TJ Null OSCP list: the boxes you can track

The TJ Null list is a community-maintained spreadsheet of OSCP-like practice machines, mostly Hack The Box, Proving Grounds and Vulnhub. This page credits the original, shows which of its Hack The Box machines are in the ZeroBox catalogue, and gives a suggested order.

What the TJ Null list is

TJ Null, writing on NetSec Focus, put together lists of practice machines that resemble what the OSCP exam rewards: a clear enumeration path, public exploits that need small edits, and classic privilege escalation. The original post, The Journey to Try Harder, links the spreadsheet, and the sheet itself is at the NetSec Focus Trophy Room. It has lists for Proving Grounds, Hack The Box and Vulnhub. The current Hack The Box tab is headed "OSCPv3 OSCP-like machines", and the list changes, so use the sheet as the source of truth.

This page does not copy the sheet. It shows which of its Hack The Box machines exist in the ZeroBox catalogue so you can track them, using the names as mirrored on 0xdf's cheat sheet on 2026-10-08.

How to work through it

On the list, in the ZeroBox catalogue

34 Hack The Box machines from the list are in the catalogue, and 5 of them carry the ZeroBox OSCP tag. Others carry tags from other tracks or none, so the last column shows the tag, not whether a box is on TJ Null's list. Machines with a ZeroBox writeup link to an attack path page; the rest link to the official room.

Machine (Hack The Box)OSDifficultyZeroBox OSCP tag
BrokerLinuxEasyYes
BusquedaLinuxEasyNo
CozyHostingLinuxEasyNo
HelpLinuxEasyNo
KeeperLinuxEasyNo
NetworkedLinuxEasyNo
PandoraLinuxEasyNo
SauLinuxEasyNo
SoccerLinuxEasyNo
UsageLinuxEasyNo
AccessWindowsEasyNo
ForestWindowsEasyYes
HeistWindowsEasyNo
MailingWindowsEasyNo
ReturnWindowsEasyNo
SaunaWindowsEasyYes
ServMonWindowsEasyNo
SupportWindowsEasyNo
TimelapseWindowsEasyNo
MagicLinuxMediumNo
MonitoredLinuxMediumNo
UpDownLinuxMediumNo
AdministratorWindowsMediumYes
AeroWindowsMediumNo
CascadeWindowsMediumNo
EscapeWindowsMediumNo
FlightWindowsMediumNo
IntelligenceWindowsMediumNo
JeevesWindowsMediumNo
ManagerWindowsMediumNo
MonteverdeWindowsMediumNo
StreamIOWindowsMediumNo
IntentionsLinuxHardNo
BlackfieldWindowsHardYes

Other machines the catalogue tags OSCP

These 37 carry the ZeroBox OSCP tag but are not on the Hack The Box tab above, mostly TryHackMe rooms. They are useful practice, but they are not TJ Null's picks. For the same machines grouped by difficulty, see OSCP-like machines.

MachinePlatformOSDifficulty
ArchetypeHTBWindowsVery Easy
KoboldHTBLinuxEasy
TimeHTBLinuxMedium
BastionHTBWindowsMedium
EscapeTwoHTBWindowsMedium
ResoluteHTBWindowsMedium
SiloHTBWindowsMedium
CyborgTHMLinuxEasy
IgniteTHMLinuxEasy
KenobiTHMLinuxEasy
LazyAdminTHMLinuxEasy
RootMeTHMLinuxEasy
SkynetTHMLinuxEasy
TomghostTHMLinuxEasy
VulnversityTHMLinuxEasy
AlfredTHMWindowsEasy
BlueTHMWindowsEasy
Buffer Overflow PrepTHMWindowsEasy
IceTHMWindowsEasy
Living Off The LandTHMWindowsEasy
Steel MountainTHMWindowsEasy
Windows Event LogsTHMWindowsEasy
Jacob the BossTHMLinuxMedium
Mr Robot CTFTHMLinuxMedium
The Cod CaperTHMLinuxMedium
Breaching Active DirectoryTHMWindowsMedium
Exploiting Active DirectoryTHMWindowsMedium
RelevantTHMWindowsMedium
VulnNet: Active (Retired)THMWindowsMedium
Windows Local PersistenceTHMWindowsMedium
Windows PrivEscTHMWindowsMedium
Windows PrivEsc ArenaTHMWindowsMedium
Brainpan 1THMLinuxHard
Daily BugleTHMLinuxHard
EnterpriseTHMWindowsHard
Raz0rBlackTHMWindowsHard
WreathTHMWindowsHard

A suggested order

  1. Easy Linux for the loop of scan, web enumeration, foothold and sudo or SUID escalation: Broker, Busqueda, CozyHosting, Help, Keeper.
  2. Easy Windows for service abuse and token privileges: Access, Forest, Heist, Mailing, Return.
  3. Medium Windows and domain boxes to build Active Directory habits: Administrator, Aero, Cascade, Escape, Flight.
  4. Hard boxes last, once the first three feel routine: Intentions, Blackfield.

Then run a timed rehearsal in the exam simulator and check your pacing against the OSCP scoring and time budget guide.

Track every box in one place.

Add the machines you are working through, log your notes and flags, and watch your time per box. Offline, no account.

Frequently asked questions

Who made the TJ Null list?

It is maintained by TJ Null (TJnull) and published through NetSec Focus as a Google Sheet. ZeroBox did not create it and does not republish it; this page links to the original and shows how it overlaps with the ZeroBox catalogue.

Is the list only Hack The Box?

No. The original guide describes separate lists for Proving Grounds, Hack The Box and Vulnhub, all on the same spreadsheet. TryHackMe rooms are not part of TJ Null's sheet, which is why ZeroBox tags them separately.

How is this page different from the OSCP-like machines page?

The OSCP-like machines page groups every machine ZeroBox tags OSCP by difficulty. This page starts from the TJ Null list itself, shows which of its Hack The Box machines the catalogue contains, and suggests an order.

Related

Sources

Last reviewed: 2026-10-08. ZeroBox is an independent project and is not affiliated with OffSec, Hack The Box or TJ Null.