# OffSec Notes

## OffSec Notes

- [Offensive Security Notes](https://cel1s0.gitbook.io/offsec-notes/readme.md)
- [Linux/Unix](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix.md)
- [Checklist - PrivEsc](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc.md): Checklist for privilege escalation in Linux
- [Related Links](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/related-links.md): There are links related to Linux/Unix privilege escalation.
- [Kernel Exploits](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/kernel-exploits.md): Common kernel exploits usage.
- [MYSQL](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/mysql.md): PrivEsc with MySQL User Defined Functions
- [HEX](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/mysql/hex.md): PrivEsc with MySQL User Defined Functions
- [SUID](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/suid.md): Using programs which has SUID bit to root shell.
- [Relative Path in SUID Program](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/relative-path-in-suid-program.md)
- [Writable /etc/passwd file](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/writable-etc-passwd-file.md)
- [Writable script in /etc/crontab](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/writable-script-in-etc-crontab.md)
- [Writable services](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/writable-services.md): Root access with writable services.
- [Sudo <=1.8.14](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/sudo-less-than-1.8.14.md): Sudo <=1.8.14 Local Privilege Escalation
- [Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/debian-openssl-predictable-prng-bruteforce-ssh-exploit.md): OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
- [Docker](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/docker.md): Using docker to get root shell.
- [Docker Escape](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/docker/docker-escape.md): There are some docker escaping technics
- [davfs2](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/davfs2.md): davfs2 1.4.6/1.4.7 - Local Privilege Escalation
- [gcore](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/gcore.md): using gcore with sudo privilege for priv esc
- [fail2ban](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/fail2ban.md)
- [git](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/git.md): Requirements: Git User SSH Priv Key and Cronjobs
- [tar with wildcard](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/tar-with-wildcard.md)
- [Exiftool](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/checklist-privesc/exiftool.md): Exiftool 7.44< <12.24 Priv Esc
- [Limited Shell Escape](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/limited-shell-escape.md): Ways to escape limited shells.
- [Wordpress](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/wordpress.md): Wordpress enumeration tools.
- [Apache Tomcat](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/apache-tomcat.md)
- [Werkzeug Console PIN bypass](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/werkzeug-console-pin-bypass.md)
- [get\_flask\_pin.py](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/werkzeug-console-pin-bypass/get_flask_pin.py.md)
- [Java Object Deserialization](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/java-object-deserialization.md)
- [Redis RCE](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/redis-rce.md): Redis 4x-5x RCE
- [mongodb](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/mongodb.md): 27017-27018
- [Postgres](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/postgres.md)
- [Erlang - 4369](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/erlang-4369.md): Erlang Cookie RCE
- [rsync - 873](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/rsync-873.md): 873/tcp
- [Sendmail ClamAV](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/sendmail-clamav.md): Sendmail with clamav-milter < 0.91.2 - Remote Command Execution
- [VNC Password Decryptor](https://cel1s0.gitbook.io/offsec-notes/readme/linux-unix/vnc-password-decryptor.md)
- [Windows](https://cel1s0.gitbook.io/offsec-notes/readme/windows.md)
- [Checklist - PrivEsc](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc.md): Checklist for privilege escalation in Windows
- [MSSQL](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/mssql.md)
- [PsExec.exe](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/psexec.exe.md)
- [Build Exploits](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/build-exploits.md)
- [Unquoted Service Paths](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/unquoted-service-paths.md)
- [SeImpersonateToken](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/seimpersonatetoken.md): SeImpersonateToken or SeAssignPrimaryToken - Enabled
- [SeRestorePrivilege](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/serestoreprivilege.md)
- [SeBackupPrivilege](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/sebackupprivilege.md)
- [Abuse GPO](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/abuse-gpo.md)
- [Job with editable file](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/job-with-editable-file.md)
- [AlwaysInstallElevated](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/alwaysinstallelevated.md)
- [Misconfigured LDAP](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/misconfigured-ldap.md): Exploiting misconfigured LAPS service.
