Recent
Responder, Kerberos, and One Bad DACL: Inside an Active Directory Attack Path
·3084 words·15 mins
No credentials, one relayed authentication, one bad DACL, and one privileged session. Here is how the full Active Directory attack path came together.
A Hook, a Can of Air, and a Fake Badge: Inside a Physical Pentester's Bag
·3151 words·15 mins
I used to imagine a 10-in-1 spy pencil with a laser. The real kit is simpler and far more clever. Here is what I carry on a physical engagement and what every tool actually does.
Proxmark3 for Beginners: From Install to Cloning a Card
A thin slip of plastic opens the door. Here’s how an attacker reads, clones, and emulates it. We build the Proxmark3 from scratch and clone a card end to end.
Starting This Blog
An intro to the blog: offensive security write-ups across network and physical penetration testing, and why I’m sharing what I learn.