TJ Null OSCP list: the boxes you can track
The TJ Null list is a community-maintained spreadsheet of OSCP-like practice machines, mostly Hack The Box, Proving Grounds and Vulnhub. This page credits the original, shows which of its Hack The Box machines are in the ZeroBox catalogue, and gives a suggested order.
What the TJ Null list is
TJ Null, writing on NetSec Focus, put together lists of practice machines that resemble what the OSCP exam rewards: a clear enumeration path, public exploits that need small edits, and classic privilege escalation. The original post, The Journey to Try Harder, links the spreadsheet, and the sheet itself is at the NetSec Focus Trophy Room. It has lists for Proving Grounds, Hack The Box and Vulnhub. The current Hack The Box tab is headed "OSCPv3 OSCP-like machines", and the list changes, so use the sheet as the source of truth.
This page does not copy the sheet. It shows which of its Hack The Box machines exist in the ZeroBox catalogue so you can track them, using the names as mirrored on 0xdf's cheat sheet on 2026-10-08.
How to work through it
- Spend the first 45 minutes of every box on enumeration alone. Write down every port, every version and every odd page before you try an exploit.
- Take no hints for an hour. If you are stuck, record exactly where, then use a hint and note what you missed.
- After each box, write a three line summary: the foothold, the escalation, and one habit to change.
- Do not binge Active Directory boxes first. Mix them in, because the exam gives that set the most points.
- Re-solve a few boxes from scratch later, with a timer.
On the list, in the ZeroBox catalogue
34 Hack The Box machines from the list are in the catalogue, and 5 of them carry the ZeroBox OSCP tag. Others carry tags from other tracks or none, so the last column shows the tag, not whether a box is on TJ Null's list. Machines with a ZeroBox writeup link to an attack path page; the rest link to the official room.
| Machine (Hack The Box) | OS | Difficulty | ZeroBox OSCP tag |
|---|---|---|---|
| Broker | Linux | Easy | Yes |
| Busqueda | Linux | Easy | No |
| CozyHosting | Linux | Easy | No |
| Help | Linux | Easy | No |
| Keeper | Linux | Easy | No |
| Networked | Linux | Easy | No |
| Pandora | Linux | Easy | No |
| Sau | Linux | Easy | No |
| Soccer | Linux | Easy | No |
| Usage | Linux | Easy | No |
| Access | Windows | Easy | No |
| Forest | Windows | Easy | Yes |
| Heist | Windows | Easy | No |
| Mailing | Windows | Easy | No |
| Return | Windows | Easy | No |
| Sauna | Windows | Easy | Yes |
| ServMon | Windows | Easy | No |
| Support | Windows | Easy | No |
| Timelapse | Windows | Easy | No |
| Magic | Linux | Medium | No |
| Monitored | Linux | Medium | No |
| UpDown | Linux | Medium | No |
| Administrator | Windows | Medium | Yes |
| Aero | Windows | Medium | No |
| Cascade | Windows | Medium | No |
| Escape | Windows | Medium | No |
| Flight | Windows | Medium | No |
| Intelligence | Windows | Medium | No |
| Jeeves | Windows | Medium | No |
| Manager | Windows | Medium | No |
| Monteverde | Windows | Medium | No |
| StreamIO | Windows | Medium | No |
| Intentions | Linux | Hard | No |
| Blackfield | Windows | Hard | Yes |
Other machines the catalogue tags OSCP
These 37 carry the ZeroBox OSCP tag but are not on the Hack The Box tab above, mostly TryHackMe rooms. They are useful practice, but they are not TJ Null's picks. For the same machines grouped by difficulty, see OSCP-like machines.
| Machine | Platform | OS | Difficulty |
|---|---|---|---|
| Archetype | HTB | Windows | Very Easy |
| Kobold | HTB | Linux | Easy |
| Time | HTB | Linux | Medium |
| Bastion | HTB | Windows | Medium |
| EscapeTwo | HTB | Windows | Medium |
| Resolute | HTB | Windows | Medium |
| Silo | HTB | Windows | Medium |
| Cyborg | THM | Linux | Easy |
| Ignite | THM | Linux | Easy |
| Kenobi | THM | Linux | Easy |
| LazyAdmin | THM | Linux | Easy |
| RootMe | THM | Linux | Easy |
| Skynet | THM | Linux | Easy |
| Tomghost | THM | Linux | Easy |
| Vulnversity | THM | Linux | Easy |
| Alfred | THM | Windows | Easy |
| Blue | THM | Windows | Easy |
| Buffer Overflow Prep | THM | Windows | Easy |
| Ice | THM | Windows | Easy |
| Living Off The Land | THM | Windows | Easy |
| Steel Mountain | THM | Windows | Easy |
| Windows Event Logs | THM | Windows | Easy |
| Jacob the Boss | THM | Linux | Medium |
| Mr Robot CTF | THM | Linux | Medium |
| The Cod Caper | THM | Linux | Medium |
| Breaching Active Directory | THM | Windows | Medium |
| Exploiting Active Directory | THM | Windows | Medium |
| Relevant | THM | Windows | Medium |
| VulnNet: Active (Retired) | THM | Windows | Medium |
| Windows Local Persistence | THM | Windows | Medium |
| Windows PrivEsc | THM | Windows | Medium |
| Windows PrivEsc Arena | THM | Windows | Medium |
| Brainpan 1 | THM | Linux | Hard |
| Daily Bugle | THM | Linux | Hard |
| Enterprise | THM | Windows | Hard |
| Raz0rBlack | THM | Windows | Hard |
| Wreath | THM | Windows | Hard |
A suggested order
- Easy Linux for the loop of scan, web enumeration, foothold and sudo or SUID escalation: Broker, Busqueda, CozyHosting, Help, Keeper.
- Easy Windows for service abuse and token privileges: Access, Forest, Heist, Mailing, Return.
- Medium Windows and domain boxes to build Active Directory habits: Administrator, Aero, Cascade, Escape, Flight.
- Hard boxes last, once the first three feel routine: Intentions, Blackfield.
Then run a timed rehearsal in the exam simulator and check your pacing against the OSCP scoring and time budget guide.
Track every box in one place.
Add the machines you are working through, log your notes and flags, and watch your time per box. Offline, no account.
Frequently asked questions
Who made the TJ Null list?
It is maintained by TJ Null (TJnull) and published through NetSec Focus as a Google Sheet. ZeroBox did not create it and does not republish it; this page links to the original and shows how it overlaps with the ZeroBox catalogue.
Is the list only Hack The Box?
No. The original guide describes separate lists for Proving Grounds, Hack The Box and Vulnhub, all on the same spreadsheet. TryHackMe rooms are not part of TJ Null's sheet, which is why ZeroBox tags them separately.
How is this page different from the OSCP-like machines page?
The OSCP-like machines page groups every machine ZeroBox tags OSCP by difficulty. This page starts from the TJ Null list itself, shows which of its Hack The Box machines the catalogue contains, and suggests an order.
Related
- OSCP-like machines by difficulty
- OSCP exam scoring and 24h time budget
- Hack The Box and TryHackMe machine directory
- Pentest methodology checklist
- HTB and TryHackMe progress tracker
Sources
- NetSec Focus: The Journey to Try Harder, by TJnull (published 2021-05-06)
- NetSec Focus Trophy Room (TJ Null sheet)
- 0xdf: OffSec exam HTB lists (used to read the current Hack The Box tab)
Last reviewed: 2026-10-08. ZeroBox is an independent project and is not affiliated with OffSec, Hack The Box or TJ Null.