Hello, Open World
Search
Ctrl
+
K
Hello, Open World
Search
Ctrl
+
K
Published
Hello, Open World
1_RTO
1.1 Red Teaming 101
1.1.1 OW64
Recon
Scenario 1: External Recon — Scanning From Outside The Network
Scenario 2: Internal Recon — On The Network, No Credentials
Scenario 3: Authenticated Pivot — SSH / Chisel / Ligolo-ng SOCKS
4. C2_SOCKS
Scenario 6: Low-Footprint Alternatives — When Nmap Says "Filtered"
Scenario 7: Blue Team Detection Architecture
8. Jump_Server_Quickstart
Open-Source Intelligence — Corporate Finance Recon Reference
Windows AD Recon — GOAD-Light Lab
Windows Tradecraft
Active Directory
1. External Initial Access
2a. Credential Harvesting
2b. Gaining Access Without Credentials
3. Entering a Domain-Joined Machine
4. Enumerating a Domain-Joined Machine
5a. Privilege Escalation
5b. Establishing Persistence
6. Enumerating Forest and Trust Relationships
7. Pivoting to Other Machines on the Network
8. Owning a Domain Admin
10. LDAP
11. Powerview
Windows Authentication, Relay, and Lateral Movement
Shared Drive
Case Studies
CVE-2016-6563
CVE-2024-9473
EDR Evasion
1c. RC4-Based Self-Decrypting Payload (C++)
**3. AES-Based Self-Decrypting Payload (C++)**
1e. Advanced UPX Methods for Modifying Binary Structure
2. Direct syscalls intro
**1. EDR Detection & Bypass Techniques**
2a. Direct Syscalls cpp
2b. Indirect Syscalls intro
2c. Indirect Syscalls -Tool
3. API Hooking
Bypass EDR!!
Windows Attacks
Enumerate Windows
OW64 Windows Tradecraft — Detailed Notes
Red Teaming 101: Master Index
0.1 SecureHomelabs
0.2 Red Team Workspace Cheatsheet
1.1a Linux Deep Dive P1
1.1b Linux Deep Dive — Part 1b: Privilege Escalation
1.1c Linux Deep Dive — Part 2: Looting, Persistence, Cleanup & C2
1.3 — macOS Post-Exploitation
Pillar 1: Linux Red Teaming & Privilege Escalation
2.1 Windows Active Directory — Attack Vectors & Paths
2. Windows AD
3. Web
4.1 — Pivoting and Tunneling
Pillar 4: Networking, Pivoting & Tunneling
Pillar 5: Cloud Attack
6.1 EDR Evasion
6.2 Syscall-Based Evasion — Deep Dive
6. EDR
Pillar 7: C2 Operations
8. Reporting
1.1 Red Teaming 101 — Index
1.2 Web
1.2.1 Learn Web
Web Architecture 101
Web security control map
4. Web Application Server Security- Defending Against Attacks
5. Databases
6. Web Caching Security- Attacks & Mitigation Strategies
8b. OAuth
8c. SAML
9. Introduction to Data Pipeline Security
1. HTTP Headers
1. What is WebAssembly (WASM) on the Web?
1.2.2 Attack Web
Data Wrapper
Java Data Wrapper
Javascript Data Wrapper
Debugger and Logger
Frappe - Python
Debugger - .net - DNN
Debugger - Docker and NodeJS
Debugger - ERPNext Frappe
Debugger - Java - VSCODE
Debugger-Docker
Logger - MongoDB
Logger - Nginx
Logger - Oracle Database
Logger - SQLite
Deserialization - .net
Black Box Appraoch
Debug with dnspy - DNN
GraphQL
0. GraphQL Attack Flow
1. GraphQL
3. Introspection - Getting information
3.5 Connection Type
6. 'Something' doesn't exist on type 'Query'
JAVA
Java 101
Javascript
Session Riding CSRF
CSRF
javascript payload session riding - CSRF
Javascript, Nodejs, Express, Webpack
NodeJS - Handlebars
MYSQL
Collation - MySQL
MariaDB Query Logging
SQLI Flow
PHP
PHP_vuln.py
postgresSQL
0. PSQL Extensions attack - UDF
1.1 PSQL Large Object Shell -linux
Goal
Large Object Reverse shell Python code
poc.c Local execution arking.
psql payload
psql poc.c - reverseshell
Remote execution py
Prototype
Example
Main Prototype pollution
Regex
regex for sqli
Regex syntax
SSRF
SSRF Basic
SSTI
Server Side Template Injection
SSTI Payload
web_pentesting_checklist
3. Command Injection
Attack Web — validation index
Golang?
