Skip to main content
Room Banner
Room Icon

Crocc Crew

Crocc Crew has created a backdoor on a Cooctus Corp Domain Controller. We're calling in the experts to find the real back door!

insane

180 min

5,083

User profile photo.

To access material, start machines and answer questions login.

Score updated
Score updated

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off
Accessing Crocc Crew

To access the Lab Machine, you will need to first connect to our network using OpenVPN. Here is a mini walkthrough of getting connected.

(Please note the browser-based machine will be able to access this machine, you will not need to connect to the .)

Answer the questions below

Go to your access page. Select your VPN server of choice and download your configuration file.

Use an OpenVPN client to connect. This example shows the client on Linux, use this guide to connect using Windows or MacOS

Change "ben.ovpn" to your config file

When you run this you see lots of text, at the end it will say “Initialization Sequence Completed”

Return to your access page. You can verify you are connected by looking on your access page. Refresh the page. You should see a green tick next to Connected. It will also show you your internal IP address.

You're now ready to start hacking! 

Alternatively, you can deploy the In-Browser Kali or Attack Box and automatically be connected to the TryHackMe Network.

Once connected to the VPN, deploy the machine and get hacking!

The Crocc Crew Strikes!

You just gained initial access into a segmented part of the network and you've found only one device -- A domain controller. It appears that it's already been hacked... Can you find out who did it?


Check out the Crocc Crew merch on Varg's Redbubble (opens in new tab).

Answer the questions below
What is the User flag?

What is the name of the account Crocc Crew planted?

What is the Privileged User's flag?

What is the Second Privileged User's flag?

What is the Root flag?