Knowledge Base
Research & Write-ups
CVE analysis, exploitation tradecraft, and field notes from real engagements.
Exploiting Polkit (CVE-2021-3560): Race Condition to Root
Turning a subtle authentication race in Polkit into reliable local privilege escalation across major Linux distros.
HTTP Request Smuggling: Advanced Desync Techniques
Chaining CL.TE and TE.CL desyncs to bypass front-end controls and reach account takeover.
Bypassing EDR with Direct Syscalls in 2024
Why userland hooking still fails, and how operators sidestep it without tripping modern telemetry.
Reverse Engineering a Modern C2 Framework
Dissecting a real command-and-control framework recovered during a red team engagement.
Unauthenticated Active Directory Recon at Scale
Mapping a domain from zero credentials — DNS, LDAP null binds, SMB sessions, and Kerberos user enum.
Pivoting Through Misconfigured IAM Roles
From a single leaked key to full account takeover via chained role assumption in AWS.