Machine / Machines

Checkpoint

State: target-state.json - Notes: notes.md The sections below are merged from companion Markdown notes for the same case. They are rendered after sanitization so the article stays precise without publishing raw flags, credentials, or target-specific secrets....

DocumentedPublished 2025-11-23Sanitized local writeup

Scenario

Checkpoint attack path

State: target-state.json - Notes: notes.md The sections below are merged from companion Markdown notes for the same case. They are rendered after sanitization so the article stays precise without publishing raw flags, credentials, or target-specific secrets....

Objective

Machine walkthrough focused on Machines evidence, validation, and reusable operator lessons.

Checkpoint sanitized attack graph

Walkthrough flow

01

Scope and service discovery

02

Attack surface mapping

03

Initial foothold

04

Privilege escalation

05

Proof captured

Source coverage

Needs source review

Status: needs source review. This article is generated from 2 sanitized Markdown sources and keeps raw flags, credentials, keys, cookies, and reusable secrets out of the rendered blog.

48% coverage
Evidence verdict

Needs source review: the page is kept as an archive entry, not a finished walkthrough, because the current source material is too thin.

  • <TARGET>-Checkpoint/walkthrough.md
  • HTB/<TARGET>-Checkpoint/notes.md

Technical Walkthrough

Checkpoint Walkthrough

Raw flags and reusable secrets are stored only under loot/.

Summary

Evidence

  • State: target-state.json
  • Notes: notes.md

Source-Backed Dossier

The sections below are merged from companion Markdown notes for the same case. They are rendered after sanitization so the article stays precise without publishing raw flags, credentials, or target-specific secrets.

Notes

Scope

FieldValue
PlatformHack The Box / simulated lab
TargetCheckpoint
DifficultyMedium
OSWindows
Active target IP<TARGET>
Hostname/domainunknown
Pwnbox<TARGET>
Attacker/VPN IPunknown
Local workspace<local workspace><TARGET>-Checkpoint
Pwnbox workspace~/htb/<TARGET>-Checkpoint
Started2026-06-13T23:25:37Z

Evidence Ledger

Time UTCPhaseCommand/ActionOutput fileFindingConfidenceNext action
2026-06-13T23:25:37Zsetuphtbctl inittarget-state.jsonWorkspace initialized by deterministic harness.HighValidate route and start baseline recon.
2026-06-13T23:25:50ZsetupTarget IP changed from previous Checkpoint instancetarget-state.jsonPrevious IP <TARGET> was unreachable from the Pwnbox gateway; new active IP is <TARGET>.HighMirror workspace to Pwnbox and validate route/service exposure.
2026-06-13T23:25:50ZsetupStore operator-provided starting credentialloot/starting-alex.turner.credStarting credential is available as a loot-only reference for quiet live validation.HighTest only after a reachable auth surface is identified.
2026-06-13T23:27:12ZbaselinePath diagnostics for new active IPenum/path-diagnostics-20260613.txtPwnbox SSH/tun0 are valid, but gateway <TARGET> returns Destination Host Unreachable for <TARGET>; targeted TCP ports are filtered/no-response.HighAlign Pwnbox and target VPN/lab region or respawn/reset Pwnbox/target before continuing.

Synthesis

Current completion state: BASELINE.

Current blocker: the active target IP is not reachable from the current Pwnbox routing path. This must be fixed before credential validation or service enumeration can be meaningful.

Raw flags and reusable secrets must be stored only under loot/.