Windows

Windows Privesc

Windows Subsystem for Linux (WSL) as an Attack Surface

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Active Directory

LAPS Internals: Storing, Reading, and Attacking Local Admin Passwords

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Telemetry: Sysmon vs ETW vs the Security Log

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
RE & Pwn

Windows Binary Exploitation: SEH Overwrites and Modern Mitigations

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Event Log Analysis for Incident Responders

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

NTFS Forensics: The Master File Table (MFT)

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Windows Registry Forensics for DFIR

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Execution Artifacts: Prefetch, Shimcache, and Amcache

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Sysmon Configuration for Endpoint Visibility

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Abusing Windows Token Privileges: The Potato Attack Family

How service accounts with SeImpersonatePrivilege escalate to SYSTEM via JuicyPotato, PrintSpoofer, and RoguePotato, plus blue-team defenses.
Windows Privesc

Privilege Escalation via Unquoted Service Paths on Windows

How unquoted Windows service paths with spaces let low-privileged users plant a binary and escalate to SYSTEM, plus blue-team defenses.
Windows Privesc

Weak Service Permissions: Privilege Escalation via SERVICE_CHANGE_CONFIG on Windows

Abuse misconfigured Windows service DACLs to rewrite binPath and escalate to SYSTEM, plus detection and hardening.
Security

DLL Hijacking: Privilege Escalation and Persistence on Windows

How DLL search order hijacking and phantom DLLs lead to privilege escalation and persistence, plus Blue Team detection and defense.
Windows Privesc

Abusing AlwaysInstallElevated for Windows Privilege Escalation

How a misconfigured AlwaysInstallElevated policy lets a low-privileged user run a malicious MSI as SYSTEM, plus detection and defense.
Windows Privesc

UAC Bypass Techniques: A Practical Overview of Auto-Elevation Abuse

A practical tour of Windows UAC bypass techniques abusing auto-elevating binaries, registry hijacks, and UACME, plus blue-team defenses.
Windows Privesc

Practical Credential Theft with Mimikatz

A hands-on guide to dumping Windows credentials with Mimikatz and the LSA protections that stop it.
Windows Privesc

Dumping LSASS Memory: Techniques and Detection Evasion

A practical guide to dumping LSASS memory with comsvcs.dll, procdump, and nanodump, plus parsing with pypykatz and blue-team defenses.
Windows Privesc

Abusing Scheduled Tasks for Windows Persistence and Privilege Escalation

How attackers abuse writable task XML, schtasks, and Task Scheduler to persist and escalate on Windows, plus blue-team detection.
Windows Privesc

Abusing Registry Autoruns for Windows Persistence and Privilege Escalation

How attackers abuse writable Run keys and other autorun locations for persistence and privesc, plus how blue teams detect it.
Windows Privesc

Named Pipe Impersonation: How Windows getsystem Really Works

A deep dive into ImpersonateNamedPipeClient and how named pipe impersonation powers Meterpreter's getsystem.
Windows Privesc

Windows Event Logs and Forensic Artifacts: Tracking and Tampering

How Windows Security event logs record attacker activity, how adversaries clear them, and how defenders detect tampering.
Windows Privesc

Practical Windows Enumeration with winPEAS

A hands-on guide to running winPEASx64 for Windows privilege escalation enumeration, with defensive countermeasures.
Windows Privesc

Abusing SeBackupPrivilege and SeRestorePrivilege for Windows Privilege Escalation

How attackers abuse SeBackupPrivilege/SeRestorePrivilege to dump SAM, SYSTEM, and ntds.dit, plus blue-team detection and defense.
Security

Living off the Land: Abusing LOLBAS Binaries on Windows

How attackers abuse certutil, bitsadmin, mshta, regsvr32 and rundll32 to download, execute and evade — plus blue-team detection.
Tools & Defense

Windows Hardening with VBS and Credential Guard: How It Works and How to Test It

A practical guide to Virtualization-Based Security, Credential Guard, HVCI, and LSA protection for red and blue teams.
Other

[Solved] Turn off VBS 100% Solved (Device Guard, Credntial Guard)

Step 1. Turn off Credential GuardDownload the DG Readiness powershell script: dgreadiness_v3.6.zipRun the script with th...
Other

Performance degradation when using WHP in a virtual environment on Windows 11 Pro 23H2

BackgroundSince virtual environments cannot normally coexist with Windows 11 Pro 23H2 Japanese Edition, it was necessary...
Vulnlab

Vulnlab Data Walkthrough by Yunolay (LFI with path traversal, Docker privileged user)Vulnlab Retro Walkthrough by Yunolay (RID Brute Force, pre-created computer accounts, ADCS Attacks)

OverviewRetro (Solo, Windows)Junior Level Windows Active Directory MachineYou will learn about pre-created computer acco...
Vulnlab

Vulnlab Baby Walkthrough by Yunolay (LDAP Enumeration, SMB Password Spraying, Privilege escalation using SeBackupPrivilege and SeRestorePrivilege)

OverviewActive Directory PentestingBaby (Solo, Windows)Junior Level Windows Active Directory MachineYou will learn about...