Published inInfoSec Write-ups·PinnedYou got Domain Admin, now what?Typically when you’re starting out on your red teaming journey, a goal on an Internal Penetration Test or maybe even the ultimate goal is to compromise the Windows Active Directory Domain. Getting to that goal is always fun and the “boss” feeling of doing it is unexplainable, particularly if it…Azure Ad Connect5 min readAzure Ad Connect5 min read
Nov 9Getting an executable from a C# Github RepositoryThis is a quick blog. I had this issue years ago but I realize people I know, whether it be coworkers, friends or even connections on LinkedIn do not know how to approach this problem and it is nothing to be ashamed of. …C Sharp Programming3 min readC Sharp Programming3 min read
Jun 30Burp Suite Certified Practitioner ReviewAfter two years of on-and-off preparation for this exam, I finally did it! Let’s get into it, shall we? “The Burp Suite Certified Practitioner (BSCP) is an official certification for web security professionals, from the makers of Burp Suite. …Burpsuitecertified7 min readBurpsuitecertified7 min read
May 8CRTP Exam ReviewYup! It has been quite the wait for another post from yours truly. But you know, life happens. I appreciate the few of you reaching out on when the next blog post would have been. I’ll try to be more consistent, no promises though. Now with that said let’s get…Crtp7 min readCrtp7 min read
Published inInfoSec Write-ups·Mar 10Fixing your AWS Cloud with ProwlerWe’ve been touching on Azure here and there through this blog, but it’s time for a change of pace. While I must admit that I’m a staunch supporter of #teamAzure, let’s give AWS a chance to shine. …Prowler4 min readProwler4 min read
Published inInfoSec Write-ups·Feb 10Securing Azure: Hunting with AzureHoundWe are back again! So I have been doing a lot of research lately and been playing around with a lot of stuff, this one interested me so you all know what’s next: This is gonna be a short one, let’s get right into it! This is intended for my…Azurehound5 min readAzurehound5 min read
Published inInfoSec Write-ups·Feb 1Unlocking the Secrets of LSAWe are back again as I promised! We will be following up on my last blog post. Let’s get right to it. So let’s talk LSA, more specifically LSA Secrets to AD Domain Admin and even Global Admin in Azure. Before we can go right into it let’s attempt to…Azure5 min readAzure5 min read
Nov 23, 2022PNPT: Practical Network Penetration Tester ReviewHaven’t blogged in a minute but what better way to start back than to review the best certification I have done thus far in my cyber security journey? Let’s get into it. Background So, this was a debate with myself for a while on whether to do eCPPTv2 or PNPT. I…Pnpt6 min readPnpt6 min read
Published inFAUN — Developer Community 🐾·Feb 18, 2022Disk Surgery in AzureTypically in your DevOps Cloud Environments things can break…badly. It may be one of the hardest things to diagnose. Whether you are running a GitHub Codespace backed by a high-performing Virtual Machine or simply an everyday VM for virtualization, everyone can be a victim of an environment breaking for whatever…Azure7 min readAzure7 min read
Feb 9, 2022The eWPT Review🔍So the goal I had for 2022 was to focus more on certifications that are more hands-on and can challenge my skillset. Why? Theoretical certifications do have their use but the more hands-on the cert, then the more relevant it is to my Security Engineer Role. It offers more value…Ewpt4 min readEwpt4 min read