About

Time it takes to read this article 2 minutes.

Welcome to yunolay.com — an independent blog about offensive and defensive security, written and maintained by Atsuki Hakozaki, a security engineer and vulnerability researcher based in Japan who goes by Yunolay. Every article here comes from hands-on lab work and real engagement experience, not from rephrasing someone else’s writeup.

Who Writes This Blog

I’m a Security Engineer, Penetration Tester, Vulnerability Researcher, Exploit Developer, and Red Teamer. My passion lies in offensive security, bug bounty hunting, and penetration testing — and in the blue-team detection work that sits on the other side of every technique. I build the labs, run the attacks, break the exploits until they work, and then write up what actually happened, including the parts that failed and why.

Professionally, I work across several roles in the Japanese and global security industry:

  • Executive Officer at Fore Co., Ltd.
  • Security Engineer at Poruto Inc.
  • Member of the Synack Red Team
  • Freelance security consultant

My goal for this site is simple: publish the practical, reproducible security notes I wish I’d had when I was learning — accurate enough that a professional can trust them, and detailed enough that a beginner can follow along in a home lab.

Certifications

My work is backed by industry certifications that require real, hands-on exploitation rather than multiple-choice exams:

  • OffSec: OSEE (Offensive Security Exploitation Expert), OSCE³ — comprising OSWE, OSEP, and OSED — and OSCP.
  • Hack The Box: HTB CPTS, HTB CWEE, and HTB CWES.
  • INE Security: eCPPTv2 and eWPTXv2.
  • IPA (Japan national exams): Information Security (SC), Applied Information Technology Engineer (AP), and Fundamental Information Technology Engineer (FE).

OSEE is OffSec’s most advanced certification, covering modern Windows exploitation and mitigation bypasses — it is the credential I’m proudest of.

Hack The Box

On Hack The Box I’ve reached the Omniscient rank — the platform’s highest — with 190+ systems owned and a peak Top 8 global ranking, across machines, challenges, and Pro Labs spanning Active Directory, web, API, and binary exploitation. I also placed 2nd in the MBSD Cybersecurity Challenge.

What You’ll Find Here

The blog covers the full offensive-to-defensive spectrum, with each topic grounded in a working example:

  • Active Directory — Kerberos attacks, delegation abuse, ACL-based privilege escalation, and the detection signals defenders can watch for.
  • Windows and Linux privilege escalation — practical enumeration and real escalation paths.
  • Web and API exploitation — from classic injection to modern server-side template injection and deserialization.
  • Reverse engineering and binary exploitation (pwn) — walking through vulnerable code to working exploits.
  • Malware analysis and C2, cloud and container security, and DFIR.
  • Lab and CTF walkthroughs — HackTheBox, Vulnlab, and similar platforms.

Wherever an article describes an attack, it also explains how blue teams detect and prevent it. Security is only useful when both sides of the technique are understood.

Editorial Approach

Everything published here is intended for education and authorized security testing only. The techniques are meant to be used against systems you own or have explicit written permission to assess. I test each procedure in a controlled lab before writing it up, cite the primary sources and tools involved, and correct articles when readers point out mistakes.

Elsewhere Online

Get in Touch

Corrections, questions, or business enquiries are always welcome — reach me through the Contact page. For how this site handles data and advertising, see the Privacy Policy and Advertising Disclosure.

Copied title and URL