Archive

Writeups & research44

Technique and methodology walkthroughs from HackTheBox, CRTO, CTFs, and research labs. Filter by domain, search by keyword, or browse the latest below.

/
Showing 44 of 44 writeups
#001 Apr 19
AD Privilege Escalation Primitives: Kerberoasting, Shadow Credentials, RBCD, Injection, and BOFs
HARDRED TEAM OPS
#002 Apr 18
Server-Side Web Pentest Playbook: Prototype Pollution, OAuth Flaws, SQLi-to-RCE, and SSRF
HARDWEB EXPLOITATION
#003 Apr 17
The Userland EDR Bypass Stack: Unhooking, Syscalls, ETW/AMSI, and Kernel Callbacks
ELITEEDR BYPASS
#004 Apr 17
Building a C2 Stack: Implants, BOF Loaders, Redirectors, and DoH Channels
HARDC2 DEVELOPMENT
#005 Apr 16
DCSync and DCShadow: Abusing Replication Rights for Credential Theft and Persistence
HARDRED TEAM OPS
#006 Apr 14
Hardware Breakpoint Hooking: Bypassing Inline EDR Hooks Without Touching Memory
ELITEEDR BYPASS
#007 Apr 11
JWT Algorithm Confusion: None, HS256/RS256 Mix-Ups, and KID Injection
MEDIUMWEB EXPLOITATION
#008 Apr 09
Beacon Object Files from Scratch: COFF Loading, Dynamic Resolution, and Battle-Tested Tradecraft
HARDC2 DEVELOPMENT
#009 Apr 07
Coerced Authentication Attacks: PetitPotam, PrinterBug, DFSCoerce, and the ADCS ESC8 Chain
HARDNETWORK SECURITY
#010 Mar 29
Sleep Obfuscation Deep Dive: Ekko, Zilean, and Foliage
HARDEDR BYPASS
#011 Mar 27
ADCS Abuse: ESC1 Through ESC8 Attack Paths
HARDNETWORK SECURITY
#012 Mar 25
Call Stack Spoofing: Defeating EDR Stack Telemetry
HARDEDR BYPASS
#013 Mar 23
Active Directory Attack Methodology: Initial Access to Domain Admin
HARDRED TEAM OPS
#014 Mar 20
Designing a Modern C2 Implant: Architecture and OPSEC
HARDC2 DEVELOPMENT
#015 Mar 17
Active Directory ACL Abuse: Every Attack Path Explained
HARDRED TEAM OPS
#016 Mar 12
Reflective DLL Injection: Theory & Practice
HARDMALWARE ANALYSIS
#017 Mar 10
.NET RAT Unpacking & C2 Protocol Extraction
MEDIUMMALWARE ANALYSIS
#018 Mar 08
Android Runtime Hooking with Frida
MEDIUMMOBILE SECURITY
#019 Mar 07
Bypassing Android Biometric Authentication via Frida
HARDMOBILE SECURITY
#020 Mar 05
NTLM Relay to LDAP: Domain Takeover
HARDNETWORK SECURITY
#021 Mar 05
Extracting Cobalt Strike Beacon Configuration
HARDMALWARE ANALYSIS
#022 Mar 02
Unpacking Malware: From UPX to Custom Crypters
HARDMALWARE ANALYSIS
#023 Feb 28
Anti-Analysis Techniques: How Malware Detects Your Sandbox
MEDIUMMALWARE ANALYSIS
#024 Feb 25
Kerberos Delegation Attacks: Unconstrained, Constrained, RBCD
HARDNETWORK SECURITY
#025 Feb 25
Java Deserialization Attacks: From Gadget Chains to RCE
HARDWEB EXPLOITATION
#026 Feb 22
Shellcode Analysis: Tips, Tricks & Common Patterns
MEDIUMMALWARE ANALYSIS
#027 Feb 20
LLMNR/NBT-NS Poisoning with Responder
MEDIUMNETWORK SECURITY
#028 Feb 18
Ret2Libc: Bypassing NX Protection
HARDBINARY EXPLOITATION
#029 Feb 18
NTLM Relay Attacks: A Comprehensive Guide
HARDNETWORK SECURITY
#030 Feb 15
Heap Exploitation 101: Tcache Poisoning on glibc 2.35
HARDBINARY EXPLOITATION
#031 Feb 15
Android APK Reverse Engineering: From APK to Source
MEDIUMMOBILE SECURITY
#032 Feb 12
Stack Canary Bypass via Format String Vulnerability
HARDBINARY EXPLOITATION
#033 Feb 10
Intercepting Flutter App Traffic with Frida
HARDMOBILE SECURITY
#034 Feb 08
x64 ROP Chains: Systematic Gadget Hunting
HARDBINARY EXPLOITATION
#035 Feb 05
The Complete Guide to Android SSL Pinning Bypass
HARDMOBILE SECURITY
#036 Feb 01
Heap Feng Shui: Controlling Memory Layout for Exploitation
HARDBINARY EXPLOITATION
#037 Dec 10
My CRTO Exam Review: Cobalt Strike, Malleable Profiles, and Adversary Simulation
HARDCERT REVIEWS
#038 Jun 04
Forged in Fortresses: My Complete HackTheBox CPTS Journey
MEDIUMCERT REVIEWS
#039 Jan 24
IIUC CyberCon 2022: CTF Challenge Solutions
MEDIUMCTF WRITEUPS
#040 Nov 07
HackTheBox Watersnake Challenge: YAML Deserialization to RCE
MEDIUMCTF WRITEUPS
#041 Apr 09
My eCPPTv2 Exam Review: Pivoting Through the Pain
MEDIUMCERT REVIEWS
#042 Dec 25
BlackHat MEA 2023 CTF Finals: Reverse Engineering Writeup
HARDCTF WRITEUPS
#043 Oct 30
BlueHens UDCTF 2023: Hardware & Reverse Engineering Writeups
MEDIUMCTF WRITEUPS
#044 Dec 13
National Cyber Drill 2021: Reverse Engineering Challenges
MEDIUMCTF WRITEUPS