HARD
HackTheBox
๐Ÿ“… 2024-01-15 ๐Ÿ† 40 pts

Active Directory Exploitation: Forest to Domain Admin

Complete walkthrough of exploiting misconfigured Active Directory permissions, from initial access to full domain compromise using BloodHound analysis and targeted Kerberoasting attacks.

Active Directory BloodHound Kerberoasting
root@ryzen:~#
MEDIUM
TryHackMe
๐Ÿ“… 2024-01-10 ๐Ÿ† 25 pts

Advanced SQL Injection to RCE

Exploiting stacked SQL queries in a custom web application, extracting data through error-based injection, and achieving remote code execution via INTO OUTFILE technique.

Web Exploitation SQLi Privilege Escalation
root@ryzen:~#
CVE
Research
๐Ÿ“… 2024-01-05 ๐Ÿšจ CVSS 9.8

Analysis of Critical RCE in Popular Framework

Deep dive into a recently disclosed remote code execution vulnerability, including root cause analysis, exploit development, and mitigation strategies.

CVE-2023-XXXX RCE PoC Development
root@ryzen:~#
RED TEAM
Red Team
๐Ÿ“… 2023-12-20 ๐ŸŽฏ Enterprise

Enterprise Red Team: From Phish to Domain Admin

Real-world red team engagement walkthrough covering initial access via spear phishing, Cobalt Strike infrastructure, and modern EDR evasion techniques.

Phishing Cobalt Strike EDR Evasion
root@ryzen:~#