// htb writeup HackTheBox 2026-05-24
Logging
HackTheBox Medium HackTheBox
seasonal
root obtained // PWNED

📋 Logging

Difficulty: Medium OS: Windows Release: HTB Season 10

A Windows AD box that leans into the logging theme — the foothold credential is sitting in a trace log on an SMB share someone left world-readable. The root path is a rogue WSUS attack, which is rare enough in CTF that it’s worth doing just for the methodology. In between there’s Shadow Credentials, a DLL hijack, and an ADCS template abuse. Busy box with a satisfying finish.


📸 Proof


🧠 Concepts Covered


💡 Hints (No Spoilers)

Foothold

User

Root


📚 Useful Reading