Algernon (OffSec PG) — Walkthrough: SmarterMail Build 6985 RCE to Instant Admin
OffSec Proving Grounds Algernon walkthrough — exploiting SmarterMail Build 6985 .NET deserialization RCE (CVE-2019-7214) on a Windows host for an i...
// offensive security · research · writeups
Offensive Security Consultant — penetration testing, red teaming, and adversary simulation, with a SOC and threat-detection background.
OffSec Proving Grounds Algernon walkthrough — exploiting SmarterMail Build 6985 .NET deserialization RCE (CVE-2019-7214) on a Windows host for an i...
OffSec Proving Grounds Hub walkthrough — retargeting the FuguHub 8.1 RCE exploit (EDB 51550) from its default HTTPS/443 config to port 8082, landin...
OffSec Proving Grounds Bratarina walkthrough — unauthenticated RCE through OpenSMTPD CVE-2020-7247 MAIL FROM command injection, landing instant roo...
Active Directory walkthrough of ShadowGate (Windows Server 2022) — anonymous SMB user enumeration, AS-REP roasting a pre-auth-disabled account, and...
Active Directory walkthrough of ShareThePain (Windows Server 2022) — coercing DC authentication from a writable SMB share, cracking the hash, abusi...
Full Active Directory walkthrough of BuildingMagic (Windows Server 2022) — chaining a web DB leak, Kerberoasting, ACL abuse, share poisoning, and P...
Attacking OWASP Top 10, auth flaws, and real-world web bugs.
Kerberos abuse, lateral movement, and domain dominance.
Adversary emulation, C2, and evasion tradecraft.
Recon workflows and high-impact vulnerability hunting.
Static & dynamic triage, unpacking, and IOCs.
Recon, attribution, and intelligence tradecraft.
↑↓ navigate · ↵ open · esc close