1. What is JWT?
WAF
WASM
Web Fingerprint — Passive-First Python Script
WebSocket
Web Security — Index
1.3 Clouds
1.3.1 Learn Cloud
0.1.1. General
0.1.1.1. Clouds
0.1.1.2. Clouds testing Scoping
0.1.1.3. Associate roles and services
0.1.2 Azure
0.1.2.1. Azure General
IAM
1 OpenID Connect
Security Token Service
1. AZ CLI Ref
AZURE CLI Tab Completion
Azure Powershell
Azure REST API with Azure CLI
Built-in Permissions
Microsoft Graph
Tenant, Subscription, Resource
0.1.2.2. Azure Services
Azure API Management
Azure App Services
Azure Automation
Azure Cosmo
Azure Function Apps
Azure Key Vaults
Azure Kubernetes
Azure Logic App
Azure Monitor
Azure Repos
Azure SQL
Azure Storage Account
Azure Virtual Machine
SDKs
Azure Services
0.1.3 AWS
0.1.3.1. AWS Resources
AWS Cloud Services
Resources
1.3.2 Attack Cloud
0.2.1. General
Cloud Security Validation — Scope Before Access
0.2.1.2. Search for Credentials - Services
0.2.1.3. Search for Credentials - File
0.2.2. AWS
flaws.cloud
AWS Practice 2 -flaws2.cloud
flaws
skills
skills
Tips
AWS Access Key to Web
AWS Signed API Request
AWS Signing and Authenticating REST requests
0.2.2.1. AWS - Search for Creds
AWS -Tools
0.2.3. Azure
PwnedLabs
1. Azure Blob Container to Initial Access
2. Unlock Access with Azure Key Vault
4. Loot Exchange, Teams and SharePoint with GraphRunner
8. Execute Azure Credential Shuffle to Achieve Objectives
skills
skills
Azure - Search for Creds!
Enumerate with credentials
Enumerate without Credentials - Inside of Virtual Machine
Tool - AADInternal
Tool - Azrecon.sh
Tool - AZSubEnum - Subdomain Enum
Collection of custom BloodHound queries
Tool - BloodHound
Tool - GraphRunner
Tool - Name mesh
Tool- RoadRecon
Tools - Password spray
0.2.4 GCP
1. GCP - Search Creds
Cloud Security — Index
1.4 Tunneling
Tunneling — Index
SSH Tunneling
1.5 Syntaxes
Syntax References — Index
Transfer files with SCP
SharpHound
SMB Download
xfreerdp
1.6 Kubernetes
Kubernetes — Index
Kubernetes Validation Catalog
Kubernetes
1.7 Wireless
Wireless and SDR — Index
Wireless
Docker
Docker — Index
1_RTO — Index
2_AI
2.1 Learn AI
01-foundations
AI Foundations — Index
AI, Machine Learning, Deep Learning, and Generative AI
Data, Training, Validation, and Inference
Neural-Network Basics
Transformers and Attention
Tokens, Embeddings, and Context
Generation, Decoding, and Hallucinations
Model Families and Multimodality
AI as a Glass Box — Observe the Complete Run
AI as a White Box — Trace a Tiny Language Model
02-using-ai
Using AI Effectively — Index
Frame the Job and Success Criteria
Prompt Anatomy
Context Engineering for Users
Verification, Citations, and Abstention
Model Selection, Cost, and Privacy
Repeatable User Workflows
03-harness-engineering
AI Harness Engineering — Index
What Is an AI Harness?
