2ubZ3r0

2ubZ3r0

Active Directory Lab Designer • Red Team Enthusiast • HackSmarter • Founder of R00tF0rce

Building realistic Active Directory penetration testing labs inspired by real-world enterprise environments.

Explore My Labs Westbridge Range R00tF0rce on HTB ZeroTrace Research

❄️ FREEZE THE DOMAIN

2ubZ3r0 profile image
2ubZ3r0

About 2ubZ3r0

Hi, I'm 2ubZ3r0. Passionate about Active Directory security, red teaming, Windows internals and realistic attack simulations. I design hands-on penetration testing labs that teach modern AD attack paths, privilege escalation and enterprise compromise techniques without unrealistic CTF gimmicks.

Active DirectoryBloodHoundKerberos AD CSMSSQLNTLM Relay WinRMRBCDShadow Credentials ESC AttacksSPN AbusePowerShell Windows PrivEsc
LinkedIn Buy Me A Coffee
[ HACK THE BOX TEAM ]

R00tF0rce

Founder

I'm the Founder of the Hack The Box team R00tF0rce. Check out the team profile and follow our activity on HTB.

Open R00tF0rce

HackSmarter Challenge Labs

Medium

StellarComms

StellarComms lab artwork

Satellite Operations / Space Tech

A realistic enterprise satellite operations environment where small pieces of public information become valuable attack vectors.

OSINTEXIFSMBBloodHoundWriteOwnerDCSync
Play on HackSmarter →
Medium

City Council

City Council lab artwork

Municipal Government

An internal government network focused on realistic Active Directory misconfigurations. Phishing, DPAPI, Kerberoasting, IIS.

KerberoastingDPAPIIISOU DelegationJuicyPotato
Play on HackSmarter →
Medium

ShadowGate 2

ShadowGate 2 lab artwork

Cybersecurity Company

Exploit vulnerable dev infrastructure, abuse delegated AD rights, restore deleted users, escalate through AD CS.

SQLiNTLMMSSQLESC7AD CS
Play on HackSmarter →
Medium

404 Bank

404 Bank lab artwork

Financial Institution

Web apps, internal services, certificate infrastructure. BloodHound, password attacks, tunneling, AD CS abuse.

KerberoastingCeWLZIPChiselESC4
Play on HackSmarter →
Hard

North Stone

North Stone lab artwork

Healthcare / Enterprise

Complex healthcare AD with multiple paths: SQL injection into linked servers, AD CS, DLL hijacking, SYSTEM priv.

SQLiLinked SQLxp_dirtreeESC13DLL Hijack
Play on HackSmarter →
Hard

NovaCart

NovaCart lab artwork

Retail Enterprise

DNS abuse, NTLM relay, certificate attacks, advanced delegation. Realistic enterprise admin mistakes.

DNSAD CSNTLMKerberosRBCD
Play on HackSmarter →
Hard

NovaForge

NovaForge lab artwork

Manufacturing

Phishing entry, credential harvesting, Firefox extraction, BloodHound, NTLM reflection, Kerberos delegation.

PhishingFirefoxBloodHoundS4UWriteSPN
Play on HackSmarter →
Featured HackSmarter Range
Hard

Westbridge University

7 Machine Active Directory Range

Westbridge University is a prestigious, well-funded academic institution that has spent the last year hardening its Active Directory infrastructure. Players are hired as internal penetration testers for a complete enterprise compromise assessment. Multi-subnet, trust relationships, modern AD, multiple attack paths.

Active DirectoryBloodHoundKerberos AD CSRBCDShadow Credentials MSSQLWinRMDCSyncLateral Movement
Play Westbridge Range

Upcoming Releases

Hard

Locktal Martin

COMING SOON

Enterprise AD focused on privilege escalation, delegation abuse, advanced Kerberos attack paths.

Medium

Hex Care

COMING SOON

Healthcare-themed AD lab featuring Windows administration mistakes, lateral movement, enterprise credential abuse.

ZEROTRACE // RESEARCH ARCHIVE

ZeroTrace Research

Technical research notes covering vulnerabilities, CVEs, offensive security tooling, evasion research and security observations. Archived here for reference.

1 Entry
Research

Customizing GodPotato for Improved Evasion

Archived technical write-up covering customization of the GodPotato project and related evasion-oriented research.

Windows Privilege Escalation Tool Research Evasion
Open Archive Entry →

Why These Labs?

Realistic Enterprise

Built from real-world internal penetration testing concepts.

Modern AD Attacks

Focus on current attack techniques used in enterprise environments.

Multiple Attack Paths

More than one valid compromise path exists in many labs.

Offensive Thinking

Enumeration matters more than guessing vulnerabilities.

Active DirectoryBloodHoundCertipyImpacketWinRM KerberosPowerShellMSSQLResponderChisel FirefoxIISSMB Active DirectoryBloodHoundCertipyImpacketWinRM KerberosPowerShellMSSQLResponderChisel FirefoxIISSMB

Like the labs?

If you've enjoyed my HackSmarter labs and want to support future content, consider buying me a coffee.

Buy Me A Coffee LinkedIn HackSmarter R00tF0rce