL Injection, OS Code execution and relative path abusing.

HackTheBox
Easy
Relevant

Interesting but easy Windows machine useful for beginners that want to learn how IIs and the SMB protocol work.

TryHackMe
Medium
Road

Realistic but easy Linux machine with lateral pivoting and an interesting privilege escalation method.

TryHackMe
Medium
Year of the Fox

Good challenge for intermediate users that includes SMB enumeration, OS code injection and path hijacking.

TryHackMe
Hard
You're in a cave

Very complex but unrealistic CTF environment simulating an RPG where you have to keep finding clues to progress.

TryHackMe
Insane
Sizzle

Advanced active directory CTF that teaches different aspects of real-world pentesting, including AD Certificate Services.

HackTheBox
Insane
Fusion Corp

Fun and interesting, but unrealistic, Windows machine aimed at beginners that want to learn Active Directory enumeration and pivoting.

TryHackMe
Hard
Carpediem

Highly Complex but fun machine that teaches about pivoting, web exploitation and container escapes.

HackTheBox
Hard
Absolute

Complex but fun Active-Directory machine with multi-step exploitation representing a real-world scenario.

HackTheBox
Insane
Resolute

Intermediate Active Directory-focused machine that teaches basics and fundamentals of AD pentesting.

HackTheBox
Medium
Cold VVars

Innovative Linux machine that teaches manual SQL injection and a unique way of abusing termux for privilege escalation.

TryHackMe
Medium

© FO