Authorized lab portfolio
Hands-on assessments, organized by the security problem—not a list of 52 machines.
These Proving Grounds writeups document work performed in authorized lab environments. Each is grouped by the attack surface or skill it develops, so a reviewer can quickly explore the areas most relevant to them.
01 / Web & APIs
Application attack paths
Labs centered on web-facing attack surfaces: input handling, file operations, CMS platforms, and modern API logic. The useful takeaway is not only how access was achieved, but which control would have disrupted the path.
Access
File-upload controls and Windows privilege boundaries.
Gogs / cronAssignment
Source-control administration and command execution risk.
RailsBoolean
Mass assignment, traversal, and SSH trust paths.
SQL injectionCockpit
Authentication failure to unsafe SUID handling.
LFIDC5
File inclusion and server-side log exposure.
GraphQLDepreciated
API enumeration and insecure application logic.
CMS uploadExfiltrated
Upload validation and scheduled-task risk.
OpenfireFired
Path traversal and unsafe setup workflows.
ConfluenceFlu
Known RCE exposure and cron-job hygiene.
JoraniJordak
Application patching and sudo review.
LaravelLavita
Debug configuration and framework RCE exposure.
InjectionLaw
Input handling and writable scheduled scripts.
Command injectionOchima
Unsafe command execution in web applications.
CS-CartPay Day
Local file inclusion and authentication hardening.
PluXmlPlum
Content-management controls and credential exposure.
FlatPressPress
CMS upload security and least privilege.
WordPress / SQLiWorkaholic
Plugin risk, credential protection, and binary hardening.
Upload + LFIZipper
Chained web flaws and scheduled-job safety.
02 / Windows & Active Directory
Identity, delegation, and endpoint controls
These labs focus on Windows trust boundaries: credential material, service permissions, Active Directory delegation, and the local rights that can turn a foothold into administrator access.
Algeron
Unpatched Windows application exposure.
FTP / schedulerAuthBy
Credential discovery and task-permission review.
Nexus / SMBBillyBoss
Vulnerability management across application and network layers.
Macro / IISCraft
User-driven execution and impersonation privileges.
TraversalDVR4
Sensitive-file exposure and administrative credential handling.
SSRF / ADHeist
Service-account controls and privilege recovery.
Email / serviceHepet
Macro defense and writable service binaries.
LDAP / LAPSHutch
Directory permissions and local-admin password protection.
H2 / DLLJacko
Database defaults and DLL search-path risk.
Legacy serviceKevin
Legacy application exposure and default credentials.
Remote accessMice
Desktop software controls and stored credentials.
MSSQL / KerberosNagoya
Service-account scope and ticket abuse.
PivotingNickel
Credential exposure, port forwarding, and segmentation.
RBCDResourced
Share hygiene and Active Directory delegation.
SMB / MSIShenzi
Share permissions and endpoint-installer policy.
Proxy / tokensSquid
Proxy exposure and impersonation privileges.
03 / Linux escalation
From foothold to root: permission design matters
A focused set of labs for understanding how local configuration decisions—sudo scope, SUID programs, writable scripts, and group membership—compound after initial access.
Banzai
Weak credentials and database service privilege.
Redis / ROPBlackGate
Service configuration and binary-defense depth.
SendmailClamAV
Mail-service configuration and patching.
SuiteCRM / sudoCrane
Application access and least-privilege sudo policy.
Upload / APKEducated
File handling, mobile artifacts, and credential risk.
Disk groupeXtplorer
Web uploads and overbroad group membership.
ImageMagick / SUIDImage
Media-processing exposure and SUID review.
RPC / SUIDPC
Service deserialization and file-permission safety.
ZookeeperPelican
Command injection and process-memory protection.
CVE / sudoScrutiny
Patch verification and constrained sudo access.
RFI / taskSlort
File permissions and scheduled-task controls.
RFI / credentialsSnookums
Remote include exposure and account hardening.
SaltStackTwiggy
Infrastructure-management patching and trust boundaries.
04 / Services & infrastructure
Discovery and attack-surface reasoning
These are intentionally presented as broad assessment studies: examine exposed services, form hypotheses from evidence, validate security assumptions, then record the defensive lesson.
Clue
Documented target assessment and evidence-led enumeration.
Assessment studyEducated 1
Documented target assessment and validation workflow.
Assessment studyInternal
Documented target assessment and internal attack surface.
CMS / servicesMonster
Backup exposure, password hygiene, and service permissions.
Multi-stageSpiderSociety
Enumeration, privilege boundaries, and movement through a network.
Every full writeup includes an authorized-lab notice, a scenario, learning objectives, technical evidence, and a concise takeaway. They are proof of practice—not a claim that a single technique is universally applicable.