Write-ups
Technical write-ups, CTF walkthroughs, and research notes.
Active Directory & Windows
4Domain privilege escalation: Kerberos abuse, ADCS templates, ACL walks, and credential theft.
- 8 min read
HackTheBox: The Frizz Writeup
Exploiting Gibbon LMS for initial access, extracting Kerberos tickets, and abusing GPO for Active Directory privilege escalation.
HackTheBoxWindowsActive DirectoryGibbon LMSKerberosGPO AbuseRead - 8 min read
HackTheBox: Puppy
An offensive Active Directory walkthrough demonstrating BloodHound analysis, KeePass brute-forcing, ACL abuse, and DPAPI credential decryption.
HackTheBoxWindowsActive DirectoryBloodHoundKeePassDPAPIACL AbuseRead - 6 min read
HackTheBox: Fluffy
An offensive Active Directory walkthrough demonstrating file indexing tool analysis, CVE-2025-24071 NTLM capture, ADCS abuse (ESC1), and Shadow Credentials.
HackTheBoxWindowsActive DirectoryNTLM RelayingADCSShadow CredentialsRead - 12 min read
HTB: Certificate
Active Directory enumeration, exploiting ZIP file upload to gain RCE, extracting database credentials, and leveraging ESC3 Certificate Templates for privilege escalation.
HTBWindowsActive DirectoryESC3PrivEscRead
Linux & Web Exploitation
10Web application RCE chains — injection, deserialization, path traversal — through to Linux privilege escalation.
- 5 min read
HackTheBox: Cypher Writeup
Exploiting Neo4j Cypher injections and escalating privileges via custom Yara rules with bbot.
HackTheBoxLinuxCypher InjectionNeo4jYaraPrivilege EscalationRead - 7 min read
HackTheBox: Code Writeup
Exploiting an insecure Python execution endpoint and abusing a backup script directory traversal to achieve root.
HackTheBoxLinuxPythonCode ExecutionDirectory TraversalHashcatRead - 6 min read
HackTheBox: Titanic Writeup
Exploiting Local File Inclusion to leak Gitea databases and abusing ImageMagick for root execution.
HackTheBoxLinuxLFIGiteaImageMagickShared Object HijackingRead - 5 min read
HackTheBox: Dog Writeup
Dumping an exposed Git repository to extract credentials, exploiting Backdrop CMS, and abusing sudo permissions in PHP.
HackTheBoxLinuxGit DumperBackdrop CMSSudo ExploitationPHPRead - 5 min read
HackTheBox: Environment
A detailed offensive security walkthrough of the Environment machine, featuring Laravel logic abuse, GPG decryption, and PATH hijacking.
HackTheBoxLinuxLaravelGPGPATH HijackingPrivilege EscalationRead - 5 min read
HackTheBox: Planning
An offensive security walkthrough detailing vhost enumeration, Grafana exploitation (CVE-2024-9264), and cronjob-based privilege escalation.
HackTheBoxLinuxGrafanaCVE-2024-9264DockerPort ForwardingRead - 6 min read
HackTheBox: Heal
An offensive security walkthrough featuring path disclosure in a Ruby on Rails application, LimeSurvey RCE, and a Consul API exploit.
HackTheBoxLinuxRuby on RailsPath DisclosureLimeSurveyConsulRead - 8 min read
HTB: Checker
Bypassing a TOTP-protected SSH login, cracking bcrypt hashes leaked by a vulnerable TeamPass instance, and winning a shared-memory race condition to escalate to root.
HTBLinuxTOTPTeamPassRace ConditionShared MemoryPrivEscRead - 12 min read
HTB: Smart Hire
Exploiting CVE-2024-37054 in MLflow via Python pickle deserialization, leading to a foothold, followed by Python module path hijacking via .pth file for root privilege escalation.
HTBLinuxCVE-2024-37054MLflowPicklePrivEscRead - 10 min read
HTB: Reactor
Exploiting Next.js CVE-2025-55182 (React2Shell) for initial access, cracking SQLite credentials, and abusing an exposed Node.js inspector for root escalation.
HTBLinuxCVE-2025-55182React2ShellNext.jsPrivEscRead
Field Guides & Research
5Reference guides, applied research projects, and CTF retrospectives.
- 25 min read
The Ultimate Guide to Binary Exploitation
A comprehensive, educational study guide on the theoretical mechanics of memory corruption vulnerabilities and modern defensive mitigations.
PwnBinary ExploitationROPAssemblyRead - 25 min read
The Ultimate Guide to Web Security
A comprehensive field guide to web application security, detailing vulnerability mechanics, theoretical examples, and defensive remediation.
WebPentestingPortSwiggerBug BountyRead - 20 min read
The Ultimate Guide to Network & Cryptography
A definitive hacker's field manual synthesizing core concepts of Network Security and Applied Cryptography.
NetworkingCryptoRSAProtocolsRead - 12 min read
Binary Explorer: Agentic RAG over MCP for Vulnerability Analysis
How I designed Binary Explorer — an MCP-based agentic system that decompiles, indexes, and queries binary vulnerabilities using FAISS and Ghidra.
LLMRAGMCPGhidraFAISSPythonRead - 6 min read
CyberChallenge.IT — Lessons from a National CTF
Key takeaways from participating in CyberChallenge.IT: exploit patterns, mindset for binary exploitation, and things I'd do differently.
CTFBinary ExploitationSecurityRead