
Linux Hacking : BankSmarter
Objective Gain initial access and escalate privileges to root, emulating a worst-case scenario where a threat actor successfully compromises a critical asset and retrieve the final flag from the /...

Objective Gain initial access and escalate privileges to root, emulating a worst-case scenario where a threat actor successfully compromises a critical asset and retrieve the final flag from the /...

Objective Abuse the iam:CreateAccessKey permission, escalate the privilege, access the s3 bucket and download sensitive information from s3 bucket. lab Solution Configure AWS CLI Configure the ...

Objective Conduct AWS pentest against a client’s account and full audit of all the IAM Users to identify any possible privilege escalation paths. Goal is to find the flag in the Secrets Manager th...

Inroduction What is Bloodhound ? In Active Directory (AD) security, BloodHound is a tool used to map and analyze relationships and permissions inside an AD environment. What Bloodhound does ? B...

Command & Control Framework What is Command & Control (C2) Framework? A Command & Control (C2) Framework is a security tool or platform that allows an operator to remotely control and...

Introduction Before initiate the application pentesting my first object is to gather as much information as I can. During the internal network penetration testing, I came across an application th...

Introduction Here, Assume, I was provided with the AWS access key and secret key of the IAM user chris. During enumeration, I discovered that chris could assume a role with full AWS Lambda access ...

Introduction In this lab Solus, I have provide lower level IAM user credentials, which has read-only access to a Lambda function. While analyzing the function, I discovered hardcoded secrets that ...

Introduction The HackSmarter Red Team has started offering AWS Penetration Testing. This fully hands-on lab provides practical experience in assessing the security of AWS environments. Throughout ...

Introduction The HackSmarter Red Team has started offering AWS Penetration Testing. This fully hands-on lab provides practical experience in assessing the security of AWS environments. Throughout ...