Penetration testing tutorials, bug bounty writeups, and privilege escalation guides.
-
A practical walkthrough of LLMNR and NBT-NS poisoning with Responder, capturing NetNTLMv2 hashes, and relaying authentication with ntlmrelayx when the hash...
active-directoryntlm-relayresponderlateral-movementwindows
August 28, 2026
-
A practical walkthrough of Kerberoasting, from enumerating service principal names to requesting service tickets and cracking them offline with hashcat....
active-directorykerberoswindowscredential-attacks
August 14, 2026
-
Step-by-step methodology for web application penetration testing covering reconnaissance, vulnerability discovery, exploitation, and reporting with...
penetration-testingweb-securityowaspmethodology
October 20, 2019
-
A real-world bug bounty writeup showing how to discover and exploit a DOM-based XSS vulnerability through source analysis, payload crafting, and filter bypassing.
xssbug-bountyweb-security
September 05, 2019
-
A guide to the best CTF and practice platforms for beginners including VulnHub, HackTheBox, TryHackMe, PentesterLab, and OWASP WebGoat.
ctfpracticebeginner
August 12, 2019
-
Exploit a writable /etc/passwd file to gain root access on Linux by adding a new user with UID 0 or modifying existing entries.
linuxprivilege-escalationpost-exploitation
July 22, 2019
-
Detect and exploit the AlwaysInstallElevated registry misconfiguration to escalate privileges on Windows using malicious MSI packages.
windowsprivilege-escalationmsi
June 18, 2019
-
Learn Windows access token impersonation techniques including SeImpersonatePrivilege abuse, incognito, and potato attacks for privilege escalation.
windowsprivilege-escalationtoken-manipulation
May 10, 2019
-
Learn how to discover and exploit DLL hijacking vulnerabilities for Windows privilege escalation using Process Monitor and msfvenom.
windowsprivilege-escalationdll-hijacking
March 15, 2019
-
A beginner-friendly guide to Mimikatz covering credential dumping with sekurlsa, lsadump, pass-the-hash attacks, running from memory, and detection avoidance.
windowsmimikatzpost-exploitationcredentials
January 14, 2019
-
Use PowerShell and PowerUp.ps1 to discover and exploit Windows privilege escalation vectors including service misconfigurations, unquoted paths, and...
windowsprivilege-escalationpowershell
November 28, 2018