Writeups
Reports and walkthroughs from labs and projects. Each one shows the method, the evidence, and what I would fix.
- 2023-07-24Social Engineering
Phishing lab: credential harvesting with the Social-Engineer Toolkit
A lab walkthrough of how a credential-harvesting phishing page is built with SET in an isolated environment, to understand what defenders and users are up against.
- 2023-07-17Threat Intelligence
Threat assessment: APT29 and APT41
A threat intelligence report profiling two state-linked actors: attribution, campaigns from the DNC intrusion to SolarWinds, TTPs mapped to MITRE ATT&CK, and defensive recommendations.
- 2023-07-13Vulnerability Management
Network vulnerability assessment with Nessus
A full vulnerability assessment report for a lab organization: scope, CVSS scoring methodology, critical through medium findings, and a prioritized remediation plan.
- 2023-07-08CTF
Capture the Flag: Linux, web, hidden flags, hash cracking and Nmap
A seven-part TryHackMe CTF worked end to end: Linux user management, file system and web flags, steganography-style hidden flags, hash cracking, and an Nmap scan report with remediation.