Blog
Notes on offensive security — technique write-ups, certification reviews, and the occasional opinion. RSS.
-
The RETurn of AMSI – Easy DLL Patching without C3
TL;DR For people that just want the slides and github link AMSI and ETW detections If you’ve been tapped into Defender (Home and / or Endpoint Product) since the end of Summer 2024, you’ve n
-
Unveiling Vulnerabilities: The Power of Penetration Testing
Human prompt: “write an article for my penetration testing website” Human paragraph: I need content for my website, not just for you, but for me. See, I won’t get good Search Engine Optimiza
-
Fallacy of the OWASP Top 10
The OWASP Top Ten is a widely recognized document that highlights the most critical security risks in web applications. It serves as a guide for developers, security professionals, and organ
-
DNS Sinkholing for ‘security’
The Power of DNS Sinkhole Devices: Exploring the Benefits of PiHole In today’s digital landscape, online security is a top concern for individuals and organizations alike. As cyber threats c
-
Evading EDR by DLL Sideloading in C#
The blog post accompanies my public conference talks on this topic. Slides are available at the bottom. One thing I learned from doing this talk is that a surprisingly high number of InfoSec
-
OSEP Review – The Experienced Penetration Tester
What I’ll Cover What The Course Is How OSEP compares to OSCP Similarities and differences The Course Review Who I am, and who this is aimed for My study plan and time involved PDF videos, ex
-
Spiceworld Virtual 2020 Practical Hacking
Spiceworks Annual IT Conference ” https://www.spiceworks.com/spiceworld/ “ For the past few years, I’ve been going to SpiceWorld and took the opportunity this year to present. My session was
-
Red Team – Windows Kits – CDB.exe
Blog Preface – “Windows Kits” While running through some MITRE techniques, I happened upon the ADK tools and SDK tools and found a great collection of programs used for development, debuggin
-
Red Team – Windows Kits – ADPlus.exe
Blog Preface – “Windows Kits” While running through some MITRE techniques, I happened upon the ADK tools and SDK tools and found a great collection of programs used for development, debuggin
-
OSCP Review
This is a review of my OSCP experience. I registered in late 2018 and received my OSCP in May of 2019 with one exam attempt. This review is coming out in 2020. The Offensive Security Certifi
-
OSWP Review
This is my review of the OSWP course material. I passed this certification in late 2019. The Offensive Security Wireless Professional is a certification course and exam that tests your knowl