Yunolay

Linux Privesc

Docker Group Membership to Host Root

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

NFS no_root_squash Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

PATH Hijacking and Relative Binary Execution

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

Cron Job Hijacking and Writable Scripts on Linux

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Abusing Windows Backup and Restore Privileges

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Pass-the-Hash: Authenticating with NTLM Hashes

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Golden Ticket Attacks: Forging TGTs with the KRBTGT Hash

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberos Constrained Delegation (KCD) and S4U Abuse

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

Linux Capabilities Abuse: cap_setuid and Friends

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

Sudo Misconfiguration and GTFOBins Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

SUID Binary Exploitation for Linux Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Print Spooler and PrintNightmare Local Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Named Pipe Impersonation for Local Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Insecure Registry Autoruns and Service ImagePath Writes

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Scheduled Task and Startup Folder Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Stored Credentials Hunting: DPAPI, Registry, and Files

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

DLL Hijacking and Search-Order Abuse on Windows

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Token Impersonation and Stealing on Windows

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

UAC Bypass Techniques via Auto-Elevating Binaries

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

AlwaysInstallElevated: MSI Privilege Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Weak Service Permissions and Binary Path Hijacking

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

Unquoted Service Path Exploitation on Windows

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Windows Privesc

SeImpersonatePrivilege Abuse: The Potato Family

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Targeted Kerberoasting with Write Access

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

NTLM Relay to LDAP and SMB: Coercion to Compromise

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LDAP Reconnaissance for Active Directory Attack Paths

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

GPO Abuse: Code Execution via Group Policy

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

DACL Abuse in Active Directory: GenericAll and WriteDACL

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Shadow Credentials: Key Trust Account Takeover

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

AD CS ESC1: Vulnerable Certificate Template Enrollment

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Resource-Based Constrained Delegation (RBCD) Abuse

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Unconstrained Delegation Abuse and TGT Capture

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Overpass-the-Hash: From NT Hash to Kerberos TGT

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Silver Ticket Attacks: Forging Service Tickets Offline

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberoasting: The Complete Guide to Mechanics, Attack, and Defense

A complete guide to Kerberoasting: how SPNs and TGS-REP enable offline cracking, plus detection and defense.
Active Directory

AS-REP Roasting: Abusing Accounts Without Kerberos Pre-Authentication

How attackers extract and crack Kerberos AS-REP hashes from accounts with pre-authentication disabled, and how blue teams defend.
Active Directory

DCSync Attack and Defense: Abusing Directory Replication Rights

How DCSync abuses AD replication rights via DRSUAPI to dump credentials, and how blue teams can detect and stop it.
Active Directory

NTLM Relay Attacks in Practice: Hands-On with ntlmrelayx

A practical walkthrough of NTLM relay attacks with Responder and ntlmrelayx, covering SMB and LDAP relay plus blue-team defenses.
Active Directory

Pass-the-Hash and Pass-the-Ticket in Practice

A hands-on guide to NTLM Pass-the-Hash and Kerberos Pass-the-Ticket attacks, with practical tooling and Blue Team defenses.
Active Directory

Golden Ticket Attacks: Abusing krbtgt for Domain Persistence

How attackers forge Kerberos TGTs with the krbtgt hash to gain persistent domain dominance, and how blue teams detect and defend.