HackTheBox - Cereal (User)

Chaining XSS, SSRF, and deserialization vulnerabilities to get RCE

HackTheBox - Blackfield

Abusing Backup Operators group to dump Active Directory database