🚧 Additional write-ups and methodology notes coming soon.
Core Skill Areas
Web & API Security
- SSRF, IDOR/BOLA, OAuth 2.0 exploitation, GraphQL injection
- Authentication bypass, JWT attacks, XXE, SSTI
- JS reverse engineering and API constant extraction
Active Directory
- BloodHound attack path analysis
- NTLM relay, ADCS ESC11 abuse
- LSASS dumping, Pass-the-Hash/Ticket
- Kerberoasting, AS-REP roasting
Methodology
- Recon: Subfinder, Amass, httpx, Shodan, gau, Katana
- Fuzzing: Feroxbuster, ffuf
- Analysis: Burp Suite Professional, truffleHog
- Classification: OWASP Top 10, OWASP API Top 10, CWE, CVSS