Archives
- 08 Jul Lab Secrets Manager and KMS Key Abuse: When One Shared Key Decrypts Everything
- 07 Jul AWS Audit Manager, Artifact, and Compliance — Evidence and Assurance
- 06 Jul Lab CloudTrail Tampering and GuardDuty Evasion: How Attackers Go Dark
- 05 Jul AWS Firewall Manager and Resource Access Manager — Centralized Policy Enforcement
- 04 Jul Lab — Lambda Attack Chain: From API Gateway Injection to AWS Account Pivot
- 03 Jul AWS Organizations and Control Tower — Multi-Account Governance
- 02 Jul Lab — Cross-Account Role Chaining: One Compromised Account to Full Org Access
- 01 Jul Amazon Cognito and Verified Permissions — App Identity and Fine-Grained Authorization
- 30 Jun Lab — S3 Misconfiguration Deep Dive: Public Buckets, Presigned URLs, Terraform State, and Snapshot Exposure
- 29 Jun IAM Access Analyzer, STS, and Authorization Controls
- 28 Jun Lab — Kubernetes Pod Escape and IRSA Abuse: From Container to AWS Account
- 27 Jun AWS IAM Identity Center — SSO, Permission Sets, and Federated Access
- 26 Jun Lab — CI/CD Pipeline Attack: GitHub Actions Secret Theft and OIDC Hardening
- 25 Jun AWS Systems Manager and Network Security Controls
- 24 Jun Lab — IAM Privilege Escalation: 8 Paths from Low-Privilege to Admin
- 23 Jun AWS Secrets Manager and ACM — Credential Rotation and TLS Certificates
- 22 Jun Lab — SSRF to IMDS: Steal AWS Credentials Through a Web App
- 21 Jun AWS KMS — Key Management, Envelope Encryption, and CloudHSM
- 20 Jun Lab — EC2 Attack Chain: Reverse Shell, IMDS Credential Theft, and GuardDuty Detection
- 19 Jun AWS WAF, Shield, and Amazon Inspector — Edge Protection and Vulnerability Scanning
- 17 Jun Cloud Incident Response and Amazon Detective — IR Playbooks and Investigation
- 15 Jun AWS Security Hub and Amazon Macie — CSPM and Data Classification
- 14 Jun Week 4 — Day 25: Putting It All Together — Security Posture Review
- 14 Jun DevSecOps Labs — Index & Ideas
- 13 Jun AWS CloudTrail and AWS Config — Audit Logging and Compliance
- 13 Jun Week 4 — Day 24: CIS Benchmarks & Compliance Basics
- 12 Jun Week 4 — Day 23: Threat Modeling with STRIDE
- 11 Jun Amazon GuardDuty — Threat Detection, Finding Types, and Automation
- 11 Jun Week 4 — Day 22: Cloud Incident Response
- 10 Jun Week 4 — Day 21: Zero Trust Architecture
- 09 Jun AWS CodePipeline and CodeBuild — CI/CD on AWS
- 08 Jun Lab — GuardDuty Sample Findings: What It Actually Detects (Zero Cost, Zero Risk)
- 07 Jun Week 3 — Day 19: Building a Full Secure CI/CD Pipeline
- 06 Jun AWS CloudFormation and CDK — Infrastructure as Code
- 06 Jun Week 3 — Day 18: DAST with OWASP ZAP
- 05 Jun MERN Web App Penetration Testing — Full Walkthrough
- 05 Jun Week 3 — Day 17: IaC Scanning with Checkov & tfsec
- 04 Jun AWS DynamoDB — NoSQL, Keys, Indexes, Streams, and DAX
- 04 Jun Week 3 — Day 16: SCA with Snyk & Dependabot
- 03 Jun Week 3 — Day 15: SAST with Semgrep
- 02 Jun TryHackMe — One Piece Room Writeup
- 02 Jun AWS RDS and Aurora — Managed Relational Databases, Multi-AZ, and Read Replicas
- 31 May AWS EBS and EFS — Block Storage, Shared Filesystems, and FSx
- 29 May AWS S3 — Object Storage, Storage Classes, Security, and Replication
- 27 May AWS ECS and EKS — Containers, Fargate, and Managed Kubernetes
- 24 May Homelab Part 9 — Cloudflare Tunnel for Secure External Access
- 24 May AWS Lambda — Serverless Functions, Triggers, and Execution Model
- 24 May Homelab Part 8 — Nextcloud Personal Cloud Storage
- 24 May Homelab Part 7 — Jellyfin Self-Hosted Media Server
