cropped cropped cybersecwriteupslogo.png
  • VAPT
  • Red Teaming
  • Tools & Scripts
  • Active Directory Pentesting
  • Pentesting Fundamentals
  • Google Dorking
  • VAPT
  • Red Teaming
  • Tools & Scripts
  • Active Directory Pentesting
  • Pentesting Fundamentals
  • Google Dorking
Latest writeups
Red Teaming

Practical Guide to Subdomain Enumeration for Red Teaming

📅 January 19, 2026 ✏ khukuririmal

In reconnaissance, what you fail to enumerate is often what hurts the most. Subdomain enumeration is one of the most critical phases of reconnaissance in any Red Team Assessment. Missed subdomains often…

Read writeup
Pentesting Fundamentals

Practical Guide for Thick Client Penetration Testing

📅 January 15, 2026 ✏ khukuririmal

Thick client applications remain a high risk yet often under-tested attack surface in enterprise environments. Unlike thin clients (browser-based apps), thick clients run directly on end-user systems, communicate with backend services over…

Read writeup
Pentesting Fundamentals

Thick Client Security Testing: Concepts, Attack Surface, Methodology & Vulnerabilities

📅 January 14, 2026 ✏ khukuririmal

Thick client applications continue to play a critical role in enterprise environments, especially within banking, finance, ERP systems, trading platforms, HR systems, OT environments, and internal administrative tools. Despite this, thick client…

Read writeup
Pentesting Fundamentals

Creating a Bootable Kali Linux USB for Professional Pentesting

📅 January 10, 2026 ✏ khukuririmal

Kali Linux is the industry-standard operating system for penetration testing, red teaming, and security research. While Kali can be installed on a laptop or run inside a virtual machine, a bootable Kali…

Read writeup
Pentesting Fundamentals

Downloading Files in Windows via CLI – Native Techniques Every Pentester Should Know

📅 January 7, 2026 ✏ khukuririmal

In real-world penetration testing, red teaming, and internal security assessments, professionals frequently operate in environments where installing tools is restricted or outright blocked. Corporate endpoints, jump servers, and internal VDIs are often…

Read writeup
Pentesting Fundamentals

Building Portable Static Binaries for Pentesting, Red Teaming & Active Directory Assessments

📅 January 4, 2026 ✏ khukuririmal

In an ideal pentesting setup, installing tools is trivial cloning a GitHub repository, installing dependencies, resolving errors, and carry the activities. Security testers often, more increasingly now come across the below: In…

Read writeup
Active Directory Pentesting

The Power of Windows Native Command-Line Utilities in Active Directory Pentesting and Internal Red Teaming

📅 January 3, 2026 ✏ khukuririmal

Active Directory Pentesting has evolved significantly over the last few years. Gone are the days when attackers or red teamers could reliably depend on dropping Python tools, importing PowerShell scripts, or executing…

Read writeup
Pentesting Fundamentals

Nmap in Internal Networks: A Practical Port-Based Cheatsheet for VAPT & Red Teaming

📅 December 26, 2025 ✏ khukuririmal

Inside an enterprise network, the attack surface extends far beyond web servers and Active Directory. Switches, printers, scanners, remote administration tools, virtualization platforms, and legacy services often expose ports that are overlooked…

Read writeup
Pentesting Fundamentals

Directory & Endpoint Discovery Without Wordlists: Smarter Recon for Real-World VAPT

📅 December 21, 2025 ✏ khukuririmal

Applications always disclose more than intended through responses, logic, metadata, archives and integrations. Directory and endpoint discovery has traditionally been synonymous with brute-force wordlists. Tools like Dirsearch, FFUF, Gobuster, and Burp Intruder…

Read writeup
Tools & Scripts

Application VAPT in Hardened Systems – Without Installing Tools

📅 December 20, 2025 ✏ khukuririmal

A Practical Approach for Banking, Internal, and Regulated Environments In an ideal world, a security tester would always be provided with a fully privileged testing machine, complete with the freedom to install…

Read writeup
« Previous 1 2 3 Next »

YouTube

Subscribe on YouTube

Recent Posts

  • WAF Bypass Techniques in VAPT and Red Team Assessments – Part 1
  • Cloud Storage Misconfigurations: A Practical Guide to S3, Azure Blob, and GCP
  • CDN Security Assessment Checklist for Pentesters: A Practical Guide to Assessing CDN-Protected Applications
  • Load Testing and Controlled DoS Assessment During Red Team Assessments
  • Cloud Bucket Enumeration in VAPT & Red Teaming

Recent Comments

  • canada pharmaceuticals online on Top 20 Useful Burp Suite Extensions for Web Application Pentesting
  • Sandip Parane on JavaScript File Analysis in VAPT: An Overlooked Goldmine for High-Impact Findings
  • HariHacks on Redefining the Traditional Black Box Web Application VAPT Approach

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • About
  • Contact
  • Disclaimer
  • Privacy Policy
© 2026 Cyber Security Writeups · authorized testing only
  • About
  • Contact
  • Disclaimer
  • Privacy Policy