ZeroBox

OSCP-Like Machines: 42 boxes by difficulty

OSCP, the Offensive Security Certified Professional, is OffSec's hands-on penetration testing certification. The exam is a proctored practical of roughly 24 hours in which you compromise standalone machines and an Active Directory environment, followed by a written report.

The 42 machines on this page are tagged OSCP in the ZeroBox catalog and come from HTB & THM. By operating system that is 26 Windows, 16 Linux. Good preparation means practising the same loop on many different targets: enumerate carefully, find a foothold, escalate, and document each step. Boxes with public exploits that need small edits, web footholds and classic Linux and Windows privilege escalation map closely to what the exam rewards.

To use the list, start at the easiest group and work upward, spending real time on enumeration before looking at any help. After each box, write down the foothold, the escalation and what you would do faster next time. 4 of these are targets I solved myself, so they link to an attack path summary on this site; the others link to the official room. Once you are comfortable, rehearse under pressure in the exam simulator, and follow the phase-by-phase pentest methodology checklist so you do not skip steps. You can also browse the technique hubs to drill one skill at a time.

Jump to difficulty

OSCP machine list by difficulty

Very Easy (1)

MachinePlatformOSTags
ArchetypeHTBWindowsMSSQL, xp_cmdshell, JuicyPotato, PowerShell

Easy (19)

MachinePlatformOSTags
KoboldHTBLinuxsuid
RootMeTHMLinuxFile-Upload, Bypass, SUID-Python
AlfredTHMWindowsOSCP, Jenkins, PowerShell, Token Impersonation
BlueTHMWindowsOSCP, EternalBlue, MS17-010, SMB
BrokerHTBLinuxActiveMQ-CVE-2023-46604, Java-Deserialization, Sudo-Nginx
Buffer Overflow PrepTHMWindowsOSCP, Buffer Overflow, x86, Mona.py
CyborgTHMLinuxOSCP, Borg Backup, Hash Cracking, Sudoers
ForestHTBWindowsAS-REP Roasting, ASREPRoasting, Active Directory, BloodHound
IceTHMWindowsOSCP, Icecast, CVE-2004-1561, Mimikatz
IgniteTHMLinuxOSCP, Fuel CMS, CVE-2018-16763, RCE
KenobiTHMLinuxOSCP, Samba, ProFTPD, SUID
LazyAdminTHMLinuxOSCP, SweetRice CMS, MySQL Backup, Sudoers
Living Off The LandTHMWindowsLOLBAS, Living Off The Land, Certutil, MSHTA
SaunaHTBWindowsAS-REP Roasting, ASREPRoasting-Attack, Active Directory, BloodHound
SkynetTHMLinuxOSCP, Samba, SquirrelMail, Cuppa CMS
Steel MountainTHMWindowsOSCP, Rejetto HFS, CVE-2014-6287, Unquoted Service Path
TomghostTHMLinuxOSCP, Ghostcat, CVE-2020-1938, Apache Tomcat
VulnversityTHMLinuxOSCP, File Upload Bypass, Burp Suite, SUID
Windows Event LogsTHMWindowsEvent Logs, Sysmon, Log Clearing, Wevtutil

Medium (16)

MachinePlatformOSTags
Mr Robot CTFTHMLinuxWordPress, Wp-login, Dictionary-Attack, Nmap-SUID
AdministratorHTBWindowsActiveDirectory, ADCS, Golden-Cert, Kerberoasting
BastionHTBWindowsExploiting-MRemoteNG, SAM Hive, SMB, VHD
Breaching Active DirectoryTHMWindowsActive Directory, NTLM Relay, LLMNR-Poisoning, Responder
EscapeTwoHTBWindowsActiveDirectory, MSSQL-Linked-Server, Coerce-Authentication, GPO-Abuse
Exploiting Active DirectoryTHMWindowsActive Directory, Kerberoasting, ASREPRoasting, Pass-the-Hash
Jacob the BossTHMLinuxJBoss, Java-Deserialization, CVE-2017-12149, SUID
RelevantTHMWindowsOSCP, SMB, IIS, WebShell
ResoluteHTBWindowsActive Directory, DLL Injection, DNSAdmins, DnsAdmins-Abuse
SiloHTBWindowsDatabase, Enumerating-Oracle-SIDs, Oracle, TNS Listener
The Cod CaperTHMLinuxOSCP, SQLi, Command Injection, Buffer Overflow
TimeHTBLinuxCVE-2019-12384, CVE-2019-12814, CVE-2019-14439, CVE-2020-24616
VulnNet: Active (Retired)THMWindowsActive Directory, Redis, GPP-Passwords, Kerberoast
Windows Local PersistenceTHMWindowsPersistence, Registry, Scheduled Tasks, Services
Windows PrivEscTHMWindowsPrivilege Escalation, UAC Bypass, Service Exploitation, DLL Hijacking
Windows PrivEsc ArenaTHMWindowsPrivilege Escalation, AlwaysInstallElevated, Unquoted Service Path, Registry

Hard (6)

MachinePlatformOSTags
BlackfieldHTBWindowsAS-REP Roasting, Active Directory, Anonymous-/-Guest, BloodHound
Brainpan 1THMLinuxOSCP, Buffer Overflow, Binary Exploitation, Wine
Daily BugleTHMLinuxOSCP, Joomla, SQLi, CVE-2019-8942
EnterpriseTHMWindowsActive Directory, ZeroLogon, SQLi, Privilege Escalation
Raz0rBlackTHMWindowsActive Directory, NFS, Kerberos, AS-REP Roasting
WreathTHMWindowsActive Directory, Pivoting, Chisel, Empire

Track your progress. ZeroBox keeps a Kanban board, notes and checklists for every box, offline in your browser. Open ZeroBox

Related guides

Machines belong to HTB & THM. ZeroBox is not affiliated with the platforms or certification bodies named here.