A practical offensive security resource built from real hands-on lab experience. Every technique documented here was executed in a real home lab.
| Section | Topics | Status |
|---|---|---|
| Windows Exploitation | Payload, Meterpreter, SYSTEM, Hashdump, Pass-the-Hash | ✅ |
| Active Directory | AS-REP Roasting, Kerberoasting, Mimikatz, Lateral Movement | ✅ |
| Web Application | SQLi, XSS, Command Injection, Filter Bypass | ✅ |
| Cheatsheets | Quick reference commands | 🔄 |
| Report Templates | Professional pentest report formats | 🔄 |
| Internship — Week 1 | Passive OSINT, subdomain enumeration, Google/GitHub dorking, visual recon | ✅ Done |
- Beginners building their first home lab
- Students preparing for CEH or eJPT
- Anyone learning offensive security hands-on
msfvenom · Metasploit · Nmap · Impacket · Hashcat · Mimikatz/Kiwi · NetExec · Burp Suite · Python3 HTTP Server · Hydra · Gobuster
- Attacker: Parrot OS on VMware
- Target 1: Windows 7 SP1 x64
- Target 2: Windows Server 2012 R2 (Domain Controller)
- Network: VMware Bridged
Built with real breaks, real errors, and real fixes. Not a tutorial copy. Every command was typed by hand.