Posts grouped by topic. Jump to a tag to find related write-ups.
- active-directory
- ai
- ansible
- anthropic
- apt
- automation
- aws
- blue-team
- bluetooth
- boofuzz
- browsers
- bug-hunting
- c2
- c3
- carving
- channels
- chat-completions
- chatgpt
- cisa
- cisco
- claude
- claude-code
- cobalt-strike
- code-review
- configuration
- csharp
- curapi
- cursor
- cursor-cli
- cve
- cve-2025-59287
- cve-2026-8795
- dcsync
- deception
- deserialization
- detection
- detection-engineering
- dfir
- dhcp
- dhcp-snooping
- dns
- docker
- drone
- edr
- egg-hunting
- encoding
- ettercap
- expdev
- exploit-development
- externalc2
- f-secure
- firefox
- fleet
- forensics
- frontier-models
- fuzzing
- gemini
- go
- golden-image
- hackmegpt
- hardware
- hhoneypot
- homelab
- honeypot
- huntress
- iac
- implant
- incident-response
- infrastructure
- irsec
- javascript
- kali-linux
- kali-tx
- kerberoasting
- kev
- kolide
- lab
- linux
- llm
- llm-security
- lpe
- malware
- malware-analysis
- mcp
- memory
- mimikatz
- mitigation
- mitre-attack
- msfvenom
- network-protocols
- network-security
- networking
- nginx
- obfuscation
- open-webui
- openai
- openai-api
- openai-compatible
- openrouter
- openwebui
- osquery
- owasp
- packer
- payloads
- pe-imports
- pentesting
- pfsense
- physical-security
- poc
- port-forwarding
- post-exploitation
- process-injection
- prompt-injection
- proxy
- purple-teaming
- python
- ransomware
- rce
- red-teaming
- red-vs-blue
- rsyslog
- security-onion
- seh
- self-hosted
- servers
- shellcode
- siem
- sigma
- slack
- soapformatter
- socat
- spoofing
- starvation
- static-analysis
- sulley
- suricata
- switching
- sysmon
- thick-clients
- threat-hunting
- tooling
- training
- tunneling
- uav
- unicode
- unquoted-service-path
- velociraptor
- venetian
- virtualization
- vulnerability-research
- vulnerable-ad
- wazuh
- web
- webshell
- wifi
- windows
- windows-server
- winexec
- wireless
- wsus
- x86
- yaml-injection
- yara
active-directory
ai
ansible
anthropic
apt
automation
aws
blue-team
- Walkthrough: The detection and analysis of the ransomware incident in IRSeC 2021
- Resource Efficient Internal Network Honeypots
- Applied Purple Teaming Series ( Attack, Detect, & Defend ) Part 3
- Applied Purple Teaming Series ( Weaponize Windows ) Part 2
- Applied Purple Teaming Series ( The Virtual Environment ) Part 1
- Studying Sysmon's Ability to Detect Process Injections Using Different Configuration Schemas
- Integrating C3 With Cobalt Strike via ExternalC2 And Studying Their Behavior
bluetooth
boofuzz
browsers
bug-hunting
c2
c3
carving
channels
chat-completions
chatgpt
cisa
cisco
claude
claude-code
cobalt-strike
code-review
configuration
csharp
curapi
cursor
cursor-cli
cve
cve-2025-59287
cve-2026-8795
dcsync
deception
deserialization
detection
detection-engineering
dfir
dhcp
dhcp-snooping
dns
docker
drone
edr
egg-hunting
encoding
ettercap
expdev
exploit-development
- Mine for Local Privilege Escalation Vulnerabilities in Windows Applications Using Automation and Virtualization
- Windows Exploit Development: Egg Hunting
- Windows Exploit Development: Unicode and Venetian shellcode techniques
- Detecting Bugs Using Network Protocol Fuzzing
- Windows Exploit Development: Utilizing imported functions (WinExec)
- Manually Encode Bytes & Shellcode Carving
