Garfield — Hard Windows machine walkthrough cover

Garfield — HackTheBox Season 10 Walkthrough

Garfield is a fiendishly complex Active Directory box that chains a hidden scriptPath ACE, logon script hijacking, RBCD against an RODC, and a forged RODC golden ticket to compromise a full Windows domain. If you want to understand how Read-Only Domain Controllers can be weaponized, this is the box for you.

April 4, 2026 · 10 min · Logan Dawson
Snapped — Hard Linux machine walkthrough cover

Snapped — HackTheBox Walkthrough

Snapped is a brutal Hard box that chains a pre-auth Nginx UI backup endpoint disclosure into a command injection foothold, then escalates via a race-condition exploit in snap-confine that poisons the dynamic linker to achieve root.

March 23, 2026 · 9 min · Logan Dawson
Pirate — Hard Windows machine walkthrough cover

Pirate — HackTheBox Season 10 Walkthrough

Pirate is a brutal Hard-rated Windows Domain Controller that chains together gMSA password extraction, ADFS internals abuse, NTLM relay over a Hyper-V double-pivot, and SPN hijacking to reach Domain Admin — a genuine enterprise attack simulation.

February 27, 2026 · 14 min · Logan Dawson
Fries — Hard Windows machine walkthrough cover

Fries — HackTheBox Walkthrough

Fries is a Hard Windows box that takes you through a dense multi-layer attack chain: credential leaks in Gitea, authenticated RCE in pgAdmin, Docker CA key theft, LDAP credential poisoning, and finally ADCS certificate abuse to own the domain.

November 22, 2025 · 9 min · Logan Dawson