lateral-movement

Active Directory

CrackMapExec/NetExec for Internal Network Assessment

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Active Directory Trust Attacks: SID History and Cross-Forest Escalation

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LAPS Internals: Storing, Reading, and Attacking Local Admin Passwords

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Lateral Movement Detection: SMB, WMI, and WinRM

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Pass-the-Hash and Pass-the-Ticket in Practice

A hands-on guide to NTLM Pass-the-Hash and Kerberos Pass-the-Ticket attacks, with practical tooling and Blue Team defenses.
Active Directory

Abusing Group Policy Objects for Privilege Escalation and Lateral Movement

How attackers weaponize editable Group Policy Objects with SharpGPOAbuse and GPP cpassword, plus blue-team detection and hardening.
Windows Privesc

Lateral Movement and Persistence with WMI

How attackers abuse WMI for remote code execution and stealthy persistence, plus the detection and defenses blue teams need.
Linux Privesc

SSH Key Hunting and Lateral Movement on Linux

Find SSH private keys, abuse authorized_keys and known_hosts, and pivot via agent forwarding across Linux hosts.
Tools & Defense

Mastering the Impacket Suite: From Lateral Movement to Credential Extraction

A practical tour of Impacket's psexec, wmiexec, secretsdump, GetUserSPNs and smbserver, plus blue-team detection.
Tools & Defense

Active Directory Defense and Monitoring: Tiering, LAPS, and Detection Engineering

A practical defender's guide to AD tiering, LAPS, honeypot accounts, ADCS hardening, and the event IDs that catch attackers.
Cloud Security

Attacking AWS STS, AssumeRole, and Cross-Account Trust

How sts:AssumeRole, weak trust policies, and missing ExternalId enable cross-account pivots, plus blue-team detection.
Containers & DevSecOps

Kubernetes RBAC Attacks: Privilege Escalation from a Compromised Service Account

How attackers abuse Kubernetes RBAC roles, bindings, and service account tokens to escalate to cluster-admin, and how to defend.