Browse posts by topic — 12 categories across the blog.
Active Directory
- Automating the Pass-The-Ticket attack Feb 2026
- CESP-ADCS Course Cheatsheet Nov 2023
- Extracting AD hashes from Unix systems Jan 2022
- Abusing SSPR in Azure to get Domain Admins Sep 2021
- ADFSbrute - Test passwords against ADFS Mar 2021
- Ntds-Analyzer - Tool to analyze Ntds.dit files Feb 2021
Cloud
Credential Access
- Creating Shadow Copies with VSS API Jan 2026
- SAMDump - Stealthy SAM Dumping Using VSS and NTAPIs Nov 2025
- MemorySnitcher and the power of NtReadVirtualMemory Jul 2025
- NimDump - Stealthy LSASS Dumping Using Only NTAPIs in Nim May 2025
- Playing with malicious Network Provider DLLs Apr 2025
- NativeBypassCredGuard - Bypass Credential Guard using only NTAPIs Dec 2024
- TrickDump update - BOF File and C/C++ ports Oct 2024
- NativeDump update - BOF File and C/C++ ports Sep 2024
- TrickDump - Dump lsass without generating a Minidump file Jul 2024
- NativeDump update - Python and Golang ports Jul 2024
- Dumping lsass using only NTAPIs by hand-crafting Minidump files Mar 2024
- Dumping Jenkins credentials Mar 2024
- MinidumpParser Feb 2024
- SharpProcessDump - Dump processes using C# Feb 2024
- Extracting AD hashes from Unix systems Jan 2022
- Customizing Lsass Dumps with C++ Aug 2021
- Customizing Lsass Dumps with C# Aug 2021
ICS/OT
Malware Development
- NimDump - Stealthy LSASS Dumping Using Only NTAPIs in Nim May 2025
- NativeTokenImpersonate - Token Impersonation using only NTAPIs Apr 2025
- NativeNtdllRemap - Stealthy ntdll.dll Remapping Apr 2025
- TrickDump update - BOF File and C/C++ ports Oct 2024
- NativeDump update - BOF File and C/C++ ports Sep 2024
- NativeDump update - Python and Golang ports Jul 2024
- goNtdllOverwrite - API Unhooking in Golang Jul 2024
- pyNtdllOverwrite - API Unhooking in Python Jul 2024
- Dumping lsass using only NTAPIs by hand-crafting Minidump files Mar 2024
- C# implementation of GetModuleHandle for remote processes Mar 2024
- Porting pinvoke.net - A gitbook for P/Invoke definitions Mar 2024
- SharpObfuscate - Payload obfuscation in C# Feb 2024
- SharpProcessDump - Dump processes using C# Feb 2024
- SharpNtdllOverwrite - API Unhooking overwriting ntdll.dll Feb 2024
- Self-deleting a binary using C# and Alternate Data Streams Jan 2024
- Playing with process injection in Golang Dec 2023
- Get process handles from process name in Go Dec 2023
- Get process handles from process name in C# Nov 2023
- Calling C# code from Powershell Nov 2023
- Alternatives to whoami Nov 2023
- StealthyEnv - Get environment variables from PEB structure Nov 2023
- Guard Pages Hooking Sep 2023
- SharpEA - Playing with Extended Attributes (EAs) using C# Aug 2023
- SharpADS - Playing with Alternate Data Streams (ADS) using C# Aug 2023
- C# implementation of GetModuleHandle Jul 2023
- C# implementation of GetProcAddress Jul 2023
- jeringuilla - Process injection framework in C# Jul 2023
- Avoiding EDRs creating a new process Mar 2023
- Customizing Lsass Dumps with C++ Aug 2021
- Customizing Lsass Dumps with C# Aug 2021
Persistence
Privilege Escalation
ROP Emporium
- ROP Emporium Challenge 7 - Ret2csu (64 bits) Jun 2020
- ROP Emporium Challenge 6 - Pivot (32 bits) Jun 2020
- ROP Emporium Challenge 6 - Pivot (64 bits) Jun 2020
- ROP Emporium Challenge 5 - Fluff (32 bits) Jun 2020
- ROP Emporium Challenge 5 - Fluff (64 bits) Jun 2020
- ROP Emporium Challenge 4 - Badchars (64 bits) Jun 2020
- ROP Emporium Challenge 4 - Badchars (32 bits) Jun 2020
- ROP Emporium Challenge 3 - Write4 (32 bits) Jun 2020
- ROP Emporium Challenge 3 - Write4 (64 bits) Jun 2020
- ROP Emporium Challenge 2 - Callme (32 bits) Jun 2020
- ROP Emporium Challenge 2 - Callme (64 bits) Jun 2020
- ROP Emporium Challenge 1 - Split (32 bits) Jun 2020
- ROP Emporium Challenge 1 - Split (64 bits) Jun 2020
- ROP Emporium Challenge 0 - ret2win (32 bits) Jun 2020
- ROP Emporium Challenge 0 - ret2win (64 bits) Jun 2020
Red Team
- Automating the Pass-The-Ticket attack Feb 2026
- DoubleTeam - Python listener based on tmux and socat Jul 2025
- FakeRebootAlert - Deceive users to reboot a system upon login Nov 2024
- DNS Exfiltration Jan 2024
- SharpCovertTube - Using Youtube as covert channel Dec 2023
- covert-control - Control systems with OneDrive, Google Drive, Youtube or Telegram Nov 2021
- Using the HTTP protocol version for exfiltration Oct 2021
- covert-tube - Control systems with Youtube Oct 2021
- Exfiltrating files using MSSQL Sep 2021
- Always "Available" in Microsoft Teams Aug 2021
- WiFi Pentesting Guide Jan 2021
SLAE
- SLAE 7 - Custom crypter Jan 2019
- SLAE 6 - Polymorphic shellcodes Jan 2019
- SLAE 5 - Shellcode functionality Jan 2019
- SLAE 4 - Custom encoding schema Jan 2019
- SLAE 3 - Egg Hunter shellcode Jan 2019
- SLAE 2 - Shell_Reverse_TCP shellcode Jan 2019
- SLAE 1 - Shell_Bind_TCP shellcode Jan 2019
Tools
- BACnet-scan - Tool for BACnet/IP and BACnet/SC discovery May 2026
- DoubleTeam - Python listener based on tmux and socat Jul 2025
- Exploring Crystal language Dec 2024
- Github Star Counter Aug 2023
- Can i pwn you? May 2023
- covert-control - Control systems with OneDrive, Google Drive, Youtube or Telegram Nov 2021
- ADFSbrute - Test passwords against ADFS Mar 2021
- Ntds-Analyzer - Tool to analyze Ntds.dit files Feb 2021
- Playing with particles.js Jan 2021
- My first post Jan 2019
Web Exploitation
- Getting RCE in an AWS service (Amazon MWAA) Jul 2025
- RCE via malicious plugin in EMQX Dashboard Mar 2025
- Portswigger Labs Writeups May 2023
- Riello UPS Restricted Shell Bypass Apr 2023
- Authenticated RCE in Weblogic Servers Mar 2023
- Exploiting Old iDRACs in 2023 Mar 2023
- CVE-2021-40845 - AlphaWeb Authenticated RCE Sep 2021
- Finding CVE-2021-31159 for ServiceDesk Plus enumeration Aug 2021