AI Harness Reference Architecture
Instruction and Context Assembly
Model Adapters and Routing
Tools and Structured Outputs
State, Memory, and Checkpoints
Permissions, Sandboxing, and Human Approval
Retries, Idempotency, and Recovery
Observability, Cost, and Run Records
Harness Contract and Lifecycle
04-agents-and-tools
90-existing-mcp-notes
MCP Discovery — Authorized Inventory
MCP Version History and Compatibility
MCP Security Engineering
91-existing-agentic-ai-note
Agentic AI
Agents and Tools — Index
Agents Versus Workflows
AI Workflow Patterns
Planning Loops and State Graphs
Tool Use and the Model Context Protocol
Multi-Agent Systems
Human-in-the-Loop Control
Skills and Capability Packages
05-knowledge-systems
AI Knowledge Systems — Index
RAG Reference Pipeline
Ingestion, Chunking, and Metadata
Retrieval, Hybrid Search, and Reranking
Grounding, Citations, and RAG Evaluation
Memory, RAG, CAG, and Fine-Tuning
Graph and Structured Retrieval
06-building-and-deployment
Building and Deploying AI — Index
API-Hosted Versus Local Models
AI Frameworks Without Lock-In
Fine-Tuning, PEFT, and Distillation
Inference, Quantization, and Serving
Multimodal Application Pipelines
AI Production Release Lifecycle
07-evaluation-and-operations
AI Evaluation and Operations — Index
Evaluation Layers and Metrics
Evaluation Datasets, Rubrics, and Edge Cases
Deterministic Checks, Model Judges, and Humans
Online Monitoring and Drift
Experiments, Versioning, and Regression Gates
AI Incidents and Change Management
08-security-privacy-governance
AI Security, Privacy, and Governance — Index
Threat-Model the Complete AI System
Prompt Injection and Untrusted Content
Data Privacy and Sensitive Information
Model, Data, and Software Supply Chain
Excessive Agency and Tool Risk
Govern, Map, Measure, and Manage AI Risk
09-automation
AI Automation — Index
Event-Driven AI Automation
Scheduled AI Research and Reporting
n8n AI Workflow Safety and Operations
10-labs
02-local-rag-cas-existing
rag_backend
0. Readme
1. Dockerfile
2. requirements.txt
3. main.py
4. doc_processor.py
5a. vectorizer.py
5b. ollama_embed.py
6. api.py
6a. config.py
6b. env
uploader.py - CLI TOOL
**🐳 Docker Compose Overview**
Practical AI Labs — Index
Lab 1 — Prompt and Verification
Lab 2 — Local RAG
Lab 3 — Read-Only Tool Agent
Lab 4 — Production Harness Capstone
11-reference
AI Reference — Index
AI Authoritative Source Ledger
Dumpster AI Research Map
AI Glossary
agentctl Research Audit — Learn AI Curriculum
Legacy AI Content Fact-Check Matrix
Core Curriculum Verification Register
Learn AI — Curriculum Index
2_AI — Index
3_Platform Internals
3.2 Windows OS
6.1 Learn Windows
1. Windows Basic
Windows Authentication System
LSASS - Local and Domain
Security Account Manager - Local
Windows Credential Manager
1. Portable Executable Structure
From PE file to process memory
3. Flow of System Calls - ntdll.dll, kernel32.dll
Win32 API and Windows Native API
5. Syscalls Flow
Windows system calls: deeper flow
5b. From Memory - PEB_TEB
1. Execution of EXE and DLL Files
7. Platform Invoke .net specific
Windows Service Control Manager
USB device discovery and driver loading
Windows Authentication Systems ( Pending)
Windows Management Instrumentation architecture
Windows Remote Management
Windows User Rights
WMIC
1a. Windows Defense Mechanism
1. EDR Intro
1. Let's understand EDR like a blue team
Windows defense mechanisms
Windows Code Integrity and App Control