- [GMSA](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/gmsa.md)
- [MS17-010](https://cel1s0.gitbook.io/offsec-notes/readme/windows/privesc/ms17-010.md): EternalBlue MS 17-010 exploiting ways without Metasploit.
- [Useful PS Scripts](https://cel1s0.gitbook.io/offsec-notes/readme/windows/useful-ps-scripts.md)
- [GetUserSPNs.ps1](https://cel1s0.gitbook.io/offsec-notes/readme/windows/useful-ps-scripts/getuserspns.ps1.md)
- [Master MDF Hash Extraction](https://cel1s0.gitbook.io/offsec-notes/readme/windows/useful-ps-scripts/master-mdf-hash-extraction.md)
- [Spray-Passwords.ps1](https://cel1s0.gitbook.io/offsec-notes/readme/windows/useful-ps-scripts/spray-passwords.ps1.md)
- [Password Extraction](https://cel1s0.gitbook.io/offsec-notes/readme/windows/password-extraction.md): In this topic your privilege has to be high privilege.
- [Office Macro](https://cel1s0.gitbook.io/offsec-notes/readme/windows/office-macro.md)
- [Microsoft Office](https://cel1s0.gitbook.io/offsec-notes/readme/windows/office-macro/microsoft-office.md)
- [Open Office](https://cel1s0.gitbook.io/offsec-notes/readme/windows/office-macro/open-office.md)
- [Post Exploitation](https://cel1s0.gitbook.io/offsec-notes/readme/windows/post-exploitation.md): It covers post exploitation steps for movements in AD.
- [Web](https://cel1s0.gitbook.io/offsec-notes/readme/web.md)
- [SQL Injection](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection.md)
- [mongodb 2.2.3](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection/mongodb-2.2.3.md)
- [UNION BASED](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection/union-based.md)
- [MSSQL](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection/union-based/mssql.md)
- [Oracle](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection/union-based/oracle.md)
- [ERROR BASED](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection/error-based.md): MSSQL
- [node.js](https://cel1s0.gitbook.io/offsec-notes/readme/web/sql-injection/node.js.md)
- [Nmap samples](https://cel1s0.gitbook.io/offsec-notes/readme/nmap-samples.md): There are some NMAP scan samples.
- [Shells](https://cel1s0.gitbook.io/offsec-notes/readme/shells.md)
- [node.js](https://cel1s0.gitbook.io/offsec-notes/readme/shells/node.js.md): https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md#nodejs
- [msfvenom samples](https://cel1s0.gitbook.io/offsec-notes/readme/shells/msfvenom-samples.md)
- [Reverse Shells](https://cel1s0.gitbook.io/offsec-notes/readme/shells/reverse-shells.md)
- [Shellter](https://cel1s0.gitbook.io/offsec-notes/readme/shells/shellter.md)
- [Enumeration](https://cel1s0.gitbook.io/offsec-notes/readme/enumeration.md)
- [SMB](https://cel1s0.gitbook.io/offsec-notes/readme/enumeration/smb.md)
- [RPC](https://cel1s0.gitbook.io/offsec-notes/readme/enumeration/rpc.md)
- [LDAP](https://cel1s0.gitbook.io/offsec-notes/readme/enumeration/ldap.md): Misconfigured LDAP service.
- [Buffer Overflow](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow.md): Stackbased BOF.
- [mona](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow/mona.md)
- [fuzzer.py](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow/fuzzer.py.md)
- [exploit.py](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow/exploit.py.md)
- [bytearray.py](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow/bytearray.py.md)
- [pattern\_offset.rb](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow/pattern_offset.rb.md)
- [pattern\_create.rb](https://cel1s0.gitbook.io/offsec-notes/readme/buffer-overflow/pattern_create.rb.md)
- [Password Cracking](https://cel1s0.gitbook.io/offsec-notes/readme/password-cracking.md)
- [File Download](https://cel1s0.gitbook.io/offsec-notes/readme/file-download.md)
- [FTP](https://cel1s0.gitbook.io/offsec-notes/readme/file-download/ftp.md): FTP usage is in non-interactive shells.
