mitre-attack

Malware & C2

Persistence Techniques on Windows: Run Keys to WMI

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Purple Teaming: Running an Adversary Emulation Exercise

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Building a Detection Pipeline with the Elastic Stack

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

Kerberoasting and AS-REP Roasting Detection Deep Dive

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Threat Hunting: Building and Testing Hypotheses

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

MITRE ATT&CK: Building a Detection Coverage Map

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Sigma Rules: Portable Detection Engineering

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Linux Privesc

Linux Persistence Techniques: Maintaining Access After Initial Compromise

A practical tour of Linux persistence: authorized_keys, cron, systemd, rc.local, and ld.so.preload, plus detection.
Tools & Defense

Hunting Windows Persistence: From Autoruns to WMI Event Subscriptions

A practical guide to planting, detecting, and analyzing Windows persistence across registry, services, tasks, and WMI.