Garfield — Hard Windows machine walkthrough cover

Garfield — HackTheBox Season 10 Walkthrough

Garfield is a fiendishly complex Active Directory box that chains a hidden scriptPath ACE, logon script hijacking, RBCD against an RODC, and a forged RODC golden ticket to compromise a full Windows domain. If you want to understand how Read-Only Domain Controllers can be weaponized, this is the box for you.

April 4, 2026 · 10 min · Logan Dawson
Eighteen — HackTheBox Windows machine walkthrough cover

Eighteen — HackTheBox Walkthrough

Eighteen is a Windows Server 2025 Domain Controller box that chains MSSQL impersonation, Werkzeug hash cracking, and the newly-disclosed BadSuccessor vulnerability (CVE-2025-53779) to achieve full domain compromise — a rare chance to exploit a live DC in a lab environment.

February 27, 2026 · 9 min · Logan Dawson
Pirate — Hard Windows machine walkthrough cover

Pirate — HackTheBox Season 10 Walkthrough

Pirate is a brutal Hard-rated Windows Domain Controller that chains together gMSA password extraction, ADFS internals abuse, NTLM relay over a Hyper-V double-pivot, and SPN hijacking to reach Domain Admin — a genuine enterprise attack simulation.

February 27, 2026 · 14 min · Logan Dawson
Monitorsfour — Medium Windows machine walkthrough cover

Monitorsfour — HackTheBox Walkthrough

MonitorsFour chains a fresh Cacti RCE vulnerability with an exposed Docker API to go from web login to full Windows host compromise — a great lesson in container escape methodology.

February 6, 2026 · 6 min · Logan Dawson
Responder — Very Easy Windows machine walkthrough cover

Responder — HackTheBox Starting Point Walkthrough

A deceptively instructive box that chains LFI with NTLM hash theft — Responder shows how a single vulnerable parameter on a Windows web server can hand you administrator credentials.

February 1, 2026 · 5 min · Logan Dawson
Archetype — HackTheBox Windows machine walkthrough cover

Archetype — HackTheBox Starting Point Walkthrough

Archetype shows how a single misconfigured SMB share cascades into full domain compromise — SSIS config files, xp_cmdshell, and PowerShell history all play a role.

January 30, 2026 · 6 min · Logan Dawson
Dancing — HackTheBox Windows machine walkthrough cover

Dancing — HackTheBox Starting Point Walkthrough

Dancing is a beginner-friendly Windows box that teaches the fundamentals of SMB enumeration. A misconfigured file share with anonymous access is all you need to grab the flag.

January 30, 2026 · 4 min · Logan Dawson
Overwatch — Medium Windows machine walkthrough cover

Overwatch — HackTheBox Walkthrough

Overwatch chains MSSQL linked server credential capture via DNS poisoning with a WCF service PowerShell injection to go from unauthenticated to Domain Admin on a Windows Server 2022 DC.

January 24, 2026 · 8 min · Logan Dawson
Eloquia — Insane Windows machine walkthrough cover

Eloquia — HackTheBox Walkthrough

An Insane-rated Windows box chaining AngularJS CSTI, a subtle OAuth logical flaw, SQLite’s load_extension for DLL-based RCE, Edge DPAPI credential decryption, and .NET AppDomainManager injection to reach SYSTEM.

December 13, 2025 · 13 min · Logan Dawson
Fries — Hard Windows machine walkthrough cover

Fries — HackTheBox Walkthrough

Fries is a Hard Windows box that takes you through a dense multi-layer attack chain: credential leaks in Gitea, authenticated RCE in pgAdmin, Docker CA key theft, LDAP credential poisoning, and finally ADCS certificate abuse to own the domain.

November 22, 2025 · 9 min · Logan Dawson