Writeups from hands-on labs: CloudGoat, Hack The Box, and similar environments. For all posts, see the full blog index.

AWS Cloud Labs

CloudGoat (cloud_breach_s3) walkthrough

Exfiltrating cardholder data from S3 by abusing IMDSv1 and a misconfigured EC2 reverse proxy — CloudGoat scenario walkthrough.

Jimmy Barrios May 13, 2025
HackTheBox Walkthroughs

Dream Job

Sherlock challenge notes on Operation Dream Job, mapping Lazarus tradecraft with MITRE ATT&CK and IOC enrichment using VirusTotal.

Jimmy Barrios Apr 13, 2025
HackTheBox Walkthroughs

Chemistry

HackTheBox Chemistry walkthrough: CIF parser code execution to foothold, credential recovery from SQLite, and local aiohttp path traversal to root flag.

Jimmy Barrios Mar 19, 2025
HackTheBox Walkthroughs

Certified

HackTheBox Certified walkthrough: starting from a low-priv AD user, abusing ACL/ownership and ADCS misconfigurations to obtain administrator access.

Jimmy Barrios Mar 19, 2025
HackTheBox Walkthroughs

Bastion

HackTheBox Bastion walkthrough: anonymous SMB backup access, offline SAM hash cracking, credential recovery from mRemoteNG config, and administrator WinRM access.

Jimmy Barrios Mar 19, 2025
HackTheBox Walkthroughs

Nest

HackTheBox Nest walkthrough: SMB share abuse, credential decryption from app configs, HQK debug access, and privileged account compromise.

Jimmy Barrios Mar 14, 2025
HackTheBox Walkthroughs

Archetype

HackTheBox Archetype walkthrough: anonymous SMB backup leak to MSSQL access, command execution via xp_cmdshell, and administrator credential recovery from PowerShell history.