- [Port Forwarding](https://cel1s0.gitbook.io/offsec-notes/readme/port-forwarding.md)
- [Dynamic Forwarding](https://cel1s0.gitbook.io/offsec-notes/readme/port-forwarding/dynamic-forwarding.md): Port Forwarding From Target Machine With SSH - Secure Way - Specify Ports with -R Option
- [Useful links](https://cel1s0.gitbook.io/offsec-notes/readme/useful-links.md)
- [Blog](https://cel1s0.gitbook.io/offsec-notes/blog.md)
- [CRTO I & II](https://cel1s0.gitbook.io/offsec-notes/blog/crto-i-and-ii.md): This blog post is a review of the courses and contains a comparison with OSCP. https://www.zeropointsecurity.co.uk/
- [OSCP Preparation](https://cel1s0.gitbook.io/offsec-notes/blog/oscp-preparation.md)
- [New OSCP Exam vs Previous OSCP Exam](https://cel1s0.gitbook.io/offsec-notes/blog/new-oscp-exam-vs-previous-oscp-exam.md)
- [Movements in AD](https://cel1s0.gitbook.io/offsec-notes/blog/movements-in-ad.md): It contains basic methodology for post exploitation.
- [PWK Lab vs PG Practice](https://cel1s0.gitbook.io/offsec-notes/blog/pwk-lab-vs-pg-practice.md)
- [PortSwigger Academy](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy.md)
- [Server-side topics](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics.md)
- [Authentication vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/authentication-vulnerabilities.md): https://portswigger.net/web-security/authentication
- [OS Command Injection](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/os-command-injection.md): https://portswigger.net/web-security/os-command-injection
- [File Path Traversal](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/file-path-traversal.md): https://portswigger.net/web-security/file-path-traversal
- [Business logic vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/business-logic-vulnerabilities.md): https://portswigger.net/web-security/logic-flaws
- [Information disclosure vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/information-disclosure-vulnerabilities.md): https://portswigger.net/web-security/information-disclosure
- [Access control vulnerabilities and privilege escalation](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/access-control-vulnerabilities-and-privilege-escalation.md): https://portswigger.net/web-security/access-control
- [File upload vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/file-upload-vulnerabilities.md): https://portswigger.net/web-security/file-upload
- [Server-side request forgery (SSRF)](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/server-side-request-forgery-ssrf.md): https://portswigger.net/web-security/ssrf
- [XML external entity (XXE) injection](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/server-side-topics/xml-external-entity-xxe-injection.md): https://portswigger.net/web-security/xxe
- [Client-side topics](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics.md)
- [Cross-site scripting](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics/cross-site-scripting.md): https://portswigger.net/web-security/cross-site-scripting
- [Cross-origin resource sharing (CORS)](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics/cross-origin-resource-sharing-cors.md): https://portswigger.net/web-security/cors
- [Cross-site request forgery (CSRF)](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics/cross-site-request-forgery-csrf.md): https://portswigger.net/web-security/csrf
- [Clickjacking (UI redressing)](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics/clickjacking-ui-redressing.md): https://portswigger.net/web-security/clickjacking
- [DOM-based vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics/dom-based-vulnerabilities.md): https://portswigger.net/web-security/dom-based
- [Testing for WebSockets security vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/client-side-topics/testing-for-websockets-security-vulnerabilities.md): https://portswigger.net/web-security/websockets
- [Advanced topics](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics.md)
- [Insecure deserialization](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/insecure-deserialization.md): https://portswigger.net/web-security/deserialization
- [Server-side template injection](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/server-side-template-injection.md): https://portswigger.net/web-security/server-side-template-injection
- [Web cache poisoning](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/web-cache-poisoning.md): https://portswigger.net/web-security/web-cache-poisoning
- [HTTP Host header attacks](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/http-host-header-attacks.md): https://portswigger.net/web-security/host-header
- [HTTP request smuggling](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/http-request-smuggling.md): https://portswigger.net/web-security/request-smuggling
- [OAuth 2.0 authentication vulnerabilities](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/oauth-2.0-authentication-vulnerabilities.md): https://portswigger.net/web-security/oauth
- [JWT attacks](https://cel1s0.gitbook.io/offsec-notes/portswigger-academy/advanced-topics/jwt-attacks.md): https://portswigger.net/web-security/jwt
- [Walkthroughs](https://cel1s0.gitbook.io/offsec-notes/walkthroughs.md)
