Yunolay

Cloud Security

GCP Privilege Escalation: Abusing Service Account Impersonation and IAM Misconfigurations

How attackers abuse actAs, setIamPolicy, and service account impersonation to escalate privileges in Google Cloud, with blue-team defenses.
Cloud Security

Cloud Metadata Service (IMDS) Attacks via SSRF: Stealing Credentials and Defending IMDSv2

How attackers pivot from SSRF to cloud credential theft through 169.254.169.254, and how IMDSv2 and hop limits stop them.
Cloud Security

Cloud Logging and Detection: Attacking and Defending CloudTrail and GuardDuty

How attackers blind CloudTrail and evade GuardDuty, and how blue teams close the detection gaps.
Cloud Security

Attacking AWS STS, AssumeRole, and Cross-Account Trust

How sts:AssumeRole, weak trust policies, and missing ExternalId enable cross-account pivots, plus blue-team detection.
Containers & DevSecOps

Docker Security Fundamentals and Hardening: From Capabilities to Rootless Containers

A practical guide to hardening Docker: Linux capabilities, seccomp, rootless mode, --privileged risks, and image scanning.
Containers & DevSecOps

Advanced Container Escape Techniques: From CAP_SYS_ADMIN to Host Root

A practical look at advanced container escape primitives — release_agent, /proc abuse, host mounts, and runc CVEs.
Containers & DevSecOps

Kubernetes RBAC Attacks: Privilege Escalation from a Compromised Service Account

How attackers abuse Kubernetes RBAC roles, bindings, and service account tokens to escalate to cluster-admin, and how to defend.
Containers & DevSecOps

Attacking the Kubernetes API Server and etcd: A Practical Offensive Guide

Hands-on offensive techniques against the Kubernetes control plane: anonymous auth, etcd secret extraction, kubelet API, and exposed dashboards.
Containers & DevSecOps

Breaking and Hardening Kubernetes Pods: Pod Security Standards, OPA Gatekeeper, and Kyverno

An offensive and defensive tour of Kubernetes pod admission control: Pod Security Standards, securityContext, OPA Gatekeeper, and Kyverno.
Containers & DevSecOps

Auditing Kubernetes Clusters with kube-bench and kube-hunter

A practical guide to auditing Kubernetes for CIS benchmark gaps and exploitable misconfigs, then remediating them.
Containers & DevSecOps

Securing the Software Supply Chain: SBOM, Sigstore, and SLSA in Practice

A hands-on guide to attacking and defending the software supply chain with SBOM, cosign, Sigstore, and SLSA.
Containers & DevSecOps

Attacking CI/CD Pipelines: Exploiting GitHub Actions and Jenkins

A practical offensive and defensive walkthrough of pwn requests, PPE, secrets exfiltration, and OIDC abuse in GitHub Actions and Jenkins.
Containers & DevSecOps

Secrets Management and Hunting Leaked Secrets in Git

Hunt leaked credentials in git history with gitleaks and trufflehog, then lock them down with HashiCorp Vault.
Containers & DevSecOps

Infrastructure as Code Security: Hunting Bugs in Terraform with tfsec and Checkov

A practical guide to attacking and defending Terraform: state file secrets, drift, least privilege, and IaC scanning with tfsec and Checkov.
Mobile API OSINT

Android Application Pentesting: Lab Setup and APK Internals

Build a reproducible Android pentest lab, learn APK structure and AndroidManifest, and triage apps with adb and MobSF.
Mobile API OSINT

Reversing Android Apps: apktool, jadx, and Frida in Practice

A practical workflow for static and dynamic Android reversing with apktool, jadx, and Frida — plus blue-team defenses.
Mobile API OSINT

iOS Application Security Testing Fundamentals

A practical primer on assessing iOS apps: IPA extraction, keychain, plist analysis, and dynamic instrumentation with Frida and objection.
Mobile API OSINT

Bypassing SSL Pinning to Intercept Mobile App APIs

A practical guide to intercepting mobile API traffic by defeating certificate pinning with Frida, objection, and Burp Suite.
Web Exploitation

REST API Penetration Testing Methodology: From Recon to BOLA

A practical, repeatable methodology for testing REST APIs: BOLA, mass assignment, broken rate limiting, and blue-team defenses.
Web Exploitation

GraphQL API Security Testing: Advanced Offensive and Defensive Techniques

Advanced GraphQL pentesting: introspection, batching abuse, depth-limit bypass, IDOR, and blue-team defenses.
Security

Breaking OAuth 2.0 and OpenID Connect: Redirect, State, and Token Attacks

A practical guide to OAuth 2.0 and OIDC attacks - redirect_uri abuse, state/CSRF, PKCE, and token leakage - with blue-team defenses.
Mobile API OSINT

OSINT for Red Teamers: Mapping People and Infrastructure

A practical red-team OSINT workflow for enumerating people and infrastructure with theHarvester, Shodan, breach data, and DNS recon.
Mobile API OSINT

Subdomain Enumeration and Attack Surface Mapping with Amass, Subfinder, and httpx

A practical recon workflow chaining amass, subfinder, httpx, and ffuf to map an organization's external attack surface.
Mobile API OSINT

Phishing and Initial Access Tradecraft for Authorized Red Teams

A practical look at pretexting, Gophish campaigns, Evilginx MFA phishing, and the blue-team controls that stop them.
Other

[Solved] Turn off VBS 100% Solved (Device Guard, Credntial Guard)

Step 1. Turn off Credential GuardDownload the DG Readiness powershell script: dgreadiness_v3.6.zipRun the script with th...
Other

Performance degradation when using WHP in a virtual environment on Windows 11 Pro 23H2

BackgroundSince virtual environments cannot normally coexist with Windows 11 Pro 23H2 Japanese Edition, it was necessary...
Vulnlab

Vulnlab Data Walkthrough by Yunolay (LFI with path traversal, Docker privileged user)Vulnlab Retro Walkthrough by Yunolay (RID Brute Force, pre-created computer accounts, ADCS Attacks)

OverviewRetro (Solo, Windows)Junior Level Windows Active Directory MachineYou will learn about pre-created computer acco...
Vulnlab

Vulnlab Feedback Walkthrough by Yunolay (Apache Tomcat Log4Shell)

OverviewFeedback (Solo, Linux)Junior Level Linux MachineYou will learn about exploiting a popular Java CVEUserThis box w...
Offensive Security Lab Japan

Vulnlab Data Walkthrough by Yunolay (LFI with path traversal, Docker privileged user)Offensive Security Lab Japan Boot2Root offsec-4-diveintoive Writeup by Yunolay (LFI2RCE via PHP Filters, RFI)

IntroduceI'm new to trying Boot2Root and was provided with a vulnerable machine, but it's mixed in with my home network ...
Vulnlab

Vulnlab Data Walkthrough by Yunolay (LFI with path traversal, Docker privileged user)

OverviewData (Solo, Linux)Junior Level Linux MachineYou will learn about getting a foothold through a CVE, cracking cust...
Vulnlab

Vulnlab Sync Walkthrough by Yunolay (Rsync, Custom Hash Crack, Writable files executed by a privileged user)

OverviewSync (Solo, Linux)Junior Level Linux Machine.You will learn about exploiting custom applications & misconfigurat...
Vulnlab

Vulnlab Baby Walkthrough by Yunolay (LDAP Enumeration, SMB Password Spraying, Privilege escalation using SeBackupPrivilege and SeRestorePrivilege)

OverviewActive Directory PentestingBaby (Solo, Windows)Junior Level Windows Active Directory MachineYou will learn about...