Skills
Cybersecurity study notes, built from practice and review.
Skill map
Browse by discipline, then open a topic to see the notes behind it.
Offensive Security8
Red Team Operations8
- Web Security3
- AI Security9
- Mobile Security1
- Systems & Architecture1
- OT Securitynot yet
Study notes
- Red Team Engagementslearning
Core ideas for planning and executing an authorized red-team engagement.
A practical mental model for Windows PE files, processes, threads, memory, and payload execution.
- Cobalt Strike Primerlearning
A mental model for Cobalt Strike's architecture, listeners, Beacon payloads, staging, and operator interaction.
- AV and EDR Defence Evasionlearning
A practical mental model for understanding how AV and EDR observe payloads, memory, process injection, scripts, and post-exploitation behavior in an authorized lab.
- Initial Accesslearning
CRTO study notes on phishing taxonomies, payloads, triggers, containers, and initial-access delivery methods.
- Persistencelearning
CRTO study notes on Windows persistence through autostart locations, logon scripts, PowerShell profiles, scheduled tasks, and COM hijacking.
- Post-Exploitationlearning
A practical model for post-exploitation situational awareness, Beacon execution choices, session passing, collection, and PowerShell execution in an authorized CRTO lab.
- Privilege Escalationlearning
A practical model for assessing Windows privilege boundaries and identifying authorized-lab escalation paths through services, execution hijacking, software vulnerabilities, and UAC.