The isolation-first foundation for a red team lab — segment design and hypervisor choice, before a single vulnerable box exists.
Notes from the
offensive side.
Write-ups, cheatsheets, and a build-along home lab for red teamers. Everything here is tested in a lab before it's published — no recycled command dumps, no untried payloads.
Recently published.
The first-pass enumeration commands for a foothold on a Linux host — what to run, and what the output is telling you.
A blocklist has to be right about every address a URL might resolve to. An allowlist only has to be right about the ones you meant. Here's why that asymmetry decides the outcome.
Where to start.
Blog
Technique deep-dives and write-ups — how a bug works, not just that it exists.
- Exploitation chains, start to finish
- Tooling internals and detection trade-offs
- Lab-reproducible, with the setup included
Cheatsheets
Command references for enumeration, privilege escalation, and post-exploitation.
- Grouped by phase, not by tool
- Copy-ready, with the flags explained
- Revised as tooling changes
Home Lab
A staged build for a red team range you can break, rebuild, and instrument.
- Isolated network and hypervisor layout
- Vulnerable-by-design Active Directory
- C2 infrastructure and detection stack
Follow the work.
Open-source tooling, write-ups, and tutorials.