Pentesting Fundamentals
📅 May 31, 2026
✏ khukuririmal
Content Delivery Networks (CDNs) have become a standard component of modern web applications. Whether it is a small startup application or a large enterprise platform, chances are that traffic is passing through…
Read writeup
Red Teaming
📅 May 29, 2026
✏ khukuririmal
Red Team engagements extend beyond identification of traditional exploitation paths such as authentication bypasses, injection flaws, exposed assets, or privilege escalation. Organizations increasingly depend on application resilience, API stability, and infrastructure availability…
Read writeup
Red Teaming
📅 May 24, 2026
✏ khukuririmal
Cloud storage has become a critical component of modern applications. Organizations frequently rely on cloud object storage services to host static assets, backups, application artifacts, logs, mobile application resources, and even sensitive…
Read writeup
VAPT
📅 April 3, 2026
✏ khukuririmal
Wireless networks often form the weakest link in an organization’s security posture. Unlike wired infrastructure, Wi-Fi signals extend beyond physical boundaries, making them inherently exposed to unauthorized access attempts. A misconfigured wireless…
Read writeup
Pentesting Fundamentals
📅 March 1, 2026
✏ khukuririmal
Getting a CVE ID (Common Vulnerabilities and Exposures) assigned to your name is a significant milestone in cybersecurity. It reflects meaningful contribution to the security ecosystem.However, let’s set expectations clearly:Finding a vulnerability…
Read writeup
Pentesting Fundamentals
📅 February 25, 2026
✏ khukuririmal
In modern enterprise environments, aggressive network scanning is no longer always practical or permitted. Mature organizations deploy IDS/IPS systems, EDR solutions, and strict change-control policies that quickly flag noisy reconnaissance or scanning…
Read writeup
Pentesting Fundamentals
📅 February 18, 2026
✏ khukuririmal
Mobile application security testing is no longer limited to just “Android vs iOS.” Modern applications span native, hybrid, WebView-based, and cross-platform architectures, each introducing unique attack surfaces, tooling requirements, and testing techniques.…
Read writeup
Red Teaming
📅 February 5, 2026
✏ khukuririmal
In modern security assessments, researchers and pentesters rarely start with direct exploits, they start with gathering information. One of the most underestimated reconnaissance tools is sitting in front of everyone which is…
Read writeup
Red Teaming
📅 January 19, 2026
✏ khukuririmal
In reconnaissance, what you fail to enumerate is often what hurts the most. Subdomain enumeration is one of the most critical phases of reconnaissance in any Red Team Assessment. Missed subdomains often…
Read writeup
Pentesting Fundamentals
📅 January 15, 2026
✏ khukuririmal
Thick client applications remain a high risk yet often under-tested attack surface in enterprise environments. Unlike thin clients (browser-based apps), thick clients run directly on end-user systems, communicate with backend services over…
Read writeup