🐀🐀🐀 0 pts earned

Under Fire

Premium Machine (Locked)

🧩 PurpleTeam

🖧 AD Network — PurpleTeam

CIRT Gateway 🔒 SIEM Station SOC Runbook Vuln Code Depot Under Fire

Internal host — not internet-facing. Reach it from your cirt-gateway shell or the in-browser Pwnbox at active-defense-lab.default.svc.cluster.local with the analyst account. This host is under constant attack from 10.99.1.1. An attacker daemon continuously plants a webshell and a malicious cron job. You must configure fail2ban, enable ufw, block the attacker, and clean up the artifacts — in the right order. The machine auto-resets every 30 minutes.

🩸 First user blood: davidkarpinski1 🩸 First root blood: davidkarpinski1
Internal machine — reachable only by pivoting from the entry host. It is not directly scannable from the internet, so external scans return filtered. This is by design, not an outage.
Target IP Premium required
User Flag Pending
Root Flag Pending

Community

Community Hints

Grade A · 1000 pts Grade B · 700 pts Grade C · 400 pts Grade D · 200 pts + 150 credits on accept

Short, stage-specific nudges — directional, spoiler-light, no exact commands.

Privilege Escalation

Five Checks, One Order suraj_pun_magar · A · 2 Jul 2026

Community

Community Walkthroughs

Grade A · 2500 pts Grade B · 1750 pts Grade C · 1000 pts Grade D · 500 pts + 300 credits on accept

🔒 Community walkthroughs are spoilers — capture the root flag on this machine to unlock them.