externalc2
f-secure
firefox
fleet
forensics
frontier-models
fuzzing
gemini
go
golden-image
hackmegpt
hardware
hhoneypot
homelab
- Insecure Active Directory Lab For Training (IaC)
- Resource Efficient Internal Network Honeypots
- Applied Purple Teaming Series ( Attack, Detect, & Defend ) Part 3
- Applied Purple Teaming Series ( Weaponize Windows ) Part 2
- Applied Purple Teaming Series ( The Virtual Environment ) Part 1
- 2019 End-of-Year Infrastructure Upgrades
honeypot
huntress
iac
implant
incident-response
- Finding 0-Days With Claude in Under an Hour
- Inside CVE-2025-59287: SoapFormatter RCE in WSUS
- Walkthrough: The detection and analysis of the ransomware incident in IRSeC 2021
- Resource Efficient Internal Network Honeypots
- Applied Purple Teaming Series ( Attack, Detect, & Defend ) Part 3
- Applied Purple Teaming Series ( The Virtual Environment ) Part 1
infrastructure
irsec
javascript
kali-linux
kali-tx
kerberoasting
kev
kolide
lab
linux
llm
llm-security
lpe
malware
malware-analysis
mcp
memory
mimikatz
mitigation
mitre-attack
msfvenom
network-protocols
network-security
networking
nginx
obfuscation
open-webui
openai
openai-api
openai-compatible
openrouter
openwebui
osquery
owasp
packer
payloads
pe-imports
pentesting
pfsense
physical-security
poc
port-forwarding
post-exploitation
process-injection
prompt-injection
proxy
purple-teaming
python
ransomware
rce
red-teaming
- Finding 0-Days With Claude in Under an Hour
- LLM Hacking: Prompt Injection
- Insecure Active Directory Lab For Training (IaC)
- Hacking From the Sky - Penetration Testing UAV
- Using Cobalt Strike with Tunnel-Manager for Distributed Hacking
- Applied Purple Teaming Series ( Attack, Detect, & Defend ) Part 3
- Applied Purple Teaming Series ( The Virtual Environment ) Part 1
- 6-Eyed-Spider Post-Exploitation Red-Team Tool
- Integrating C3 With Cobalt Strike via ExternalC2 And Studying Their Behavior
- A Golden Image for Our Pentest VMs
red-vs-blue
rsyslog
security-onion
seh
self-hosted
servers
shellcode
siem
sigma
slack
soapformatter
socat
spoofing
starvation
static-analysis
sulley
suricata
switching
sysmon
thick-clients
threat-hunting
- Walkthrough: The detection and analysis of the ransomware incident in IRSeC 2021
- Resource Efficient Internal Network Honeypots
- Applied Purple Teaming Series ( Attack, Detect, & Defend ) Part 3
- Applied Purple Teaming Series ( The Virtual Environment ) Part 1
- Studying Sysmon's Ability to Detect Process Injections Using Different Configuration Schemas
tooling
training
tunneling
uav
unicode
unquoted-service-path
velociraptor
venetian
virtualization
vulnerability-research
vulnerable-ad
wazuh
web
webshell
wifi
windows
- Inside CVE-2025-59287: SoapFormatter RCE in WSUS
- Insecure Active Directory Lab For Training (IaC)
- Mine for Local Privilege Escalation Vulnerabilities in Windows Applications Using Automation and Virtualization
- Applied Purple Teaming Series ( Weaponize Windows ) Part 2
- Studying Sysmon's Ability to Detect Process Injections Using Different Configuration Schemas
- 6-Eyed-Spider Post-Exploitation Red-Team Tool
- Windows Exploit Development: Egg Hunting
- Windows Exploit Development: Unicode and Venetian shellcode techniques
- Windows Exploit Development: Utilizing imported functions (WinExec)
- Manually Encode Bytes & Shellcode Carving