- 24 May Homelab Part 6 — Persistent Storage with Longhorn
- 24 May Homelab Part 5 — MetalLB and Nginx Ingress
- 24 May Homelab Part 4 — K3s Single Node Kubernetes Setup
- 24 May Homelab Part 3 — Internal DNS with AdGuard Home
- 24 May Homelab Infrastructure Breakdown — How It All Comes Together
- 24 May Homelab Part 2 — VMware Setup and VM Planning
- 24 May Homelab Part 1 — What I'm Building and Why
- 24 May Linux Networking — Full Reference
- 22 May AWS EC2 — Instances, AMIs, Storage, Auto Scaling, and Pricing
- 21 May AWS VPC Architecture Patterns — Inbound, Outbound, and Inspection VPCs
- 20 May Network Protocols Deep-Dive
- 19 May AWS VPC — Virtual Private Cloud Full Walkthrough
- 19 May Cloud Security & DevSecOps — Daily Study Plan
- 17 May AWS Global Infrastructure — Regions, AZs, and Edge Locations
- 16 May AWS Load Balancers — ALB, NLB, Target Groups, and Listeners
- 13 May AWS CloudFront — CDN, Distributions, Cache Policies, and Security
- 11 May AWS Route 53 — DNS, Routing Policies, and Health Checks
- 09 May AWS CLI & IAM — Credentials, Roles, Policies, and Attack Paths
- 08 May YAML & GitHub Actions Walkthrough
- 08 May Terraform Full Walkthrough
- 08 May Kubernetes Full Walkthrough
- 08 May Docker Full Walkthrough
- 06 May Phase 5: Observability & Security Hardening — CloudWatch, Secrets Manager, and Structured Logging
- 06 May Phase 4: CI/CD Pipeline with GitHub Actions — Complete Walkthrough
- 30 Apr Phase 3: Provisioning a 3-Tier AWS Network with Terraform — Walkthrough
- 21 Apr Phase 2: Containerizing a 3-Tier MERN Stack With Docker Compose — Walkthrough
- 21 Apr Chapter 9 Administration Calls
- 14 Apr Phase 1: Building a Secure MERN Backend From a Firebase App —Walkthrough
- 14 Apr Chapter 8 Put on the Monitor's Cap
- 07 Apr Chapter 7 The Old-Boy Network
- 01 Apr Chapter 6 The Backup Plan
- 30 Mar Phase 0: Setting-Up-The-Infrastructure
- 30 Mar FYP Proposal - Research & Planning
- 25 Mar Windows Privilege Escalation & Rooting Windows Machines
- 25 Mar Chapter 5 Tangled Web Not At All
- 24 Mar Phase 0: MindCraft Overview
- 18 Mar Understanding & Fixing Exploits, Privilege Escalation (Part 2)
- 18 Mar Chapter 4 Texting and Driving
- 13 Mar Week 2 — Day 13: Runtime Security with Falco
- 12 Mar Week 2 — Day 12: Kubernetes RBAC & Pod Security
- 11 Mar Antivirus Evasion & Privilege Escalation (Part 1)
- 11 Mar Chapter 3 File In, File Out
- 11 Mar Week 2 — Day 11: Container Image Scanning with Trivy
- 10 Mar Week 2 — Day 10: Docker Security Hardening
- 09 Mar Week 2 — Day 9: HashiCorp Vault Basics
- 08 Mar Week 2 — Day 8: AWS Secrets Manager & Parameter Store
- 06 Mar Week 1 — Day 6: AWS WAF & Shield
- 05 Mar LookUp Challenge
- 05 Mar Nmap commands note
- 05 Mar Week 1 — Day 5: Amazon Inspector
- 04 Mar TShark: CLI Wireshark Features
- 04 Mar Locating & Fixing Exploits, Password Attacks
- 04 Mar Chapter 2 Have a Good Command
- 04 Mar Week 1 — Day 4: GuardDuty & Security Hub
- 04 Mar Root me
- 03 Mar Conversor
- 03 Mar Expressway
- 03 Mar Week 1 — Day 3: CloudTrail & AWS Config
- 02 Mar SharkChallengeI
- 02 Mar Week 1 — Day 2: SCPs & Permission Boundaries
- 02 Mar TShark: The Basics
- 01 Mar Week 1 — Day 1: AWS IAM Deep Dive
- 25 Feb Chapter 1 Shell Something Out
- 24 Feb Network Security Protocols
- 24 Feb Network Device Hardening
- 20 Feb Reconnaissance, Scanning & Web Application Attacks
- 18 Feb CMesS
- 15 Feb Linux System Hardening
- 14 Feb SQL Injection & Client-Side Attacks
- 14 Feb Linux CLI Notes
- 11 Feb Linux Fundamentals & Information Gathering
- 11 Feb WEEK1-Writeup