- [PG Practice](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice.md)
- [Linux](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux.md)
- [WARM UP](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up.md): 10 points
- [Bratarina](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/bratarina.md)
- [ClamAV](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/clamav.md)
- [Exfiltrated](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/exfiltrated.md)
- [Hawat](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/hawat.md)
- [Interface](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/interface.md)
- [Muddy](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/muddy.md)
- [Pebbles](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/pebbles.md)
- [Twiggy](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/twiggy.md)
- [Wombo](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/warm-up/wombo.md)
- [GET TO WORK](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work.md): 20 points
- [Banzai](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/banzai.md)
- [Cassios](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/cassios.md)
- [Dibble](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/dibble.md)
- [Fail](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/fail.md)
- [G00g](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/g00g.md)
- [Hetemit](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/hetemit.md)
- [Hunit](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/hunit.md)
- [Maria](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/maria.md)
- [Nappa](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/nappa.md)
- [Nibbels](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/nibbels.md)
- [Nukem](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/nukem.md)
- [Payday](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/payday.md)
- [Pelican](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/pelican.md)
- [Readys](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/readys.md)
- [Roquefort](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/roquefort.md)
- [Snookums](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/snookums.md)
- [Sorcerer](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/sorcerer.md)
- [Splodge](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/splodge.md)
- [Sybaris](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/sybaris.md)
- [Walla](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/walla.md)
- [Webcal](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/webcal.md)
- [XposedAPI](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/xposedapi.md)
- [ZenPhoto](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/zenphoto.md)
- [Zino](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/zino.md)
- [QuackerJack](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/get-to-work/quackerjack.md)
- [TRY HARDER](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/try-harder.md): 25 points
- [Clyde](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/try-harder/clyde.md)
- [Peppo](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/try-harder/peppo.md)
- [Sirol](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/linux/try-harder/sirol.md)
- [Windows](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows.md)
- [WARM UP](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up.md): 10 points
- [Algernon](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up/algernon.md)
- [Compromised](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up/compromised.md)
- [Helpdesk](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up/helpdesk.md)
- [Internal](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up/internal.md)
- [Kevin](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up/kevin.md)
- [Metallus](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/warm-up/metallus.md)
- [GET TO WORK](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work.md): 20 points
- [AuthBy](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/authby.md)
- [Billyboss](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/billyboss.md)
- [Craft](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/craft.md)
- [Fish](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/fish.md)
- [Hutch](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/hutch.md)
- [Jacko](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/jacko.md)
- [Nickel](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/nickel.md)
- [Shenzi](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/shenzi.md)
- [Slort](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/get-to-work/slort.md)
- [TRY HARDER](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/try-harder.md): 25 points
- [Heist](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/try-harder/heist.md)
- [Meathead](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/try-harder/meathead.md)
- [Vault](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/windows/try-harder/vault.md)
- [Template](https://cel1s0.gitbook.io/offsec-notes/walkthroughs/pg-practice/template.md)
- [About the author](https://cel1s0.gitbook.io/offsec-notes/about-the-author.md)
