Checklist Featured

Web Application Pentest Checklist

The complete web checklist turned into a how-to-test field guide: for every item — recon, authentication, sessions, access control, injection, business logic, file handling, APIs, client-side, infra, crypto and info-disclosure, plus SaaS / banking / e-commerce / healthcare / admin specifics — the scenario, the real command (ffuf, sqlmap, nuclei, jwt_tool, Burp), the step-by-step, the exact finding to report, and the fix.

Jun 18, 2026 · 34m read
Read article →
Pro Labs ★ Premium Featured

HackTheBox CAPE Exam — Detailed Walkthrough

Step-by-step HackTheBox CAPE exam walkthrough — a multi-forest Active Directory environment across three trust boundaries. Every command explained, all flags and the full compromise chain.

Jun 26, 2026 · 31m read
Read article →
Checklist Featured

Wireless Pentest Checklist

A Wi-Fi-focused wireless pentest checklist turned into a how-to-test field guide: survey and recon, WEP, WPA2-PSK (4-way handshake and PMKID cracking), WPA3 and downgrade, WPS, Enterprise 802.1X/EAP (evil twin and credential relay, certificate validation), rogue AP / evil twin / captive portal, deauth and management-frame protection, client-side attacks, and guest/corporate segmentation — plus Bluetooth/BLE — each with the scenario, the real command (aircrack-ng, hcxdumptool, hashcat, hostapd-wp

Jun 18, 2026 · 9m read
Read article →
Topic
145 articles

Walkthroughs

Step-by-step HackTheBox machine writeups, Pro Labs, Fortresses and exam-lab walkthroughs — full recon, exploitation and privilege …

Topic
42 articles

AI/LLM Security

LLM and ML security — prompt injection, jailbreaks, RAG attacks, adversarial ML and AI red teaming.

Topic
34 articles

Active Directory

Attacking and defending Active Directory — Kerberoasting, ADCS, delegation, ACL abuse, BloodHound, trusts and persistence.

Topic
32 articles

Red Team

Adversary simulation — C2, phishing, initial access, AV/EDR evasion, lateral movement and persistence.

Topic
25 articles

Mobile Security

Android and iOS pentesting — Frida, APK/IPA reverse engineering, SSL pinning bypass and insecure storage.

Topic
22 articles

Network Security

Network attack and defence — ARP/DHCP/VLAN abuse, MITM, pivoting, Wi-Fi, BLE, SNMP and SMB.

Topic
13 articles

Checklist

Field-ready pentest checklists turned into step-by-step "how to test" guides — for every item: the scenario, the real co…

Topic
11 articles

Pro Labs

Multi-host HackTheBox Pro Lab walkthroughs — full enterprise-network compromise across forests and flags.

Topic
8 articles

Cloud Security

Cloud attack paths — AWS, Azure and GCP IAM, Kubernetes, container escapes and CI/CD pipeline abuse.

Topic
4 articles

Fortress

HackTheBox Fortress walkthroughs — multi-flag vendor challenge labs spanning web, binary, crypto and more.

Topic
3 articles

OSINT

Open-source intelligence — target profiling, breach data, dark-web monitoring and OSINT tooling.

Topic
3 articles

Certifications

Exam reviews and prep guides — OSCP, CPTS, CWEE and more, with strategy, lab notes and real exam experience.