Red team & pentest notes, labs, research and certification write-ups. Enjoy!
Recent posts
Container Escapes: host device mount
A privileged container mounts the host root disk read-write and owns the box.
Container Escapes: core_pattern
A privileged container writes core_pattern to run code as root on the host.
From Containers to Pods – Engineering Multi-Container Isolation
An architectural study of pod-based isolation, explaining shared network namespaces, inter-container communication, e...
Containers from Scratch: Linux Isolation Primitives in Action!
A deep dive into creating a secure sandbox using Namespaces, Cgroups, Capabilities, and Seccomp-BPF filters in Go and...
seniority != mastery
When Experience Outpaces Relevance
Container Security - Defense in Layers!
Isolation Layers: Namespaces, Capabilities, Cgroups, AppArmor & SELinux and Seccomp!
Hacking Kubernetes!
API Server, Kubelet API, ETCD Storage and More!
Attack AD CS Now!!
DPAPI, CBA Patch, Template Reconfiguration, Certificate Forgery and More!
3 - Lateral mov & Persistence (Azure)
Pass-the-PRT, Runbooks, cloud to on-prem, Golden SAML and More!
2 - Enumeration & Privilege Escalation (Azure)
Storage Accounts, Key Vaults, Blobs, RBAC, Dynamic Groups and more!
1 - Intro & Recon (Azure)
Introduction to Azure concepts, Discovery and Recon of services and Apps, Initial Access Attacks and More!
CARTP - Review
Honest Review CARTP - Azure Pentesting!
Get familiar with Azure Pentesting!
Going deeper with Azure!
Hacking Containers!
Container escape, Extract Info from Registry, Bypass Restrictions and more!
Intro to Cloud Pentesting!
Wanna learn Cloud Pentesting? Start here!