Yunolay

Tools & Defense

John the Ripper in Practice: From Hash Extraction to Rule-Based Cracking

A practical guide to John the Ripper: *2john extraction, format detection, wordlist and rule-based attacks, plus blue-team defenses.
Security

Reverse Shell Cheat Sheet: From One-Liners to a Stable TTY

A practical reverse shell cheat sheet covering bash, nc, python and PowerShell payloads plus TTY upgrade and detection.
Tools & Defense

Generating Payloads with msfvenom: Formats, Encoders, and Staged vs Stageless

A practical guide to msfvenom payload generation: formats, encoders, and the difference between staged and stageless shellcode.
Tools & Defense

Pivoting and Tunneling: A Practical Guide to Chisel, Ligolo-ng, and SSH

Reach internal networks through a compromised host using chisel, ligolo-ng, SSH, and proxychains, and learn how defenders detect it.
Tools & Defense

OSINT for Penetration Testers: A Practical Introduction to Passive Reconnaissance

A hands-on intro to OSINT for pentesters: theHarvester, recon-ng, Google dorks, Shodan, and Maltego, plus blue-team defenses.
Tools & Defense

Passive and Active Reconnaissance: Subdomain Enumeration with Amass and ffuf

A practical walkthrough of passive and active recon: DNS footprinting, subdomain enumeration with Amass, and vhost/path fuzzing with ffuf.
Tools & Defense

AWS Security Fundamentals and Attack Techniques: IAM, S3, and the Metadata Service

A practical primer on attacking and defending AWS: IAM enumeration, S3 misconfigurations, IMDS abuse, and Pacu.
Tools & Defense

Azure and Entra ID Attacks: A Practical Primer with AADInternals and ROADtools

A hands-on introduction to Entra ID attacks: device code phishing, illicit consent grants, token theft, and the blue-team controls that stop them.
Tools & Defense

Kubernetes Security 101: From kubectl to RBAC and Token Theft

A practical intro to Kubernetes security: kubectl, RBAC, service account token abuse, kube-hunter scanning, and how to defend.
Tools & Defense

Breaking Out: A Practical Guide to Linux Container Escape Techniques

How privileged containers, host mounts, cgroups, and CAP_SYS_ADMIN lead to container escape, plus blue-team defenses.
Tools & Defense

Log4Shell (CVE-2021-44228): Anatomy of the JNDI/LDAP Exploit

A practical breakdown of Log4Shell: how the JNDI/LDAP lookup leads to RCE, a marshalsec PoC, WAF bypass tricks, and defenses.
Tools & Defense

Windows Hardening with VBS and Credential Guard: How It Works and How to Test It

A practical guide to Virtualization-Based Security, Credential Guard, HVCI, and LSA protection for red and blue teams.
Tools & Defense

Active Directory Defense and Monitoring: Tiering, LAPS, and Detection Engineering

A practical defender's guide to AD tiering, LAPS, honeypot accounts, ADCS hardening, and the event IDs that catch attackers.
Tools & Defense

Penetration Testing Methodology and Reporting: From Scoping to Executive Summary

A practical guide to running a structured penetration test with PTES, capturing solid evidence, scoring with CVSS, and writing reports that get fixed.
RE & Pwn

x86-64 Assembly Primer for Reverse Engineers

A practical x86-64 assembly primer covering registers, the System V ABI, the stack, and GDB disassembly for reverse engineers.
RE & Pwn

Getting Started with Ghidra for Reverse Engineering and Malware Analysis

A practical introduction to Ghidra's CodeBrowser, decompiler, function graph, data types, and scripting for RE and malware work.
RE & Pwn

Reverse Engineering with radare2 and rizin: A Practical Walkthrough

A hands-on guide to static and visual binary reversing with radare2 and rizin, covering aaa, pdf, visual mode, and Cutter.
RE & Pwn

Stack-Based Buffer Overflows: From Crash to Shell

A practical walkthrough of classic stack-based buffer overflows: EIP control, offset discovery, bad chars, and shell.
RE & Pwn

Defeating ASLR, NX, and Stack Canaries: A Practical Exploitation Primer

How modern memory-protection layers (ASLR, NX, canaries) work and how attackers chain leaks, ret2libc, and brute force to bypass them.
RE & Pwn

