Overview
01
→
02
→
03
→
04
→
05
→
06
→
07
→
08
→
09
→
10
→
11
→
12
→
13
→
14
→
15
→
16
→
17
→
18
→
19
→
20
→
21
→
Windows Internals
DLL Internals
DLL loading, hijacking, proxying, and injection techniques.
Windows Internals
PE Structure
Portable Executable format: headers, sections, imports, and exports.
Windows Internals
Processes & Threads
Process creation, hollowing, injection, and thread manipulation.
Windows Internals
Security Mechanisms
ASLR, DEP, CFG, PPL, and Windows security subsystem internals.
Windows Internals
Memory Mapping
Virtual memory, section objects, VAD trees, and mapped files.
Active Directory
Kerberos
Kerberoasting, AS-REP, delegation attacks, and ticket abuse.
Active Directory
LAPS
Local Administrator Password Solution — enumeration and bypass.
Active Directory
Certificate Services (AD CS)
ESC1–ESC8 abuse, template misconfigurations, and certificate theft.
Red Team
Post-Exploitation Enumeration
Host and domain enumeration after initial foothold.
Red Team
Privilege Escalation
Local and domain privilege escalation techniques on Windows.
Red Team
Lateral Movement
Pass-the-Hash, Pass-the-Ticket, WMI, DCOM, and SMB relay.
Red Team
Persistence
Registry, scheduled tasks, services, and AD persistence mechanisms.
Red Team
OPSEC
Avoiding detection: log evasion, AMSI bypass, and EDR blinding.
Red Team
Proxying & Traffic Channeling
SOCKS proxies, port forwarding, and traffic redirection techniques.
Web Security
CSRF
Cross-site request forgery — patterns, bypasses, and SameSite evasion.
Web Security
GraphQL
Introspection, batching attacks, IDOR, and auth bypass in GraphQL APIs.
Web Security
HTTP Request Smuggling
CL.TE and TE.CL desync, server-side request poisoning.
Web Security
JWT Attacks
Algorithm confusion, none algorithm, kid injection, and secret cracking.
Web Security
Logic Flaws
Business logic vulnerabilities, price manipulation, and workflow bypass.
Web Security
Race Conditions
Single-endpoint and multi-endpoint races, limit overrun, and TOCTOU.
Web Security
WebSocket Attacks
CSWSH, message hijacking, and WebSocket-based SSRF chains.
no results — try a different filter