Platform Internals — Index
4_Domain Playbooks
Drones
01-drone-landscape
02-radio-and-frequency-guide
03-safe-learning-path
LiteWing ESP32 Drone — From Box to First Flight
LiteWing First-Flight Runbook
LiteWing ML Autonomy — Phased Project Plan
RadioMaster Boxer ELRS — bench-only setup reference
RadioMaster Boxer — EdgeTX and internal ELRS firmware upgrade bench guide
11-wifi-fpv-drone-101-target-to-attack
_moc
sources-and-fact-check
linux
Linux Domain Playbook — Index
01-linux-internal-device-scan
02-linux-log-system
Mobility
01-methodology
Mobility Research Guideline — Initial Entry Vectors (Equipment & Site Focus)
02-theory
Mobility Security Assessment Threat Model
Mobility — The 5G Core, End to End
03-phases
02-ue-android-sim
04-open5gs_lab
00_index
01_4g_lte_fundamentals
02_5g_nsa_architecture
03_5g_sa_architecture
04_lab_4g_epc_docker
05_lab_5g_nsa_docker
06_lab_5g_sa_docker
07_kubernetes_deployment
08_threat_model_4g
09_threat_model_5g
10_threat_model_k8s_telecom
11_real_world_ss7_signaling
12_real_world_sim_identity
13_real_world_sms_malware
14_real_world_apt_mobile_ops
15_real_world_attack_matrix
16_android_cell_analysis
17_test_plan_4g_5g_holistic
18_test_plan_mobility_site_to_core
05-hardware
Mobile Security Research Lab — Equipment Guide
Pixel 9 — Mobile Security Research Setup
06-toolkit
MBX-02 & MBX-08 — App Interception Toolkit
07-test-plans
Master Blackbox UE-to-Node Test Plan
09-evidence
Telecom Fraud Evidence Matrix
Scattered Spider to Telecom Fraud Evidence Matrix
12-incidents
01-proxy-cleanup-2026-05-22
02-proxy-cleanup-script
13-apt-threat-intelligence
Mobility APT Threat Intelligence — Index
Documented APT and Telecom Intrusion Campaigns
Mobility Attack Surfaces and Inspection Files
Local Open5GS Lab APT Exposure Map
Mobility APT Defensive Validation Backlog
Mobility APT Research Source Ledger
Mobility Domain Playbook — Index
windows
Choosing a DLL for Read-only Inspection
Windows Playbook — Index
Windows 11 Security Engineering — Map of Content
Module 1 — Kernel and Privilege Rings
Module 2 — User Mode and Syscalls
Module 3 — DLLs, Loaders, and PE
Module 4 — Filesystem, Folders, and Artifacts
Module 5 — Processes, Threads, and Handles
Module 6 — Applications, Services, and Autoruns
Module 7 — Security Engineer Map
Lab Workbook — Windows 11 (192.168.50.114)
Windows Defender — Architecture and Rulesets (Deep Dive)
Lab Baseline — Windows 11 (192.168.50.114)
Module 9 — Evidence, Event Logs, and Artifacts
Module 10 — LSASS, Identity, and Authentication
Lab Tools Inventory — Windows 11 (.114)
Module 11 — Sysmon First Hunt Workbook
AD Domain Lab Setup — TESTER.LAB
Module 26 — c2_rust Win11 Implant Hunt Correlation
30-windows-internal-device-scan
Domain Playbooks — Index
5_Projects
Phase 1 — Mobility (M1–M6)
999. Stuff
Automation
Automate OSWE starting routine
Learn Programming
Learn C_C++
**🔹 Fixing "openssl-mingw-w64 not found" & Missing OpenSSL Headers in MinGW**
Learn Python
Threading
uv
Venv
Learn Rust
Rust Cross-Compilation Guide (Linux to Windows)
Publish Stuff
Digital Garden and github issue
Digital Garden Resources
Publish free
Use Gemini with Obsidian
9999. Projects with Kids
Make Water
Start a Fire
Published — Index
2c. Indirect Syscalls -Tool
#redteam
#ow64
#windows-tradecraft
#edr-evasion
2c. Indirect Syscalls -Tool
https://github.com/klezVirus/SysWhispers3
Enter your search text in the box above
Select a result to preview