Return-Oriented Programming (ROP) Fundamentals: From Gadgets to ret2syscall

A practical introduction to ROP: gadgets, ROPgadget, ret2libc, ret2syscall, stack pivots, and the defenses that stop them.
RE & Pwn

Format String Vulnerabilities Explained: From %p Leaks to Arbitrary Write

A practical walkthrough of format string bugs: leaking memory with %p, writing with %n, and pivoting to GOT overwrite.
RE & Pwn

Heap Exploitation: Use-After-Free and tcache Poisoning in glibc

A practical walkthrough of UAF and tcache poisoning in glibc malloc, with PoC, gdb commands, and blue-team defenses.
RE & Pwn

GDB with pwndbg and GEF: A Practical Exploit-Dev Workflow

A hands-on exploit-dev workflow with GDB plus pwndbg/GEF: breakpoints, telescope, vmmap, heap inspection, and pattern search.
RE & Pwn

Writing Exploits with pwntools: From cyclic to ROP and shellcode

A practical guide to building Linux binary exploits with pwntools: cyclic offsets, ELF parsing, p64, ROP, and shellcraft.
Malware & C2

Building a Malware Analysis Lab with REMnux and FLARE-VM

A practical guide to building an isolated REMnux + FLARE-VM lab with snapshots, INetSim, and FakeNet for safe malware analysis.
Malware & C2

Static Analysis of Windows PE Files: Headers, Imports, Strings, and capa

A practical walkthrough of statically triaging Windows PE files using pestudio, capa, and the CLI — plus blue-team detection.
Malware & C2

Dynamic Malware Analysis in a Sandbox: A Practical Behavioral Workflow

A hands-on guide to dynamic malware analysis with Procmon, Process Hacker, and Wireshark, plus Blue Team detection.
Malware & C2

Unpacking Packed Malware: From UPX to Custom Packers

A hands-on guide to manually unpacking UPX and custom packers using entropy, OEP detection, x64dbg, and Scylla import rebuild.
Malware & C2

Windows Shellcode: Writing and Analyzing Position-Independent Payloads

Build a position-independent Windows shellcode with PEB walking and API hashing, then dissect it with scdbg and a debugger.
Malware & C2

Process Injection Internals: DLL Injection, Reflective Loading, and Process Hollowing

A practical breakdown of classic DLL injection, reflective loading, and process hollowing on Windows, plus blue-team detection.
Malware & C2

Writing Effective YARA Detection Rules

A practical guide to writing precise YARA rules using strings, hex patterns, imphash, and conditions for malware detection.
Malware & C2

C2 Frameworks Explained: Cobalt Strike, Sliver, and Mythic

A practical tour of Cobalt Strike, Sliver, and Mythic — beacons, listeners, malleable profiles, redirectors, and OPSEC for red and blue teams.
Malware & C2

Dissecting Malicious Office Documents: VBA Macros, Stomping, and IOC Extraction

A hands-on guide to triaging malicious Office maldocs with oletools, defeating VBA stomping, and extracting IOCs.
Tools & Defense

Hunting Windows Persistence: From Autoruns to WMI Event Subscriptions

A practical guide to planting, detecting, and analyzing Windows persistence across registry, services, tasks, and WMI.
Cloud Security

AWS IAM Privilege Escalation Paths: From Low-Priv Credentials to Account Takeover

A practical look at common AWS IAM privilege escalation paths, PoC commands, and the blue-team controls that shut them down.
Cloud Security

Attacking and Securing Amazon S3: Buckets, Policies, and Presigned URLs

A practical guide to enumerating, exploiting, and hardening Amazon S3 buckets, ACLs, policies, and presigned URLs.
Cloud Security

Breaking Serverless: Attacking AWS Lambda from Event Injection to RCE

How attackers turn Lambda event injection into code execution and credential theft, and how blue teams stop it.
Cloud Security

Enumerating and Exploiting AWS with Pacu

A practical walkthrough of using Pacu to enumerate AWS identities, IAM permissions, and discover privilege escalation paths.
Cloud Security

Azure & Entra ID Attack Paths: Hunting Privilege Escalation with AzureHound

Advanced Entra ID attack paths: AzureHound enumeration, role assignment abuse, dynamic group injection, and OAuth consent grants.
Cloud Security

Abusing Azure Managed Identities: From IMDS Token Theft to ARM Takeover

How attackers steal IMDS access tokens from Azure Managed Identities and pivot into the ARM API, plus blue-team detection.