Skills

Cybersecurity study notes, built from practice and review.

Skill map

Browse by discipline, then open a topic to see the notes behind it.

Study notes

  • Red Team Engagements

    Core ideas for planning and executing an authorized red-team engagement.

  • Malware Essentials for Windows Payloads

    A practical mental model for Windows PE files, processes, threads, memory, and payload execution.

  • Cobalt Strike Primer

    A mental model for Cobalt Strike's architecture, listeners, Beacon payloads, staging, and operator interaction.

  • AV and EDR Defence Evasion

    A practical mental model for understanding how AV and EDR observe payloads, memory, process injection, scripts, and post-exploitation behavior in an authorized lab.

  • Initial Access

    CRTO study notes on phishing taxonomies, payloads, triggers, containers, and initial-access delivery methods.

  • Persistence

    CRTO study notes on Windows persistence through autostart locations, logon scripts, PowerShell profiles, scheduled tasks, and COM hijacking.

  • Post-Exploitation

    A practical model for post-exploitation situational awareness, Beacon execution choices, session passing, collection, and PowerShell execution in an authorized CRTO lab.

  • Privilege Escalation

    A practical model for assessing Windows privilege boundaries and identifying authorized-lab escalation paths through services, execution hijacking, software vulnerabilities, and UAC.

Ryan Sacatani

Simply curious about the world, constantly building and breaking things for fun.

sacataniryan1@gmail.com ↗

BrowseBrowse topics