2026-07

RE & Pwn

House of Orange

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

House of Lore

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

House of Tangerine

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

House of Einherjar

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

House of Mind

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

House of Husk

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

FILE Struct Leaks: Turning fread/fwrite into Arbitrary Read/Write

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

tcache Poisoning: A Deep Dive

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

Exit Handlers: Abusing __run_exit_handlers and TLS dtor lists

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

FSOP in Modern glibc: House of Apple 2

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

__malloc_hook and __free_hook Overwrites (glibc < 2.34)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Volume Shadow Copies (VSS) for Credential and File Recovery

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Credential Guard and LSA Protection (PPL): How They Work

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

COM Hijacking for Persistence and Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Windows Access Tokens Deep Dive: Integrity Levels and Privileges

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Firewall and WFP Tampering: Risks and Detection

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Building a Vulnerability Management Program

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Application Control with AppLocker and WDAC: Design and Gaps

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Malware & C2

Abusing BITS Jobs for Download and Persistence

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Windows Subsystem for Linux (WSL) as an Attack Surface

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Data Loss Prevention (DLP): Concepts and Evasion Awareness

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Single Sign-On (SSO) Threats and Hardening

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Web Exploitation

Session Management: Cookies, Tokens, and Fixation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Web Exploitation

API Gateway Security Patterns

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Web Exploitation

Rate Limiting and Anti-Automation Defenses

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Security Logging and Monitoring: What to Collect and Why

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Purple Teaming: Running an Adversary Emulation Exercise

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Just-in-Time Access and Secrets Rotation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

SAML vs OIDC: A Security Comparison

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Phishing-Resistant MFA: FIDO2 and WebAuthn Internals

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Zero Trust Architecture: Principles and Pitfalls

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Pre-Created Computer Accounts and Pre-Windows 2000 Compatibility Risks

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberos Encryption Types: RC4 vs AES and Downgrade Risks

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Active Directory Trust Attacks: SID History and Cross-Forest Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LAPS Internals: Storing, Reading, and Attacking Local Admin Passwords

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Group Managed Service Accounts (gMSA) and the KDS Root Key

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Timeroasting: Abusing NTP Authentication in Active Directory

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Web Exploitation

Content Security Policy: Building a Strict, Nonce-Based Policy

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

sAMAccountName Spoofing: noPac (CVE-2021-42278 / CVE-2021-42287)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Building a Detection Pipeline with the Elastic Stack

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...